개인정보 처리방침
Expra의 데이터 처리, 보관, 삭제, 제3자 서비스 정보를 확인하세요.
데이터 사용
앱 기능 제공, 동기화, 지원 응답, 안정성 개선에 필요한 정보만 다룹니다.
삭제와 보관
계정 또는 데이터 삭제는 앱 안의 삭제 기능이나 지원 이메일을 통해 요청할 수 있습니다.
추적 제한
광고 목적의 제3자 추적이나 개인정보 판매를 전제로 설계하지 않았습니다.
Effective: 2026-05-02 · Last updated: 2026-10-01
Expra ("we", "our") is published by OOTSSU. This policy describes what data Expra collects, where it is stored, why, and how to remove it.
Where your receipts are stored
Your expense records (vendor name, amount, VAT, currency, date, category, notes) and the receipt photos you scan are saved on your device, in Expra's local database (also read by the Expra home-screen widget to show this month's total). They are uploaded to our server only if you have Expra Pro and have connected an account, to sync them across your devices. Receipt photos are never synced — only the text fields above.
What we collect
- Guest account — no sign-in is required. On first launch Expra creates an anonymous guest account on our server (Supabase): a random identifier with no email or name. It is used for AI scan limits and to link purchases.
- Connected account (optional) — if you choose Settings → Account → Connect Account, we also store your email address (email sign-in; the password is stored only as a one-way hash by our authentication service), or the Apple or Google account identifier and the email and name that provider shares.
- Synced expense records — only for Expra Pro with a connected account, as described above.
- Receipt images for AI scan — when you use AI scan, the image is sent to our
expra-scanserver function for text extraction. We do not store the image on our servers. - AI scan usage — to enforce the free plan's 10 scans per month and the Pro fair-use limit (200 per day), we store a count of scans per account per month or day. It contains no image and no receipt content.
- Abuse prevention — because anyone can create new guest accounts (signing out or deleting your data gives a guest a fresh account, so the free monthly limit is a fair-use limit rather than a strict per-person one), we also keep a daily count of scans keyed by a salted one-way hash of your IP address (IPv6 is grouped by network prefix) and a daily total across all users. The IP address itself is never stored.
- Camera & photo library access — used only when you photograph a receipt or pick an image, and only with your permission.
- Subscription status — verified via RevenueCat, linked to your pseudonymous Expra account identifier. Payment details are handled by the Apple App Store and never reach us.
Cloud transmission
During an AI scan only the receipt image is sent, over HTTPS, to our expra-scan function, which forwards it to Anthropic's Claude API to read the vendor, date, amounts and category, and returns just those fields. We do not keep the image or the AI's raw output. On Anthropic's side, request inputs and outputs are deleted within 30 days under its standard commercial API terms — we do not hold a zero-data-retention agreement. No GPS, contacts, or other personal data is transmitted.
How we use your data
- Reading receipts with AI and showing your monthly and yearly spending on your device
- Syncing records across devices (Expra Pro with a connected account)
- Enforcing free-plan and fair-use limits
- Subscription management and Pro feature access
Third-party processors
We do not sell or share your data for advertising or marketing. We work with the following processors to run the service:
- Supabase — authentication and database for guest/connected accounts, scan usage counts and Pro sync (supabase.com)
- Anthropic (Claude) — AI receipt text extraction (anthropic.com)
- RevenueCat — subscription management (revenuecat.com)
Signing out
Signing out of a connected account starts a new, empty guest session. Receipts saved under the account you signed out of stay on this device but are hidden, and appear again if you sign back in to that account on this device. To remove them, sign in and delete your data.
Deleting your data
Settings → Account → Delete Account (connected account) or Delete Data (guest). After you confirm, we delete your Expra records on our server (synced receipts and your Expra profile) and the receipts stored on this device. OOTSSU apps share one sign-in service: if no other OOTSSU app uses the same sign-in, your sign-in record (email, Apple/Google identifier, or guest identifier) is deleted too; otherwise it is kept only so the other app keeps working, with no Expra data linked to it. If the deletion cannot be completed (for example, you are offline), nothing is deleted, you stay signed in, and the app shows the reason. See how to delete your account and data for the email route and what is kept.
What is kept: the AI scan usage counts and IP-hash daily counts described above (no receipt content), used only to enforce limits, and purchase records held by Apple and RevenueCat as required for billing, refunds and tax. Deleting your data does not cancel a subscription.
Tracking
Expra does not track you across other apps or websites and contains no advertising SDK.
Children
Expra is not directed to children under 13. We do not knowingly collect data from children under 13.
Contact
지원이 필요하신가요?
앱, 계정, 결제, 데이터 삭제 문의는 이메일로 보내주세요.