Zeebro Privacy Policy
Version 0.5 — DRAFT of 2026-07-28 · not yet in force · requires legal review before publication Placeholders to resolve before launch: effective date, final raw-image retention period.
In short: Your receipts are yours — nobody can see what you bought. What becomes public is only anonymous price information: product X costs €Y at store Z. You can delete your account at any time; your personal data is erased, and the anonymous prices already shared with the community stay (they were never linked to you publicly in the first place). We don't sell personal data, we don't show ads, and we host in the EU.
1. Who we are
Zeebro ("we", "us") is operated by a sole trader established in Italy, who is the data controller for the processing described in this policy. The operator's legal name is at the foot of this page. Contact for privacy matters: [email protected].
Zeebro is a collaborative grocery-price app: users scan receipts and shelf tags, and the community gets anonymous, verified price information in return.
This policy covers the Zeebro mobile app (iOS and Android), the zeebro.io website (including the waitlist and beta signup), and related Zeebro services. It is drafted in English; translations are provided for convenience, and the English version prevails.
2. What data we process
| Category | What | Where it comes from |
|---|---|---|
| Account | Email address, display name, language preference | You, at signup |
| Waitlist / beta signup | Email address | You, on zeebro.io |
| Deletion request | Email address | You, if you ask us to delete an account from the web instead of in the app |
| Contributions | Receipt photos, shelf-tag photos, product photos, receipt QR codes, your answers to clarification questions and edits | You, when you scan or contribute |
| Extracted purchase data | Products, prices, quantities, store, purchase date read from your receipts by our automated extraction | Derived from your contributions |
| Location | Your device location — while you use nearby-price features, and recorded with a shelf-tag photo (see below) — or a location you pick manually | You, with your permission — you can deny it and pick a location on the map instead |
| Technical | Device type, app version, crash reports, and product-analytics events (screens used, features tapped) | Your device |
| Usage counters | Number of uploads, searches, contribution statistics, trust score | Generated by the service |
What we deliberately do NOT keep: our automated extraction is instructed to ignore personal data printed on receipts (names, loyalty-card numbers, payment-card digits), so none of it is stored — a protection that also covers any third party whose discarded receipt is submitted. To be precise about what that does and does not mean: the extraction service receives the photograph as you took it, so anything printed on the receipt is visible to it in the moment; what the instruction prevents is that data ever being returned to us or written down. Raw receipt images are stored in a private bucket accessible only to you and our moderation tooling, and are deleted [90] days after processing. We do not build location histories. For "prices near me", your coordinates are used to answer the query and are not kept. When you photograph a shelf tag, that capture records where it was taken — we need it to check the feature is available in your country, and our moderators use it to judge whether a price is plausible — and we delete those coordinates 30 days after the capture is processed.
3. What becomes public — and what never does
When your contribution is accepted, the community sees only the anonymous observation: product, store, price, and date. Published prices, product photos accepted into the shared catalog, and product information corrections carry no public attribution — nobody, including other users, can see who contributed them or link a purchase to you.
Never public: your identity, your email, your receipts, your purchase history, your location.
4. Why we process it (legal bases, GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the service: accounts, extraction, your private purchase history and spending dashboard, the shared price database | Contract (Art. 6(1)(b)) |
| Nearby prices using your location | Consent (Art. 6(1)(a)) — via the device permission, revocable anytime |
| Moderation, abuse prevention, rate limiting, service security | Legitimate interest (Art. 6(1)(f)) |
| Aggregated, anonymous statistics (e.g. average prices, regional consumption patterns) | Legitimate interest (Art. 6(1)(f)); the outputs are anonymous and no longer personal data |
| Product analytics and crash reporting | Consent or legitimate interest depending on configuration — [resolve with counsel: PRD open question #5] |
| Push notifications (price alerts, summaries) | Consent — opt-in, per-type toggles |
Automated processing. Reading purchase data out of your images and first-line screening of contributions (duplicate, abuse, and quality checks) are automated, and a contribution may be held back or rejected automatically. These checks affect only the contribution and your contributor standing — we make no automated decisions with legal or similarly significant effects for you, and we do not profile you for advertising. You can always ask for human review of a refused contribution via [email protected].
5. Processors and recipients
We use a small number of service providers (processors) under data-processing agreements. The roles below are what matters and will not change quietly; the named provider for each is the one we use today and may be replaced by another bound to the same terms, in which case we update this list.
- Supabase — database, authentication, storage; hosted on AWS eu-west-1 (Ireland).
- Automated extraction — reads the images you submit and returns the products and prices. It receives the photograph as taken, including anything printed on it; it is not given your name, email or account. We use a paid tier whose terms exclude using what we send to train the provider's models. Currently: Google (Gemini API).
- Map and place lookup — resolving store names and addresses to locations. Store data only; no user identity is sent. Currently: Google (Places API).
- Railway — image processing (receipt cropping, product-photo cleanup) on EU-region infrastructure [verify region].
- Resend — delivery of account and waitlist emails (confirmations, sign-in, double opt-in).
- Cloudflare — runs zeebro.io's domain and content delivery (so it sees the requests your browser makes to us) and forwards website analytics events on our behalf.
- Mailbox hosting — receives and stores the email you send to our addresses, including anything you send us about your privacy rights. Hosted in Switzerland. Currently: Migadu.
- PostHog (EU cloud) — product analytics for the website and app; on the website it runs cookieless (§8).
- Open Food Facts — when you scan a barcode we don't recognize, our server queries the Open Food Facts product database. Only the barcode is sent — never your identity, IP address, or location.
- Google ML Kit — barcode and price-tag detection runs on your device: camera frames are analyzed locally and are not sent to Google (the library may contact Google to download its detection models).
- [When enabled] Sentry — crash reporting; Firebase Cloud Messaging — push notification delivery.
We do not sell personal data. We may offer third parties (e.g. retailers, researchers) aggregated, anonymous statistics — such as average prices or category demand by area — with minimum group sizes that make re-identification impossible. Individual purchase data is never shared, licensed, or sold. If we run partner promotions (e.g. converting points into a retailer coupon — Terms §8), the partner receives only aggregate redemption reporting, never your identity or purchase history.
If a transfer outside the EU/EEA ever occurs (e.g. some Google processing), it is covered by the EU Standard Contractual Clauses or an adequacy decision.
Disclosure required by law. We may disclose personal data where a law, court order, or competent authority validly requires it. We assess every such request, disclose only the minimum necessary, push back on requests we consider overbroad or unlawful, and inform you where we are legally permitted to.
6. Retention
- Raw uploaded images: deleted [90] days after successful processing/moderation.
- Coordinates recorded with a shelf-tag capture: deleted 30 days after processing.
- Extracted purchase data and your private history: kept while your account exists.
- Published anonymous observations: kept indefinitely — they are the community dataset and contain no personal data.
- Waitlist emails: until you unsubscribe, or shortly after beta invitations conclude.
- Web deletion requests: kept only until the request is carried out, then deleted with the account.
- Logs and abuse records: up to [12] months.
7. Account deletion
You can delete your account at any time in the app (Profile → Account). If you can no longer sign in, request it at zeebro.io/delete-account — we verify you own the address before deleting anything. What happens:
- Your account, email, display name, private receipts, images, and personal purchase history are deleted.
- Price observations already published to the community were shared anonymously; on deletion, any internal link between them and your account is irreversibly removed (anonymization). The historical price data itself remains part of the shared database — it no longer relates to any identifiable person and therefore is no longer personal data.
- To keep duplicate-submission fraud detectable, fiscal identifiers/fingerprints of receipts already processed are retained after deletion in a form no longer linked to you or to any account.
8. Cookies, on-device storage, and the website
The app stores your sign-in session and preferences (language, settings) on your device — they are needed for the app to work and stay there. Barcode and price-tag detection runs on-device (§5): camera frames are analyzed locally, and only the images you choose to submit are uploaded.
The zeebro.io website sets no advertising or cross-site tracking cookies. Website analytics run in cookieless mode — no identifier is stored in your browser, and we see only anonymous, aggregate usage. If we ever introduce cookies that require consent, we will ask first. Joining the waitlist stores your email address only after you confirm it (double opt-in).
9. Security
Your data is hosted in the EU and encrypted in transit and at rest. Database access is enforced row-by-row, so your private data is readable only by your own account and our moderation tooling; receipt images live in private storage buckets. Passwords are stored hashed, infrastructure access is limited to authorized operators, and rate limiting and abuse screening protect the service against misuse. No system is perfectly secure — if a breach ever affects your data, we will notify you and the supervisory authority as the GDPR requires.
10. Your rights
Under the GDPR you have the right to access, rectify, erase, and receive a copy of your data (portability), to object to processing based on legitimate interest, and to withdraw consent at any time. Contact [email protected] — we may ask you to verify your identity, and we respond within one month (extendable by up to two further months for complex requests; we will tell you if we need longer). You also have the right to complain to a supervisory authority — in Italy, where we are established, the Garante per la protezione dei dati personali (garanteprivacy.it), or the data-protection authority of your own EU country of residence.
For users in Brazil, equivalent rights apply under the LGPD once the service operates there.
11. Children
Zeebro is not directed at children and requires users to be 16 or older.
12. Changes
We will announce material changes to this policy in the app at least 30 days before they take effect. The current version is always available at zeebro.io/privacy and in the app.
© 2026 Zeebro
FARIAS DE FREITAS ANDRADE BRUNO