Splitproof Privacy Policy
1. What Splitproof is (and isn't)
Splitproof is a group expense ledger. It records IOUs between people in a group. It never moves money, never connects to your bank, and never processes payments. Settling up happens in external apps you choose.
2. Data we collect
Account data. When you sign up (Apple, Google, or email magic link) we store: your email address, a display name, and an authentication identifier from your sign-in provider. Sign in with Apple may provide a relay email.
Group and expense data. Content you and your group members enter: group names, member display names, expenses (description, amounts, dates, currencies, categories), settlements, and the edit history of these records. Note: group members can add people by name who have no account ("ghost members") — if someone added your name, see §7.
Exchange rates. We store daily published reference exchange rates (e.g. ECB). These are public data, not personal data.
Device data. {If/when push ships (1.1): a push notification token per device. Until then: none.} We do not collect advertising identifiers, location, contacts, or browsing data.
Receipts (Pro, future). {Include only at 1.2:} Receipt photos you upload are stored privately, visible only to your group, and processed to extract line items. See §{X}.
3. What we do NOT collect
No ads, no ad trackers, no analytics SDKs that profile you {verify at submission — if a crash reporter is added, name it here}, no contacts access, no location, no financial account credentials, no payment card data.
4. How data is used
Solely to provide the service: showing shared expenses to your group, computing balances, syncing between your devices, sending notifications you opted into. We do not sell data, share it with advertisers, or use it to train AI models.
5. Where data lives
Data is stored with our hosting provider {Supabase — region: {fill}}. A copy of your groups is cached on your device so the app works offline; deleting the app removes the local copy.
6. Sharing
Your expense data is visible to members of the same group — that is the product. Service providers acting on our behalf: {Supabase (hosting/auth), Expo (push delivery, at 1.1), RevenueCat (subscription status, at 1.2), {LLM provider} (receipt image processing, at 1.2, Pro only)}. We disclose data if legally required.
7. Ghost members (people without accounts)
Group organizers may record expenses for a named person who hasn't installed the app. That record consists of a display name and their share of group expenses, visible only within that group. If your name appears in a group and you want it changed or removed, contact us or ask the group organizer.
8. Deleting your account
You can delete your account in the app (Settings → Delete account). This permanently deletes your sign-in identity and email. Because other people's balances depend on shared history, the expense records themselves remain in the group under your display name, no longer linked to any account — identical to a ghost member. {Verify this wording against the final claim/unclaim implementation before shipping.}
9. Retention
Group data is retained while the group exists so members keep their records. {Receipt image retention: resolve Spec 05 OQ2 before 1.2 and state it here.}
10. Your rights
Access, correction, deletion, export (in-app CSV export gives you your groups' full data at any time). {GDPR/Israeli Privacy Protection Law boilerplate — legal review; you're IL-based serving EU users, so both apply.}
11. Children
Splitproof is not directed at children under {13/16 per region}. Weights for kids in family splits are labels entered by adults, not child accounts.
12. Changes
We'll post changes here with a new effective date; material changes get in-app notice.