Privacy policy
How Kvito handles your data. An overview of which information we use, why we use it, and which rights you have.
In short
- Kvito is CASA AL1 approved. Read more underSecurity and in section 12.
- You decide whether to connect Gmail, enable autoscan (Premium), share receipts, use the referral programme or use Amanda.
- We only process information necessary to deliver, secure and improve Kvito.
- You must be at least 16 years old to create an account.
- Paid subscription purchases are handled by the Apple App Store or Google Play. We do not receive your card details.
- We do not sell your personal data to advertisers or data brokers.
- You can request a PDF data export, clear Amanda and mail history and delete your profile in the app, or write to kontakt@kvito.dk.
1. Who are we?
Kvito (Danish business reg. no. CVR 44353687) is an app for storing, importing and understanding receipts, as well as helping with price match and Amanda. Kvito is the data controller for the personal data processed through the app and related services, including kvito.dk.
You can contact us at kontakt@kvito.dk. We have not appointed a data protection officer.
2. Legal bases for processing
We process personal data on the following legal bases under GDPR Article 6:
- Performance of a contract (art. 6(1)(b)): account, profile, receipts, sharing, referral programme, data exports, Amanda and the technical operation of features you choose to use.
- Consent (art. 6(1)(a)): connecting Gmail, optional features and processing where you actively grant permission. Consent can be withdrawn, for example by disconnecting Gmail.
- Legitimate interest (art. 6(1)(f)): security, abuse prevention, troubleshooting, limited technical logs and improving stability, unless your interests override ours.
- Legal obligation (art. 6(1)(c)): when we must store or disclose information under applicable law.
Paid subscription purchases (Starter, Standard or Premium) are handled primarily by the Apple App Store or Google Play as payment processors. Kvito receives information about your active subscription and plan in order to deliver the associated features.
3. Which information do we process?
We may process the following categories of information when you use the app:
- Account information: login email, display name, Supabase user ID and information about logins and sessions.
- Profile and settings: profile picture, connected email, Gmail link status, automatic scan settings, notification level (none / important / all), preferences and saved price match details such as store emails and account details when you enter them yourself.
- Subscription status: whether you use the free plan or a paid plan (Starter, Standard, Premium), any bonus access from the referral programme, which subscription product is linked to the purchase, and local quota and plan details on the device.
- Receipt data: store, date, amount, line items, payment method, reference numbers, notes, deadlines for returns, price match and warranty claims / guarantees, as well as any original PDF files. The number of stored receipts may be limited by your plan.
- Price match and market scan: found price match opportunities, scan status, saved price match preferences and store recipients for claims.
- Store policy and product information: cached store terms (returns, price match, warranty, insurance, subscription), found sources and URLs, product warranty links and discovery runs linked to receipts.
- Sharing data: if you send or receive receipts, including the recipient’s email, invitation status, share links (for example share.kvito.dk), receipt summary and any messages you write yourself.
- Referral data: your personal referral code, who has redeemed the code, time of redemption, status of paying referred users and information about earned rewards.
- Push and device data on mobile: FCM device token, platform and whether push is enabled for your account.
- Gmail data: if you enable the integration, including your Gmail address, message IDs, history markers, relevant labels and folder information, the email content or attachments necessary to find and extract receipts, and, if you have Premium and have enabled autoscan, an encrypted refresh token and technical status information about server side scan runs.
- Amanda data: your questions, answers, conversation history, titles and previews, and any receipt references if you ask about specific purchases.
- Bug reports and feedback: if you actively send a bug report or feedback via the app, including your message, optional name and contact email, technical event data and any screenshots sent to Sentry.
- Contact via kvito.dk: name, email and message from the contact form, a ticket number and technical data for abuse protection.
- Technical and security data: device and browser, timestamps, error logs and network metadata recorded by our providers for operations and security.
4. What do we use your information for?
Your information is used to:
- Create, maintain and secure your account, including profile updates and login email changes via a confirmation flow.
- Activate, verify and display subscription access according to your plan (free, Starter, Standard or Premium) when you buy, restore or use a subscription.
- Store, synchronise and display your receipts and associated documents.
- Import receipts from images, PDF files (on supported devices) and emails, and attempt to extract structured data from them.
- Show an overview of returns, price match and warranty claims / guarantees, including automatically finding store policy and product warranty from public sources.
- Scan the market for price match opportunities and display found opportunities in the app.
- Send push notifications about return and guarantee deadlines for all users, and about price match opportunities for users with Standard or Premium, as well as other notifications according to your setting and plan.
- Operate Amanda and store conversation history for a limited period, with quotas depending on your plan.
- Handle invitations and sharing of receipts with other users when you choose to, including share links.
- Administer the referral programme, including counting paying referred users and granting temporary bonus access according to the programme rules.
- Enforce the receipt archive’s plan limits and automatic clean up on downgrade when necessary.
- Create price match drafts, send price match claims on behalf of users with Standard or Premium, send receipts at your request and remember the details you choose to save for these features.
- Prepare and send a PDF data export to your account email when you request it.
- Monitor errors, process your bug reports and feedback and improve the stability and security of the service.
Price match in the app (viewing opportunities, push for finds and sending claims) is only available to users with Standard or Premium. Users on Free or Starter cannot view price match opportunities, receive push or send claims.
5. Google and Gmail integration
If you connect your Gmail account, we ask Google for permissions to read your mailbox and, when you use relevant features, create drafts or send emails on your behalf.
- Manual mail scanning can search broadly in your connected Gmail, including archived emails and relevant folders, but not spam or trash. The number of manual scans depends on your plan (weekly on Free, Starter and Standard; daily on Premium).
- Automatic Gmail scanning is only available with Premium and requires Gmail to be connected and the feature to be enabled. The import runs securely on Kvito’s server at scheduled times, even when the app is closed. If you no longer have Premium, autoscan is automatically disabled. For autoscan we may store an encrypted Gmail refresh token and technical status information about scan runs on the server.
- We do not store your full mailbox as a separate database. We only process the content necessary to identify receipts, and then store the extracted receipt data, necessary technical cache information and any PDF receipts you import.
You can disconnect Gmail or turn off autoscan at any time on the Account page. This stops future access, clears local Gmail tokens and links on your device, and stops future server side autoscan runs.
6. Google user data and Limited Use
Kvito’s use and transfer of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements.
- We use Gmail data only for user facing features in the app that are clear to you: importing receipts from email, autoscan when you have enabled it (Premium), creating drafts and sending emails when you request it.
- We do not sell Google user data. We do not use Google user data for advertising, retargeting, data brokerage or credit worthiness.
- We do not allow human access to your mailbox unless you ask for support and consent to us viewing specific messages, it is necessary for security (for example abuse or troubleshooting), or the law requires it.
- We may transfer relevant excerpts to processors necessary for the feature (for example Supabase for secure operation and encrypted token storage, OpenAI to extract receipt data from email excerpts), only to deliver the features you asked for.
For the security approval (CASA AL1), see section 12 and oursecurity page.
7. AI, automated processing and transparency
We use automated models via our AI server functions to, among other things:
- extract data from receipt images, emails and PDF pages,
- answer questions in Amanda,
- help structure or verify certain store and product information,
- find and summarise store policy from public sources,
- discover product specific warranty or complaint years,
- assess price match rules and market scan results.
This means that relevant text excerpts, images, PDF content, receipt fields, store names, product names and Amanda messages may be sent to our AI processors via Supabase Edge Functions.
Kvito may automatically search a store’s public website and other public sources to find return, price match, warranty, insurance and subscription terms linked to your receipts. We may store store name, found URLs, summarised policy text, deadlines and technical discovery status in a cache so you do not have to look it up every time.
Kvito may scan the market for lower prices on items from your receipts via server functions. This may include product names, prices, store name and search queries sent to external price search services (for example SearchAPI or SerpAPI). Found opportunities and scan status are stored on the receipt and in price match data linked to your account.
AI generated content can be inaccurate and is not legal advice. Kvito does not make decisions with legal effects, or similarly significant decisions, based solely on automated processing. Amanda and receipt extraction are assistance tools, and you should verify the information before acting on it.
8. Sharing with third parties
We do not sell your personal data. We may share relevant data with the following data processors and services:
- Supabase: authentication, database, storage, Edge Functions and operation of the app.
- OpenAI: AI processing for receipt extraction, Amanda, store policy and related features.
- Google: Google Sign In, Gmail OAuth and Gmail APIs when you connect your account, as well as Firebase Cloud Messaging for push notifications on iOS and Android.
- Apple App Store and Google Play: processing of purchases, subscriptions, offer codes, receipts and refunds when you buy a paid subscription. Kvito does not receive full payment card details, but may receive information about your active subscription and product ID from the App Store or Google Play.
- Sentry: error monitoring, performance, session replay on errors and user feedback / bug reports when you send them or when the app records technical errors.
- Resend: transactional emails such as data exports, receipts you want sent to yourself or shared, password resets and similar.
- Price search and web search (for example SearchAPI or SerpAPI): when we scan the market for price match or search public store sites for policy and contact, only the queries and results necessary for the feature.
When you share a receipt with another user in the app, that recipient can see the receipt details you choose to share. We may also disclose information if required by law, or if necessary to protect the service against abuse.
9. Retention and deletion
We store data for as long as necessary to deliver the service, but not everything is kept for the same period:
- Account data, profile data, profile picture, receipts and PDF data are normally kept until you delete them individually or delete your profile.
- Receipt shares and invitations are kept until they are answered, expired or deleted as part of account deletion.
- Cached store policies and product policy links are kept until replaced by newer findings or deleted as part of account deletion.
- Price match opportunities and scan status on receipts are kept until the receipt is deleted or updated.
- FCM device tokens are kept while you are signed in and have push enabled, and are deleted or disabled on logout, opt out or account deletion.
- Amanda conversations, titles and previews are kept for up to 30 days from the latest activity and are then deleted automatically, unless you clear them earlier in the app.
- Email import history for receipt emails, including raw text and HTML, parser fields and learning feedback, is kept until you clear the history in the app or delete your profile. This does not delete the receipts that have already been created.
- Local Gmail tokens and cache data on your device are short lived and may be renewed or deleted automatically. They are also cleared when you disconnect Gmail.
- Technical security logs and audit logs for sensitive actions (for example login, data export, account deletion) are kept for up to 12 months for operations, abuse prevention and troubleshooting, and are then deleted automatically.
- Bug reports and feedback in Sentry are retained under Sentry’s own retention rules.
- Enquiries to kontakt@kvito.dk about illegal content, support or data protection are kept for as long as necessary for handling and documentation, typically up to 12 months.
From the app, under Account → Your data & privacy, you can request a PDF data export, clear your Amanda history, clear your email import history and delete your profile. If you want full deletion of any remaining authentication or security information, you can contact us.
10. Your rights
Under the General Data Protection Regulation (GDPR), you typically have the right to:
- Access the information we process about you.
- Have inaccurate information corrected.
- Have your information deleted.
- Have processing restricted, object to processing and, where relevant, receive your data in a usable format.
- Withdraw consent, for example by disconnecting Gmail.
- Lodge a complaint with the Danish Data Protection Agency (datatilsynet.dk).
Contact us at kontakt@kvito.dk if you want to exercise your rights.
11. Local storage and cookies
The app uses local storage to save necessary settings and cache data such as Gmail link status, short lived tokens, automatic scan settings, notification level, price match preferences, local notification IDs, seen status for in app notifications, the selected theme, technical cache information and local subscription plan status.
On web, Google Sign In and the Gmail connection may set cookies from Google when you sign in or authorise access. These cookies are necessary for sign in and the Gmail integration to work.
On the marketing website kvito.dk we show a cookie banner on the first visit. Your consent choice is stored in localStorage. See also our cookie policy. We do not use cookies or local storage for third party advertising or analytics tracking on the marketing website.
12. Security approval and international transfers
CASA AL1
Kvito is CASA AL1 approved (Cloud Application Security Assessment, Assurance Level 1). This is an independent security assessment that Google uses as part of app verification for access to sensitive Google APIs. The approval means the app has been assessed against the security requirements that apply to that type of access.
You can read a shorter explanation on our security page.
Technical measures and transfers
Some data processing may take place outside the EU/EEA via our providers, especially Google and OpenAI, depending on the feature you use. Transfers typically rely on the European Commission’s Standard Contractual Clauses (SCC) and/or other lawful transfer mechanisms made available by the providers.
We use access control, provider security and reasonable technical and organisational measures to protect your data, but no solution is 100% secure.
13. Subscriptions and payments
When you purchase Starter, Standard or Premium, payment and subscription administration are handled by the Apple App Store (iOS) or Google Play (Android). Kvito does not receive your full payment card details.
We may receive and store information from the App Store or Google Play that a valid subscription is active, as well as which subscription product was purchased. We also store locally on the device which plan is active, so the app can display and unlock features according to the chosen plan.
Apple and Google process information about purchases, billing and refunds under their own privacy policies. If you have questions about payment, refunds or cancellation, please contact the App Store or Google Play. Contact us atkontakt@kvito.dk if subscription access is not activated correctly after a valid purchase.
Kvito has a free plan and three optional, auto renewing paid plans: Starter, Standard and Premium. The plans have different archive limits, Amanda quotas, mail scan quotas and access to price match (view, push and send) and Gmail autoscan. Current limits are shown in the app.
14. Referral programme
If you use the referral programme, we process information about your referral code, who has redeemed the code, the time of redemption, whether an invited user has become a paying subscriber, and which subscription plan the invited user has chosen (only for calculating the reward under the programme rules). We also process information about earned rewards, including the bonus period and bonus plan. The processing is done to deliver the programme, prevent abuse and show you your status in the app. The legal basis is typically performance of a contract and legitimate interest in abuse prevention.
15. Push notifications
On iOS and Android, Kvito can send push notifications via Firebase Cloud Messaging (FCM) when you grant permission on the device. We register an FCM device token, platform (iOS/Android) and whether push is enabled for your account so we can deliver messages about return and warranty deadlines, price match opportunities (Standard and Premium), mail scans, receipt shares, the referral programme and other updates according to your notification setting.
You can choose none, important only or all notifications in the app. The device token is deleted or disabled when you sign out, delete your profile or opt out of push on the device.
16. Bug reports and feedback
Kvito uses Sentry for error monitoring, performance measurements and optional user feedback when you report a bug or send feedback from the app. This may include technical event data, stack traces, device and app version, user id or email (if signed in), routing context, performance traces and, for bug reports, a screenshot.
Feedback and bug reports are only sent when you actively submit them, unless the app’s automatic feedback prompt appears after an unexpected error in release. You can always dismiss or choose not to send. Sentry may also receive limited session replay on errors. Processing is done to fix bugs, improve stability and respond to your enquiries.
17. Contact, requests and security incidents
If you want to exercise your rights, report a possible security issue or ask questions about our data processing, you can contact us at kontakt@kvito.dk.
To protect both you and other users, we may ask for reasonable proof of your identity before we disclose, correct or delete information. Nothing in this policy limits your mandatory rights under applicable data protection law.
18. Changes to this policy
We may update this privacy policy from time to time. Significant changes will be communicated via the app and/or on kvito.dk. The latest version is always available on this page and under Account → Privacy policy in the app.