Privacy Policy
Effective Date: August 16, 2026 • Last Updated: August 30, 2026 • App: Covered (iOS: gr.plenum.covered-app / Android: gr.plenum.covered) • Developer: Plenum
1 Introduction & Core Philosophy
Welcome to Covered (“we”, “our”, or “us”), an application developed and operated by Plenum (“Plenum”, “Company”). Covered is designed to help you organize and manage your product warranties, expiry dates, purchase receipts, and digital storage room passes (such as parking tickets, transit passes, and loyalty barcodes).
Our architectural philosophy is Privacy by Design and Offline-First. We do not sell your personal data, we do not monetize your purchase history, and we do not profile you for behavioral advertising. This Privacy Policy details how data is handled when you use the Covered mobile applications for iOS and Android, or access related services.
2 Information We Collect & How We Use It
A. Account & Authentication Data
Covered offers optional sign-in via Google, Apple (“Sign in with Apple”), and Plenum SSO. Signing in creates an account so that AI receipt scanning and cloud backup can work; the app is fully usable without an account.
When you sign in, we store a stable account identifier from the provider, and the email address if the provider gives us one.
If you choose “Hide My Email”, Apple gives us a private relay address (@privaterelay.appleid.com) instead of your real one. We never receive the real address and cannot determine it.
Purpose: Used strictly to authenticate your session, enable AI receipt scanning and cloud backup, sync your Covered Pro subscription status across your devices, and deliver critical security alerts.
B. User Content (Warranties, Receipts & Storage Vault)
Information you record in the app—such as item names, purchase prices, purchase dates, warranty expiration periods, receipt photos, category tags, barcode numbers, transit tickets, parking passes, and notes—is saved locally on your device by default.
Purpose: Stored locally to provide instant offline utility, calculate warranty expiration timelines, and trigger local reminder notifications.
C. Device Identifiers & Technical Diagnostics
We may process anonymous diagnostic logs, operating system versions, device model identifiers, and push notification tokens (APNs / FCM) for scheduling warranty expiration alerts.
Purpose: Maintaining application stability, troubleshooting crashes, and delivering push notifications that you have enabled.
3 AI Receipt & Document Processing (Google Gemini Vision)
Stateless Optical & Vision Processing
Covered provides an optional AI-assisted scanner to automatically parse merchant names, purchase totals, and warranty periods from photo receipts and documents using the Google Gemini API.
🔒 Zero Retention & Zero AI Training Guarantee:
- Images submitted for smart extraction are transmitted encrypted via HTTPS / TLS 1.3 directly to enterprise API endpoints.
- Images and parsed text are processed statelessly in real-time and are immediately discarded after returning the structured data to your device.
- Your receipts and personal documents are NEVER used to train, retrain, or improve foundational AI or machine learning models.
- Your receipts are never stored on Google servers or shared with any advertising brokers.
4 On-Device Barcode & QR Code Processing
When using the Storage Room to scan barcodes, parking tickets, or loyalty QR codes, barcode decoding is performed 100% on-device using Apple Vision / Google ML Kit frameworks. Camera frames are processed in volatile memory on your hardware and never leave your phone.
5 Third-Party Service Providers
We work exclusively with vetted infrastructure providers to deliver essential app functions:
6 Data Retention & Security
We employ rigorous technical safeguards to protect your records:
- Encryption in Transit: All communications between the app and servers use TLS 1.3 / HTTPS encryption.
- Encryption at Rest: Local data stored on iOS utilizes Apple's Data Protection Keychain, and Android data utilizes Jetpack Security EncryptedSharedPreferences.
- Cloud Backup Privacy: When you activate Google Drive backup, the backup archive is stored in your personal, sandboxed app data directory accessible solely by your account credentials.
7 User Rights, GDPR & Account Deletion
Regardless of where you reside, we respect your rights under the General Data Protection Regulation (GDPR), UK GDPR, and California Consumer Privacy Act (CCPA/CPRA):
8 Children's Privacy
Covered is not directed to children under the age of 13 (or under 16 in the EEA/UK). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately.
Contact & Data Protection Officer
If you have any questions, feedback, or requests regarding this Privacy Policy or your data, please contact our privacy team:
Plenum Studio • Covered App Division
Email: support@plenum.gr
Website: https://plenum.gr
Jurisdiction: Athens, Greece (European Union)