Hiện trang này chỉ có bản tiếng Anh.
Privacy Policy and Terms of Service
Effective date: July 16, 2026
This document sets out the Privacy Policy and Terms of Service for Cirola ("we", "us", or "our"), operated by Cirola Technologies Inc. It explains how we collect, use, share, and protect information when you use any of our products — currently Cirola Pocket (receipt tracking) — along with the related websites and services (together, the "Service"). As we launch additional products (such as Cirola Chill), this document will be updated to cover any new data practices specific to those products. By creating an account or using the Service, you agree to be bound by these terms and the practices described here.
1. Information We Collect
We collect only the information needed to operate the Service. We do not sell personal information, and we do not use your data for advertising targeting across other apps or websites.
Account information
- Email address and name — provided by you during registration or by your chosen sign-in provider (Google or Apple).
- Password — stored only as a one-way salted hash. We never see, store, or transmit your actual password.
- Provider identifier — if you sign in with Google or Apple, we store the stable user ID the provider gives us. For Apple, this is the opaque
subclaim from your identity token; we do not receive your real Apple ID. - Account membership — if you share an account with other users, we store the relationship between user accounts and shared wallets.
Receipt and financial data
- Receipt images — photos you take or upload of your receipts. Captured images are uploaded to our cloud storage so they can be parsed; on the free tier they are automatically deleted 30 days after upload (see Section 7).
- OCR text and parsed items — the text extracted from your receipts, along with structured fields such as store name, items, prices, quantities, and totals.
- Spending entries — manual entries you create, including amounts, dates, currency, and notes.
- Followed items and price notifications — the list of items you have chosen to track, and the price history we generate from aggregated receipts.
- Inbound email receipts — if you create a Cirola email inbox (e.g.
yourname@p.cirola.com) and forward order-confirmation emails to it — either manually or via an automatic inbox filter — the forwarded emails are received on your behalf, parsed into receipts, and associated with your account. The original email stays in your personal inbox as your proof of purchase.
Device and technical data
- Device information — platform (iOS / Android), OS version, device model, app version and build.
- Language and regional settings — the app language you chose, your device's locale (for example fr-CA), timezone, and preferred currency. Collected when you register and refreshed when you sign in, so the app can serve you in the right language and so we can understand, in aggregate, where our users are and which languages matter most.
- Approximate location (country only) — we derive the country you are connecting from (for example "CA") from your connection when you register or sign in. We store the two-letter country code only — never your precise location. The app does not request or use GPS. This helps us understand where Cirola is being used so we can prioritize languages, currencies, and regional features. None of this is used for advertising.
- IP address — logged for security, abuse-prevention, and rate limiting. IP addresses are not stored with your profile; only the derived country code (above) is kept.
- Diagnostics, crashes, and performance — collected through Sentry so we can identify and fix bugs. This may include stack traces, timestamps, and anonymized identifiers, but excludes receipt contents.
Purchase data
If you subscribe to a paid tier, your purchase is processed by Apple (App Store) or Google (Play Store). We receive a subscription status signal through RevenueCat — we never receive or store your payment card details.
Advertising (Free tier only)
If you use the free tier, the app displays a small banner ad served by Google AdMob. These ads help cover the basic costs of keeping Cirola free — nothing more. We request non-personalized ads only: the app does not ask for cross-app tracking permission and does not share advertising identifiers for personalized targeting. AdMob may still collect device information, IP address, and general interaction data to serve and measure ads. This data is governed by Google's Privacy Policy. Pro subscribers do not see ads and no ad-related data is collected for them.
Affiliate links (all tiers)
When the app shows you a link to a product page on a retailer's website (for example Amazon or Walmart), that link may include our affiliate ID. If you make a purchase after following such a link, Cirola may earn a small commission from the retailer at no extra cost to you — the price you pay is unchanged. As an Amazon Associate, Cirola earns from qualifying purchases. Affiliate IDs are added only at the moment you open a link; they do not change the products identified on your receipts, the prices displayed, or any data stored in your account, and we do not share any of your personal information with the retailer. Where several retailer links are available for the same product, links to retailers we partner with may be listed first.
What we do NOT collect
- We do not collect your precise location.
- We do not access your contacts, calendar, or health data.
- We do not use cross-app tracking identifiers beyond what is required by the ad network on the free tier.
2. How We Use Your Information
We use the information we collect to:
- Provide the core features of the Service — storing your receipts, parsing them with optical character recognition, categorizing your spending, and showing analytics.
- Authenticate you securely and maintain your session.
- Match receipt items to products using third-party product databases and search engines, so you can track prices over time and across stores.
- Generate price-change notifications for items you follow.
- Detect and prevent abuse, fraud, and automated attacks.
- Monitor performance, fix crashes, and improve the app.
- Send transactional emails — activation codes, password resets, and (for account owners) administrative notifications.
- Comply with legal obligations and respond to lawful requests.
3. AI and Automated Processing
To turn a receipt image or email into structured data, we use third-party large language models and vision models (including Google Gemini, OpenAI GPT, models hosted on AWS Bedrock, and Google Vertex AI Search). Processing a receipt requires sending its contents to these providers:
- For photographed receipts, we send the OCR text or a compressed image of the receipt.
- For receipts received through your Cirola email alias, we send the text of the email (and any PDF attachments converted to text).
We do not separately attach your Cirola account identifiers (your account email, display name, or internal user ID) when we call these providers. However, the receipt content itself may contain personal information printed, photographed, or quoted by the retailer, such as your name, a shipping or billing address, an email address, a phone number, a loyalty-card number, or the last few digits of a payment card.
This applies to every ingestion path:
- Photographed receipts — whatever is visible in the photo, including anything printed at the top or bottom of the paper receipt, is sent to the AI provider as an image or as OCR text.
- Email receipts — the full text of the order-confirmation email, which often includes personal details quoted in the message body, is sent to the AI provider.
In all cases, we do not strip, mask, redact, or pseudonymize this content before sending it. The AI provider sees whatever the receipt or email contained.
Our primary AI provider: Google (paid tier)
Receipt parsing is performed almost entirely by Google Gemini, accessed through Google's commercial paid offerings (Gemini API paid tier / Google Cloud Vertex AI) — not through the free consumer or developer tiers.
Under Google's data governance terms for these paid services, Google contractually commits that:
- Content sent to Gemini through Cirola is not used to train or improve Google's machine learning models.
- Google processes the content only to return a parsed response to us.
- Google does not retain the content beyond what is needed to operate the service and, where retained for abuse monitoring, deletes it according to its published retention policy.
You can read Google's binding commitment directly: Generative AI on Vertex AI — Data governance and the Gemini API Additional Terms of Service.
Other AI providers we may occasionally use
For a small number of narrower tasks (such as lightweight quality checks on product-name matches) we may route requests through other commercial AI APIs, including OpenAI, Groq, and models hosted on Amazon Web Services Bedrock (such as Anthropic Claude and Meta Llama variants), all accessed via paid commercial API tiers whose terms similarly prohibit training on customer inputs. AWS contractually commits that content sent to Bedrock is not used to train the underlying foundation models, is not shared with the model provider, and is not stored beyond what is needed to return your response — see AWS Bedrock data privacy FAQ. We do not use the free consumer-facing chatbot versions of any of these services.
Automated processing happens only when you ask us to — by capturing a receipt, forwarding a receipt email to your Cirola inbox, or looking up a price. No automated decision produces legal or similarly significant effects for you. If you would prefer that a specific receipt not be sent to a third-party AI provider, do not capture it in the app and do not forward it to your Cirola email alias.
AI accuracy disclaimer
AI-powered features — including receipt parsing, item extraction, price detection, and product matching — are provided on a best-effort basis. While we continuously work to improve accuracy, AI can and does make mistakes. Parsed amounts, item names, quantities, and other extracted data may occasionally be incorrect or incomplete. You should always verify important financial information against your original receipts. Cirola is not liable for decisions made based on AI-parsed data.
4. Third Parties and Sub-Processors
We share data with a small, carefully chosen set of service providers that help us run the Service. We do not sell your personal information to anyone.
| Provider | Purpose |
|---|---|
| Google Cloud Platform | Hosting, databases, and Vertex AI Search for product matching. |
| Amazon Web Services (S3 / SES / SNS / SQS) | Storing receipt images in a private S3 bucket, delivering transactional email, receiving inbound email receipts, and staging email payloads for processing. |
| Google Sign-In | OAuth authentication if you choose to sign in with your Google account. |
| Apple Sign in with Apple | OAuth authentication if you choose to sign in with your Apple ID. |
| Google Gemini (paid Vertex AI / Gemini API) | Primary large language model for receipt parsing and product matching. Content is not used to train Google's models — see Section 3 for the linked commitment. |
| OpenAI / Groq (paid APIs) | Occasional use for narrower tasks (e.g. confidence checks). Paid commercial API tiers only — no training on customer inputs. |
| AWS Bedrock (paid) | Occasional use for narrower AI tasks via foundation models hosted by AWS (e.g. Anthropic Claude, Meta Llama). AWS contractually commits content is not used to train the underlying models and is not shared with the model provider. |
| LiteLLM proxy | Self-hosted routing layer that forwards requests to the AI providers above. Runs on our own infrastructure. |
| Sentry | Crash reporting, performance monitoring, and diagnostics. |
| RevenueCat | Subscription status management (we never receive card details). |
| Google AdMob | Advertising on the free tier (non-personalized ads only) — helps cover the basic costs of the free plan. Collects device information and interaction data to serve and measure ads. Pro subscribers are not affected. |
| Retailer affiliate programs (e.g. Amazon Associates) | Product links you choose to open may carry our affiliate ID, so Cirola may earn a commission on qualifying purchases at no extra cost to you. No personal information is shared with the retailer; the retailer's own privacy policy applies once you are on their site. |
| Apple App Store / Google Play Store | Payment processing for paid subscriptions. |
We may also disclose information if required to do so by law, or in response to a valid legal request from a public authority.
5. Data Residency and International Transfers
All user data is stored primarily in Canada. Backups are replicated to the United States for disaster recovery purposes. AI processing (receipt parsing, product matching, and related intelligence features) is performed in the United States. Where required, we rely on appropriate legal mechanisms (such as Standard Contractual Clauses) for cross-border transfers of personal data.
6. Service Availability
We target a service availability of 99.9% measured on a monthly basis (approximately 43 minutes of unplanned downtime per month). Scheduled maintenance windows are excluded from this calculation. We do not currently offer financial credits for downtime but will notify users of any significant service disruption via the app or email.
7. How Long We Keep Your Data
- Account data — kept while your account is active. You can delete your account at any time from the app.
- Receipt images (Free tier) — cloud-stored images are automatically deleted 30 days after upload. On-device images are kept until you delete them yourself.
- Receipt images (Paid tier) — kept as long as you keep the entry, or until you delete the entry or your account.
- Parsed receipt data — retained while your account is active, and in aggregated / de-identified form afterwards (see "Account deletion" below).
- Diagnostic and crash data — retained according to Sentry's default retention, typically 30–90 days.
- Security and rate-limit logs — retained for up to 7 days.
- Inbound email payloads (raw) — retained in our email staging bucket for up to 30 days, then deleted automatically.
8. Account Deletion
You can permanently delete your account from inside the app (Settings → Delete Account). When you delete your account, we will:
- Delete your personal profile (name, email, password hash, OAuth identifiers).
- Delete your spending entries, shopping lists, account memberships, authentication tokens, and any subscription and bug-report records linked to you.
- Delete cloud-stored receipt images associated with your account.
Important: to preserve the integrity of aggregated price history — which other users rely on — the parsed text of individual receipt items (product name, store, price, date) is retained in anonymized form, with the link to your user account removed. This anonymized data cannot be re-associated with you.
If you sign in with Apple, we also revoke any Apple OAuth tokens we hold on your behalf. You can additionally revoke Cirola's access from iOS Settings → Apple ID → Sign in with Apple.
9. Your Privacy Rights
Depending on where you live, you may have the following rights over your personal data under laws such as Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and the Brazilian Lei Geral de Proteção de Dados (LGPD):
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data (by deleting your account, or by contacting us).
- Export a copy of your data in a portable format.
- Object to, or restrict, certain processing activities.
- Withdraw consent you previously gave.
- Lodge a complaint with your local data protection authority — for example, the ANPD in Brazil, or the CNIL, ICO, or your national supervisory authority in the EU/UK.
To exercise any of these rights, contact us at support@cirola.com. We will respond within the timeframes required by applicable law. We do not charge a fee for reasonable requests.
We do not sell or "share" your personal information in the sense defined by the CCPA. If that ever changes, we will update this page and provide the opt-out controls required by law.
10. Acceptable Use and Content Policy
Cirola is designed for managing receipts, expenses, and shopping data. You agree not to upload images or content that is offensive, sexually explicit, violent, hateful, harassing, illegal, or otherwise inappropriate. This includes but is not limited to:
- Pornographic or sexually explicit material
- Violent, graphic, or disturbing imagery
- Hate speech, harassment, or discriminatory content
- Content that exploits or endangers minors
- Illegal content or content promoting illegal activity
- Spam, malware, or deceptive content
We use automated systems, including AI-based content moderation, to detect inappropriate uploads. If a violation is detected, we reserve the right to immediately deactivate your account without prior notice. Repeated or severe violations may result in permanent account termination and deletion of all associated data.
If you believe your account was deactivated in error, please contact us at support@cirola.com.
Fair use and monthly usage limits
To protect the Service from abuse and keep costs sustainable for everyone, we apply per-user monthly caps on the most expensive operations. These apply to every account (Free and Pro) and reset at the start of each calendar month:
- AI-processed receipts — up to 250 receipts per month run through our AI parsing pipeline.
- Items per receipt — up to 40 line items are extracted per receipt; additional items are truncated.
- Cloud image uploads — up to 250 receipt images stored in the cloud per month.
- Store lookups (Google Places) — up to 500 unique store lookups per month. Repeated receipts from the same store are served from our cache and do not count toward this limit.
If you reach a limit, the affected operation is skipped for the remainder of the month — the rest of the app keeps working normally. Limits may be adjusted over time as infrastructure costs and usage patterns evolve; material changes are announced per Section 18 below.
11. Security
We use industry-standard safeguards to protect your data, including encryption in transit (TLS), encryption at rest for stored receipt images and backups, hashed passwords, rate limiting, and access controls on our backend systems. We do not store or have access to your payment card details at any time.
No method of transmission or storage is 100% secure, but we work hard to protect your information. In the event of a data breach that affects your personal data, we will notify affected users within 72 hours of becoming aware of the breach, and will report to the relevant supervisory authority where required by law (e.g., GDPR, PIPEDA).
12. Limitation of Liability
Cirola is a receipt management and expense tracking tool — it is not a financial advisor, accountant, or tax service. You should not rely solely on Cirola for tax filing, financial reporting, or any decision with legal or financial consequences.
To the maximum extent permitted by applicable law, Cirola and its affiliates, officers, employees, and agents shall not be liable for any indirect, incidental, special, consequential, or punitive damages — including but not limited to loss of profits, data, or goodwill — arising out of or in connection with your use of the Service.
In no event shall our total aggregate liability exceed the amount you paid us in the twelve (12) months preceding the event giving rise to the claim, or fifty Canadian dollars (CAD $50), whichever is greater.
13. Disclaimer of Warranties
The Service is provided "as is" and "as available" without warranties of any kind, whether express, implied, or statutory, including but not limited to implied warranties of merchantability, fitness for a particular purpose, accuracy, and non-infringement.
We do not warrant that the Service will be uninterrupted, error-free, or completely secure, or that AI-parsed receipt data will be accurate or complete. We do not guarantee that product prices, store information, or any other data derived from receipts or third-party sources will be correct.
14. Governing Law and Jurisdiction
These terms and your use of the Service are governed by and construed in accordance with the laws of the Province of Ontario, Canada, without regard to its conflict of law provisions.
Any disputes arising from or relating to the Service shall be subject to the exclusive jurisdiction of the courts located in Ontario, Canada. You agree to submit to the personal jurisdiction of such courts.
15. Account Inactivity
If your account remains inactive (no logins, no receipt uploads, no API activity) for a continuous period of 12 months, we may send you a notification and subsequently delete your account and all associated data after an additional 30-day grace period. This helps us manage resources and protect dormant accounts from unauthorized access.
If you wish to keep your account active, simply log in at least once every 12 months. You may also export your data at any time through the app before deletion occurs.
16. Refund Policy
Pro subscriptions are billed and managed entirely through the Apple App Store or Google Play Store. Refund requests must be submitted directly to Apple or Google according to their respective refund policies. Cirola does not process payments directly and cannot issue refunds.
If you experience a technical issue that prevents you from using Pro features you are paying for, please contact us at support@cirola.com and we will do our best to resolve the issue promptly.
17. Intellectual Property and Data Ownership
Your data belongs to you. You retain full ownership of all receipt images, text, and personal financial data you upload to Cirola. We do not claim any ownership rights over your content.
By using the Service, you grant us a limited, non-exclusive license to process, store, and display your data solely to provide and improve the Service for you.
We reserve the right to use anonymized and aggregated data — from which no individual user can be identified — to power features such as our public price comparison API, generate market insights, and improve our AI models. This aggregated data cannot be traced back to you or your account.
The Cirola name, logo, and all related branding, software code, AI models, and documentation are the intellectual property of Cirola and are protected by applicable copyright, trademark, and other intellectual property laws.
18. Service Modifications
We reserve the right to modify, suspend, or discontinue any part of the Service at any time. We will make reasonable efforts to notify you of material changes — such as feature removals or pricing changes — at least 30 days in advance via email or in-app notification.
If a change materially reduces the functionality of a feature you are actively paying for, you may cancel your subscription before the change takes effect. Continued use of the Service after the change constitutes acceptance of the modified terms.
We will never delete your existing data as a result of a service change without giving you the opportunity to export it first.
19. Indemnification
You agree to indemnify, defend, and hold harmless Cirola Technologies Inc. and its officers, directors, employees, and agents from and against any claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or in any way connected with: (a) your use of the Service; (b) your violation of these terms; (c) your violation of any third-party rights; or (d) content you upload to the Service that violates our Acceptable Use policy.
20. Force Majeure
We shall not be liable for any failure or delay in performing our obligations under these terms where such failure or delay results from circumstances beyond our reasonable control, including but not limited to: natural disasters, pandemics, acts of government, internet or telecommunications failures, power outages, cyberattacks, or disruptions to third-party cloud infrastructure providers.
21. Children's Privacy
The Service is not directed to children under 13 (or the minimum age of digital consent in your country, whichever is higher). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
22. Severability and Entire Agreement
If any provision of these terms is found to be unenforceable or invalid by a court of competent jurisdiction, that provision shall be limited or eliminated to the minimum extent necessary so that the remaining provisions remain in full force and effect.
This document constitutes the entire agreement between you and Cirola Technologies Inc. regarding your use of the Service, and supersedes all prior agreements, representations, and understandings — whether written or oral — relating to the same subject matter.
23. Changes to These Terms
We may update this Privacy Policy and Terms of Service from time to time. When we do, we will update the "Effective date" at the top of this page and, for material changes, notify you in the app or by email. Your continued use of the Service after the revised terms take effect constitutes your acceptance of the changes. Please review this page periodically.
24. Language and Translations
This document is offered in several languages for your convenience. The English version is the authoritative text: if there is any conflict, ambiguity, or discrepancy between a translation and the English original, the English version prevails and governs your relationship with us.
Translations are provided in good faith but may not capture every legal nuance of the original. If a translated passage is unclear, please refer to the English version or contact us for clarification.
25. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at:
You can also reach us through our contact page.