Your purchase data, explained
Purchase Intelligence combines information from bank accounts and Gmail you choose to connect. It helps you remember purchases, organize items, and check evidence of refunds, subscription price changes and return deadlines.
Who is responsible
- Operator / data controller
- SIA Timeless Solutions, registration number 40203628354, Kartupeļu iela 35 - 2, Rīga, Latvia. Registration and address checked in the Latvian Register of Enterprises.
- Privacy and support contact
- info@tlsolutions.io, the operator's business support contact.
- App website and API
- The operator's purchaseintel.app domain is registered, with verified DNS and public HTTPS. purchaseintel.app serves the app's owner-pilot website; api.purchaseintel.app is the public HTTPS API host. Public reachability does not authorize connected-account processing.
- Legal-page URLs
- purchaseintel.app/privacy and purchaseintel.app/terms are the canonical addresses for the published owner-pilot policies.
- Notice version and effective date
- owner-pilot-v1 · Effective 4 October 2026.
Information used to build your inventory
- Account information: your sign-in email, password hash, account identifier and session information. Provider authorization credentials are stored separately in encrypted form.
- Connected bank information: account and transaction identifiers, dates, amounts, currencies, payment direction, booking status, merchant information and supported order references returned by the bank provider. The app does not request your bank login password.
- Connected Gmail information: the importer reads message identifiers, sender, subject, dates, message text and supported attachment information to identify purchase evidence. Supported PDF text may be extracted during processing. Accepted records retain identifiers, subject, dates, structured purchase facts, source links and quoted evidence excerpts limited to 1,500 characters. An excerpt can contain all of a short message. Unbounded original message bodies and original attachment files are not retained by this import path; unrelated messages may be read during selection but are not intentionally archived.
- Purchase records: items, payment associations, evidence excerpts and source links, purchase categories, supported findings, rule decision records and corrections you make. Remote-model responses are not created by the rules-only pilot; any future model data use is covered by a separate notice and approval.
- Operational information: connection status, import coverage, job status and limited technical errors needed to run and protect the service. The deployed server journal has a 256 MB limit, daily rotation and a 30-day age-retention setting, with an active cleanup timer. Request access logs are disabled. Infrastructure may still process network identifiers. Cleanup depends on successful operation; failures require operational correction.
The app does not save original email attachment files as a general document library. Structured export is described below. A message about a purchase can still contain sensitive details or information about another person; connecting Gmail can expose those details to processing.
What a connection permits
Bank access is read-only account information through Enable Banking and your bank's consent flow. It cannot initiate payments. Availability and history depend on the bank, selected accounts and consent expiry.
Gmail uses the gmail.readonly permission. Google grants broader message-reading access than just receipts; the app selects purchase evidence within that access. This permission cannot send, edit or delete your email. See Google's description of Gmail permissions.
The initial Gmail import targets recent purchase messages, then may expand to older purchase history. Import coverage and last synchronization are shown in the app. A missing receipt or incomplete connection can leave a purchase unresolved.
This policy covers the personal owner pilot. Gmail connection uses the configured test-user flow; real bank access depends on the provider's enabled production application and permitted accounts. A working website, sandbox or personal test does not establish public-app verification or approval for an unrestricted audience.
How the information is used
The service uses your connected information to reconstruct purchases, match payments to evidence, organize your inventory, update supported findings, show the reason for a match, apply your corrections and synchronize changes.
Purchase findings are suggestions for your review. The app does not decide whether you qualify for credit, alter your bank account, cancel subscriptions, make merchant claims or send merchant emails.
We do not sell connected data, use it for advertising or credit scoring, or use it to train a general model. Human access to Gmail-derived information is limited to documented permission for specific data or the security and legal cases allowed by Google's policy.
Purchase Intelligence's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Legal bases for this pilot: we process account information, requested imports, purchase inventory and corrections to provide the service you request under the service agreement. Limited operational information is processed for our legitimate interest in proportionate service security and prevention of abuse. Optional remote AI is disabled; any future transfer for that option requires a separate current disclosure and specific approval. Bank and Google permissions authorize technical access and remain separate from these processing purposes.
Hosting and service providers
The application server and separate encrypted backup storage are hosted by Hetzner in Helsinki, Finland. Deployment checks confirmed a private database on the encrypted data mount, public HTTPS with private container ports, and controlled reboot/unlock recovery. An actual off-host backup passed full integrity, isolated database restore and recovery-key checks. The combined deployed test also confirmed acknowledged off-host deletion, deletion replay from the current remote ledger into an older backup, and clearing restored credentials, sessions and remote-AI approval. The owner confirmed independent encrypted storage of the updated recovery bundle including the ledger key; this is a copy confirmation, not a vault restore test. At publication, no personal bank/Gmail records have been imported; remote models remain disabled. EU application hosting does not make external source or future model providers EU-only.
Enable Banking and your selected bank handle bank authorization and supply account information. Google supplies the Gmail API and authorization service. Their services have their own terms and privacy information, including Enable Banking's privacy notice and Google's privacy policy.
Initial pilot: remote AI is off. Purchase analysis uses rules and supported parsers on our Hetzner service. Purchase email, attachment text and transaction facts are not sent to TypeSafe or Gemini while this option is disabled. Unfamiliar or incomplete evidence may remain unresolved. Bank and Gmail source connections have their own read-only authorizations; they do not enable remote AI.
The following are planned model processors, not active recipients in this pilot. Any future enablement needs a separate current notice and explicit approval:
- TypeSafe Jev: may receive minimized merchant, amount, date and order-reference facts for matching, or item names and a limited purchase excerpt for classification. TypeSafe's published policy states US hosting and says input is not used for model training. It does not establish zero retention. See TypeSafe's privacy policy.
- Google Gemini through Vertex AI: may receive selected message subject and text, including extracted attachment text, for structured purchase extraction. The planned route requires a supported model and verified EU processing location. A European location name alone is insufficient: some European locations are outside the EU. Google's documented training restriction and retention conditions apply; zero retention is not assumed. See processing locations and data governance.
Future remote-AI conditions: this rules-only owner policy does not enable models. Before that option can be offered, the exact provider, data sent, retention, processing location, terms and relevant transfer arrangements must be disclosed in its notice, and your approval recorded. Provider configuration alone is not your approval. No consumer Gemini API processing is part of this pilot.
The implemented account control keeps remote analysis off by default and records the exact notice version and content accepted. Hosted synthetic checks confirmed the default-off state, refusal to enable unavailable processing, withdrawal, consent-history export and account deletion. You can keep your bank and Gmail connected without remote analysis. Turning it off stops new provider requests and clears our cached AI responses; it retains your purchase history and cannot retract requests already sent. Provider retention rules continue to apply to information already received. Material processor, location or purpose changes require a new notice and renewed approval. Remote-model processing and its separate notice remain unapproved and disabled; these synthetic checks do not authorize a live model transfer.
Retention, disconnect and deletion
Current application records remain in the active database while your account exists. Disconnecting a source stops future imports and removes its locally held authorization credentials; it retains previously imported purchase history and evidence. Reconnecting can resume imports.
Deleting your account removes its active database records, source evidence, purchase records, corrections, connection credentials and jobs. The app also attempts to revoke provider access. Provider outages can prevent that attempt from succeeding; review permissions in your Google account or the Enable Banking consent manager if necessary. Deleting the app alone does not delete the server account. Deleting the account does not delete source emails or bank records at their providers.
Backup snapshots can contain earlier account data after active deletion. The deployment backup job rotates seven daily, four weekly and three monthly encrypted snapshots and prunes snapshots older than 90 days after each successful backup. Failed jobs or a service outage can delay pruning; operators must monitor and resolve those failures. Backups are for recovery, not routine use. This is a normal-operation retention policy, not an immediate physical-erasure guarantee.
Deletion completion: before confirming account deletion, the service records the request in a separate encrypted off-host deletion ledger and verifies its durable acknowledgement. Only then does it commit removal of your active account data and report success. If confirmation is unavailable, deletion fails before active removal is committed; retry or contact support. An interrupted request can already have an off-host recovery record. Requests in the independently checked off-host ledger are applied during recovery, even if interruption prevented a successful app response. Provider revocation remains an attempted action, not a guarantee.
The recovery record contains only opaque account and deletion-request identifiers, a timestamp and format version, without mailbox contents, bank records, email address or tokens. It is retained separately to prevent restoring deleted accounts for as long as relevant database snapshots can be recovered. It is not removed with the active account. This pilot has no automatic age compaction of those records; we review removal after the corresponding restorable backups have expired. The backup retention period is not a promise of automatic ledger deletion.
Recovery: a recovered database stays isolated until the complete current off-host deletion ledger is fetched, authenticated and applied. Missing, inaccessible or invalid deletion records block exposure of that database. Surviving purchase history and corrections may be restored, but saved bank/Gmail credentials, authorization states, import cursors, coverage and model caches are cleared, unfinished imports are cancelled, previous sessions invalidated and optional remote-AI approval disabled. You must sign in again and reconnect sources; any future remote AI requires fresh approval of the current notice. Restoring an old backup does not resume a withdrawn connection or AI permission.
Normalized purchase history and the quoted evidence needed for the inventory are kept while your account exists, then removed from the active service on completed account deletion. Original mailbox bodies and attachment files are not archived. The rules-only pilot creates no remote-model response cache. Any future model cache needs its own reviewed retention process; a read expiry alone is not physical deletion. Operational log and backup cleanup depend on successful scheduled work, and failed runs may delay removal. Recovery records cover the period when older snapshots could reintroduce deleted accounts.
Your controls and rights
You can choose accounts to connect, disconnect them, correct purchase names, item statuses and payment associations, dismiss findings, export structured account data and delete the account. The current export includes purchase views, connections, decision records and your remote-analysis choice and notice history; it is not a complete mailbox, original attachment archive or copy of every provider record.
Where the GDPR applies, rights include access, correction, erasure, restriction, portability and objection under the relevant conditions. You may withdraw consent where processing relies on consent, and complain to a competent data protection authority. See the European Commission's explanation of these rights.
Send privacy or support requests to info@tlsolutions.io. We check identity proportionately and respond within the applicable legal time limit. You may complain to Latvia's Data State Inspectorate, or another competent authority such as the authority where you live. In-app structured export does not replace a full access request.
Protecting data and updating this notice
Host checks confirmed restricted firewall access, encrypted application persistence, non-root application containers and a private database. Deployed synthetic account checks passed for purchase reconstruction, corrections, account isolation and deletion. Controlled reboot recovery confirmed the application stayed stopped while the encrypted volume was locked and recovered after an operator unlocked it. Public site/API HTTPS passed certificate and hostname verification. A separate off-host backup passed full integrity and isolated database/key restoration checks. The combined deployed recovery test removed the deleted synthetic account using the current remote ledger despite an older local journal, retained the control account's purchases and corrections, and verified restored connection/job/session/AI-approval restrictions. Missing remote records and a wrong decryption key blocked recovery. Real-provider imports and real-world analysis accuracy remain unverified. These checks are not an independent security audit or a compliance certification.
These static legal pages use no analytics, advertising scripts or nonessential cookies. That statement covers these pages, not independent bank or Google authorization websites.
Material changes to purposes, recipients or access must be explained before they take effect, with new approval where required. The effective notice must identify its version and date.