Privacy Policy
Last updated: 28 August 2026.
At Garantio, protecting your personal data is a priority. This policy explains what information is processed, why, and how you stay in control, in line with the General Data Protection Regulation (GDPR).
In short
- Garantio processes the data you enter or scan in order to track your warranties: products, receipts, claim files.
- The receipt is read on your phone. The photo of the receipt is never sent to an artificial-intelligence provider.
- We never sell your data and we do not use it to profile you.
- You can export all of your data and delete your account permanently from the app.
- The garantio.fr website sets no cookies and uses no analytics tooling.
Data controller
The controller for the data of the website and the Garantio app is Programini, 2 Rue du Colonel Chambonnet, 69500 Bron, France.
For any question about your personal data: contact@programini.com. Data protection officer (where applicable): none appointed.
What data we process
- Account data: Email address, first name, last name. If you sign in with Google, Apple or Microsoft, we receive your identifier and your verified email address from that provider; we never see your password.
- Household: Household name, invite code, list of members and their roles. A household’s warranties are visible to its members.
- Product data: What you enter or scan: product, brand, category, room, price, purchase date, store, warranty durations, notes.
- Documents: Photos of receipts and invoices that you choose to save as proof of purchase.
- Claim files: Description of the fault, type of request, seller details, sender address and the formal notice letters generated as PDFs.
- Notifications: Your device notification token (Firebase Cloud Messaging) and the history of reminders sent, so we can warn you before a warranty expires.
- Partner offers: When a partner offer is displayed, we record the display and any click, linked to your account, in order to measure how the offer performs.
- Technical data: Connection and security logs (timestamp, IP address, error type) strictly necessary to operate, troubleshoot and secure the service.
Receipt analysis: what stays on your phone
When you photograph a receipt, text recognition runs locally on your device. Only the extracted text is then sent to our servers, and on to a language-model provider, to be structured into fields (product, brand, store, price, date).
The image of the receipt is never sent to the artificial-intelligence provider. It is only stored as proof of purchase if you choose to keep it. Provider used for structuring: OpenAI — United States.
You can check, correct or delete every piece of information obtained before saving it.
Why we process it (legal bases)
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the app and its features | Performance of a contract |
| Account and household management | Performance of a contract |
| Sending warranty expiry reminders | Performance of a contract |
| Generating formal notice letters | Performance of a contract |
| Security, fraud prevention and logging | Legitimate interest |
| Measuring partner offer performance | Legitimate interest |
| User support | Contract / legitimate interest |
| Legal and accounting obligations | Legal obligation |
How long we keep data
- Your account, product, document and claim data are kept for as long as your account is active.
- When the account is deleted they are erased permanently, unless a legal retention obligation applies.
- Technical and security logs: 12 months maximum, unless a legal obligation or ongoing security investigation requires longer retention.
- Support conversations: 3 years from the last contact.
- Partner offer events: 24 months from the event.
Recipients and processors
Your data is never sold. It is accessible to the members of your household, to the Garantio team strictly as far as necessary, and to the following providers, which act on our behalf under contractual data-protection commitments:
- Application and database hosting: Programini — France (European Union)
- Proof-of-purchase storage: Microsoft Azure Blob Storage, or the application server’s own storage depending on the production configuration.
- AI receipt structuring: OpenAI — United States
- Push notifications: Google — Firebase Cloud Messaging.
- Third-party sign-in: Google, Apple and Microsoft, only if you choose that sign-in method.
- Service emails: Programini — transactional email (no-reply@garantio.fr)
- In-app purchases: RevenueCat, together with Apple’s App Store and Google Play. Garantio being free, no payment is processed to date; we never have access to your bank details.
Transfers outside the European Union
Some providers may process data outside the European Union. Such transfers are covered by appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses. Transfers may involve the United States (OpenAI, Google/Firebase, Apple, Microsoft, RevenueCat), covered by the European Commission’s Standard Contractual Clauses.
Cookies and trackers
- The garantio.fr website sets no cookies: no analytics, no advertising, and no fonts or scripts loaded from a third-party service. No consent banner is therefore required.
- The account area uses a single strictly necessary cookie (
garantio_session), encrypted and not readable by scripts, which keeps your session open. It is removed when you sign out. - The mobile app uses no advertising cookie.
- If advertising space is introduced in the app, this section will be updated and your consent will be collected where the law requires it. Not applicable at this time.
Your rights
Under the GDPR you have the following rights over your data:
- Access and rectification: view and correct your data, directly in the app.
- Portability: export all of your data as a ZIP archive from the app settings or from your account area.
- Erasure: delete your account and your data permanently.
- Restriction and objection: ask us to restrict a processing activity or object to it, in particular those based on legitimate interest.
- Withdrawal of consent at any time, where processing is based on your consent.
To exercise these rights, write to contact@programini.com. You may also lodge a complaint with the CNIL, the French supervisory authority, or with the authority of your country of residence.
Security
- Traffic between the app and our servers is encrypted (HTTPS/TLS).
- Passwords are stored as hashes, never in clear text.
- Access to a household’s data is checked server-side on every request.
- We apply data minimisation: only the data the service needs is collected.
Children
Garantio is not intended for children under 15 and does not knowingly collect their data. If you believe an account was created by a minor without the required authorisation, write to us and we will delete it.
Changes to this policy
This policy may change, in particular when a feature or a provider is added. Any material change will be signalled on the website or in the app. The last updated date appears at the top of this page.
See also: Legal Notice · Terms of Service