Who is responsible for this
Presylo is an independent product operated from the Philippines. For the purposes of the Data Privacy Act of 2012 (Republic Act 10173), Presylo is the personal information controller for the data described here, and can be reached at privacy@presylo.com.
This notice covers the Presylo website at www.presylo.com and the Presylo app for Android and iOS. They are the same product: the app is the same interface, packaged for a phone, talking to the same account.
What Presylo holds
Your account
An email address, a display name, and a password you choose. The password is handled by our authentication provider and is stored hashed — it is never visible to us. If you sign in with Google instead, we receive your email address and name from Google, not your Google password.
What you record
The substance of the product: shopping lists and their items, the shops and branches you visit, shopping trips, receipts and their lines, the prices you paid, and the price history built from them. If you use the vehicle and fuel features, that includes your vehicles and their fuel entries and odometer readings.
Your profile photo, if you add one
Optional. It is uploaded from your device straight to Cloudinary, our image host, using a signature minted by our server — the image does not pass through our own backend. We store the resulting address. Without one, Presylo draws your initials.
Technical records
Ordinary server records: the request, the time, and an error identifier when something fails. Your IP address is used to rate-limit requests so the service is not overwhelmed. We keep an audit log of significant changes to your own data so that history can be explained back to you.
What Presylo does not collect
- Your device’s location. The app never asks for it.
- Your contacts, photo library, calendar, or messages.
- Your private shopping, receipt, list, or account records for advertising. Google advertising tags appear only on the public pages described below, never in the signed-in app or packaged mobile app.
How receipt reading works, exactly
This is the part of Presylo that touches a photograph, so it is worth stating in detail.
By default, the reading happens on your device. The text recognition runs inside the app itself. What reaches our server is the result: the shop, the lines, the amounts, the totals, plus the file name and a checksum used to keep you from processing the same photo twice. The image stays where it was taken.
If on-device reading fails, you may press the AI reading button. That sends the photo to Anthropic’s Claude API for one transcription call. The photo is not written to our disk or our database, and it is used for that call only. If you have supplied your own Anthropic key in the app, the call is made with your key and billed to you; otherwise it uses ours. This never happens on its own — it is a button you press for one receipt at a time.
Extraction is treated as a draft either way. Presylo asks you to review what was read before any of it is written into your history.
Who else processes it
Presylo is a small product and relies on a short list of providers. Each one gets only what its job requires.
- Neon — hosts the database and runs the sign-in system. This is where your account and your records live.
- Vercel — serves the website and the API the app talks to.
- Cloudinary — stores profile photos, and only those.
- Anthropic — receives a receipt photo only when you press the AI reading button, for that one call.
- Google Analytics — measures use of this website. It is not included in the Android or iOS app.
- Google AdSense — serves and measures advertising on selected public pages. It is not loaded in the signed-in app, account and invite pages, this Privacy Notice, or the Android and iOS apps.
The service providers above process data for the purposes described here and under their applicable terms. Google may use information from public-page visits to deliver, limit, and measure advertising as explained in the next section. We do not sell or rent your private Presylo records, and we have never disclosed any to a government body; if we were compelled to, we would tell you unless the law forbade it.
How long it is kept, and how to end it
Your records are kept for as long as your account exists, because the product’s whole purpose is the long view: a price from two years ago is the one that tells you whether today’s is fair.
You can delete the account yourself, from inside Presylo. Open Profile, choose “Delete my account and data”, and confirm. It happens immediately and cannot be undone: the account, your lists, trips, receipts, purchases, price history, vehicles, and any profile photo are erased, and the sign-in itself is removed so the account no longer exists. Community posts you made are removed or permanently de-identified so they can no longer be traced to you.
If you share a household with someone else, deleting your account hands that household to the longest-standing member left in it rather than destroying their records along with yours. Lists you had shared with other people stay with them.
If you cannot reach the app — you have lost the device, or the sign-in no longer works — write to privacy@presylo.com from the address on the account and we will do it for you within 30 days. Backups are overwritten on their own cycle either way, within 90 days.
Anything you asked us to keep for legal or accounting reasons — a record of a donation, for example — is kept only for as long as the law requires it.
Your rights over this data
Under the Data Privacy Act you may ask to see what we hold about you, correct anything wrong, object to a particular use, ask for a copy in a portable form, or have it erased. Presylo already exports your purchase history as a spreadsheet from inside the app, and the rest of these you can start with one message to privacy@presylo.com. We answer within 30 days and never charge for it.
If you think we have handled your data badly and we have not put it right, you can complain to the National Privacy Commission at privacy.gov.ph.
How it is protected
On a phone you can also ask Presylo to lock itself, so opening the app needs your fingerprint, your face, or the device passcode. That check is made by the phone and answered yes or no; no biometric data is readable by the app, and none of it is ever sent to us. It protects a handed-over phone, and does not change how you sign in.
Everything travels over HTTPS. Sessions are held in a signed cookie rather than in a token the page can read. Any secret you entrust to Presylo — your own AI key, for instance — is encrypted at rest with AES-256-GCM under a key held outside the database, so a copy of the database alone does not reveal it. Requests are rate limited, and every read of your data resolves who is asking before it returns anything.
None of that is a guarantee. If a breach ever affects your data we will tell you and the National Privacy Commission, promptly and in plain language.
Children
Presylo is built for people who run a household budget and is not directed at children under 13. We do not knowingly hold data about them. If you believe a child has created an account, write to us and we will remove it.
Changes to this notice
When this notice changes, the date at the top changes with it, and the change is recorded in the public updates log. If a change materially affects how your data is used, we will tell you in the app before it takes effect rather than relying on you to re-read this page.