LaCasitaOS

Privacy Policy

Last updated: 24 August 2026

LaCasitaOS (“the app”, “we”) helps people who share a home or a trip split expenses, run a chore rota and keep shared lists. This policy explains what personal data we process, why, on what legal basis, and what you can do about it. It is written for the General Data Protection Regulation (EU) 2016/679.

1. Who is responsible

The data controller is the operator of LaCasitaOS. You can reach us at any time at clerici.teo5@gmail.com, which is the contact point for every request described in this policy.

We have not appointed a Data Protection Officer, as we are not required to under Article 37.

2. What we collect

DataWhere it comes from
Account — email address, display name, and profile picture URL if you sign in with GoogleYou, or your Google account at sign-in
Household data — household and trip names, invite codes, and the display names of the people in themYou and the people you share with
Financial records — expense titles, amounts, categories, dates, who paid, who shared, the resulting balances and any payments recorded between membersYou and the people you share with
Reimbursement details — a PayPal.me handle, a Satispay link, and/or an IBAN with the name on the account, if you choose to add themYou, in Settings. Shown only to a housemate who currently owes you money, on the balances screen
Receipt photographs and the line items extracted from them, including an inferred product type such as “Dairy” or “Cleaning”You, when you scan a receipt
Household activity — chores and who completed them, shopping and wishlist entries, reported issues, calendar events, chore points and rewardsYou and the people you share with
Subscription — if you buy Premium: an identifier for your customer record at our payment processor, which plan you are on, and whether that subscription is currently in good standingOur payment processor, when you subscribe or your subscription changes
Unsent entries held on your device — shopping, wishlist and issue entries you add while offline, kept in your browser’s own storage until they can be sentYou. It never leaves your device until it reaches us as an ordinary entry, and we cannot read it while it is there
Technical data — a language-preference cookie, short-lived counters used to rate-limit abusive requests, and aggregate page-view statisticsCollected automatically

We do not collect or store payment card details, and we never see them. If you subscribe to Premium, checkout happens on Stripe’s own hosted page and your card number, expiry and security code are submitted directly to Stripe. What comes back to us is listed in the table above: a Stripe customer identifier, the plan and its status — nothing else. We also do not collect bank details or any special-category data.

Separately from that: between housemates, LaCasitaOS records who owes whom and does not move money. Marking a debt settled is a note that a payment happened elsewhere; it is not a transfer, and this is not a payment service. The only money that moves through this app is your own subscription payment to us.

3. Why we process it, and on what basis

  • To provide the service — creating your account, running the shared ledger, showing balances and lists. Legal basis: performance of a contract, Article 6(1)(b).
  • To read receipts you choose to scan — extracting the line items so the bill can be split by what each person had. Legal basis: performance of a contract, Article 6(1)(b).
  • To keep the service secure and available — rate limiting, abuse prevention, diagnosing faults. Legal basis: legitimate interests, Article 6(1)(f), being our interest in a service that stays up and is not abused.
  • To understand aggregate usage — cookieless page-view counts that do not identify you. Legal basis: legitimate interests, Article 6(1)(f).

4. Automated processing of receipts

When you scan a receipt, the photograph is analysed by a third-party vision model (x.ai) to read the merchant, the line items and their prices, and to label each line with a product type. This is not automated decision-making with legal or similarly significant effects under Article 22: nothing is decided about you, every extracted line is shown to you for correction before it is saved, and how an expense is split is determined by the choices you and your housemates make afterwards.

Product-type labelling can be switched off entirely in Settings → AI smart categorisation. With it off, no product classification is requested or stored. This is a genuine opt-out rather than a display setting: the instruction is removed from the request, so the model is never asked rather than asked and ignored.

Several photographs of one receipt. A till receipt longer than a camera frame can be photographed in up to five overlapping sections, which you can turn off in Settings → Multi-photo receipt scanning. Every photograph in that set is uploaded to our storage and the addresses of all of them are sent to the vision model in a single request, because only a model that can see both sides of a join can tell a repeated row from something genuinely bought twice. The expense that results keeps one of the images — the first — and the remaining photographs stay in storage without being attached to anything. They are subject to the same access caveat as any other receipt image in section 6, and they are removed when the household is deleted.

What is sent, and what is not. The request carries the photographs and nothing else: no name, no email address, no household, no balance and no identifier of you or the people you live with. The model returns text — merchant, lines, prices, an optional product type — and we keep the text. We do not use your receipts or anything read from them to train models, and we do not grant our provider the right to do so. What the provider may do on its own side is governed by its API terms, which are its published terms in force at the time of the request.

4a. What is and is not sent for receipt reading

Only the photographs you choose to scan are sent, and only when you press scan. Nothing else goes with them: not your email address, not your name, not your household’s name, not your balances, and not any other expense. The model receives images and returns text and figures.

We keep nothing from a scan except the expense you save. The extracted lines exist in the request and in the review screen; if you abandon a scan, nothing about it is kept by us. What the model provider retains, and for how long, is governed by its own terms — we link them rather than paraphrase them, because that is a statement only they can make.

You can switch off the part that guesses a product type — “Dairy”, “Cleaning” — in Settings. Switching it off means the model is never asked for it, rather than asked and ignored.

5. Who else processes your data

We use a small number of processors, each under a data processing agreement and each acting only on our instructions:

ProcessorPurpose & location
SupabaseDatabase, authentication and file storage. Hosted in the European Union (AWS, eu-west-1).
VercelApplication hosting and aggregate, cookieless analytics.
StripePayment processing, subscription billing and invoices, and only if you buy Premium. Stripe collects your card details directly and we never receive them. Contracted through Stripe Payments Europe, Ltd. (Ireland); Stripe may process some data in the United States. For your payment data Stripe acts as an independent controller under its own privacy policy, not merely on our instructions.
x.aiReading receipt photographs you choose to scan. Processing takes place in the United States.
GoogleSign-in, and only if you choose “Continue with Google”.

Where a processor is outside the European Economic Area, the transfer relies on the European Commission’s Standard Contractual Clauses. We do not sell personal data, and we do not share it for advertising.

6. Receipt images — please read

Receipt photographs are stored at long, randomly generated addresses that are not listed or indexed. However, anyone who obtains the exact address of an image can view it without signing in. Treat a receipt photograph as you would a photo shared by link. We are moving this storage behind signed, expiring URLs; until then, avoid scanning receipts that show information you would not want a link-holder to see.

7. What other people in your household can see

A household is a shared space by design. Everyone who has joined it can see its expenses, receipts, balances, chores, lists and the points recorded against each member. They cannot see your email address, your other households, or anything from a household they are not in.

8. How long we keep it

  • While your account exists, we keep your account data and the households you belong to.
  • If you leave a household, your profile there becomes an unclaimed placeholder and your name is detached from your account. The household’s financial records remain, because deleting one person’s share would corrupt everybody else’s balances. You can rejoin with the invite code.
  • If a household is deleted, every expense, receipt, balance, chore and list belonging to it is removed permanently.
  • Photographs from a multi-photo scan that were not attached to the expense stay in storage for the life of the household and are removed with it. We do not currently delete them earlier, and we would rather say so than imply a cleanup that does not run.
  • Rate-limiting counters expire automatically within hours.

Subscription and payment records are kept for as long as tax and accounting law requires — generally several years — even after you delete your account. That obligation overrides a deletion request for those records specifically, and for nothing else. The record is an invoice and a plan history; it contains no card details, because we never had any.

9. Your rights

Under the GDPR you have the right to:

  • obtain a copy of the personal data we hold about you (Article 15);
  • have inaccurate data corrected (Article 16);
  • have your data erased (Article 17);
  • restrict how we process it (Article 18);
  • receive it in a portable, machine-readable form (Article 20);
  • object to processing based on our legitimate interests (Article 21); and
  • withdraw consent at any time, where consent is the basis.

Write to clerici.teo5@gmail.com and we will respond within one month.

9a. Deleting your account, and exactly what that removes

You can erase your account yourself, at any time, from Settings → Danger zone. There is no waiting period and no support ticket. It is immediate and it cannot be undone.

What is deleted: your email address, your display name, your profile photo, any reimbursement details you saved (PayPal handle, Satispay link, IBAN), your billing customer record, your push-notification registrations, and your sign-in itself. Any active subscription is cancelled at the same moment, so nothing is billed afterwards. Any household in which you were the last remaining member is deleted in full, with every expense, balance, chore and list in it.

One thing is kept on purpose. When your account is erased we store a one-way SHA-256 hash of your email address — 64 characters that cannot be turned back into the address — and nothing else: no name, no id, no link to anything above. Its only use is that a second account registered on the same address starts on the Free tier rather than on a second thirty-day trial. It is not used to identify you, is not shared, and is retained on the basis of our legitimate interest in offering one opening trial per person (Article 6(1)(f)). We do not track IP addresses or device fingerprints for this or any other purpose.

What stays, and why. Expenses you shared with other people remain on their ledgers, showing the name you used in that household. Your profile there becomes an unclaimed placeholder, the same as if you had simply left.

This is not a limitation of the software. A shared ledger is joint personal data: “Ana paid €62 and Marco owed €14 of it” is Marco’s record of his own spending just as much as it is Ana’s. Erasing one side of it would not remove a fact — it would leave everybody else with a ledger that no longer adds up and a history they cannot account for. We therefore keep the minimum needed to preserve their records, on the basis of the legitimate interests of the other people in your household (Article 6(1)(f)), as permitted by Article 17(3).

You cannot delete your account while you owe money or are owed it, or while housemates are waiting on receipts you have not answered. The app tells you which household and which amount. Settle up and the deletion goes through — it is a step, not a refusal.

If you want your first name removed from another household’s historical expenses as well, write to clerici.teo5@gmail.com. We will weigh your request against the other members’ interest in an intelligible record and tell you what we have decided, and why.

You also have the right to complain to your national data protection authority. In Spain this is the Agencia Española de Protección de Datos; in Italy, the Garante per la protezione dei dati personali.

10. Cookies and similar technologies

We set two kinds of browser storage, both strictly necessary and neither used for advertising or cross-site tracking: a session cookie that keeps you signed in, and a language cookie remembering your chosen locale. Your device also stores small preferences locally, such as whether you have seen the introduction and whether AI categorisation is on. Analytics are cookieless and aggregate.

11. Children

LaCasitaOS is not intended for anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

12. Security

Data is encrypted in transit. Database access is restricted at row level so one household cannot read another’s, and every request is checked against your membership before any household data is returned. Passwords are handled by our authentication provider and are never visible to us. No system is perfectly secure; if a breach affects your rights we will notify you and the relevant authority as Articles 33 and 34 require.

13. Changes to this policy

We will update this page when the app changes, and revise the date at the top. Material changes will be announced in the app before they take effect.

Questions about any of this: clerici.teo5@gmail.com.