Privacy Policy

Last updated: September 2026

1. Overview

This policy explains what data Hipzap — the receipt bookkeeping app, which also keeps your membership cards — collects, where it is stored, and the choices you have.

2. What we collect

We collect what the features need to work, the diagnostics and sign-in records we need to keep Hipzap working and secure (see section 5), and the anonymous usage statistics described in section 11:

  • Membership cards — brand name, card number or barcode, and an optional photo of the card.
  • Receipt images and statement files — the photos of receipts you take and the PDF statements you upload to record expenses. They are sent to an AI service, which extracts the details.
  • Expense records — amounts, categories, dates, and any notes you add.
  • Preferences — your chosen language and currency.
  • Account — if you bind one, your email address (used for verification codes and account recovery).
  • Shared group content — if you join a shared group, the ledgers, entries, comments, names and photos you share there are visible to the other members of that group.
  • Safety records — if you report a member or block someone, we store the report (your description, up to 1,000 characters, and a copy of the reported content, up to 2,000 characters) and who you have blocked.
  • Health-related information — a receipt from a pharmacy or clinic can reveal health information about you. If you photograph such a receipt, the image and the extracted line items are stored on our servers and the expense may be classified into a medical category. You can always record these expenses manually instead, without a photo.
  • Diagnostics — when changes you make cannot be synced, the app sends us a short technical report so we can find and fix the problem. It says which kind of data is affected, how many changes are waiting and for how long, and gives a brief error message, together with which of our apps you are using and, depending on the app version, its version number and your device’s operating system version. When you are signed in, these reports are linked to your account. Separately, the iOS and Android apps check for app updates automatically; if the app has crashed, the next check also carries the technical error log from that crash. In the web and Telegram versions, if a page runs into an error, the app sends us the error details described in section 4.
  • Devices and sign-ins — when you sign in, and while you stay signed in, we record the IP address you connect from, the country we work out from that address, and which version of Hipzap (web, Telegram, iOS or Android) and the details your browser or app reports about itself (such as the browser, operating system and device type). This is how the Devices page shows where you are signed in, and how we spot sign-ins that may not be yours. If you turn notifications on, we also keep your device’s push token, a random registration code, and its language and time zone, so that notifications reach you at the right local time. If your account is connected to Telegram (see section 4), we keep your Telegram user ID, so that you can sign in from inside Telegram with one tap and receive reminders there. Each time the iOS or Android app checks for updates, it also sends a random installation ID, so that when you report a problem we can tell which installation ran into it.

3. Where your data is stored

As a guest, your cards, expense records, and preferences are stored on your device (local storage) or in your Telegram cloud storage, which is tied to your Telegram account and synced by Telegram — not by us. We do not hold this data on our servers.

Once you bind an email address, your expense records and cards are stored on our servers so they can sync across your devices. A copy also stays on each device, so the app keeps working offline.

4. Third-party services

We share the minimum necessary with a small number of providers:

  • Google Gemini — the receipt photos and the PDF statements you upload are processed to extract the merchant, the amounts and the dates. Text you ask us to translate, such as a comment in a shared group, is processed in the same way. Google processes this data outside the UK, under Google’s standard data-protection terms.
  • Resend — sends the emails we send you, such as verification codes, account notices, and the reminders and group updates you choose to receive by email.
  • Cloudflare — runs the app and our API. It stores the receipt and card images you upload. It also holds a synchronisation copy of your records, such as your expenses, cards and budgets, so that your devices stay up to date. It holds encrypted backups of our database. Its Web Analytics loads only after you accept analytics cookies, and it counts page views anonymously (see section 11). It also keeps request logs, which include IP addresses, installation IDs and crash logs from update checks, for 7 days (see section 7).
  • Paddle — processes the payment when you subscribe to Hipzap Plus on the web, and sets the cookies its checkout needs.
  • Netcup — the German provider whose server, in Germany, holds our database.
  • Backblaze B2 — holds encrypted backups of that database in a separate location.
  • RevenueCat — handles subscriptions bought inside the iOS and Android apps. It receives your Hipzap account identifier and the app store’s subscription identifiers, so we can tell whether your Plus is active.
  • Apple and Google — when you turn notifications on, your device’s push token and the contents of each notification pass through Apple’s or Google’s push service to reach your device. Those contents include the title and the text of the notification, the group the notification belongs to, and the screen it opens in the app. Separately, if you add a card to Apple Wallet, Apple holds a push token for that card so that we can send updates to it. That happens whether or not you have turned notifications on.
  • Telegram — our team receives technical alerts in a Telegram channel. An alert about an error in the web or Telegram version of Hipzap can include the error message and where in the code it happened, the address of the page you were on, and the details your browser reports about itself (such as the browser, operating system and device type) and its language. An alert about a problem on our servers can include the address that was requested. An alert about changes that could not be synced says how many people are affected and gives a brief error message.
  • Telegram (reminders) — if your Hipzap account is connected to Telegram, your reminders for card payments and recurring bills are also sent to you as messages from our Telegram bot, which means Telegram receives them in order to deliver them. Your account is connected automatically when you add an email address while using Hipzap inside Telegram, or when you choose to link Telegram in your account settings. These reminders are on by default. Each reminder includes the name of the recurring bill or, for a card payment, the card number as masked on your statement (such as its last four digits), and when it is due, but not the amount. You can switch Telegram reminders off in your notification settings.

Some of these providers are based outside the UK, and some of them process your data outside the UK. Where we send personal data outside the UK, we rely on a transfer mechanism allowed by UK data protection law, such as the UK International Data Transfer Addendum to the European Commission’s standard contractual clauses. If you would like a copy of the safeguards that apply to a particular provider, email support@hipzap.net and we will send it to you.

5. How we use your data

We use your data to run the app — to extract and categorise expenses, store and display your cards, sync bound accounts across devices, and secure your account — and to count anonymous usage statistics that show us which parts of the app work and which do not (section 11). We do not sell your data or use it for advertising.

Our legal bases are: performing our contract with you (running the app, syncing your bound account, and taking payment for Hipzap Plus); our legitimate interests (keeping the Service secure, preventing abuse, handling reports, and measuring how the Service is used so we can improve it); and your consent where you give it. Where we rely on consent, you can withdraw it at any time.

We use diagnostics, crash logs, installation IDs and sign-in records to keep Hipzap working and secure: to find and fix faults, including working out which installation ran into a problem you report, and to spot sign-ins that may not be yours. We rely on our legitimate interests for this, and we do not use this data for anything else. Sending you notifications and reminders is part of running the app for you (our contract with you); you can switch each kind off in your notification settings.

6. Your rights

You are in control of your data:

  • Delete your account — from your account settings. Your account is deactivated straight away and you are signed out everywhere. If you sign in again within 30 days, everything comes back. After 30 days we permanently delete your expense records, receipt images, cards, budgets and personal ledgers, including the image files in our storage.
  • Access and correct — view and edit your expense records and cards at any time in the app.
  • Guest data — clearing the app or your Telegram cloud storage removes guest data from that surface.
  • Portability, restriction and objection — you can ask for a copy of your data in a portable form, ask us to restrict or stop certain processing, or object to it. Email support@hipzap.net. If you are not happy with our response, you can complain to the UK Information Commissioner’s Office (ico.org.uk).

7. Data retention

Your expense records are kept until you delete them or close your account. Receipt photos are deleted sooner: we keep them for up to 10 days on the free plan and up to 90 days with Hipzap Plus, and there is also a storage limit (50 MB free, 500 MB with Plus) — when either limit is reached, the oldest photos are deleted first. The expense records themselves are not affected. When you close your account there is a 30-day window during which signing in restores it; after that the data is permanently deleted. Entries and comments you wrote inside a shared group stay with that group so the group’s records remain readable to the other members. Guest data lives only on your device or in your Telegram cloud storage for as long as you keep it there. Anonymous usage statistics are kept separately and for a shorter time — see section 11.

If you unsubscribe from marketing emails, we keep a record of that choice even after you close your account. We store it as a one-way hash of your email address, not the address itself. Without it, signing up again with the same address would start those emails over — which is the opposite of what you asked for.

Records of where you are signed in are deleted 30 days after that session ends — for example, when you sign out, sign that device out, or the session expires. The details we keep to send notifications to a device (its push token and registration code) are deleted when you sign out on that device, when Apple or Google tells us the device can no longer receive notifications, or as soon as you ask us to close your account. If you add a card to Apple Wallet, the registration Apple Wallet makes with us for that card is deleted when you remove the card from Apple Wallet. When you close your account, all remaining sign-in records are deleted at the end of the 30-day window described above. Technical alerts in our team’s Telegram channel, including the error details described in section 4, are deleted automatically after 30 days. The request logs kept by Cloudflare, our hosting provider, include IP addresses, installation IDs, crash logs from update checks and the sync reports described in section 2, and are kept for 7 days. When a sync problem is reported, the account it relates to is also held for up to six hours so that we can count how many people are affected; after that, only the counts remain.

8. Children

The Service is not directed at children under 13, and we do not knowingly collect their data.

9. Changes

We may update this policy as the Service evolves. Material changes will be reflected by the “last updated” date above.

10. Contact

Questions or requests about your data? Email support@hipzap.net.

The data controller for the Service is:

Legal name
CODER TECH LTD
Registration number
16353079
Registered office
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Contact
support@hipzap.net

11. Cookies and on-device storage

The web and Telegram versions use a small number of cookies and similar browser-storage techniques, in two groups: strictly necessary ones the app cannot work without, and analytics that runs only with your consent. The iOS and Android apps use no advertising or tracking cookies; signing in inside the apps relies on the same strictly necessary session cookies as the web version, kept by your device’s operating system. All four versions — web, Telegram, iOS and Android — also send us anonymous usage statistics, described at the end of this section, which you can switch off at any time.

  • Signing in (strictly necessary) — hipzap_session (kept for up to 7 days) and hipzap_refresh (up to 30 days) are HttpOnly cookies that identify your signed-in session and keep you signed in; hipzap_auth and hipzap_tier (up to 7 days) are companion hints so the interface can show the right signed-in state without exposing the session token. Opening Hipzap through an invite or introduction link may also set a cookie for up to 30 days that records which link brought you, so sign-up can honour that link.
  • Preferences and offline data (strictly necessary) — your language (hipzap_locale, kept for up to a year), your cookie choice, display settings, and the on-device copy of your cards and expense records that keeps the app usable offline (see section 3). None of it is used for tracking.
  • Analytics — anonymous page-view counts via Cloudflare Web Analytics, plus the usage statistics described below. On the web and in Telegram these are sent only after you accept analytics cookies; the iOS and Android apps set no analytics cookies at all and send the usage statistics directly, with the switch described below to stop them. No cross-site tracking and no advertising identifiers.
  • Device identifiers (strictly necessary) — the iOS and Android apps keep a random installation ID on your device (shown as “Diagnostic ID” on the Help & Support page, so you can include it when you contact us), which is sent when the app checks for updates so that we can trace faults you report, and, if you turn notifications on, a random registration code for push notifications. Neither is used for advertising or to track you across other apps or websites.

You can change your choice at any time via “Cookie Preferences” in the page footer or on the Policy & Support page, or by clearing site data in your browser.

Usage statistics — we count how far people get through the main steps of the app, so we can see where it goes wrong and fix it. An event records only that a step happened: a receipt was scanned, an extraction finished, a card was saved, the subscription page was opened. It never carries your amounts, merchants, categories, line items, notes, card or group names, search terms, photos or file names, and it carries no account, device or advertising identifier. Besides the step itself, an event carries only which of our apps you are using (iOS, Android, web or Telegram) and its version number, plus — the first time you open the app — the language it is set to. We do not store your IP address with the statistics either: our server uses it only for a moment, mixing it with your browser or app identification and a secret we replace every day to produce a one-way code, so events from the same day can be counted as one visit while events from different days cannot be linked at all — the address itself is never stored with the statistics. To be precise about two things, both of which are there for security and fault-finding and are not part of the statistics: like every other public part of our service, the web address these events are sent to is rate-limited to stop abuse, which briefly holds a counter against your IP address for five minutes; and, like every request to our service, the request that carries the events appears in the request logs kept by Cloudflare, our hosting provider, for 7 days (see section 7). Those logs show your IP address and that a request was made, but not what the events say.

We keep individual events for up to 3 months; after that only daily counts per event and platform remain, for up to 25 months. For statistics of this kind — used only to measure and improve our own service, not passed to any analytics company, and never used for advertising or to build a profile of you — UK privacy rules do not require us to ask for your consent, as long as we explain it clearly and give you a simple, free way to object. This is that explanation, and here is the way to object: “Help improve Hipzap”, in Settings → Privacy & security, switches the statistics off on that device immediately and clears anything still waiting to be sent. On the web and in Telegram we ask anyway, as part of your cookie choice. A small number of counts are recorded by our servers rather than by the app — that a sign-in code was sent, or that a reminder went out — and those carry no identifier of any kind, so they cannot be traced back to you and are not affected by the switch.