Warrio

Privacy Policy

Last updated 2026-09-23

Who operates Warrio

Warrio is operated by Livio Maroni, Rietstrasse 29, 8840 Einsiedeln, Switzerland. Warrio is run by an individual, not by a company.

For any privacy or data-protection question, and to exercise any of the rights described below, write to Liviomaroni1@gmail.com.

What this policy covers

This policy covers the Warrio web application and the Warrio app for iPhone. The iPhone app displays the same web application inside a native container, so the two handle your data identically. Where a feature exists on only one of them, this policy says so.

It does not cover other companies' websites or services you may reach from Warrio.

Who can use Warrio, and where

You must be at least 18 years old to create a Warrio account. Warrio asks for your date of birth once to confirm this; it is checked, never stored, and beyond that check Warrio does not verify your age — providing it is your confirmation that you meet this requirement. If you believe someone under 18 has created an account, write to Liviomaroni1@gmail.com and it will be deleted.

Warrio is available worldwide. It is offered in English and is not tailored to the law of any particular country.

What information Warrio collects

Account information: your email address, and the display name you choose. Your password is handled by Warrio's authentication provider and is never visible to the operator.

Subscription and payment information: if you buy Warrio Pro, Warrio stores the customer and subscription identifiers the payment provider issues, which plan you bought, whether it is set to renew, and the date your current paid period ends. The payment itself is never handled by Warrio and your card details are never stored by it. Where you pay depends on where you bought: in the Warrio app for iPhone the payment is made on Apple's own sheet and goes to Apple, and on the web it is made on Stripe's own pages, where Stripe also asks for a billing address — the billing country is read from Stripe each time it sends a subscription message, and no copy of your address is kept.

Records you create: items you own, warranty details, insurance policies, recurring payment records, and any notes you write. These are whatever you choose to enter.

Documents you upload or scan: receipts, invoices, policy documents and similar files, together with details such as the document name, type, issue and expiry dates, provider and file size.

AI processing data: the document image you scan, sent for extraction as described below, and a record that a scan happened.

Authentication and security information: your sign-in session, and the technical signals used to tell people from automated abuse on the sign-in, sign-up and password-reset forms.

Settings: your reminder preferences, currency, theme, and whether app lock is on.

Limited technical information: the IP address and standard connection details that any web service receives in order to answer a request.

Warrio does not collect your location, does not build an advertising profile, and does not buy or sell personal data.

Why each kind of information is processed

Account information is processed to create and operate your account, to sign you in, and to contact you about your account.

Subscription information is processed to give you the plan you paid for, to apply the limits that come with it, to let you manage or cancel it, and to answer questions about a payment.

The records and documents you create are processed for the only purpose the product has: storing them for you, showing them back to you, and calculating the warranty and expiry reminders you asked for.

Document images are processed to extract the details you asked Warrio to read, so you do not have to type them.

Authentication and security information is processed to keep your account yours, and to stop automated attacks on the sign-in forms.

Settings are processed so the app behaves the way you configured it.

Limited technical information is processed to deliver the service, to keep it secure, and to investigate faults and abuse.

Information about other people

Sharing with other people is not available. Warrio cannot show your items to anyone else — there is no account for them, no invitation, and no way for another person to read anything in yours. The screen that offered it has been closed rather than left saying otherwise.

You may already have recorded family members, to note who an item or policy belongs to. Warrio stored the name you typed and nothing else about that person. No invitation was ever sent, no account was created for them, and Warrio has no other relationship with them.

Those entries are kept. They stay in your account, they are included when you export your data, and they are deleted when you delete your account. You can still edit or remove any of them at any time.

Your records may also mention other people in other ways — a policy holder on an insurance document, or a name printed on a receipt.

You are responsible for having an appropriate basis or permission to enter another person's information where that is required where you live. If someone asks you to remove information about them, you can edit or delete it in the app; if they contact Liviomaroni1@gmail.com directly, the request will be passed to you, because it is your account that holds the record.

Identity and travel documents

Warrio lets you store identity and travel documents — for example a passport, national identity card, driving licence, visa or residence permit — so that it can remind you before they expire.

For these document types Warrio deliberately does NOT collect the document number. A passport or identity-card number is a durable identifier of a person and cannot be changed after a leak, and the expiry reminder does not need it. The field is not offered for these types, any number produced by scanning is discarded before saving, and the database itself rejects a stored number for them.

What is kept for an identity document is the document type, the issuing authority if you enter one, the issue and expiry dates, and the image you uploaded.

If you scan one of these documents rather than typing its details in, the image is sent to Warrio's backend and forwarded to Google to be read, exactly as a receipt is — see "Scanning receipts and documents with AI". Adding the document by entering its details yourself still stores the file in your account, but sends nothing to Google.

How your documents are stored

Uploaded and scanned document files are stored in a private file store. They are never public, are never listed to anyone else, and every file path is scoped to the account that owns it.

When you open a document, Warrio generates a link that grants access to that one file and expires after five minutes.

Every database record is protected so that only your own account can read or change it.

Scanning receipts and documents with AI

When you scan a receipt, or any other document, the image does not stay on your device. Warrio sends it to its own backend, which forwards the image to an external AI provider that reads the document and returns the extracted details for you to confirm.

That provider is Google. Warrio uses Google's Gemini API, on Google's paid tier, and Google is the only external AI provider that receives your documents. The service is configured to refuse to run at all if any other provider were configured, so a second company cannot quietly be added to this path.

Only two things are sent with each request: a fixed instruction telling the model what to extract, and the single document being analysed. Your email address, your name, your account identifier, your other items and documents, and your plan are not sent.

Google's own terms, privacy notice and security practices for paid use of the Gemini API apply to this processing. Warrio does not control Google's systems and makes no promise of its own here about how long Google holds a request, whether any person may review it, or whether it contributes to Google's services — Google's current terms govern that, and they can change. If that matters to you, read Google's terms for the Gemini API before scanning a document.

Warrio itself does not keep the copy of the image it sends for analysis, and does not keep the model's response. A separate, smaller copy of the same document is saved to your account only if you accept the scan result — that copy is the one described under "How your documents are stored".

This applies to every kind of scan, not only receipts. An insurance policy, a passport, an identity card, a driving licence, a visa or a residence permit is sent to Warrio's backend and forwarded to Google in exactly the same way, because the same service reads all of them. Identity and travel documents are not given a separate, private route. If you would rather not send one of these documents to Google, add it by entering its details yourself instead of scanning it.

Warrio also uses text recognition running inside the app, on your own device, as a fallback — for receipts and for other documents alike — when the AI service cannot be reached. That fallback sends nothing to a server and is less accurate. It is a fallback, not the normal path: a normal scan does send your document to Google as described above.

What Warrio records about AI use

For each scan Warrio stores a usage record containing your account identifier, the kind of scan, whether it succeeded, the size of the input in bytes, the number of tokens the provider reported, and the time. It exists to enforce the scan allowance on your plan.

For each request Warrio sends to the AI provider during a scan, it also stores an AI request record containing your account identifier, your plan at the time, the attempt number, the model identifier and service tier, how the request ended and its response status, the token counts the provider reported, how long the request took, and the time. It exists so Warrio can measure what the scanning service costs.

These records contain no document content, no image, no prompt and no model response. Error logs record error categories only.

Where your data is stored

Your account, your records and your document files are stored using Supabase, which provides the database, authentication and file storage. This data is held in Supabase's EU (Ireland) region.

The Warrio web application itself is delivered as static files through Vercel's content delivery network. Vercel serves the application code; your account data is not stored there.

Service providers Warrio uses

Supabase — database, authentication and private file storage. It holds your account, your records and your documents.

Google — the Gemini API, which receives a receipt image when you scan one, as described above.

Vercel — hosting and delivery of the application files. It receives the network requests that load the app.

Cloudflare — the Turnstile bot check on the sign-in, sign-up and password-reset forms.

Stripe — the payment provider for buying Warrio Pro on the web. Your card and billing details are entered on Stripe's own page and go to Stripe, not to Warrio. Stripe tells Warrio's backend when a subscription starts, changes or ends; Warrio stores the customer and subscription identifiers Stripe issues, and reads the billing country Stripe holds for you each time one of those messages arrives, without keeping a copy of your address.

Apple — the payment provider for buying Warrio Pro in the Warrio app for iPhone, and only for the purchase itself. The purchase is made through Apple's App Store: your payment details are entered on Apple's own sheet and go to Apple, not to Warrio, and Apple tells Warrio's backend when a subscription starts, renews, changes or ends so that the plan can be applied to your account. So that the purchase can be matched to the right account, Warrio attaches your Warrio account identifier to it, and Apple keeps that identifier with the transaction.

RevenueCat — the service the Warrio app for iPhone uses to manage App Store subscriptions. When you are signed in, the app gives RevenueCat your Warrio account identifier, and RevenueCat receives the details of an App Store purchase made under it: which plan, when it renews, and whether it is still active. It never receives your payment details, and it does not receive your records, your documents, or anything read from them.

Resend — the provider that delivers Warrio's emails, including the reminder email described below. To send one it receives your email address, your display name, and the content of that day's reminders: the names of the items, policies, documents and renewals the reminder is about, and their dates. There is no way to send you a reminder about your passport without telling the sender that it is about your passport. It receives nothing else — not your documents, not your files, not your prices, not your notes, and not the records that are not in that day's reminder. If you turn the reminder email off in Settings, Resend receives nothing about you at all beyond the confirmation and password-reset emails Warrio has to send to operate your account.

PostHog — the product-analytics provider for the iPhone app, hosted in the European Union. It receives the small fixed list of events described below under “Storage on your device”, and the technical information any such request carries, such as a device identifier generated by Warrio for this purpose. It does not receive your records, your documents, or anything read from them.

These providers process your information to provide their service to Warrio. Warrio does not sell your personal data, does not share it for advertising, and does not give it to data brokers.

International processing

Warrio is operated from Switzerland. Your account data and document files are stored in the EU (Ireland).

Some providers operate globally, so a request may be processed outside those places — in particular the AI provider, the payment providers, the subscription service the iPhone app uses, the bot-protection provider and the email provider. Apple, RevenueCat and Stripe are based in the United States, so a purchase and the subscription record that follows it are processed there. Resend is based in the United States, so a reminder email, including the item and document names in it, is processed there on its way to you. Because Warrio is available worldwide, using it will normally involve your information crossing a border.

Where your information is transferred out of the country you live in, that transfer happens because it is necessary to provide the service you asked for.

Bot protection on sign-in

The sign-in, sign-up and password reset forms use Cloudflare Turnstile, which distinguishes people from automated abuse. To do that, Cloudflare receives your IP address and technical signals from your browser when one of those three forms is used.

Turnstile is not used anywhere else in the app, and Warrio does not use it to track you.

Emails Warrio sends

Warrio sends three kinds of email, all of them about your own account. Two are one-offs you trigger: confirming your email address when you sign up or change it, and sending you a reset link when you ask to recover your password.

The third is the reminder email. It is a single daily message, sent only on days when something you have recorded is coming up, and it lists those things by name — the item, the insurance policy, the document or the renewal, and the date it is due. That is the point of it: a reminder that does not say what it is about is not a reminder. It is one email listing everything due, never one per thing. It carries no advertising and no tracking image, and the only links in it open Warrio and these settings.

You can turn the reminder email off in Settings, under Reminders. Turning it off stops the email and nothing else — your reminders still appear in the app, on the home screen and in the notifications list, exactly as before. The four switches beside it control which reminders exist at all.

Sending it means your email address, your display name and the names and dates in that day's reminders are given to Resend, the email provider, so it can deliver the message. See "Service providers Warrio uses".

Resend answers each send with an identifier for the message, and Warrio keeps that identifier beside the reminder it belongs to. It is an opaque provider reference — not your address, not the subject, and nothing the message said — and it is kept for one reason: so that a reminder which did not arrive can be traced with the provider rather than guessed at. It is deleted with your account.

Warrio does not send marketing or promotional email, and there is no mailing list.

Storage on your device, cookies, analytics and statistics

Warrio does not set cookies. It uses your browser's local storage to keep your signed-in session, a flag recording that you have seen the introduction, and a queue of changes not yet synchronised. All of it is needed for the app to work, and clearing your browser data removes it. Signing out clears the queued changes for that account.

The iPhone app reports a small, fixed list of product events to PostHog, so that it is possible to see how often the app is opened and whether the Pro screen is reached — nothing more. The complete list is: the app was opened, the Pro screen was shown, and the Pro screen was closed. Each carries only which screen it was and why it appeared. No event carries the name of anything you own, any document, any text read from a document, any date, any price, your email address, or any identifier of a record in your account. Warrio contains no advertising, no crash-reporting service, no session recording and no behavioural tracking, does not track you across other apps or websites, and never asks for permission to track you. The web version of Warrio reports nothing at all.

Aggregate figures may be published or reported — for example how many documents are stored across all accounts in total. These are counts. They are not built into a profile of you, are not shared with advertisers, and do not identify anyone.

Exporting your data

You can download a copy of your data at any time from Settings. The export is a JSON file containing your account details, settings, items, insurance policies, payments, notifications, family entries and your document records.

Document files themselves are not included in the export. Each document appears with its details and its storage path; to obtain the original files, open them in the app or write to Liviomaroni1@gmail.com.

Deleting your account

You can permanently delete your account from Settings inside the app. You can also ask for deletion by writing to Liviomaroni1@gmail.com.

Deletion removes your account and your profile, your items, warranties and insurance records, your payment records, your document records, your notifications, your settings, your family entries, your scan usage records and your AI request records, and deletes your uploaded files from private storage.

Before your account is removed, Warrio checks that your files have actually gone from storage. If that check fails the deletion stops and your account is left in place, so that files can never be left behind with no owner and no way to reach them. You can retry, or write to Liviomaroni1@gmail.com.

Deletion cannot be undone. Export your data first if you want to keep a copy. Please also read the section below on how long data is kept, which explains the limits of what deletion can reach.

If you bought Warrio Pro on the web, deleting your account also ends that subscription: as part of the deletion Warrio asks Stripe to cancel it.

Important: if you bought Warrio Pro in the Warrio app for iPhone, deleting your Warrio account does NOT cancel it. Subscriptions bought through Apple are managed by Apple and must be cancelled in the Subscriptions section of your Apple account settings. Deleting your Warrio account without cancelling there would leave the subscription billing.

How long data is kept, and what backups mean

Your data is kept for as long as your account exists. When you delete your account it is removed from the live service straight away, as described above.

Backups are the honest limit on that. Warrio's database runs on Supabase's Pro plan, which takes scheduled backups; continuous point-in-time recovery is not enabled. A backup taken before you deleted something can therefore still contain it until that backup is rotated out in the normal cycle. Warrio cannot delete individual records from a backup that has already been taken.

Database backups and uploaded files are different things. Your document files are not part of the database backups; they live in the private file store and are deleted from it directly when you delete a document or your account.

Warrio's providers also keep technical and security logs — records of requests, addresses and errors — under their own retention schedules, which Warrio does not control. A limited amount of internal record-keeping may likewise survive a deletion for a short time where it is needed for security, fraud prevention, handling a dispute, or meeting a legal obligation.

Sent email is its own case, and not the same as a technical log. Resend keeps a record of each message it delivered under its own retention schedule, and that record contains the message itself — so it holds the item and document names that were in that day's reminder, for as long as Resend keeps it. Warrio cannot delete it there. Deleting your Warrio account stops any further email; it does not reach back into messages already sent.

Records of a purchase are the exception to deletion. Warrio's own subscription record goes with your account, but the payment provider keeps its own record of what you were charged under its own retention rules — Apple, together with RevenueCat, for a purchase made in the Warrio app for iPhone, and Stripe for one made on the web — and Warrio cannot delete it there. Accounting records of a sale are likewise kept for as long as the operator is required to keep them, separately from your account.

For those reasons this policy does not promise that every technical copy of your data disappears the instant you press delete. What it promises is that the live service no longer holds it, that your files are removed from storage, and that the remaining copies expire on the schedules described here.

Data processed by the AI provider is governed by that provider's own terms, not by this section — see "Scanning receipts and documents with AI".

Your rights

You can access and correct your information directly in the app, export it, and delete your account and its data at any time.

Depending on where you live you may have further rights over your personal data — for example to obtain a copy, to have inaccurate data corrected, to have data erased, to object to or restrict certain processing, to receive it in a portable form, and to complain to a supervisory authority in your country.

To make a request, write to Liviomaroni1@gmail.com. You will not be charged for making one, and you will not be treated differently for having made one.

Changes to this policy

If this policy changes in a way that materially affects you, the updated version will be published here and the date at the top will change. Continuing to use Warrio after that means the updated policy applies.

Contact

Livio Maroni, Rietstrasse 29, 8840 Einsiedeln, Switzerland.

Privacy contact: Liviomaroni1@gmail.com.