Warranty Sage Privacy Policy
Effective date: 17 August 2026
Warranty Sage works without an account. Signed out, the app makes no network calls at all.
Signing in is optional, and it exists for two features: a free cloud backup of your vault,
and receipt scanning. This policy explains what we hold when you sign in, and that we hold
nothing when you do not.
In plain English
-
Your items, photos, reminders and exports all live on your phone. Signed out, nothing you
store is sent anywhere, to us or to anyone.
-
If you sign in with Google, we store the account identifier Google gives us and, if Google
returns one, your email address. The email is used only to answer support mail you send
us; it is never a login key you can lose.
-
Cloud backup is a mirror. While signed in, your item records and photos are copied to
storage we operate, so a second device or a replacement phone can get them back. The phone
holds the original; deleting the account deletes the mirror, not the vault.
-
Receipt scanning sends the photographed receipt to be read, then discards it. The image is
not stored and not logged.
-
We run on Cloudflare's infrastructure, and Cloudflare is the only company that processes
data for us. Google signs you in and distributes the app through Google Play.
- No ads, no trackers, no analytics, no crash reporting, no selling data. Ever.
-
You can export your whole vault as a single file at any time, signed in or not, and delete
your account in the app or at
warrantysage.whataboutalist.app/delete-account.
1. Data controller
The data controller responsible for your personal data is the individual developer of
Warranty Sage, established in Greece. For any privacy-related enquiry, contact
christos@sudo-ezekiel.com.
2. Data we collect
Everything in this section applies only while you are signed in. Signed
out, the app makes no network calls and we receive nothing.
-
Account data: The account identifier Google supplies when you sign in,
which links your sign-ins to one account, and your email address if Google returns one.
The email is kept for support correspondence only; it is never required and never used as
a credential.
-
Session records: A hashed session token and its expiry per signed-in
device, so you stay signed in. We never store the token itself, and we never retain the
Google ID token used at sign-in.
-
Item records: The items you choose to back up: names, stores, prices,
purchase dates, warranty lengths, serial numbers and notes. They are stored as opaque
records that our server saves and serves back without parsing or reading their contents.
-
Photos: Receipt and product photos you back up, kept in a private storage
bucket and served only to the account that uploaded them.
-
Receipt scans (processed and discarded): When you scan a receipt, the
image is sent to be read and is then discarded. It is never written to storage and never
logged, including when a scan fails or is retried. We keep a count of how many scans your
account has used in the current month (scanning is capped at 10 scans per calendar month).
-
Purchase state: Whether your account has made the one-time storage
purchase, recorded after the purchase is verified with Google Play. We never see or store
payment details; Google Play handles the payment.
-
Support email content: If you email us, we keep the correspondence for as
long as needed to resolve your request.
3. Data we do NOT collect
- Signed out, nothing. The app makes no network calls until you sign in.
- No analytics or tracking services, and no crash reporting.
- No advertising identifiers, and no ads.
- No location tracking.
- We never sell or monetize your data in any way.
-
We do not read, mine, analyze or train anything on your vault contents. Items and photos
are stored to be served back to the account that wrote them, and for no other purpose.
-
We do not store scanned receipt images, plaintext session tokens, Google ID tokens, or
payment card details.
If a future version ever adds an analytics or crash-reporting feature, it will be opt-in and
this policy will be updated first.
4. Legal basis for processing
-
Contract performance (GDPR Article 6(1)(b)): Processing your account
data, session records, item records and photos is necessary to provide the services you
turn on by signing in: cloud backup, multi-device sync, and receipt scanning.
-
Legitimate interest (Article 6(1)(f)): Keeping a free service available:
per-account storage and scan quotas, per-address limits on account creation, the
platform-level protections Cloudflare applies in front of our API, and answering support
mail you send us.
5. How we use your data
- Authentication: To sign you in and identify your account.
- Backup and sync: To keep a copy of your vault on our servers and deliver it to your devices.
- Receipt scanning: To read the receipt you photograph and return the extracted fields to you. The image itself is discarded after the scan.
- Purchase verification: To confirm the one-time storage purchase with Google Play and raise your account's storage ceiling.
- Support: To answer questions you email us.
We send no email of any kind: no marketing, no verification mail, no notifications. We do
not use your data for advertising, profiling, or any automated decision-making with legal
effect.
6. Data sharing
We never sell your data. Data is visible to or handled by:
-
Service providers (processors): The companies listed in section 7, which
host and deliver the service under our instructions and their data processing terms.
-
Legal requirements: We may disclose data if required by law or to protect
our legal rights. We have never received such a request.
Nobody else. Warranty Sage is single-user: there are no groups, no shared vaults, and no
other user who can see your data.
7. Third-party processors
| Processor | Role | Data touched |
| Cloudflare, Inc. |
Hosting and storage: Workers (the API and this website), D1 (database), R2 (photos), KV (a cache of Google's public signing keys, which holds no user data), and Workers AI (reading scanned receipts) |
All server-stored data listed in section 2; scanned receipt images during the scan only, after which they are discarded |
| Google LLC |
Sign-in (Google is the identity provider that authenticates you and tells us your account identifier and email), app distribution through Google Play, and payment handling for the one-time purchase through Google Play Billing |
Your Google account identity at sign-in, under Google's own privacy policy; install, update and purchase handling by Google Play |
| Buy Me a Coffee |
Optional donation page. Not a processor for us: it receives nothing unless you go there yourself |
Nothing, unless you choose to visit and donate. The link opens in your system browser; any data you enter there is governed by Buy Me a Coffee's own privacy policy. Donating grants no in-app benefit and we receive no personal data back from it. |
Receipt scanning runs on Cloudflare's Workers AI, on the same infrastructure as everything
else, precisely so that reading a receipt adds no additional processor to this table. No
other third parties receive your data.
8. International data transfers
Your data is stored on Cloudflare's infrastructure, which may process and store data on
servers located outside the European Economic Area (EEA), including in the United States.
Cloudflare's Data Processing Addendum incorporates the EU Standard Contractual Clauses
(SCCs) as the legal mechanism for these transfers, ensuring your data receives an equivalent
level of protection. Signing in involves Google, which processes your Google account data
under its own privacy policy and transfer mechanisms.
9. Data retention
- Active accounts: We retain your data for as long as your account exists.
-
Account deletion: Requesting deletion signs out every device immediately
and starts a seven-day window. When the window ends, a daily job permanently erases
everything we hold for the account: the account record, session records, item records,
photos, scan counters and purchase state. Signing in again during the window cancels the
deletion. See section 13.
- Scanned receipt images: Never retained. Discarded when the scan completes or fails.
- Support correspondence: Kept only as long as needed to resolve your request.
10. Data storage and security
- All traffic between the app and our servers is encrypted in transit (TLS).
- Data at rest in Cloudflare D1 and R2 is encrypted by Cloudflare.
-
Every API request is authenticated, and every read and write is checked server-side
against the account it belongs to. Photos live in a private bucket that is never publicly
reachable and are served only to the account that uploaded them.
-
Session tokens are stored on our side as hashes, never in readable form, and on your
device in the operating system's secure storage rather than in plain text. Google's
identity tokens are verified against Google's published signing keys and are not retained.
-
Our server logs may record IP addresses and account identifiers for operating the service.
They never contain item contents, photo bytes, scanned text, or session tokens. A scan is
logged as a quota increment and nothing about what was scanned.
- Our API sits behind Cloudflare, which applies its platform-level protections to every request.
No system is perfectly secure, but the amount of data we hold is the minimum the features
you turn on need, and the default is that we hold nothing at all.
11. Your rights under GDPR
- Right of access (Article 15): Request a copy of the personal data we hold about you.
- Right to rectification (Article 16): Request correction of inaccurate or incomplete data.
- Right to erasure (Article 17): Request deletion of your personal data.
- Right to restriction (Article 18): Request that we limit how we process your data in certain circumstances.
- Right to data portability (Article 20): Request your data in a structured, machine-readable format.
- Right to object (Article 21): Object to processing based on legitimate interest.
12. How to exercise your rights
-
Access and portability: Use the in-app export (Settings, then Backup) at
any time, signed in or not. It produces one file containing your complete vault: every
item and every photo. Because the server only ever holds a mirror of that vault plus the
account data listed in section 2, the export is a full copy of your content. If you cannot
reach the app, email christos@sudo-ezekiel.com.
-
Rectification: Every field of every item is editable in the app, and
edits sync to the mirror. To correct account data (your email address), email us.
-
Erasure: Delete your account in the app (Settings, then Delete account),
or on the web at
warrantysage.whataboutalist.app/delete-account,
which works after you have uninstalled the app.
- Anything else: Email us. We respond within 30 days.
13. Account deletion
You can delete your account two ways:
What happens when you request deletion:
- Every signed-in device is signed out immediately and syncing stops immediately.
-
A seven-day window starts. When it ends, everything we hold for the account is permanently
erased: the account record, sessions, item records, photos, scan counters and purchase
state.
-
Signing in again during the seven days offers to cancel the deletion. The window exists so
that a misclick, or someone briefly holding your unlocked phone, cannot irreversibly
destroy your backup.
-
The vault on your phone is untouched unless you also tick "erase this
device too" when deleting from the app. Deleting the account deletes the mirror, not the
vault: your items, photos and reminders keep working on the phone exactly as they did
before you ever signed in.
14. Breach notification
If a personal data breach occurs that is likely to result in a risk to your rights and
freedoms, we will notify the competent supervisory authority within 72 hours of becoming
aware of it (GDPR Article 33) and, where the risk is high, notify affected users directly
without undue delay (GDPR Article 34), describing what happened, what data was involved, and
what we are doing about it.
15. Cookies and local storage
The Warranty Sage app is not a tracking website and sets no advertising or analytics cookies.
-
On your device, the app stores your vault (items and photos), your
preferences (for example the theme), and, if you sign in, your session token in the
operating system's secure storage.
-
Our web pages (this policy, the terms, the deletion page) set no cookies.
The deletion page loads Google's own sign-in script, because signing in with Google is how
the page verifies that the account is yours; that script runs on that page only and is
governed by Google's privacy policy. Cloudflare may set strictly technical cookies or
headers needed to serve and protect the site; these are not used to track you across
sites.
16. Children's privacy
Warranty Sage is a household tool intended for adults. It is not directed at children under
13, and we do not knowingly collect data from children. If you believe a child has provided
us with personal data, contact us and we will delete it promptly.
17. California privacy rights
Warranty Sage does not meet the thresholds that make the CCPA/CPRA apply to it. Regardless,
for California residents: the categories of personal information we collect, and only if you
sign in, are identifiers (a Google account identifier and an email address), user-generated
content (item records) and photos. We do not sell or share personal information as those
terms are defined in the CPRA. You can exercise rights to know, correct, and delete through
the same mechanisms described in section 12, without discrimination.
18. Right to lodge a complaint
If you believe we are handling your data unlawfully, you have the right to lodge a complaint
with your local supervisory authority. In Greece, this is the Hellenic Data Protection
Authority (HDPA): www.dpa.gr, Kifissias 1-3, 115 23 Athens,
Greece, +30 210 6475 600.
19. Changes
We may update this policy from time to time. Changes will be posted on this page with an
updated effective date. For significant changes, we will notify signed-in users in the app
before the changes take effect.
20. Contact
Questions about this policy:
christos@sudo-ezekiel.com