Privacy Policy
Last updated: 21 August 2026
Tsjek helps you remember what you'd otherwise lose: warranties, gift cards, credit, loyalty cards and deadlines, with a nudge before something expires. To do that we store only what's truly needed — everything in the European Union, with no ads and without selling your data. This policy explains, in plain language, what we process and why.
Who's responsible?
Tsjek is an app by Tonenite. For anything about your data — questions, access, complaints — reach us at info@tsjek.app. Tonenite is the data controller for your data under the GDPR.
What data do we process?
- Your account: your email address, which you use to log in without a password via a one-time code, and — if you like — a display name you choose yourself.
- What you add yourself: the items in your vault — titles, stores, amounts, purchase and expiry dates, barcodes (including those of your loyalty cards), serial numbers, notes, and for a vehicle for instance the licence plate or chassis number if you fill them in — and the photos or PDFs of receipts you provide.
- To run the app: limited technical data needed to run the app: your reminder settings, the status of a scan, how many scans you made this month (for the free limit) and, if you take Tsjek Plus, the status of your subscription.
- Anonymous counters: we count how often certain steps happen (for example how many first items are created on a day) — one number per day, without who. If we ask you at the start how you found us, we store that answer separately from your account.
We deliberately don't store scans of identity documents. For documents with an expiry date (ID card, passport, inspection) we keep only the date and your label — not the document itself.
What do we use it for, and on what basis?
- The core function (storing your items and alerting you in time) we process to perform our agreement with you — that's what you use the app for.
- AI extraction of a receipt photo is part of that function: we read the photo to fill in store, amount, date and warranty term. The scan immediately becomes an item in your vault, which you can always check and adjust (see below).
- Extras you switch on yourself — a nudge near a store, your household, found deals, community codes — we process only when you use them, and you can stop at any time.
- Email forwarding, analytics or marketing happen only with your explicit consent, separately per purpose, which you can withdraw at any time. Today there is no analytics SDK in the app and email forwarding isn't available yet. We do keep simple usage statistics in our own database (which features are used, never the content); you can switch that off in Settings > Privacy.
How does the AI extraction work?
When you scan a receipt, the photo immediately becomes an item in your vault, labelled "To process". A vision model from Mistral AI (a European AI provider, Paris) reads the photo and fills in the fields — store, amount, date, warranty term — without making you go through a confirmation screen first. If the model is unsure, the app marks the item "Worth a check?" and asks you a few short questions when you open it. Every filled-in field stays editable, and the app is honest about what was a guess: an estimated date is labelled "estimated", an amount "read from the receipt".
Mistral only receives the photo and returns the result as structured fields — no name, email address or other account data. We talk to the AI service through a thin layer, so we can switch providers without needing more data; the current provider is always listed on Who processes your data? (in Dutch). We automatically delete the raw photo and the intermediate result after processing, at the latest after 7 days. Only the filled-in item and the photos you choose to keep with it stay in your vault. If you scan without internet, the app keeps the scan temporarily on your device and processes it as soon as you're back online.
A nudge near a store
For a gift card or credit you can switch on "Remind me here" per item: you'll then get a nudge when you're near that store or venue. Here's how it works:
- Your position stays on your device. The operating system (iOS or Android) itself watches a zone around the store — "geofencing" — and tells the app when you enter it. Your location or your movements are never sent to our servers and are stored nowhere. Sorting your loyalty cards by distance also happens entirely on your device.
- What we store is the store's location — the coordinates of the store or venue you chose, not yours.
- Looking up the store happens in OpenStreetMap. Our server looks up the address of a store or venue via the geocoding service Photon (Komoot, Germany); the branches of a chain are requested by your device directly from the Overpass API. In both cases only a store name and the country are sent, never your position. With a direct request from your device, such a service does see your device's IP address, like any website.
- The map on which you pick a place yourself loads map tiles from Geoapify (EU, Germany, under a data processing agreement). That service sees your device's IP address and which map area you're viewing — no account data.
- Always voluntary. You switch it on per item and can switch it off at any time; the location permission itself is managed in your device's settings.
Found deals
In Tsjek Plus we show discount vouchers for stores where you already keep cards or vouchers. We fetch those vouchers from the affiliate networks Daisycon and Awin to our own server, as one shared catalogue without personal data. Which vouchers suit you is decided by the app on your device, by comparing that catalogue with the stores in your own vault. So nothing about you goes to those networks: no cards, no vouchers, no stores. Only when you tap a voucher yourself and open the store does the link pass through the network — from then on the network sees your visit, as with any link on the internet, and we may earn a commission if you buy something. We build no profile of you and don't track what you tap.
Your household and share links
With Tsjek Plus you can create a household (up to 6 members) and invite people with a code. You choose per item whether to share it. A shared item is visible to everyone in your household — title, store, dates, amounts, barcode, notes and the attached photos — and they get the reminder too. What you don't share stays yours alone: household members never see your whole vault. You can stop sharing per item, leave the household at any time, and the admin can remove members. Your display name is visible to your household members, so they can see who shared what.
If you share a voucher as a link, whoever has that link sees only the title, the store, the barcode and the expiry date — never amounts, notes or who you are. You can revoke a share link at any time.
Community codes and deals
You can share discount codes with other Tsjek users and indicate whether a code worked. A shared code is visible to all users. We store the code, the store and, internally, your user ID — so you can delete your own code and we can stop abuse. Other users never see your name or email address: codes appear anonymously. If a code is reported by several users (from three reports, and at least as many reports as confirmations), we hide it automatically. Links can't be shared; the temporary deals in the Deals tab are, for now, posted by us.
Tsjek Plus and payments
You buy Tsjek Plus through the App Store (Apple) or Google Play (Google). Payment runs entirely through them: we never see your card or bank details. What we do receive is a proof of purchase that our server verifies with Apple or Google to activate your subscription. We store which subscription you have (Plus or Plus Family), through which store, until when it runs, and the transaction number the store assigns to it — so we can correctly process renewals, cancellations and refunds when Apple or Google notify us of them.
Who processes your data for us?
We work with a small number of processors, all in the EU or under a data processing agreement. We sell your data to no one.
| Processor | What for | Where |
|---|---|---|
| Supabase | Database, file storage and login | EU (Frankfurt) |
| Mistral AI | AI extraction from receipt photos | EU (Paris) |
| Scaleway | Sending your one-time login codes | EU (France) |
| Geoapify | Map tiles when picking a store | EU (Germany) |
| Photon (Komoot) & Overpass API | Looking up a store or venue in OpenStreetMap — they only get the store name | EU, public services |
| MailerLite | Waitlist and launch emails | Under a data processing agreement |
| Apple & Google | App distribution and payments for Tsjek Plus | Under a data processing agreement |
The affiliate networks Daisycon and Awin aren't in this list: they get nothing about you unless you open a link yourself (see "Found deals"). Notifications are created by the app itself on your device; no push service is involved. What each party does and doesn't see is on Who processes your data? (in Dutch).
How long do we keep everything?
- Raw receipt photos and intermediate AI results: automatically deleted after processing, at the latest after 7 days.
- Your items, your account and your subscription status: as long as you use your account.
- Community codes you shared: until you delete them; they disappear along with your account.
- After deletion: your account is first deactivated and, after 30 days, permanently erased, including your photos and files.
Your rights
Under the GDPR you have the right to access, rectification, erasure, portability and objection, and you may withdraw your consent. We turned the most important rights into a button in the app, on the Account screen:
- Export my data gives you all your items and attachments in one file.
- Delete my account puts your account on hold for 30 days — sign in again within that time and everything is still there — and then erases everything permanently, photos included.
You can also always email info@tsjek.app. If you disagree with how we handle your data, you may file a complaint with the Belgian Data Protection Authority.
Security
- All data and processing stay in the European Union.
- Encrypted traffic (TLS) and encrypted storage.
- The database enforces at row level that you can only see your own data — and what your household shares with you — not just the app, but the database itself.
- A copy of your items is stored encrypted on your device, so the app also works without internet; it's wiped when you log out or delete your account.
- You can lock the app with face recognition or fingerprint.
This website
On tsjek.app, when you sign up for the waitlist we store only your email address (plus whether you saw the Dutch, French or English version), and we sync that address to our email tool MailerLite to notify you once at launch. No tracking cookies, no advertising SDKs, no profiling.
Children
Tsjek isn't intended for children under 16 and we don't knowingly collect their data. If you're under 18, you use Tsjek with the consent of a parent or guardian — see also our terms of use.
Changes
If this policy changes, we'll update the date at the top. For a significant change, we'll notify you in the app or by email.
Contact
Questions about your privacy? Email info@tsjek.app. We'll reply as fast as we can.