Privacy Policy
Last Updated: April 2026
Summary: Hikae stores your receipt data locally on your device. Free users enjoy fully on-device processing. Pro users' receipt images are securely sent to our server for AI-powered extraction, then immediately discarded after processing. We do not store, sell, or share your receipt images or personal data.
Introduction
This Privacy Policy describes how Hikae ("we", "our", or "the app") handles your information. We are committed to protecting your privacy and being transparent about our practices.
Data collection and storage
What we collect
Hikae collects and stores the following data locally on your device:
- Receipt data: Store name, date, total amount, tax amount, currency, and line items extracted from scanned receipts
- Receipt images: Photos of your receipts, stored as JPEG files on your device
- Categories: Auto-assigned and user-edited spending categories
- Preferences: App settings and notification preferences
How we store your data
All data is stored locally on your device only using a local SQLite database. This means:
- Your receipt data and images are not uploaded to any server for storage
- You have full control over your data at all times
Exception: Pro users who enable iCloud Sync have their receipt data backed up to their personal Apple iCloud account. See the iCloud Sync section below for details.
AI-powered extraction (Pro feature)
Important: This section applies only to Pro subscribers. Free users use fully on-device OCR processing โ no data ever leaves the device.
When Pro users scan a receipt, the receipt image is:
- Sent securely (HTTPS) to our processing server hosted on Cloudflare
- Forwarded to a third-party AI provider (currently Google Gemini) for text extraction
- Immediately discarded after the extraction result is returned โ we do not store, cache, or log your receipt images on our servers
The extracted text data (store name, amounts, items) is returned to your device and stored locally. The image itself is never retained on any server.
Third-party AI provider
We currently use Google's Gemini API for receipt extraction. Google's data usage policy for their API applies. We may change AI providers in the future to improve accuracy or reduce costs โ this policy will be updated accordingly. Regardless of provider:
- Images are sent only for the purpose of text extraction
- No personal identifying information is sent alongside the image
- We use API-tier access which does not use your data for model training
Data we do NOT collect
Hikae does not collect, transmit, or process:
- Personal identifying information (name, email, phone number, etc.)
- Location data
- Device identifiers for tracking purposes
- Usage analytics or crash reports
- Any data from other apps on your device
Hikae Pro and subscriptions
Purchase processing
- Subscriptions are processed through Apple's App Store (In-App Purchase)
- We use RevenueCat as our payment infrastructure to manage subscription status
- RevenueCat receives an anonymous app user ID and purchase transaction data from Apple โ no personal information (name, email, etc.) is shared
- We do not collect or store any payment details โ Apple handles all billing
iCloud Sync (Pro feature)
Pro users have the option to enable iCloud Sync for their receipt data:
- Data is synced through your personal Apple iCloud account via Apple's CloudKit framework
- Only you can access your iCloud data โ it is tied to your Apple ID
- We do not have access to your iCloud data
- Sync can be disabled at any time; local data is always preserved
Widget data sharing
The app uses Apple's App Groups feature to share spending data between the main app and home screen/lock screen widgets. This sharing happens entirely on your device and does not involve any external servers.
Third-party services
Hikae uses the following third-party services:
- RevenueCat: Subscription management. Receives only an anonymous user ID and Apple transaction data
- Google Gemini API: Receipt image extraction for Pro users only. Images are processed and immediately discarded
Hikae does not use:
- No analytics services (e.g., Google Analytics, Firebase)
- No advertising networks
- No crash reporting tools
- No social media integrations
Data retention and deletion
How long we keep your data
Your data remains on your device until you:
- Delete individual receipts within the app
- Delete the app from your device
- Reset or restore your device
How to delete your data
To permanently delete all your data, delete the app from your device. All receipt data, images, and preferences will be removed.
Children's privacy
Hikae is not directed at children under 13 years of age and does not knowingly collect information from children.
Data security
We take data security seriously:
- All data is stored locally on your device
- The app does not require an account or login
- When receipt images are sent for AI extraction (Pro only), all communication uses HTTPS encryption
- Receipt images are never stored or logged on our servers
Your rights
You have complete control over your data:
- Access: All your data is visible in the app
- Modification: You can edit any receipt data at any time
- Deletion: You can delete individual receipts or all data
- Export: Pro users can export data as CSV or PDF
Changes to this privacy policy
We may update this Privacy Policy from time to time. When we do:
- The "Last Updated" date at the top will be revised
- If changes are significant, we will notify users through an app update description
- Continued use of the app after changes constitutes acceptance of the new policy
International data transfers
For Pro users, receipt images are temporarily processed on servers operated by Cloudflare (global edge network) and forwarded to Google's API infrastructure. These transfers are encrypted and the images are not stored. For free users, no data leaves the device.
Legal basis for processing (GDPR)
For users in the European Economic Area, our legal basis for processing your data is:
- Consent: By using the app and scanning receipts, you consent to local storage of receipt data
- Consent (Pro): By subscribing to Pro and using AI extraction, you consent to temporary processing of receipt images on our servers
- Legitimate interest: Providing receipt scanning functionality requires storing the data you capture
You may withdraw consent at any time by deleting your data or uninstalling the app.
California privacy rights (CCPA)
For California residents:
- We do not sell your personal information
- We do not share your personal information with third parties for marketing
- All data is stored locally on your device
Compliance
This app complies with:
- Apple App Store review guidelines
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- Children's Online Privacy Protection Act (COPPA)
- Act on the Protection of Personal Information (APPI) โ Japan