Information We Collect
When you use Paragonix, we collect:
- Authentication Data: Email address, name, and profile picture from OAuth providers (Google, Microsoft, GitHub)
- Receipt Data: Receipt images and text extracted via OCR/AI parsing
- Usage Data: Upload counts, timestamps, and session information
- Technical Data: IP address, browser type, and device information
How We Use Your Information
We use your data to:
- Process receipt uploads using Google's Gemini AI for text extraction and parsing
- Enable real-time WebSocket collaboration on receipt splitting
- Enforce daily scan limits (currently 10 receipts per 24 hours when signed in, and 2 for guests)
- Display contextual advertisements through Google AdSense
- Improve our service and user experience
Our Legal Basis for Using Your Data
Under Article 6 of the GDPR, we must have a legal basis for each purpose. Ours are:
- Performance of a contract (Art. 6(1)(b)): creating and running your account, storing your receipts, scanning them with our AI provider, calculating the split, and showing other participants what they owe. This is what you asked us to do, and we cannot provide the service without it.
- Our legitimate interests (Art. 6(1)(f)): enforcing daily scan limits, preventing abuse and fraud, keeping security logs, and comparing de-identified price statistics across receipts to operate internal Statistix features and, after separate legal review, support a future public ParagonIX price index. Our interest is keeping a free service available and useful; we have weighed this against your rights, and you can object or opt out at any time from your profile.
- Your consent (Art. 6(1)(a)): analytics, advertising cookies, and reimbursement reminder emails. Each is asked for separately, and you can withdraw any of them at any time — through Cookie Settings for the first two, and from your profile for reminder emails. Withdrawing does not affect processing carried out beforehand.
- Legal obligation (Art. 6(1)(c)): keeping records we are required to keep, and responding to lawful requests from authorities.
Third-Party Services
We share data with the following service providers:
- Google — Gemini API (United States): Your receipt image is sent to Google for AI text extraction and parsing. We use the paid tier of the Gemini API, under which Google does not use your receipts to train or improve its models, and retains them only for a limited period to detect abuse and to meet legal obligations. OpenAI, Anthropic and xAI are configured as alternative providers; we will update this policy before changing the provider that processes your receipts. Transfers to the United States rely on the EU–U.S. Data Privacy Framework, under which Google LLC is certified.
- Google AdSense: We display contextual advertisements using only product names, categories, and seller location from receipts. No personal information is shared with advertisers.
- Google Analytics (United States): Aggregated, pseudonymous usage analytics. We never send your name, email, or receipt contents — data is keyed to a random identifier only, with Google Signals and ad personalization disabled. Analytics cookies are set only with your consent.
- OAuth Providers: Google, Microsoft, and GitHub for authentication only.
- AWS S3: Encrypted storage for receipt images.
- reCAPTCHA Enterprise: Google's spam and bot protection service.
Note: We do NOT sell your personal data to any third parties.
Data Storage and Security
Your data is protected with:
- Encrypted PostgreSQL database storage
- HTTPS encryption for all communications
- Access controls and authentication requirements
- Automatically rotated logs, kept for security monitoring
Data Retention
- Receipts scanned as a guest (not signed in): deleted automatically 7 days after they are created, together with the uploaded image — unless a signed-in user has joined the receipt, in which case it is kept for them.
- Receipts on a signed-in account: kept until you delete the receipt or your account, either of which you can do at any time. Deleting a receipt nobody else has joined removes it and its image; on a shared receipt we remove you and leave the other participants' split intact.
- User accounts: Retained until deletion is requested
- Security logs: rotated automatically — we keep a limited number of recent log files, so how far back they reach depends on how busy the service has been.
- De-identified price-statistics rows: rows in the ParagonIX fact store may be kept longer than account receipts and may survive receipt or account deletion, because they are built without account identifiers, session identifiers, receipt tokens, receipt numbers, buyer identity, cashier or terminal identifiers, and clock times. You can opt out from your profile before future eligible receipts enter that feed.
ParagonIX Price Statistics Boundary
The public ParagonIX price index is not currently enabled. The technical feed for it is limited to de-identified receipt rows: seller, city, country, postal code, purchase date, currency, receipt total, item names, quantities, prices, and categories. It excludes account IDs, emails, session IDs, receipt tokens, receipt numbers, buyer names, buyer tax IDs, cashier IDs, terminal IDs, and exact clock times. Published index pages, if enabled after legal review, will show only aggregate series that meet contributor and receipt-count thresholds, not raw receipt rows.
Automated access to the service remains governed by the Terms of Service. We may permit normal search-engine crawling of public pages, but scraping private receipts, raw datasets, or non-public endpoints is not allowed.
Your Rights Under GDPR
You have the following rights regarding your personal data:
- Access: Request a copy of your data via Export Data
- Rectification: Correct inaccurate data through your profile
- Erasure: Delete your account and all associated data via Delete Account
- Portability: Receive your data in machine-readable JSON format
- Objection: Object to data processing by contacting us
User Content and Ownership
Users retain all rights to uploaded receipt images. AI-generated parsed data (JSON structures, extracted text) has no copyright protection.
Data Controller
Alibee (Tax ID: 5792070360), established in Poland, acts as Data Controller for all user data processed through Paragonix. You can reach us at support@paragonix.pl.
Children's Privacy
Paragonix is not intended for users under 16 years old. We do not knowingly collect data from children under 16. Poland, where we are established, sets the age of consent for online services at 16 under Article 8 GDPR.
Cookies and Tracking
We use cookies for:
- Session management and authentication
- Security and CSRF protection
- Analytics (Google Analytics) and advertising (Google AdSense)
Google Consent Mode v2 is implemented to manage advertising and analytics cookies in compliance with GDPR.
Governing Law and Jurisdiction
This Privacy Policy is governed by Polish law. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of Polish courts.
Changes to This Policy
We may update this Privacy Policy from time to time. Continued use of the service after changes constitutes acceptance of the updated policy. Users will be notified of significant changes via banner notification.
Contact Us
For privacy concerns or data requests, email us at support@paragonix.pl, or use our feedback form.
You also have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa).