Tomos — Privacy Policy
Last updated: 2026-09-28
This Privacy Policy explains how [Company Legal Name] ("Tomos", "we", "us") collects, uses, and discloses personal information when you use the Tomos mobile app and related services (the "Service"). We are the organization responsible for the personal information under our control, and we handle it in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
If you have questions or requests about your privacy, contact us at [email protected].
1. What we collect
We collect only what we need to run the Service:
- Account & identity. Your email address, and an identifier from your sign-in method — a Google account identifier (Google Sign-In), an Apple account identifier (Sign in with Apple), or a one-time email sign-in ("magic link") token. We also store your chosen primary currency.
- Receipt data you create. When you scan a receipt, we extract structured information from it — merchant name, date, total and tax amounts, currency, and individual line items — and store that structured data together with the AI extraction result. We do not store the original receipt image. The image is processed to extract the data and then discarded.
- Bank statements you upload. When you upload a bank or credit-card statement, we extract and store the institution name, the account type, the last four digits of the account number, the statement period, and each transaction — its date, the description as printed by your bank, amount, direction, type, and running balance. We also store the payee name and spending category we infer for each transaction. We never store the full account or card number, and we do not store the statement file itself — the PDF is processed to extract the data and then discarded. Transaction descriptions can include the names of people and businesses you paid or were paid by (for example, an e-transfer recipient); we use them only to organize your own finances.
- Settings you create. Budgets, category corrections, and payee rules you set up.
- Usage & account state. Your scan count, credit balance, subscription tier, and subscription expiry, used to operate quotas and billing.
- Payment identifiers. When you purchase a subscription or credits, our payment processors create identifiers we store to manage your purchase — a Stripe customer identifier and/or a Google Play purchase token. We never receive or store your full card number — card details are handled entirely by the payment processor.
- Technical/diagnostic data. Basic logs needed to operate and secure the Service (e.g., error and request logs). When our servers hit an error, an error report is sent to our error-monitoring provider (Sentry); it can include technical details of the request that failed. We do not use third-party advertising or analytics SDKs.
We do not knowingly collect special categories of sensitive information, and the Service is not directed to children.
2. How receipt and statement processing works (AI processing)
To turn a receipt into structured data, the receipt image is sent to our AI/OCR processor, Google (Gemini), which returns the extracted text and fields. The image is used only to perform this extraction and is not retained by us afterward.
To read a bank statement, we send its text to the same processor. Before we send it, we shorten long account and card numbers to their last four digits; the transaction descriptions, dates, and amounts are sent as they appear. The processor also suggests a payee name and spending category for each transaction.
Extraction and categorization are automated and may be inaccurate — you can review and edit extracted receipt data, and you should verify results before relying on them.
3. Why we use your information
We use personal information to:
- create and operate your account and authenticate you;
- extract, store, display, and let you edit and export your receipt data;
- organize your bank and card transactions, budgets, and spending by category;
- provide price-tracking and history features across your own receipts;
- operate scan quotas, credits, and subscriptions, and process payments;
- maintain security, prevent abuse, and meet legal obligations;
- respond to your support requests.
We rely on your consent (which you may withdraw — see Section 7) and on the purposes a reasonable person would consider appropriate in the circumstances.
4. How we share information (sub-processors)
We do not sell your personal information. We share it only with service providers who process it on our behalf, under contract, to deliver the Service:
| Provider | Purpose |
|---|---|
| Google (Gemini AI) | Receipt and bank-statement extraction; payee and category suggestions |
| Google (Sign-In) | Authentication (if you use Google Sign-In) |
| Apple (Sign in with Apple) | Authentication (if you use Apple Sign-In) |
| Resend | Sending sign-in ("magic link") emails |
| Stripe | Subscription and credit-pack payments |
| Google Play Billing | In-app purchases on Android |
| Sentry | Error monitoring for our servers |
| Our hosting/infrastructure provider | Running the backend, database, and cache |
We may also disclose information if required by law, to enforce our Terms, or to protect the rights, safety, or property of users or the public.
5. Where your information is processed
We operate the Service using infrastructure and the providers above, which may store and process information in Canada and/or the United States. Where information is processed outside your province or country, it may be subject to the laws of those jurisdictions, including lawful access by courts and government authorities. We take reasonable steps to ensure providers protect your information with comparable safeguards.
6. Retention and deletion
- Receipts, statements, and account data are retained for as long as your account is active, so your history and price trends remain available to you. We do not impose a fixed expiry on your history.
- A receipt or statement you delete is removed from your history immediately and permanently purged after a 30-day grace period.
- You can delete your account at any time from Settings → Delete account. Deletion soft-deletes your account immediately (you are signed out and the data is no longer accessible) and permanently purges it after a 30-day grace period. Before deletion completes, the app offers you a downloadable copy of your data, including your receipts, statements, and budgets.
- We retain limited records where required for legal, tax, security, or fraud-prevention purposes, for no longer than necessary.
7. Your rights and choices
Subject to applicable law, you may:
- Access the personal information we hold about you and request a copy (the in-app delete flow also provides a full data export);
- Correct inaccurate information — you can edit your receipt data directly in the app;
- Withdraw consent and delete your account, subject to legal or contractual restrictions;
- Ask questions or make a complaint about our handling of your information.
To exercise these rights, email [email protected]. We will respond within the timeframe required by applicable law. If you are not satisfied, you may contact the Office of the Privacy Commissioner of Canada (www.priv.gc.ca).
8. Security
We use reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the information — including encrypted transport (HTTPS), authentication tokens, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. Children
The Service is intended for adults and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.
10. Changes to this policy
We may update this policy from time to time. We will revise the "Last updated" date above and, for material changes, provide a more prominent notice. Your continued use of the Service after a change takes effect means you accept the updated policy.
11. Contact
[Company Legal Name] [Business address] Email: [email protected]