Guuster← Back to Home

Privacy Policy

Last Updated: July 27, 2026

Introduction

This Privacy Policy describes how Guuster ("we", "us", or "our") collects, uses, and shares information when you use our website, mobile application, and related services (collectively, the "Service"). We are committed to protecting your privacy and being transparent about our data practices.

Information We Collect

Information You Provide

When you create an account or use our Service, we may collect:

  • Account information: Email address, name, and profile details provided during registration (including via Google or Apple Sign-In).
  • Receipt data: Photos and images of receipts you upload for scanning and analysis.
  • Location data: Location information you provide or that is derived from your use of location-based features (e.g., finding nearby deals).

Receipt images and loyalty numbers

A printed receipt often carries more than a list of what you bought. It may show a loyalty or customer card number, and sometimes the last few digits of the payment card used. We want to be precise about what happens to that, because "we don't collect it" on its own would not be the whole picture.

  • What we extract: only the product names, prices, quantities, store, date and currency. We do not read, extract, use or store loyalty card numbers, customer numbers or payment card details, and none of those has a place to be stored in our database.
  • What is transmitted: the whole image is sent to OpenAI to be read, because the text has to be extracted from the picture. Anything printed on the receipt, including a loyalty number, is part of that image while it is being processed. This is why we list it here rather than leaving it unsaid.
  • What we keep: nothing. The image is held in memory only for as long as the request takes and is never written to our database or file storage. We keep no copy of the photo after the text has been extracted, so we cannot show it to you again, and neither can anyone else.

If you would rather a loyalty number never left your device at all, covering that part of the receipt before taking the photo keeps it out of the image entirely.

Information Automatically Collected

When you visit our website, we automatically collect certain technical information, including:

  • Device information (device type, operating system)
  • Browser type and version
  • Pages visited and interactions with our website
  • Date and time of your visit

Analytics and Error Tracking

We use Sentry and PostHog to help us understand how our Service performs and to improve the user experience.

Sentry

  • Session replays: Recordings of how the app is used, so we can see what led up to a problem. All text, all images and all graphics are masked before the recording leaves your device — a replay shows the shape of the screen and where you tapped, not what was written or shown on it. That means a receipt you are photographing or viewing appears as a blank block, never as a readable image. We record a small sample of ordinary sessions, and sessions where an error occurred.
  • Error and crash tracking: Technical information about failures, including stack traces and device context. We have disabled the option that would attach personal identifiers such as your IP address to these reports.
  • In-app feedback: If you send feedback from inside the app, your message goes to Sentry. You can choose to attach a screenshot; if you do, that screenshot is sent with it. Nothing is attached unless you add it yourself, so please avoid including a receipt or a loyalty number in a screenshot you send us.
  • Performance monitoring: Data about load times and application performance.

PostHog

  • Product analytics: Usage patterns, feature interactions, and user journeys to help us improve the Service.
  • AI/LLM usage tracking: Metrics about our AI-powered features — which model ran, how long it took, how many tokens it used, what it cost and whether it failed. The content sent to and returned by the model is deliberately excluded, so receipt images and extracted receipt text are never recorded in our analytics.

How We Use Your Information

We use the information we collect to:

  • Provide the Service: Scan and analyze receipts, track prices, and find deals using AI-powered features.
  • Authenticate your account: Verify your identity via email, Google, or Apple Sign-In.
  • Communicate with you: Send you updates, product news, and other information related to Guuster.
  • Improve our Service: Analyze usage patterns to improve functionality and user experience.
  • Fix issues: Identify and resolve technical problems with our Service.

Third-Party Services

We use the following third-party services that may collect information:

Sentry

Purpose: Error tracking, performance monitoring, and session replays.

Data shared: Error logs, device information, masked session recordings, and any feedback you send from inside the app together with a screenshot if you attach one.

Location: European Union. Our Sentry organisation uses the EU data region, so this data is not transferred to the United States.

Privacy policy: https://sentry.io/privacy/

Resend

Purpose: Email delivery service for sending notifications and updates.

Data shared: Email address.

Location: Ireland (European Union). Our sending domain is configured in Resend's EU region.

Privacy policy: https://resend.com/legal/privacy-policy

Supabase

Purpose: Database hosting and user authentication (including email, Google, and Apple Sign-In).

Data shared: Account information, user data, and authentication tokens.

Location: Stockholm, Sweden (European Union). Your account and receipt data are stored in the EU.

Privacy policy: https://supabase.com/privacy

PostHog

Purpose: Product analytics and AI/LLM usage tracking.

Data shared: Usage events, device information, and feature interaction data. For AI features, only metrics about the request — never the receipt image, the prompt or the model's response.

Location: European Union. Our PostHog project is hosted in the EU region, so this analytics data is not transferred to the United States.

Privacy policy: https://posthog.com/privacy

OpenAI

Purpose: AI-powered receipt scanning and analysis, and matching products to product types.

Data shared: The receipt images you upload, sent for text extraction. A receipt may show a loyalty or customer card number, and occasionally the last digits of a payment card — so those are transmitted as part of the image, even though we do not extract or store them (see "Receipt images and loyalty numbers" above). We also send product names, without any account identifier, to match them to product types.

Location: United States. Processing your receipt therefore involves a transfer of personal data outside Switzerland and the EEA.

Safeguard: We have accepted OpenAI's Data Processing Addendum, which incorporates the European Commission's Standard Contractual Clauses together with the adaptations that apply to transfers from Switzerland. This is the legal safeguard for the transfer described above. You can ask us for a copy at any time by emailing [email protected].

Privacy policy: https://openai.com/policies/privacy-policy

Google Maps Platform

Purpose: Location-based services including geocoding and finding nearby deals.

Data shared: Location data and address information.

Privacy policy: https://policies.google.com/privacy

Google & Apple Sign-In

Purpose: Third-party authentication providers for account creation and login.

Data shared: Authentication tokens and basic profile information (name, email) as authorized by you during sign-in.

Privacy policies: Google / Apple

Railway

Purpose: Cloud hosting provider for our API backend infrastructure.

Data shared: All data processed by our API passes through Railway's infrastructure, including server logs.

Location: Netherlands (European Union). Our API runs in Railway's EU West region.

Privacy policy: https://railway.com/legal/privacy

Data Storage and Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encrypted connections (HTTPS/TLS) for all data transmission
  • Secure storage practices with our database provider
  • Limited access to personal data

However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

Where Your Data Is Held

Almost everything stays in Europe. Your account and receipt data are stored in Sweden, our API runs in the Netherlands, our email is sent from Ireland, and our analytics and error tracking are in the EU regions of PostHog and Sentry.

There is one exception, and it is the important one: reading the text off a receipt is done by OpenAI, in the United States. Uploading a receipt therefore transfers that image — including anything printed on it — outside Switzerland and the EEA. That transfer is made under the Standard Contractual Clauses described in the OpenAI section above. Nothing else you give us leaves Europe, and the image itself is not stored by us at either end.

Google receives store addresses for geocoding, and Google or Apple receive sign-in details if you use their sign-in, under their own policies linked above.

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data and account.
  • Opt-out: Unsubscribe from our communications at any time using the link in our emails.

To exercise these rights, please contact us at the email address provided below.

Data Retention

We retain your personal data for as long as your account is active or as needed to provide you with the Service. If you delete your account, your data will be permanently removed. Analytics and error tracking data is retained according to our third-party providers' policies (typically 90 days).

Receipt images are an exception, and a deliberate one: we do not retain them at all. A photo you upload exists only in memory for the moments it takes to read the text from it, and is never written to our database or file storage. What we keep is the extracted result — products, prices, store, date — not the picture it came from. OpenAI, which performs the extraction, applies its own retention to API requests under the policy linked above.

Children's Privacy

Our Service is not intended for children under the age of 13. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the "Last Updated" date at the top of this page. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.

Contact Us

Guuster is operated by Gergő Bence Starosta, who is the controller responsible for the personal data described in this policy.

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: