NegosyoKlaro · by EM Labs
Privacy Policy
Effective date: August 10, 2026
The short version
NegosyoKlaro is a point-of-sale and inventory app for small Philippine businesses. Your business records — sales, inventory, customers, utang, cash — are kept in the app on your phone, not on our servers. We keep a small cloud account (your sign-in identity and subscription status) so you can sign in and use paid features. If you choose to scan a supplier receipt with Smart Resibo, that one photo is sent for text extraction — that is the single exception to everything staying on your phone, and it is explained in full below. We do not run ads, we include no analytics, tracking or crash-reporting software, and we do not sell data.
A. Information kept on your device
Everything you record while running your store is saved in a local database inside the app on your phone:
- Products, categories, prices, barcodes, and stock levels
- Sales, receipts, and cash movements
- Stock purchases, suppliers, and price history
- Capital and business-year records
- Customer (suki) names and utang balances that you enter — these stay on your phone and are never uploaded to us
- Product photos you take. They are re-encoded by the app before being saved, which removes camera metadata such as location
- Your GCash / QR Ph payment image, if you add one. It is re-encoded the same way and is shown to your customers by you, on your phone — we never receive it
- Your Owner Lock PIN, stored as a one-way derived value in your phone's secure keychain. We never see it and there is no recovery bypass
Because these records live on your device, deleting the app deletes them, and we cannot recover them for you. NegosyoKlaro does not back up your business data to our cloud — there is no feature that uploads your ledgers, and the app says the same thing in its settings.
B. Information in your account (our cloud)
Sign-in and subscriptions are powered by Supabase, our cloud database provider. Your account holds account-level records only:
- Your Philippine mobile number (if you sign in by SMS code) and/or your email address and a password. Passwords are handled by our authentication provider; we never see them in plain text
- An optional recovery email, if you choose to add one
- Your profile name
- A record that your store is claimed by your account, together with a random per-installation identifier, used to stop someone else claiming the same store
- Subscription and trial status — for example an active Pro Preview or a paid subscription — including a mirror of your App Store subscription state
- Smart Resibo scan records, described in section D
- If you signed up through a sales partner and entered a referral code, the record linking your store to that partner
We use this to sign you in, to let you get back to your account on a new phone, to enforce plan limits fairly, and to operate the paid subscription. We do not use it for advertising or profiling.
C. Subscriptions and payment
Paid plans are purchased through Apple's App Store. Apple processes the payment — we never receive your card details.
We use RevenueCat to manage subscription state. The app does not send RevenueCat your name, email address or phone number, and we have verified that against our own source code. What RevenueCat receives is:
- A subscription account identifier — a random internal code, not your email or phone. If you have not created a cloud account, RevenueCat generates its own anonymous identifier instead
- Your purchase and subscription status, including the receipt Apple issues, which RevenueCat validates on our behalf
- Technical information its software attaches to its own requests automatically. This includes your device's vendor identifier (an Apple-generated code specific to this device and our app, which resets when you delete the app), your device model, iOS and app version, language settings, App Store country, and network information such as your IP address. We do not control this — it is part of how the service operates — and we do not enable its advertising-attribution or advertising-identifier features
This traffic happens when you open the subscription or upgrade screens, or make or restore a purchase — not while you are recording sales. Apple and RevenueCat keep their own transaction records under their own privacy policies.
D. Smart Resibo (receipt scanning)
This is the one place where something you recorded leaves your phone, and it only happens when you ask for it. When you tap to scan a supplier receipt, the app sends that photo to our own server endpoint, which passes it to an AI text-extraction provider — currently Mistral AI — to read the items on it.
- The photo is sent only when you tap to scan. Never automatically.
- Our endpoint does not attach your name, number, or account identity to the image it sends to the provider.
- We do not keep the receipt image. It is not written to any of our databases and not uploaded to any file or object storage. It exists on our server only in memory for the seconds the extraction takes, and our own code writes no log entry containing the image or anything read from it.
- We do not keep the provider's response either. It is used to pull out the fields you then review — shop name, date, and each item's name, price and quantity — and is released as soon as that finishes. Nothing from the scan is written to your phone unless you choose to save the purchase, and then only the purchase itself is saved, locally, like your other records.
- What we do keep is a scan record. For each scan we store a SHA-256 fingerprint — a one-way hash that cannot be turned back into the picture — together with your account and store identifiers, the time, and the outcome. We keep it to count your plan's scan allowance, to avoid charging you twice for the same receipt, and to detect abuse. It contains no receipt text and no image.
- Your plan decides your allowance: free accounts have no provider scans, a Pro Preview includes one, and a paid Pro plan includes 30 per month.
- Processing by the AI provider is governed by that provider's own terms and its own retention practices, which are theirs to state, not ours.
Temporary copies on your phone. iOS makes working copies of the picture while you scan: one created by the system photo picker, and one resized copy the app prepares to send. The app deletes the copies it owns when the scan finishes, when you replace or remove the image, when you cancel the review, and when you leave the scan screen. Two honest limits: while an extraction error is on screen offering Retry, the copy is deliberately kept so you do not have to photograph the receipt again; and if the app is force-quit or terminated by iOS mid-scan, a copy can be left for iOS to clear on its own schedule. These files never leave your device and are removed when you delete the app.
E. Your phone's own backup is not our cloud
If you have iCloud Backup or an encrypted computer backup switched on, Apple's backup of your phone can include the app's local database, your product photos and your QR image — the same as for other apps. That is your backup, under your Apple account and Apple's privacy policy. It is not a NegosyoKlaro cloud sync, we cannot read it, and it does not give us a copy of your business records. Your Owner Lock credential is deliberately excluded from device backups.
We mention it because it is the honest answer to “where else could my records be?” — and because it is currently your best protection against a lost or broken phone.
Camera, photos, and barcodes
- Barcode scanning uses your camera on the device. Only the barcode number is saved, to your local product record. No barcode image leaves your phone and no external barcode service is contacted.
- Product photos (camera or photo library) are saved inside the app on your phone and are not uploaded.
- Face ID, if you turn on Owner Lock, is checked by iOS. The app only receives a yes-or-no answer; your biometric data never reaches us or the app.
What we do not do
- No advertising and no advertising SDKs
- No analytics, tracking, attribution or crash-reporting SDK of any kind. We do not use Apple's App Tracking Transparency framework, we never request your advertising identifier, and we do not track you across other companies' apps or websites
- No selling or renting of data
- No push notifications
- No location, contacts or microphone access — the app does not ask for them
- No upload of your sales, inventory, customer or utang records. Section D is the only path by which anything you recorded leaves the device, and only when you start it
Retention and deletion
Account records are kept while your account exists. The records on your phone are yours and stay until you delete them or the app.
Account deletion is built into the app: Settings → Delete account. Because deletion is permanent, the app deletes your account on our servers first and only wipes the phone once that has succeeded — if it cannot reach us, nothing is deleted and you can try again. Deleting your account:
- Deletes your cloud account and the records tied to it — your profile, your store claim, your subscription and trial state, your scan records and your referral link
- Wipes the business records, product photos and QR image from the app on that phone, and clears your Owner Lock credential
Some limited records are deliberately kept afterwards, because deleting them would let the account be used to escape an obligation or to claim a one-time benefit twice. These are:
- Partner-programme accounting. If a sales partner introduced your store, the record of what we owe or paid that partner survives. It no longer points at a live account
- One-time-benefit and anti-abuse bookkeeping. Markers that record that a trial or launch benefit has already been used. These are stored as one-way values or opaque identifiers, not as readable contact details
- Billing and subscription records held by Apple and RevenueCat under their own policies, which we cannot delete on your behalf
Deleting your NegosyoKlaro account does not cancel an App Store subscription. Cancel that in iOS Settings → your name → Subscriptions.
Security — honestly stated
- Traffic to our servers uses encrypted connections, and provider keys are kept on our servers, never inside the app. We do not claim end-to-end encryption: this is transport encryption plus server-side access control.
- Owner Lock (PIN / Face ID) protects the app's owner-only screens on a shared phone. It is an app-level lock: it does not encrypt the database file, so your phone's own passcode remains the strongest protection for your data.
- Because your business data is stored on your device and we do not offer a cloud backup, a lost or broken phone can mean lost records. Keeping your phone's own backup switched on is your safety net today.
Information about other people
When you record a customer's name and their utang balance, you are recording information about someone else. Those entries stay on your phone and we never receive them — but you are the one responsible for what you record about your customers and for handling it fairly, including if a customer asks you about it.
Children's privacy
NegosyoKlaro is a business tool intended for adults running a store. It is not directed at children, and we do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
If we change how the app handles data — for example, if a cloud backup ever ships — we will update this page and its effective date before the change reaches you in an app update.
Contact
EM Labs
Email: support@emlabscorp.com