Chrometis Logo

Vaulto Privacy Policy

Effective date: May 18, 2026

Terms of Use Delete Account

1. Who We Are

Vaulto is operated by Chrometis OÜ, Ahtri tn 12, 15551 Tallinn, Estonia, registration number 17340556. Contact for privacy requests: vaulto@chrometis.com.

2. What Vaulto Does

Vaulto helps users capture, scan, import, organize, search, export, and review receipts and invoices. It can read content with OCR, QR parsing, and AI-assisted extraction, track warranties and spending, manage subscriptions, and support optional accountant sharing.

3. Data We Collect

  • Account and profile: email, user ID, sign-in data, name, date of birth if provided, language, country, plan, subscription status, app settings, analytics and ad consent choices.
  • Tax profile: personal NIF, company NIF, company name, and default tax profile if you add them.
  • Receipts and invoices: photos, scans, PDFs, shared files, thumbnails, QR data, extracted text, supplier/store names, NIF/VAT, buyer NIF, invoice numbers, ATCUD, dates, items, categories, brands, quantities, totals, VAT, discounts, notes, warranty data, and status.
  • Sharing and notifications: accountant email, share status, company NIF used for access control, push tokens, notification preferences, spending limits, and usage/fair-use counters.
  • Device, security, analytics, ads, and purchases: app version, operating system, diagnostics, logs, Firebase App Check integrity signals, optional analytics events, Free-plan ad interaction data, advertising identifiers where consent is required, and Apple/Google purchase entitlement data.

4. Permissions

The app may request camera access to scan documents, photo/file access to import documents, notification permission for reminders or accountant notifications, and tracking/advertising permission where required for personalized ads or ad measurement.

Vaulto does not intentionally request or use precise location, coarse location, microphone/audio recording, contacts, calendar, SMS, call logs, health data, or broad external storage permissions. If a platform, SDK, or operating system displays related technical strings because of bundled camera, document, advertising, or system frameworks, those permissions are not used by Vaulto unless a future feature is clearly disclosed and consented to where required.

5. How We Use Data

  • Provide login, storage, sync, search, export, warranty tracking, spending views, tax profiles, accountant sharing, and support.
  • Process images, PDFs, QR codes, and text with OCR and AI-assisted extraction.
  • Manage subscriptions, plan limits, entitlements, fair-use controls, ads, consent, security, fraud prevention, and abuse prevention.
  • Improve reliability and features through diagnostics and optional analytics.
  • Detect, investigate, prevent, and respond to fraud, forged documents, fake accounts, chargeback abuse, automated scraping, attempts to bypass subscriptions or ads, attacks against App Check or backend APIs, excessive OCR usage, and other violations.
  • Comply with legal obligations and enforce our terms.

OCR, QR, and AI extraction are best-effort features and can be wrong or incomplete. Review important data before relying on it.

Uploading images, PDFs, or other files for OCR/AI analysis or cloud storage may use mobile data and consume your internet plan, especially on mobile networks.

Vaulto does not replace the original receipt, invoice, or proof of purchase. You remain responsible for keeping and presenting the original document whenever requested by a store, warranty provider, employer, accountant, tax authority, government body, court, regulator, or any other entity with a valid reason to request it.

6. Legal Bases

Where GDPR applies, we rely on contract to provide the app, consent for optional analytics, personalized ads/tracking and notifications where required, legitimate interests for security, abuse prevention, diagnostics and service improvement, and legal obligation where applicable.

7. Service Providers and Sharing

We do not sell personal data. We use Google Firebase and Google Cloud for auth, database, storage, functions, App Check, hosting, logging and backend operations; OpenAI for backend OCR/AI extraction; Google Mobile Ads and Google UMP for Free-plan ads and consent; Apple App Store and Google Play for purchases and subscriptions; Expo for push notifications where enabled; and accountants/collaborators only when you enable sharing.

We may disclose account, transaction, security, and document-related data when reasonably necessary to investigate abuse, protect users or the service, enforce the Terms, respond to chargebacks or app store disputes, comply with valid legal process, or cooperate with tax, consumer protection, law enforcement, judicial, regulatory, or government authorities.

8. International Transfers

Data may be processed in the EEA, United States, and other countries where our providers operate. Where required, we use safeguards such as standard contractual clauses, adequacy decisions, provider data processing terms, or other lawful transfer mechanisms.

9. Retention and Deletion

We keep data while your account is active or while needed to provide the service. Temporary OCR analysis files are intended to be removed when no longer needed. On Free and Basic, receipt photos are intended to remain on your device after processing and are not included in persistent cloud photo storage. Premium and Pro may include persistent cloud photo storage.

You can delete your account in app Settings or at delete-account.html. When deletion is completed, we delete the authentication account, cloud profile, cloud receipts/invoices, associated cloud images where technically available, and related app data, and clear local data where possible. Some data may be retained for legal compliance, security, fraud prevention, disputes, accounting, or backups/log expiry. Subscriptions must be cancelled separately in Apple App Store or Google Play settings.

Deletion requests may be delayed or limited where we must retain specific records to protect against malicious activity, investigate suspected abuse, comply with law, resolve disputes, enforce rights, maintain audit logs, or prevent repeated violations. We retain only what we reasonably need for those purposes and restrict access where possible.

10. Your Choices and Rights

Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing, and to withdraw consent. In the app you can edit/delete records, export data, manage optional analytics, manage ad preferences where available, and delete your account. You can also contact vaulto@chrometis.com.

11. Security and Children

We use safeguards including encryption in transit, provider-managed controls, access controls, Firebase rules, App Check, and monitoring. For abuse prevention, we may use rate limits, fair-use counters, App Check tokens, integrity checks, server-side subscription and rewarded-ad validation, file type and size validation, storage path validation, audit logs, and account re-authentication before sensitive actions. We may suspend, restrict, or block access to features when activity appears fraudulent, abusive, automated, unsafe, or inconsistent with the Terms. No system is completely secure. Vaulto is not intended for children under 16 and we do not knowingly collect their data.

12. Changes

We may update this policy when app features, providers, laws, or data practices change. Material changes will be communicated in the app or on our website where appropriate.