Warranty Sage Privacy Policy

Effective date: 17 August 2026

Warranty Sage works without an account. Signed out, the app makes no network calls at all. Signing in is optional, and it exists for two features: a free cloud backup of your vault, and receipt scanning. This policy explains what we hold when you sign in, and that we hold nothing when you do not.

In plain English

1. Data controller

The data controller responsible for your personal data is the individual developer of Warranty Sage, established in Greece. For any privacy-related enquiry, contact christos@sudo-ezekiel.com.

2. Data we collect

Everything in this section applies only while you are signed in. Signed out, the app makes no network calls and we receive nothing.

3. Data we do NOT collect

If a future version ever adds an analytics or crash-reporting feature, it will be opt-in and this policy will be updated first.

4. Legal basis for processing

5. How we use your data

We send no email of any kind: no marketing, no verification mail, no notifications. We do not use your data for advertising, profiling, or any automated decision-making with legal effect.

6. Data sharing

We never sell your data. Data is visible to or handled by:

Nobody else. Warranty Sage is single-user: there are no groups, no shared vaults, and no other user who can see your data.

7. Third-party processors

ProcessorRoleData touched
Cloudflare, Inc. Hosting and storage: Workers (the API and this website), D1 (database), R2 (photos), KV (a cache of Google's public signing keys, which holds no user data), and Workers AI (reading scanned receipts) All server-stored data listed in section 2; scanned receipt images during the scan only, after which they are discarded
Google LLC Sign-in (Google is the identity provider that authenticates you and tells us your account identifier and email), app distribution through Google Play, and payment handling for the one-time purchase through Google Play Billing Your Google account identity at sign-in, under Google's own privacy policy; install, update and purchase handling by Google Play
Buy Me a Coffee Optional donation page. Not a processor for us: it receives nothing unless you go there yourself Nothing, unless you choose to visit and donate. The link opens in your system browser; any data you enter there is governed by Buy Me a Coffee's own privacy policy. Donating grants no in-app benefit and we receive no personal data back from it.

Receipt scanning runs on Cloudflare's Workers AI, on the same infrastructure as everything else, precisely so that reading a receipt adds no additional processor to this table. No other third parties receive your data.

8. International data transfers

Your data is stored on Cloudflare's infrastructure, which may process and store data on servers located outside the European Economic Area (EEA), including in the United States. Cloudflare's Data Processing Addendum incorporates the EU Standard Contractual Clauses (SCCs) as the legal mechanism for these transfers, ensuring your data receives an equivalent level of protection. Signing in involves Google, which processes your Google account data under its own privacy policy and transfer mechanisms.

9. Data retention

10. Data storage and security

No system is perfectly secure, but the amount of data we hold is the minimum the features you turn on need, and the default is that we hold nothing at all.

11. Your rights under GDPR

12. How to exercise your rights

13. Account deletion

You can delete your account two ways:

What happens when you request deletion:

14. Breach notification

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it (GDPR Article 33) and, where the risk is high, notify affected users directly without undue delay (GDPR Article 34), describing what happened, what data was involved, and what we are doing about it.

15. Cookies and local storage

The Warranty Sage app is not a tracking website and sets no advertising or analytics cookies.

16. Children's privacy

Warranty Sage is a household tool intended for adults. It is not directed at children under 13, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

17. California privacy rights

Warranty Sage does not meet the thresholds that make the CCPA/CPRA apply to it. Regardless, for California residents: the categories of personal information we collect, and only if you sign in, are identifiers (a Google account identifier and an email address), user-generated content (item records) and photos. We do not sell or share personal information as those terms are defined in the CPRA. You can exercise rights to know, correct, and delete through the same mechanisms described in section 12, without discrimination.

18. Right to lodge a complaint

If you believe we are handling your data unlawfully, you have the right to lodge a complaint with your local supervisory authority. In Greece, this is the Hellenic Data Protection Authority (HDPA): www.dpa.gr, Kifissias 1-3, 115 23 Athens, Greece, +30 210 6475 600.

19. Changes

We may update this policy from time to time. Changes will be posted on this page with an updated effective date. For significant changes, we will notify signed-in users in the app before the changes take effect.

20. Contact

Questions about this policy: christos@sudo-ezekiel.com