Privacy Policy
Bonlo
This policy describes what data the Bonlo app processes and why. The controller is Denys Vasyliuk, Essen, Germany (full address in the Impressum). Contact: hi@moonage.me.
In case of doubt, the German version prevails.
In short
- You don’t need an account. No ads, no tracking, no analytics or crash reporting tools, no selling of data.
- Your receipts, their photos, the shopping list, the budget and the statistics stay on your iPhone.
- To read a receipt, the app sends its image to an AI model. The result comes back to your device; we keep neither the image nor the receipt.
1. What stays on your device only
Receipts and their items, the photos they were read from, the shopping list, your dictionary of categories and prices, the budget and settings are stored only on your device and are not sent to us.
- Widgets get a copy of the numbers they need (budget, shopping list) through shared storage on the device. They send nothing over the internet.
- Face ID / passcode: the lock uses iOS. The app receives no biometric data, only the answer “unlocked” or “not unlocked”.
- Notifications (budget, reminder before shopping) are scheduled and shown on the device.
- Export (CSV, JSON) is only created when you start it and goes wherever you share it.
- Siri and Shortcuts run inside the app on the device.
2. What is sent to read a receipt
When you photograph a receipt or choose a photo, screenshot or PDF, a reduced image is created and sent through our server (section 3) to Anthropic (the Claude model). The image is re-encoded: the photo’s location and other metadata are not sent. What comes back is the store, date, items and totals. If the total doesn’t add up, our server sends the same image a second time with a note on what didn’t match. “Recognise again” sends a receipt’s stored photo once more.
So that product names appear in your language and shopping list entries land in the right aisle, only the names as text — from the receipt and from your list — are sent through our server to OpenAI, or to Anthropic if OpenAI is unavailable. Prices, store and date are not included.
In settings you can choose recognition on the device (Apple Intelligence) instead. Then no image and no name leaves your device.
3. Our server
Requests to Anthropic and OpenAI go through our server at Cloudflare. It holds the image and names only while the request runs, forwards them and does not store them. For the free scans and your subscription to work, and to protect the service against abuse, it stores:
- a random key of your app installation, confirmed by Apple through App Attest, together with that confirmation — it reveals neither your name nor your Apple ID; reinstalling the app creates a new one;
- how many of the 10 free scans have been used;
- how many requests came in the current hour and the current day (protection against abuse);
- whether and which subscription is active (section 4).
So that the 10 free scans don’t start over when you reinstall the app, we use Apple DeviceCheck: the app creates a one-time token and sends it with the scan and with the request for the remaining scans to our server, which uses it to read and set two bits for your device at Apple that roughly record how many free scans have been used. Apple stores these two bits for your device; we receive no identifier of your device, and the bits hold nothing about you beyond that number.
Like any server on the internet, Cloudflare receives your device’s IP address to deliver the request and to fend off attacks. Our server does not store it. Its operating log holds only numbers and outcomes — type of request, size, duration, cost, whether the receipt check passed — without the installation key, IP address, image or product names.
4. Subscription
You buy and manage subscriptions through the App Store. Apple handles payment; we receive no payment data, only confirmation of which subscription is active.
After a purchase and when the app starts, the app sends the purchase confirmation signed by Apple to our server. Apple also tells our server about renewals, cancellations, plan changes and refunds (App Store Server Notifications). The server checks Apple’s signature and stores for your subscription:
- the transaction numbers Apple gives the subscription — they reveal neither your name nor your Apple ID;
- the plan (Basic or Plus), the start and end of the paid period, whether the subscription renews and whether it was refunded;
- how many scans have been used in the current subscription month;
- which installations (section 3) use the subscription.
5. Purposes and legal bases
- Reading receipts, translating names, subscription and scan allowance — to perform our contract with you (Art. 6(1)(b) GDPR).
- Protecting the service against abuse (App Attest, DeviceCheck, rate limits) — our legitimate interest in secure, affordable operation (Art. 6(1)(f) GDPR).
- Replying to emails and support requests — Art. 6(1)(b) or (f) GDPR.
6. Service providers and transfers to third countries
| Provider | Purpose | Based in |
|---|---|---|
| Anthropic PBC | reading the receipt image, fallback for translations | USA |
| OpenAI, L.L.C. | translating product names, shopping list aisles | USA |
| Cloudflare, Inc. | our server (section 3) | USA |
| Apple | App Store, subscription, App Attest, DeviceCheck | Ireland / USA |
Anthropic, OpenAI and Cloudflare process data on our behalf under a data processing agreement. Transfers to the USA are covered by the EU-US Data Privacy Framework and/or the EU Standard Contractual Clauses. Under their terms, Anthropic and OpenAI do not use data sent through their API to train their models; they keep it only for a limited period for abuse detection and delete it afterwards.
7. Retention and deletion
Data on the device stays until you delete it: one receipt with its photo from the receipt itself, everything at once under Settings → Data, or by deleting the app.
On our server we delete automatically, once a day:
- an installation’s key, its free-scan counter and its link to a subscription 12 months after its last request;
- a subscription’s data (section 4) 12 months after it ended and neither the app nor Apple has reported on it;
- the per-hour and per-day request counters after two days.
Cloudflare deletes the server’s operating log after 7 days.
The two DeviceCheck bits at Apple remain after you delete the app — that is what they are for. They only say roughly how many free scans have been used on the device.
8. Your rights
You have the right to access, rectification, erasure, restriction of processing, objection and data portability. Write to hi@moonage.me. You can also lodge a complaint with a data protection supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.
9. Security
All communication with the services is encrypted (HTTPS). iOS protects the data on the device; you can also lock the app with Face ID or a passcode.
10. Changes
If the app or the way it handles data changes, we update this policy on this page and change the date above.
11. Contact
Denys Vasyliuk, Essen, Germany — hi@moonage.me