Bonstructer Receipt Notes · de.bonstructer.notebook

Datenschutz / Privacy

Kontakt / Impressum: Chrischosoft · info@bonstructer.com

Stand: 2. Oktober 2026 · Fassung 7

Updated: 2 October 2026 · Version 7

Diese Seite setzt keine Cookies. Sie nutzt Cloudflare Web Analytics für anonyme Besucherstatistiken (keine Cookies, keine personenbezogenen Daten, keine Weitergabe zu Werbezwecken). Es werden keine Werbeskripte geladen.

This page sets no cookies. It uses Cloudflare Web Analytics for anonymous visitor statistics (no cookies, no personal data, no sharing for advertising purposes). No advertising scripts are loaded.

Datenschutzerklärung (Deutsch)

Verantwortlich für Bonstructer Receipt Notes ist Chrischosoft. Kontakt: info@bonstructer.com.

1. Worum es geht

Bonstructer Receipt Notes speichert deine Kassenbons (Foto, PDF oder Text) und beantwortet Fragen dazu. Wir verarbeiten nur, was nötig ist, um diesen Vertrag zu erfüllen (DSGVO Art. 6 Abs. 1 lit. b) — keine Marketing-Einwilligung.

2. Welche Daten wir verarbeiten

Konto. Anmeldung über Firebase Authentication: Google-Konto (E-Mail, Nutzerkennung), Apple-ID über „Mit Apple anmelden“ (E-Mail oder private Weiterleitungsadresse von Apple, Nutzerkennung) oder E-Mail und Passwort. Wir speichern die Firebase-UID und die E-Mail, um dich zuzuordnen. Bei der Registrierung in der iPhone-App bestätigt Apple App Attest, dass die Anfrage von einer echten, unveränderten Installation der App kommt; wir erhalten dabei einen Schlüsselnachweis von Apple, keine Gerätekennung.

Bons. Von dir hochgeladene Fotos und PDFs sowie eingefügter Text. Originale liegen in Google Cloud Storage. Erkannte Zeilen, Laden, Datum, Beträge und Korrekturen liegen in Firestore.

OCR. Fotos und PDFs werden zur Texterkennung an einen KI-Dienst von Google Cloud (Vertex AI) geschickt; Google speichert sie dabei nicht und nutzt sie nicht zum Training. LlamaParse / LlamaCloud (EU-Endpunkt) nutzen wir nicht im Regelbetrieb, nur in Ausnahmefällen, wenn wir es von Hand einschalten. Den erkannten Text speichern wir in deinem Notizbuch.

Chat. Deine Fragen und der Notebook-Inhalt (Bons, Summen) werden an einen KI-Dienst von Google Cloud (Vertex AI) geschickt, damit die App antworten kann. Token-Verbrauch und ein Ausschnitt der Frage können im Workspace-Nutzungsprotokoll stehen. „KI nur in der EU“. Standardmäßig kann die KI-Verarbeitung (Texterkennung und Chat) außerhalb der EU stattfinden. Schaltest du „KI nur in der EU“ ein – jederzeit in den App-Einstellungen oder im Chat-Menü (⋮) –, läuft die KI-Analyse deiner Bons und Chats nur in EU-Rechenzentren unseres Cloud-Anbieters. Bei hoher Last kann das langsamer sein oder öfter fehlschlagen. Das betrifft nur die KI-Verarbeitung; Hosting und Speicherung liegen ohnehin in der EU. Chatverläufe liegen in deinem Cloud-Workspace, im selben Notes-Cloud-Speicher wie die Bons.

Nutzung und Abrechnung. Speicherbelegung, vorausbezahlte OCR-Scan-Seiten und Chat-Guthaben. Käufe in der Android-App und im Web: Stripe Checkout, wenn diese Zahlung erscheint; Google Play, wenn du über Play Billing bezahlst. Käufe in der iPhone-App laufen ausschließlich als In-App-Kauf über den App Store (Apple StoreKit): Apple wickelt die Zahlung ab, wir sehen keine Zahlungsdaten. Wir erhalten die von Apple signierte Transaktion (Produkt, Transaktionsnummer, Zeitpunkt, Verlängerungs- und Erstattungsstatus) aus der App und über App Store Server Notifications und schreiben das Guthaben deinem Konto gut.

Markierungen. Wenn du einen Bon zur Prüfung markierst, können Hinweistext und Parse-Ausschnitte genutzt werden, um die Bon-Erkennung zu verbessern. Eine Markierung samt der dafür angelegten Bon-Kopie löschen wir 3 Tage nach ihrem Abschluss. Als Testfall können wir anonymisierte Textauszüge ohne Zahlungsdaten behalten.

Gerät. Sitzungstoken auf dem Gerät. In der Android-App können Kamerafotos zuerst über Google Play-Dienste erfasst werden, in der iPhone-App über die Systemkamera; danach werden sie an unsere API gesendet.

Herkunft. Kamst du über einen unserer Links oder eine Anzeige (Kennzeichen src / utm_* im Link oder im Google-Play-Installationsverweis), speichern wir dieses Kennzeichen einmalig an deinem Konto, um zu messen, welcher Kanal funktioniert — selbst erhoben, ohne Tracking-Pixel und ohne Cookies. Bis zur Anmeldung legen wir es nur mit deiner Einwilligung (Hinweis „Kampagnen-Messung“ auf bonstructer.com) höchstens 30 Tage im Browser-Speicher ab (§ 25 Abs. 1 TDDDG, Art. 6 Abs. 1 lit. a DSGVO); ohne Einwilligung wird es nur innerhalb desselben Besuchs über den Link weitergereicht und nicht gespeichert. Widerruf jederzeit über „Datenschutz-Einstellungen“ in der Fußzeile der Startseite — das gespeicherte Kennzeichen wird dann gelöscht. Klicks auf unsere App- und Play-Links zählen wir zusätzlich anonym auf unserem Server (nur Tagessummen je Kennzeichen, ohne IP-Adresse, Gerät oder Konto).

Rückmeldung an Meta. Nur wenn du über eine Anzeige auf Facebook oder Instagram kamst und der Kampagnen-Messung zugestimmt hast, melden wir Meta Platforms Ireland Ltd. von unserem Server zurück, ob daraus ein Klick auf einen unserer App-Links („Lead“), ein Gastzugang („StartTrial“) oder eine Registrierung („CompleteRegistration“, einmal je Konto) wurde. Übermittelt werden nur der Ereignisname, der Zeitpunkt, bei Klicks welcher unserer Links es war, und die Klick-Kennung fbclid, die Meta selbst an den Anzeigen-Link gehängt hat — keine IP-Adresse, kein Gerät oder Browser, keine E-Mail, keine Konto-ID, keine Bons. Die fbclid speichern wir nicht an deinem Konto. Zweck: Messung, welche Anzeigen wirken. Rechtsgrundlage: deine Einwilligung (Art. 6 Abs. 1 lit. a DSGVO), widerrufbar über „Datenschutz-Einstellungen“ auf der Startseite; bereits gesendete Ereignisse verarbeitet Meta nach seinen eigenen Regeln (Meta-Datenschutzrichtlinie).

3. Was wir nicht tun

Keine Werbebanner, kein Autoplay, keine Tracking-Pixel, keine Crashlytics- oder Analyse-SDKs. Google-Suche ist für den Chat in Bonstructer Receipt Notes ausgeschaltet. Die iPhone-App zeigt keine Werbung, enthält kein Werbe-SDK, liest keine Werbe-ID und betreibt kein Tracking. In der Android-App ist Werbung standardmäßig aus. Optional kannst du dort belohnte Videos einschalten, um AIC zu verdienen (Google AdMob). Das SDK wird erst nach dieser Einwilligung genutzt. Bons, Chat, Korrekturen und Kontodaten werden nicht an AdMob übermittelt und nicht für Werbung verwendet. Wir verkaufen deine Daten nicht.

4. Empfänger / Auftragsverarbeiter

5. Speicherdauer

Bons, Originale, Chatverläufe, Chat-Nutzungsdaten und Guthaben bleiben, solange dein Konto besteht oder bis du einzelne Bons löschst. Wenn du das Konto löschst, wird es zuerst deaktiviert. Nach 3 Tagen entfernen wir Notebook-Dateien, Bon-Datensätze, Chatverläufe, Korrekturen, Markierungen, Abrechnungszähler und — soweit möglich — die Firebase-Anmeldung. Bis dahin kann ein Operator das Konto wiederherstellen. Zahlungsanbieter können Belege nach eigenen Pflichten länger halten.

Screenshots, die du einer Rückmeldung beifügst, löschen wir automatisch 3 Tage, nachdem wir die Rückmeldung als erledigt markiert haben. Der Text der Rückmeldung und der Austausch dazu bleiben erhalten.

6. Deine Rechte

Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit und Widerspruch nach der DSGVO. Schreib an info@bonstructer.com. Du kannst außerdem bei einer Datenschutzaufsicht Beschwerde einlegen (in Deutschland typisch die Aufsicht deines Bundeslands).

Konto löschen: Melde dich unter https://bonstructer-api-924783129865.europe-west3.run.app/account/delete an und bestätige die Löschung. Das Konto wird deaktiviert; nach 3 Tagen entfernen wir Bons, Originale, Chatverläufe, Korrekturen, Markierungen, Nutzungsdaten und die Firebase-Anmeldung dieses Kontos. Datenexport: https://bonstructer-api-924783129865.europe-west3.run.app/account/export.

7. Kinder

Bonstructer Receipt Notes richtet sich nicht an Kinder unter 16 Jahren. Wir holen keine elterliche Einwilligung für jüngere Nutzer ein.

8. Änderungen

Eine neue Fassung erscheint unter dieser URL. In der App bleibt der Kurzhinweis unter Nutzungsbedingungen und Datenschutz.


Privacy policy (English)

The controller for Bonstructer Receipt Notes is Chrischosoft. Contact: info@bonstructer.com.

1. What the app does

Bonstructer Receipt Notes stores your receipts (photo, PDF, or pasted text) and answers questions about them. We process this data to perform that contract (GDPR Art. 6(1)(b)) — not as a marketing opt-in.

2. Data we process

Account. Sign-in through Firebase Authentication: a Google account (email, user id), an Apple ID through Sign in with Apple (email or Apple's private relay address, user id), or email and password. We store the Firebase UID and email to identify you. When you sign up in the iPhone app, Apple App Attest confirms that the request comes from a genuine, unmodified install of the app; we receive a key attestation from Apple, not a device identifier.

Receipts. Photos and PDFs you upload, and pasted text. Originals are stored in Google Cloud Storage. Parsed lines, shop, date, amounts, and your corrections are stored in Firestore.

OCR. Photos and PDFs are sent to a Google Cloud AI service (Vertex AI) for text recognition; Google does not retain them or use them for training. LlamaParse / LlamaCloud (EU endpoint) is not used in normal operation, only in exceptional cases when we switch it on manually. We keep the recognized text in your notebook.

Chat. Your questions and notebook contents (receipts, totals) are sent to a Google Cloud AI service (Vertex AI) so the app can answer. Token use and a clipped copy of the question may be written to the workspace usage log. “AI in the EU only”. By default, AI processing (text recognition and chat) may take place outside the EU. If you switch on “AI in the EU only” – any time in the app settings or in the chat menu (⋮) – AI analysis of your receipts and chats runs only in EU data centres of our cloud provider. Under heavy load this can be slower or fail more often. This covers AI processing only; hosting and storage are in the EU either way. Chat history is stored in your cloud workspace, in the same Notes cloud as your receipts.

Usage and billing. Storage used, prepaid OCR scan pages, and chat credits. Purchases in the Android app and on the web: Stripe Checkout when that payment flow is shown; Google Play when you pay through Play Billing. Purchases in the iPhone app are App Store in-app purchases only (Apple StoreKit): Apple processes the payment and we never see payment details. We receive the Apple-signed transaction (product, transaction id, time, renewal and refund status) from the app and through App Store Server Notifications, and credit your account.

Flags. If you flag a receipt for review, your note and parse excerpts may be used to improve receipt recognition. We delete a flag and the receipt copy made for it 3 days after it is closed. We may keep anonymized text excerpts without payment data as test cases.

On device. Session tokens. Camera capture may use Google Play services in the Android app or the system camera in the iPhone app, then the image is uploaded to our API.

Source. If you came through one of our links or an ad (the src / utm_* tag in the link or in the Google Play install referrer), we store that tag once on your account to measure which channel works — first-party, with no tracking pixel and no cookies. Until you sign in we keep it in browser storage for at most 30 days only with your consent (the “Campaign measurement” notice on bonstructer.com; § 25(1) TDDDG, Art. 6(1)(a) GDPR); without consent it is only passed along in the link during the same visit and not stored. You can withdraw any time via “Privacy settings” in the landing page footer, which deletes the stored tag. We also count clicks on our app and Play links anonymously on our server (daily totals per tag only, no IP address, device or account).

Reporting back to Meta. Only if you came from a Facebook or Instagram ad and accepted campaign measurement, our server tells Meta Platforms Ireland Ltd. whether it led to a click on one of our app links (“Lead”), a guest trial (“StartTrial”) or a registration (“CompleteRegistration”, once per account). We send only the event name, the time, for clicks which of our links it was, and the click id fbclid that Meta itself added to the ad link — no IP address, no device or browser, no email, no account id, no receipts. We do not store the fbclid on your account. Purpose: measuring which ads work. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw via “Privacy settings” on the landing page; events already sent are processed by Meta under its own terms (Meta Privacy Policy).

3. What we do not do

No ad banners, no autoplay, no tracking pixels, no Crashlytics or analytics SDKs. Google Search grounding is off for chat in Bonstructer Receipt Notes. The iPhone app shows no ads, contains no ad SDK, reads no advertising identifier and does no tracking. In the Android app ads are off by default. Optionally you can turn on rewarded videos there to earn AIC (Google AdMob). That SDK is used only after you opt in. Receipts, chat, corrections and account data are not sent to AdMob and are not used for advertising. We do not sell your data.

4. Recipients / processors

5. Retention

Receipts, originals, chat history, chat usage records, and credit balances stay while your account exists, or until you delete individual receipts. If you delete the account it is deactivated first. After 3 days we remove notebook files, receipt records, chat history, corrections, flags, billing meters, and — where possible — the Firebase sign-in. An operator can restore the account until then. Payment providers may keep invoices under their own legal duties.

Screenshots you attach to feedback are deleted automatically 3 days after we mark that feedback as done. The feedback text and the conversation about it are kept.

6. Your rights

Access, rectification, erasure, restriction, portability, and objection under the GDPR. Email info@bonstructer.com. You may also lodge a complaint with a supervisory authority (in Germany, typically the authority of your federal state).

Delete account: sign in at https://bonstructer-api-924783129865.europe-west3.run.app/account/delete and confirm deletion. The account is deactivated; after 3 days we remove receipts, originals, chat history, corrections, flags, usage data, and this account’s Firebase sign-in. Data export: https://bonstructer-api-924783129865.europe-west3.run.app/account/export.

7. Children

Bonstructer Receipt Notes is not directed at children under 16. We do not seek parental consent for younger users.

8. Changes

Updated versions will be published at this URL. The app still shows a short terms and privacy notice.