Privacy policy
Last updated: September 29, 2026
This page explains which data is processed when you use Tasarruf, why, and how you stay in control. The information notice under the Turkish data protection law (KVKK) is a separate page.
Read the KVKK information notice
In short
- Anonymous account: no name, e-mail or phone number needed.
- No ads, no data sales, no tracking SDKs.
- Receipt images are encrypted with a key of your own account; you can delete a photo separately from its receipt.
- OpenAI is used to read receipts, and your consent is asked for that separately.
- Export is always free; access to your own records is never locked.
Data controller
The Tasarruf app and this site are run by Sayfa. Sayfa is the controller of your personal data. For any question or request, write to [email protected].
What we process
- Receipt and invoice images and the PDFs you share.
- Lines extracted from the receipt: product name, quantity, unit, unit price, line amount, discount and VAT rate.
- Amounts: subtotal, VAT, total, payment type and, if present, only the last 4 digits of the card.
- Seller details: store name, branch, the seller's tax number, receipt number, Z number and e-Arşiv ETTN.
- The date and time of the purchase.
- Your corrections, product matches and category choices.
- The text your phone read from the receipt on the device (sent to the server to help with reading).
- Your anonymous account id, session data and, if you add one, the public key of your passkey.
Even when printed on the receipt, the buyer's name, address, phone number, e-mail, Turkish ID number, loyalty card number and full card number are not stored; they are filtered out during reading. We do not collect your location, contacts, advertising id or other photos on your device.
Purposes
- Reading, checking and saving receipts.
- Matching the same product across receipts; calculating price history, unit prices, monthly spending and your personal basket index.
- Protecting your account and data, and preventing abuse and automated attacks.
- Understanding how the app is used through anonymous aggregate counts.
- Answering your requests and meeting our legal obligations.
Legal bases
- Entering into and performing a contract: Tasarruf's core service of reading and storing your receipts and showing you price and spending information (KVKK art. 5(2)(c); GDPR art. 6(1)(b)). The core service never depends on explicit consent.
- Separate explicit consent for sending receipt images to the AI provider: asked in its own step, naming the provider, before your first scan.
- Separate explicit consent for purchases that may reveal health information (for example pharmacy receipts): asked in its own step (KVKK art. 6; GDPR art. 9(2)(a)). Tasarruf never builds health, religion or similar sensitive categories or inferences from such purchases.
- Legitimate interest: account security and abuse prevention (KVKK art. 5(2)(f); GDPR art. 6(1)(f)).
- Legal obligation: lawful requests from competent authorities (KVKK art. 5(2)(ç); GDPR art. 6(1)(c)).
You can withdraw your consents at any time in the app's Settings. Withdrawing does not affect processing done before, and it does not limit access to your existing records.
Reading receipts with AI
To read the lines, the receipt image and the text read on the device are sent to OpenAI's API only from our server, never from the app. The app contains no AI provider keys. The request does not include your name, account id or device details.
Under OpenAI's API terms, data sent through the API is not used to train models by default. The model's answer is never saved as is; it is checked against the totals and the amounts on the receipt.
Service providers and where data is kept
We share your data only with providers that help us run the service and act on our instructions:
Hetzner Online
- What for
- Servers and database
- Where
- European Union (Germany, Finland)
Cloudflare
- What for
- Domain, secure connections and encrypted receipt image storage (R2)
- Where
- Image storage in the EU region; network service global
OpenAI
- What for
- Reading the lines from receipt images
- Where
- United States
Some of these providers are outside Türkiye, so this sharing is a cross-border transfer and is made under the safeguards of KVKK art. 9 and Chapter V of the GDPR. We share your data with no one else, and we never sell it.
Ads, sales and tracking
- Tasarruf shows no ads and works with no ad networks.
- It never sells or rents your personal data.
- The app has no third-party tracking or analytics SDKs; this site uses no cookies and no analytics tools.
- The app sends only anonymous counts made of an event name and coarse ranges (for example “a receipt was saved, 2nd receipt”). These counts contain no identity, IP address, amounts, products, stores, text or images, and no identifier is stored on the device for them.
Security
- All traffic between the app and the server is encrypted (TLS).
- Receipt images are re-encoded, which removes location and device data (EXIF). They are stored encrypted with a key of your own account (AES-GCM) and shown to you only after ownership is checked.
- Access tokens are short-lived; only a hash of refresh tokens is stored.
- Server logs contain no receipt text, images or links to them.
How long we keep data
- Your data is kept while your account exists. You can delete a receipt's photo without deleting the receipt.
- When you delete your account, the key that opens your images is deleted first; all your data is fully deleted within 30 days.
- Backups are kept for at most 30 days and then expire.
- Anonymous accounts unused for 24 months are deleted after a notice in the app.
- Anonymous aggregate counts contain no personal data and may be kept independently of these periods.
Your rights
Under KVKK art. 11 you have the right to learn whether your personal data is processed, to request information if it is, to learn the purpose of processing and whether it is used accordingly, to know the third parties in Türkiye or abroad it is transferred to, to request correction if it is incomplete or wrong, to request its deletion or destruction, to request that these actions be notified to the third parties it was transferred to, to object to a result against you arising solely from automated analysis, and to claim compensation for damage caused by unlawful processing.
If the GDPR applies to you, you also have the rights of access, rectification, erasure, restriction, data portability, objection, withdrawal of consent and to lodge a complaint with the supervisory authority in your country.
You can use many of them directly in the app: export your data as JSON for free, correct or delete any record and delete your account. For other requests write to [email protected]; we answer free of charge within 30 days at the latest.
Changes
If we change this policy, the current version is published on this page. We announce important changes in the app as well.