Skip to content
Tasarruf— Tasarruf home

Privacy policy

Last updated: September 29, 2026

This page explains which data is processed when you use Tasarruf, why, and how you stay in control. The information notice under the Turkish data protection law (KVKK) is a separate page.

Read the KVKK information notice

In short

  • Anonymous account: no name, e-mail or phone number needed.
  • No ads, no data sales, no tracking SDKs.
  • Receipt images are encrypted with a key of your own account; you can delete a photo separately from its receipt.
  • OpenAI is used to read receipts, and your consent is asked for that separately.
  • Export is always free; access to your own records is never locked.

Data controller

The Tasarruf app and this site are run by Sayfa. Sayfa is the controller of your personal data. For any question or request, write to [email protected].

What we process

  • Receipt and invoice images and the PDFs you share.
  • Lines extracted from the receipt: product name, quantity, unit, unit price, line amount, discount and VAT rate.
  • Amounts: subtotal, VAT, total, payment type and, if present, only the last 4 digits of the card.
  • Seller details: store name, branch, the seller's tax number, receipt number, Z number and e-Arşiv ETTN.
  • The date and time of the purchase.
  • Your corrections, product matches and category choices.
  • The text your phone read from the receipt on the device (sent to the server to help with reading).
  • Your anonymous account id, session data and, if you add one, the public key of your passkey.

Even when printed on the receipt, the buyer's name, address, phone number, e-mail, Turkish ID number, loyalty card number and full card number are not stored; they are filtered out during reading. We do not collect your location, contacts, advertising id or other photos on your device.

Purposes

  • Reading, checking and saving receipts.
  • Matching the same product across receipts; calculating price history, unit prices, monthly spending and your personal basket index.
  • Protecting your account and data, and preventing abuse and automated attacks.
  • Understanding how the app is used through anonymous aggregate counts.
  • Answering your requests and meeting our legal obligations.

Reading receipts with AI

To read the lines, the receipt image and the text read on the device are sent to OpenAI's API only from our server, never from the app. The app contains no AI provider keys. The request does not include your name, account id or device details.

Under OpenAI's API terms, data sent through the API is not used to train models by default. The model's answer is never saved as is; it is checked against the totals and the amounts on the receipt.

Service providers and where data is kept

We share your data only with providers that help us run the service and act on our instructions:

  • Hetzner Online

    What for
    Servers and database
    Where
    European Union (Germany, Finland)
  • Cloudflare

    What for
    Domain, secure connections and encrypted receipt image storage (R2)
    Where
    Image storage in the EU region; network service global
  • OpenAI

    What for
    Reading the lines from receipt images
    Where
    United States

Some of these providers are outside Türkiye, so this sharing is a cross-border transfer and is made under the safeguards of KVKK art. 9 and Chapter V of the GDPR. We share your data with no one else, and we never sell it.

Ads, sales and tracking

  • Tasarruf shows no ads and works with no ad networks.
  • It never sells or rents your personal data.
  • The app has no third-party tracking or analytics SDKs; this site uses no cookies and no analytics tools.
  • The app sends only anonymous counts made of an event name and coarse ranges (for example “a receipt was saved, 2nd receipt”). These counts contain no identity, IP address, amounts, products, stores, text or images, and no identifier is stored on the device for them.

Security

  • All traffic between the app and the server is encrypted (TLS).
  • Receipt images are re-encoded, which removes location and device data (EXIF). They are stored encrypted with a key of your own account (AES-GCM) and shown to you only after ownership is checked.
  • Access tokens are short-lived; only a hash of refresh tokens is stored.
  • Server logs contain no receipt text, images or links to them.

How long we keep data

  • Your data is kept while your account exists. You can delete a receipt's photo without deleting the receipt.
  • When you delete your account, the key that opens your images is deleted first; all your data is fully deleted within 30 days.
  • Backups are kept for at most 30 days and then expire.
  • Anonymous accounts unused for 24 months are deleted after a notice in the app.
  • Anonymous aggregate counts contain no personal data and may be kept independently of these periods.

Your rights

Under KVKK art. 11 you have the right to learn whether your personal data is processed, to request information if it is, to learn the purpose of processing and whether it is used accordingly, to know the third parties in Türkiye or abroad it is transferred to, to request correction if it is incomplete or wrong, to request its deletion or destruction, to request that these actions be notified to the third parties it was transferred to, to object to a result against you arising solely from automated analysis, and to claim compensation for damage caused by unlawful processing.

If the GDPR applies to you, you also have the rights of access, rectification, erasure, restriction, data portability, objection, withdrawal of consent and to lodge a complaint with the supervisory authority in your country.

You can use many of them directly in the app: export your data as JSON for free, correct or delete any record and delete your account. For other requests write to [email protected]; we answer free of charge within 30 days at the latest.

Changes

If we change this policy, the current version is published on this page. We announce important changes in the app as well.