Privacy Policy

Last updated: 28 May 2026

1. Who we are

Chekkly is operated by Stepan Dobrianskyi as a sole trader ("we", "us", "our"). If you have any questions about this policy or wish to exercise your data rights, contact us at stepan.dobrianskyi.dev@gmail.com.

2. What data we collect

We collect only what is necessary to run the service:

  • Account information — your email address and display name, provided when you sign up.
  • Workspace content — receipt metadata you enter or scan (date, store name, total amount, currency), individual product names and prices, and the last 4 digits of a payment card used to identify who paid ("My Cards" feature).

Receipt text recognition uses two complementary technologies. Google ML Kit runs locally on your device for fast, on-device OCR. For improved accuracy, cropped receipt images may also be sent to Google AI Studio for processing — no image is stored by Google beyond the duration of a single API request.

3. How we use your data

We use your data solely to provide the Chekkly service:

  • Creating and managing your account and workspaces.
  • Calculating shared expenses and debt balances among workspace members.
  • Sending you email verification and authentication messages.

We do not use your data for advertising, profiling, or selling to third parties.

4. Lawful basis (GDPR)

We process your personal data on the basis of contract performance (Article 6(1)(b) GDPR) — processing is necessary to deliver the service you signed up for.

5. Where data is stored

Your account and workspace data is stored on Supabase, a cloud database provider hosted on AWS infrastructure. Data may be stored in the EU or other regions depending on project configuration. Supabase is a GDPR-compliant sub-processor.

Receipt text recognition uses Google ML Kit (on-device) and Google AI Studio (cloud). Cropped receipt images sent to Google AI Studio are processed transiently and not retained beyond the API request.

6. Third-party processors

Processor Purpose
Supabase Database and authentication hosting
Apple Inc. App Store distribution and in-app purchases
Google LLC Play Store distribution, on-device ML Kit text recognition, and Google AI Studio cloud OCR
RevenueCat Subscription and purchase management (will be used when in-app subscriptions launch)

Each processor is bound by a data processing agreement and is required to handle data in accordance with applicable privacy law.

7. Data retention

We retain your data for as long as your account is active. When you delete your account (via Settings → Delete account in the app), all personal data — including your email, display name, workspace content, and receipt data — is permanently and irreversibly deleted. No backups of deleted accounts are retained.

8. Your rights under GDPR

If you are located in the European Economic Area, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — delete your account and all associated data directly from the app (Settings → Delete account).
  • Portability — receive your data in a machine-readable format (CSV/PDF export — available when this feature launches).
  • Restriction — ask us to restrict processing in certain circumstances.
  • Objection — object to processing where we rely on legitimate interests.
  • Lodge a complaint — you have the right to lodge a complaint with your local data protection supervisory authority.

To exercise any right other than erasure, email us at stepan.dobrianskyi.dev@gmail.com. We will respond within 30 days.

9. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify you via email or an in-app notice at least 14 days before the change takes effect. Continued use of the app after that date constitutes acceptance of the revised policy.

10. Contact

For any privacy-related question or request:
stepan.dobrianskyi.dev@gmail.com