NegosyoKlaro · by EM Labs
Privacy Policy
The short version
NegosyoKlaro is a point-of-sale and inventory app for small Philippine businesses. Your business records — sales, inventory, customers, utang, cash — are kept in the app on your phone. We keep a small cloud account (your sign-in identity and subscription status) so you can sign in and use paid features. Two things you choose to do send your records off the phone: Cloud Backup, an optional Pro feature that copies your store records to our cloud service so you can restore them on a new phone (section B2), and Smart Resibo, which sends one receipt photo for text extraction (section D). Nothing leaves your phone unless you start it. We do not run ads, we include no analytics, tracking or crash-reporting software, and we do not sell data.
A. Information kept on your device
Everything you record while running your store is saved in a local database inside the app on your phone:
- Products, categories, prices, barcodes, and stock levels
- Sales, receipts, and cash movements
- Stock purchases, suppliers, and price history
- Capital and business-year records
- Customer (suki) names, phone numbers and utang balances that you enter — these stay on your phone, and reach our cloud only inside a Cloud Backup you choose to make (section B2)
- Product photos you take. They are re-encoded by the app before being saved, which removes camera metadata such as location
- Your GCash / QR Ph payment image, if you add one. It is re-encoded the same way and is shown to your customers by you, on your phone — we never receive it
- Your Owner Lock PIN, stored as a one-way derived value in your phone's secure keychain. We never see it and there is no recovery bypass
Because these records live on your device, deleting the app deletes them from that phone. If you have made a Cloud Backup (section B2), you can restore that copy onto a new or reset phone; if you have not, we cannot recover them for you. Nothing is backed up unless you use Cloud Backup.
B. Information in your account (our cloud)
Sign-in and subscriptions are powered by Supabase, our cloud database provider. Your account holds account-level records only:
- Your email address. Signing in works by a six-digit code we email you, so there is no password — we neither ask for one nor store one. Authentication itself is operated by Supabase
- A Philippine mobile number, only on accounts created before August 2026 that verified one at the time. It is kept as historical contact information and can no longer be used to sign in; accounts created since then have none
- An optional recovery email, if you choose to add one
- Your profile name
- A record that your store is claimed by your account, together with a random per-installation identifier, used to stop someone else claiming the same store
- Subscription and trial status, including a mirror of your subscription state as reported by the app store you bought through
- Smart Resibo scan records, described in section D
- If you signed up through a sales partner and entered a referral code, the record linking your store to that partner
We use this to sign you in, to let you get back to your account on a new phone, to enforce plan limits fairly, and to operate the paid subscription. We do not use it for advertising or profiling.
B2. Cloud Backup and Cloud Restore (optional, Pro)
What it is. Cloud Backup is an optional feature of the paid Pro plan. Nothing is backed up automatically: a backup is made only when you tap Back Up Now in Settings → Data backup. Cloud Restore copies your most recent backup onto a phone that has no store records yet — a new phone, or one that was reset — for the account and store that made it.
What is copied. The records you keep in the app for your store: your store profile and settings (store name, business type, the barangay, city and province you entered, your GCash name and number if you added them, and your starting capital), products, prices, stock and suppliers, sales and cash movements, capital and business-year records, and your customers' names, phone numbers and utang ledger. Your display name is included so the restored store shows it. Your sign-in email, any phone number on your account, and your Owner Lock PIN are never included.
What is not copied. Product photos and your GCash QR image stay on your phone and are not part of Cloud Backup, so they do not come back with a restore. Receipt photos are never stored by us (section D). Your subscription, referral and account records are not part of the backup; they live in your account (section B).
Operational records. To run the service we also keep a small amount of information about each backup: which phone made it, when, how many records it holds, and verification values that let us check the copy is complete. These describe the backup, not your business.
Where it is kept and who can reach it. The copy is stored in our cloud database, operated for us by Supabase in Singapore — the same provider that holds your account (section B). RevenueCat, which handles your subscription status (section C), does not receive your backup or anything in it. Access is tied to your account and your store: only the account that owns the store can back it up or restore it, and only while a Pro plan is active. We use this copy for one purpose — to give it back to you when you restore. We do not read, analyse, sell or share it, and it is not used for advertising.
One backup phone. Backups for a store are made from one phone at a time. When you restore onto a new phone and choose to back up from it, the old phone stops backing up; the records on the old phone stay there.
If Pro ends. Your records stay on your phone and keep working. You can still see that a backup exists and when it was made. Your cloud backup may remain stored after your Pro access ends. Active Pro access is required to create a new backup or restore a backup.
How long we keep it. Your cloud backup may remain stored after your Pro plan ends. We have not set a fixed retention period, and we do not promise that a backup will stay available indefinitely; if we adopt a retention schedule, this page will describe it before it takes effect. Deleting the app from your phone does not delete your cloud backup. Deleting your NegosyoKlaro account removes it, together with the rest of your account (see Retention and deletion).
Security, honestly stated. Your backup travels over encrypted connections and is stored on our provider's infrastructure behind server-side access controls. We do not claim end-to-end encryption: this is transport encryption plus access control, and we do not claim to be technically unable to read the stored copy.
C. Subscriptions and payment
Paid plans are purchased through the app store you installed from — Apple's App Store on iPhone, Google Play on Android. That store processes the payment; we never receive your card details.
We use RevenueCat to manage subscription state, on both platforms. The app does not send RevenueCat your name, email address or phone number, and we have verified that against our own source code. What RevenueCat receives is:
- A subscription account identifier — a random internal code, not your email or phone. If you have not created a cloud account, RevenueCat generates its own anonymous identifier instead
- Your purchase and subscription status, including the receipt or purchase token the store issues, which RevenueCat validates on our behalf
- Technical information its software attaches to its own requests automatically — your device model, operating-system and app version, language settings, store country, and network information such as your IP address. We do not control this; it is part of how the service operates
- No advertising identifier, and no per-device advertising code on either platform. The app never asks RevenueCat to collect Apple's identifier for vendors or advertisers, and never asks it to collect Android's advertising ID — its advertising-attribution features are not enabled
This traffic happens when you open the subscription or upgrade screens, or make or restore a purchase — not while you are recording sales. Apple, Google and RevenueCat keep their own transaction records under their own privacy policies.
D. Smart Resibo (receipt scanning)
This is the one place where something you recorded leaves your phone, and it only happens when you ask for it. When you tap to scan a supplier receipt, the app sends that photo to our own server endpoint, which passes it to an AI text-extraction provider — currently Mistral AI — to read the items on it.
- The photo is sent only when you tap to scan. Never automatically.
- Our endpoint does not attach your name, number, or account identity to the image it sends to the provider.
- We do not keep the receipt image. It is not written to any of our databases and not uploaded to any file or object storage. It exists on our server only in memory for the seconds the extraction takes, and our own code writes no log entry containing the image or anything read from it.
- We do not keep the provider's response either. It is used to pull out the fields you then review — shop name, date, and each item's name, price and quantity — and is released as soon as that finishes. Nothing from the scan is written to your phone unless you choose to save the purchase, and then only the purchase itself is saved, locally, like your other records.
- What we do keep is a scan record. For each scan we store a SHA-256 fingerprint — a one-way hash that cannot be turned back into the picture — together with your account and store identifiers, the time, and the outcome. We keep it to count your plan's scan allowance, to avoid charging you twice for the same receipt, and to detect abuse. It contains no receipt text and no image.
- Your plan decides your allowance: free accounts have no provider scans, and a paid Pro plan includes 30 per calendar month (Philippine time, with no carryover). A small number of older accounts hold a one-off Pro Preview allowance of a single scan; that plan is no longer offered.
- Processing by the AI provider is governed by that provider's own terms and its own retention practices, which are theirs to state, not ours.
Temporary copies on your phone. Your phone makes working copies of the picture while you scan: one created by the system photo picker, and one resized copy the app prepares to send. The app deletes the copies it owns when the scan finishes, when you replace or remove the image, when you cancel the review, and when you leave the scan screen. Two honest limits: while an extraction error is on screen offering Retry, the copy is deliberately kept so you do not have to photograph the receipt again; and if the app is force-quit or shut down by the system mid-scan, a copy can be left for the operating system to clear on its own schedule. These files are written to the app's own private storage, never to your shared photo gallery or Downloads folder — they never leave your device and are removed when you delete the app.
E. Your phone's own backup is not our cloud
If your phone's own backup is switched on, it can include the app's local database, your product photos and your QR image — the same as for other apps:
- On iPhoneiCloud Backup, or an encrypted computer backup, under your Apple account and Apple's privacy policy.
- On AndroidAndroid Auto Backup — what you see as Backup by Google One — and device-to-device transfer when you set up a new phone, under your Google account and Google's privacy policy. The app does not opt out of it.
Either way that is your backup, held by Apple or Google, not by us. It is not a NegosyoKlaro cloud sync, we cannot read it, and it does not give us a copy of your business records. Your Owner Lock credential is deliberately excluded from device backups.
We mention it because it is the honest answer to “where else could my records be?” — and because, if you do not use Cloud Backup, it is your only protection against a lost or broken phone.
Camera, photos, and barcodes
- Barcode scanning uses your camera on the device. Only the barcode number is saved, to your local product record. No barcode image leaves your phone and no external barcode service is contacted.
- Product photos (camera or photo library) are saved inside the app on your phone and are not uploaded.
- Biometric unlock, if you turn on Owner Lock, is checked by your phone — Face ID or Touch ID on iPhone, your device's own fingerprint or face unlock on Android. The app only receives a yes-or-no answer; your biometric data never reaches us or the app.
What we do not do
- No advertising and no advertising SDKs
- No analytics, tracking, attribution or crash-reporting SDK of any kind. We do not use Apple's App Tracking Transparency framework, we never request Apple's advertising identifier or Android's advertising ID, and we do not track you across other companies' apps or websites
- No selling or renting of data
- No push notifications
- No location, contacts or microphone access — the app does not ask for them
- No upload of your sales, inventory, customer or utang records unless you start it yourself — by tapping Back Up Now (section B2) or by scanning a receipt (section D). There is no automatic sync
Retention and deletion
Account records are kept while your account exists. The records on your phone are yours and stay until you delete them or the app.
Account deletion is built into the app: Settings → Delete account. Because deletion is permanent, the app deletes your account on our servers first and only wipes the phone once that has succeeded — if it cannot reach us, nothing is deleted and you can try again.
You can also ask us to delete it without opening the app — useful if you changed phones or have already uninstalled it. See how to request account deletion, which also explains what we ask for and how we check the request really comes from the account owner.
Deleting your account removes, from our servers:
- Your sign-in account and your profile
- Your store record and the claim linking that store to you
- The referral attribution and referral-claim records tied to that store, if you entered a sales partner's code
- Any first-year referral discount benefit and offer-code allocation recorded for that store
- Your current subscription and trial status held on our servers
- Your Smart Resibo scan records — the counters and fingerprints from section D
- Your Cloud Backup — every backup copy of your store's records and the operational records about it (section B2)
Deleting from inside the app also wipes the business records, product photos and QR image from the app on that phone, and clears your Owner Lock credential. If you delete by asking us instead, remove the app from your phone to clear those.
Deleting the app from your phone does not delete your cloud backup; deleting your account does.
We cannot promise that every historical record about an account disappears. A limited set is deliberately kept, because deleting it would erase money owed to someone else, or would let a closed account be used to claim a one-time benefit twice:
- Partner-programme accounting. If a sales partner introduced your store, the record of what we owe or paid that partner survives, along with the record that a purchase qualified for it
- Subscription and billing event evidence. The store notifications behind a purchase, renewal or refund — the evidence behind money that moved
- One-time-benefit, cohort and anti-abuse markers. Records that a launch or trial benefit was already used. These hold one-way values or opaque identifiers, never readable contact details
- Partner and audit records, where keeping them remains necessary
- Billing records held by Apple, Google and RevenueCat under their own policies, which we cannot delete on your behalf
What those retained records still contain is the internal identifiers they were created with — an account id, a store id, a purchase reference — which stop resolving to anything once the account is gone. They hold no name, email address, phone number or password.
We do not state a fixed retention period for them, because we have not set one. Publishing a number we do not actually enforce would be worse than saying so plainly. If we adopt a retention schedule, this page will describe it before it takes effect.
Deleting your NegosyoKlaro account does not cancel a paid subscription. Cancel that with the store you bought through: on iPhone in Settings → your name → Subscriptions; on Android in the Google Play Store under Payments & subscriptions → Subscriptions.
Security — honestly stated
- Traffic to our servers uses encrypted connections, and provider keys are kept on our servers, never inside the app. We do not claim end-to-end encryption: this is transport encryption plus server-side access control.
- Owner Lock (PIN / Face ID) protects the app's owner-only screens on a shared phone. It is an app-level lock: it does not encrypt the database file, so your phone's own passcode remains the strongest protection for your data.
- Your business data is stored on your device. A lost or broken phone can mean lost records unless you have a backup — your phone's own backup (section E) or a NegosyoKlaro Cloud Backup (section B2, Pro).
Information about other people
When you record a customer's name and their utang balance, you are recording information about someone else. Those entries stay on your phone, and reach our servers only inside a Cloud Backup you choose to make, where we keep them solely to restore them to you — but you are the one responsible for what you record about your customers and for handling it fairly, including if a customer asks you about it.
Children's privacy
NegosyoKlaro is a business tool intended for adults running a store. It is not directed at children, and we do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
If we change how the app handles data — for example, if we add a new feature that sends data off your phone — we will update this page and its effective date before the change reaches you in an app update.
Contact
EM Labs
Email: support@emlabscorp.com
