Back to Moolo

Privacy Policy

Last updated: August 28, 2026

Moolo is a receipt-scanning expense tracker. This policy explains what happens to your information when you use it.

The short version: your receipts are stored on your device, not on our servers. To read a receipt, a photo of it is sent to an AI service and the result comes back to your device. We use anonymous analytics to improve the app, but never send your receipt content off your device. We don't sell your data, we don't show ads, and we don't have an account system that ties your receipts to your identity.

1. Who we are

Moolo is operated by Moolo Software, located in British Columbia, Canada.

For any privacy question, or to exercise the rights described in section 9, contact: hello@moolo.io

We are the organization responsible for the personal information described below, as that term is used in Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA).

2. What is stored on your device

Everything Moolo knows about your spending lives on your device:

This information is stored in your browser's local storage and IndexedDB, or in the app's local storage on iOS and Android. It is not transmitted to us, and we cannot see it.

This also means it is your responsibility. If you clear your browser data, uninstall the app, or lose the device, this information is gone. Moolo does not currently offer a backup or sync service.

3. What is sent off your device, and to whom

3.1 Reading a receipt

When you scan a receipt, two things leave your device:

A photo of the receipt is sent to OpenAI to be read. OpenAI's model transcribes the text and returns the store, date, line items, and prices.

The item names and store name from that transcription are then sent to Anthropic to be tidied up — turning abbreviated register text like "MILK 2% 4L HOMO" into a readable name. No prices, totals, or images are sent to Anthropic.

Both requests pass through our own server (hosted by Vercel), which holds the API credentials. We do not store the receipt image or the extracted data on that server.

What those providers do with it: Under their current API terms, neither OpenAI nor Anthropic uses data submitted through their APIs to train their models. OpenAI retains API inputs and outputs for a limited period (currently up to 30 days) for abuse monitoring before deleting them. These are their policies, not ours, and they may change — we encourage you to read them directly:

We may change AI providers in future. If we do, we will update this policy and ask you to review the disclosure again before your next scan.

3.2 Technical information at our server

To keep the service running and to prevent abuse, our server records the following for each scan request:

We use this to understand cost and reliability. It is not used for advertising or profiling.

3.3 Anonymous accuracy logging

When you correct something Moolo extracted, the app records that a correction happened — for example, "the store name was changed" or "3 of 12 items were edited." It records only that a change occurred and how many, never what the receipt said or what you typed. This tells us how accurate extraction is without ever seeing your data.

3.4 Displaying store logos

The store's website domain is sent to Brandfetch to fetch and display that store's logo in the app. Each time a logo is shown, Brandfetch receives the domain, along with your device's IP address, browser user agent, and the time of the request. It never receives item names, prices, totals, dates, the receipt image, or any account identifier — Moolo has no accounts.

4. What we do not do

5. Analytics

Moolo uses Google Firebase Analytics to understand how the app is used, so we can improve it. This service is operated by Google.

What we send: anonymous, aggregate usage events — for example, that a receipt was scanned or that the shopping list was opened — along with standard technical information Firebase collects automatically (such as device type, app version, and a random, resettable app-instance identifier).

What we never send: none of these events contain your receipt content. We never send store names, item names, prices, totals, dates, your shopping list contents, or any data extracted from your receipts to Firebase or Google. The events record that an action happened, never what was on your receipt.

This information is not tied to an account (Moolo has none), is not used for advertising, and is processed by Google under its own terms: firebase.google.com/support/privacy. You can find Google's data practices at policies.google.com/privacy.

Our marketing website (moolo.io) uses Vercel Web Analytics to count visits and understand which pages people view. It is privacy-friendly by design: it uses no cookies, does not record your session, and does not collect personal information or track you across sites. This is separate from the app analytics described above.

6. Legal basis and consent

We collect and use personal information with your consent, which you give by using the app after being shown the disclosure about AI processing that appears before your first scan. You can withdraw consent at any time by ceasing to use the scanning feature; because your receipts are stored locally, deleting the app removes them.

7. Storage and location of information

Your receipts remain on your device, wherever that is.

The limited technical information described in section 3.2 is processed on servers operated by Vercel Inc., Upstash Inc., and Google LLC, which may be located in the United States. Requests to OpenAI, Anthropic, and Brandfetch are processed on their infrastructure, which may also be located in the United States. Information stored outside Canada may be accessible to foreign courts and law enforcement under the laws of that jurisdiction.

8. Retention

9. Your rights

Under PIPEDA and BC's PIPA you have the right to:

Because your receipts are stored on your device and we do not operate accounts, most of this is directly in your hands — you can view, edit, and delete any receipt in the app at any time, and "Delete all receipts" in Settings removes everything.

For the limited technical information we do hold, contact us at hello@moolo.io and we will respond within 30 days.

If you are not satisfied with our response, you may contact:

10. Children

Moolo is not directed at children and is not intended for use by anyone under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

11. Security

Receipt data on your device is protected by your device's own security — your passcode, biometrics, and operating system protections. Data in transit to our server and to the AI providers is encrypted using TLS. API credentials are held on our server and never exposed in the app.

No system is perfectly secure. We cannot guarantee absolute security, and you should protect your device accordingly.

12. Changes to this policy

We may update this policy. When we make a material change — particularly a change to what is sent off your device or to whom — we will update the date at the top and show the disclosure again in the app before your next scan.

13. Contact

Moolo Software British Columbia, Canada hello@moolo.io