fis_takip Privacy Policy
Last Updated: March 30, 2026
Effective Date: March 30, 2026
Welcome to fis_takip ("we", "us", "our"). This Privacy Policy explains how we collect, use, disclose, retain and protect personal information when you use the fis_takip mobile applications on iOS and Android (the "App") and related services. By using the App, you consent to the practices described in this policy.
1. Information We Collect
We collect information that you provide directly, information collected automatically when you use the App, and information obtained from third-party services we integrate with. Types of information we collect include:
Account & Contact Information
- Name and email address collected when you create an account, sign in with Google/Apple, or provide contact details.
- Profile photo if you upload one.
Device & Technical Information
- Device model, operating system and version, app version, device identifiers, language, time zone, crash and diagnostic data, and other technical metadata necessary to provide and improve the App.
Photos, Media & Receipt Images
- Images and multi-page scans of receipts you capture or import for processing and storage.
- Any metadata associated with those images (e.g., timestamps, device camera metadata) if provided.
Financial & Transactional Information
- Extracted receipt data such as merchant name, line items, prices, taxes, totals, dates, categories and other structured data derived from your receipts.
- Payment transaction records related to your purchases of premium subscriptions (receipt identifiers, transaction dates, purchase amounts, billing tokens) as necessary to manage subscriptions and comply with financial and tax obligations.
Usage & Analytics Data
- Interaction and usage data (features used, frequency, session duration) collected for product analytics and troubleshooting. We may collect aggregated or pseudonymized analytics data via Firebase.
Authentication & Third-Party Account Data
- When you sign in using Google or Apple, we receive authentication information and basic profile information permitted by the provider (e.g., name and email) to create and manage your account.
What we do not collect (directly)
- We do not collect payment card numbers directly in the App; platform stores (Apple App Store / Google Play) handle payment processing for subscriptions. We do collect transactional identifiers and receipts for subscription management.
2. How We Use Your Information
We use the information we collect for the following purposes:
To provide and operate the App
- Process and store receipts and images, extract line items and categories using AI, and present analyses, charts and the Wallet Persona feature.
- Authenticate and manage your account and any linked third-party sign-ins.
For AI-powered processing and features
- Send receipt images and extracted data to Google Gemini AI to extract text, categorize items, and generate insights used by the App’s features (see the AI/Automated Processing Disclosure for details).
To manage subscriptions and purchases
- Process purchase confirmations, manage auto-renewing subscriptions, confirm receipts, enable premium features, and handle renewals.
To communicate with you
- Send transactional messages (account confirmations, receipts, billing notices), service-related updates, security alerts, and respond to support inquiries. With your consent, we may send promotional messages about features or offers; you can opt out of promotional messages.
For analytics, improvement and research
- Analyze usage patterns and performance to improve the App, fix bugs, and develop new features. We may use aggregated or pseudonymized data for internal research.
For security, fraud prevention and legal compliance
- Detect and prevent fraud, abuse or other harmful activity; meet legal and regulatory obligations.
For other purposes with your consent
- Where we ask for your consent to process data for other specific purposes, we will only use the data as permitted.
3. Data Sharing and Third Parties
We do not sell your personal information. We share data only as described below and under appropriate safeguards (e.g., contracts, access controls):
Service Providers and Processors
- Google Generative AI (Google Gemini AI): Receipts images and related data are transmitted to Google’s generative AI services for optical character recognition (OCR), text extraction and categorization. Google processes this data as a processor on our behalf.
- Firebase services (Firebase Authentication, Cloud Firestore, Firebase Core): Used for authentication, cloud storage, database, analytics and application infrastructure.
- Google Sign-In and Sign in with Apple: Used for user authentication when you choose to sign in with these providers.
- Image picker, camera and device libraries: Local device components and libraries used to capture and import images (these operate on-device; the App may then upload images to our servers/processing services with your permission).
- Purchases Flutter (in-app purchase handler) and platform billing services: For subscription and transaction management.
- Share_plus: To enable content sharing from the App.
- Other third-party providers that perform services on our behalf (support, hosting, payment reconciliation, legal, and compliance).
Legal & Safety Disclosures
- We may disclose information to comply with legal obligations, respond to lawful requests by public authorities, protect our rights, investigate fraud or illegal activity, or to protect the safety of users.
Business Transfers
- If we are involved in a merger, acquisition, bankruptcy, reorganization, sale of assets or similar corporate transaction, personal information may be transferred as part of that transaction. We will notify users of any change in ownership or control that affects personal information.
Aggregated & De-identified Data
- We may share aggregated, de-identified or anonymized information that does not identify you or your account for analytics, research or commercial purposes.
Third-party links and integrations
- The App may link to or integrate with third-party services. Those services have their own privacy policies and practices. We are not responsible for third-party data handling beyond our contractual obligations.
International data transfers
- Data you provide may be stored and processed in countries outside your own (for example, United States and other countries where our service providers operate). Where required, we use standard contractual clauses, other lawful transfer mechanisms, and technical and organizational safeguards to protect international transfers.
4. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law.
Typical retention timelines:
- Account data and user-provided content (including receipt images and extracted data): Retained until you delete your account. After account deletion we retain backup copies for a limited period (up to 90 days) for disaster recovery and deletion processes.
- Subscription and transactional records: Retained for a period necessary to fulfill accounting, tax and audit obligations (typically up to 7 years), or longer if required by law.
- Analytics and diagnostic data: Aggregated or pseudonymized analytics data is retained for up to 24 months unless otherwise anonymized.
- Legal, security and compliance records: Retained as long as necessary to comply with legal requirements or to protect our rights.
When you request deletion of your account, we will remove account-identifiable data from active systems and databases and purge backups as described above. Residual copies may persist in backup media for the periods stated.
5. Security Measures
We implement administrative, technical and physical safeguards designed to protect your personal information, including:
- Encryption in transit using industry-standard TLS/HTTPS and encryption at rest for stored data in our cloud infrastructure (via Firebase and provider-managed encryption).
- Access controls, role-based access and least-privilege policies for internal systems.
- Authentication safeguards (secure token-based authentication, integration with Firebase Authentication, optional platform sign-in providers).
- Secure software development practices, regular security testing and vulnerability management.
- Data minimization practices and internal policies to limit access to personal data to authorized personnel only.
No system is completely secure. While we strive to protect your information, we cannot guarantee absolute security. If we become aware of a data breach that poses a risk to users’ rights and freedoms, we will comply with applicable breach notification laws.
6. Children's Privacy
The App is not intended for children under the age of 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children under this age. If we learn that we have collected personal information from a child under the applicable minimum age without verified parental consent, we will take steps to delete that information as soon as possible. If you believe we might have information from a child under the applicable minimum age, please contact us at the email address below.
7. Your Rights (GDPR/CCPA compliant)
If you reside in the European Economic Area (EEA), the UK, California, or other jurisdictions with privacy rights, you have certain rights regarding your personal information. These may include:
Right to Access
- Request a copy of personal data we hold about you.
Right to Rectification
- Request correction of inaccurate or incomplete personal data.
Right to Erasure ("Right to be Forgotten")
- Request deletion of personal data where applicable (subject to legal exceptions).
Right to Restrict or Object to Processing
- Request restriction of processing or object to processing based on legitimate interest, including profiling.
Right to Data Portability
- Request a machine-readable copy of your data for transfer to another service provider where technically feasible (e.g., receipt data and extracted line items).
Right to Withdraw Consent
- If processing is based on consent, you may withdraw consent at any time. Withdrawal will not affect the lawfulness of processing prior to withdrawal.
California privacy rights (CCPA/CPRA) — for California residents
- Right to know categories and specific pieces of personal information collected, purpose of collection, categories of sources, and third parties with whom we share data.
- Right to delete personal information (subject to exceptions).
- Right to opt-out of sale of personal information. We do not sell personal information as defined under the CCPA/CPRA.
- Right to limit use and disclosure of sensitive personal information for purposes other than providing services.
How to exercise your rights
- Submit requests by emailing fis-takip-2@forvibe.app. Include sufficient information to identify your account and the request you are making.
- We may need to verify your identity before fulfilling requests to protect against unauthorized disclosures. We endeavor to respond to verified requests within applicable legal timeframes.
- Rights may be limited where exceptions apply (e.g., legal obligations, fraud prevention, technical feasibility).
8. AI / Automated Processing Disclosure
AI services and automated processing are core to certain App features (receipt extraction, categorization, Wallet Persona). Important disclosures:
Services used
- We use Google Generative AI (Google Gemini AI) to process receipt images and extract structured data (line items, totals, taxes, merchant name) and to assist in generating behavioral insights used in the "Wallet Persona" feature.
What is processed and why
- Receipt images and relevant metadata are sent to Google’s AI services to perform OCR, itemization, categorization and other automated analyses. Processed outputs (structured receipt data, categories, summaries and Wallet Persona output) are returned to the App and stored in our systems to provide and improve the service.
Legal basis and user control
- Where GDPR applies, our legal basis for processing necessary to provide the App is performance of a contract and/or legitimate interests. For processing that requires consent (e.g., sensitive profiling), we will obtain explicit consent. You may opt out of AI profiling features (such as Wallet Persona) by disabling them in the App settings or by contacting us; disabling may limit some features.
Profiling & automated decisions
- The Wallet Persona feature uses automated analyses to generate a psychological-style profile of spending behavior. This profiling is intended for informational and educational purposes and should not be relied upon as professional financial or psychological advice. You can request human review or request that automated profiling be restricted or deleted.
Accuracy & limitations
- AI outputs may be imperfect. OCR and categorization may misclassify items; Wallet Persona insights are probabilistic and are not determinative. You are responsible for reviewing and correcting extracted data as needed.
Third-party processing
- Google processes data under its own privacy policy and data processing agreements. See Google’s privacy documentation for more details about how Google processes customer data.
9. In-App Purchases & Subscriptions
The App operates on a freemium model with optional premium subscriptions that unlock additional features.
Auto-renewing subscriptions
- Subscriptions automatically renew unless cancelled. Billing and payment processing are handled by the Apple App Store or Google Play Store. Your platform account will be charged for renewal according to the subscription terms you selected.
Managing and cancelling subscriptions
- To manage, change or cancel subscriptions, use your Apple or Google account subscription settings. Cancelling a subscription will prevent future renewal but will not retroactively refund past charges unless the platform (App Store/Play Store) provides a refund. Contact the respective store for refunds.
Trial periods and promotional offers
- If you receive a free trial, it will convert to a paid subscription unless cancelled before the trial ends. Terms of trials and promotional offers will be presented at sign-up.
Restoration of purchases
- You can restore purchases associated with your platform account (e.g., when reinstalling the App) using the platform’s restore purchase mechanisms or through in-app restore options.
Data after cancellation
- Your account data and previously uploaded receipts remain in your account after subscription cancellation unless you delete your account. Some premium-only content or features may be disabled once a subscription expires.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or new features. When we make material changes, we will provide notice via the App, by email (if you have provided an email address), or by posting a prominent notice. The "Last Updated" timestamp at the top indicates when this policy was last revised. Continued use of the App after the Effective Date constitutes acceptance of the revised Privacy Policy.
11. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or our data practices, please contact:
fis_takip
Email: fis-takip-2@forvibe.app
Website: https://fis-takip-2.forvibe.app
If you are located in the EU/EEA/UK and wish to exercise your GDPR rights, or if you are a California resident wishing to exercise your CCPA rights, please contact us at the email above and include relevant details to help us locate your account and verify your identity.
By using fis_takip, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.