Privacy Policy
Last updated: 9 September 2026
This policy explains what personal data Splitini (“we”, “us”) collects, why, and your rights over it. Splitini is a group expense-sharing app; it works only by storing the shared-expense information you and your group choose to enter.
Who we are
Section titled “Who we are”Splitini is operated by Gabriele Marrone. For any privacy question or request, contact privacy@splitini.com.
What we collect
Section titled “What we collect”We only collect what the app needs to function. We do not run advertising, and we do not use third-party analytics or tracking.
- Account — your email address and, if you use password sign-in, a password (stored only in hashed form by our authentication provider). If you sign in by phone one-time code, your phone number.
- Profile — your display name and default-currency preference, and — only if you pick a language instead of following your phone — which language that is. It is stored for one purpose: so a notification can be written in it while the app is closed. See Notifications below.
- Payment handles you add — e.g. a PayPal.me username, a Satispay link or phone number, an IBAN, or other free-text payment details. These are shown to the people you share a group with only after they accept membership of that group.
- Group content — group names, member display names, expenses (amounts, categories, dates, notes), how they are split, and recorded settlements.
- Receipt photos, only if you scan or attach one — a photo you take or choose. Your phone shrinks it before it is sent. It is stored with the expense it belongs to and can be seen by the other people in that group. If you want the app to read it for you, see Scanning a receipt below.
- A voice recording, only while you are saying an expense — if you use Say it, what you say is recorded and sent to be turned into the details of an expense. The recording is never kept — not on your phone, and not by us. What you said is written into the expense’s notes as text, where the other people in that group can read it; you can change it or delete it before you save. See Saying an expense below.
- Invitations — email addresses you enter to invite someone to a group, and the email address used to match invitations addressed to you. If you choose Invite by email, we send one message to that address on your behalf: it says who invited them, which group, and carries a link. It is not a mailing list, there is nothing to unsubscribe from, and we do not send anything else to that address. There are limits on how often the same address can be invited. The address is kept with the group place it was reserved for, and is cleared the moment they accept.
- Friends — when you accept someone’s invitation (or they accept yours), we record that the two of you are connected, which invitation created it, and when. This is what lets you add the same people to a new group without inviting them again. It links only the person who invited and the person who accepted — sharing a group with someone does not connect you to them. The connection outlasts the group it came from; you can remove it at any time from the members screen, which removes it for both of you and leaves your shared expenses and settlements untouched.
- Technical data — standard server and request logs (such as IP address and timestamps) generated by our hosting providers for security and reliability.
- A notification token, only if you turn notifications on — an identifier Google issues to your app installation, together with the platform and app version it came from. It identifies the installation, not you, and we store it only so we can send notifications to it. If you never enable notifications, no such identifier is ever stored. It is removed when you sign out, when you switch accounts, when Google tells us it is no longer valid, and when you delete your account.
Some settings never leave your phone at all. Which currency you last used in each group is remembered on your device only, purely so the app can prefill it next time. It is not sent to us and it disappears when you uninstall the app.
Your language choice is kept on your phone too — that copy is what the app itself reads. If you pick a language rather than following the phone, a copy is also stored with your account, for one reason: the part of the app that writes a notification runs while Splitini is closed and cannot read your phone’s settings, so the language has to travel with the notification. Nothing else reads it. Follow the system instead and nothing is stored — notifications follow your phone’s own language.
What the app keeps on your device
Section titled “What the app keeps on your device”So the app still works when you have no signal, it saves a copy on your phone of your groups, their members’ display names, expenses, settlements and balances. That copy necessarily includes information about the other people in your groups — their group display names and the amounts they paid or owe — because that is what those screens show. It is only ever a copy of what the app was already allowed to show you.
This happens in the background, not only for the screens you happen to visit: when the app starts, it fetches your most recent groups so they are readable later without a connection, whether or not you open them. Otherwise being offline would work for the group you looked at yesterday and fail for the one beside it, with no way for you to know which.
The camera is also used to scan an invite QR code, if you choose to. That one never produces a photo at all: the picture is read on your phone as it comes off the camera, only to find the invite code inside it. Nothing is saved, and nothing is sent to us — the code it reads is the same ten characters you could have typed by hand.
When you photograph a receipt, your phone writes the picture to a temporary file so it can be shrunk. That file is deleted as soon as the photo has been sent, and the app never writes the picture to your phone’s storage again.
If sending it fails — a dropped connection, a slow moment — the shrunk picture is kept in the app’s memory so you can try again without photographing the receipt a second time. It is not saved to your phone, and it is gone as soon as you leave the expense form or close the app.
If you add, edit or delete an expense while offline, that change is also held on your phone until it can be sent. It stays there, marked as waiting, until it reaches us — or until you discard it. While it is waiting, your balances are worked out on your phone so they reflect it; the app labels those figures as an estimate and will not let you settle up against them.
If you allow notifications, two different things can produce one, and they work differently.
The first tells you that changes you made offline have gone through. That notification is created on your phone, not sent to it by us, and nothing about it leaves your device. It names the group and the number of changes, never amounts.
The second tells you about activity in your groups while the app is closed: an expense you are part of being added, changed or removed, a settlement that names you, or someone adding or inviting you to a group. These are sent by us, through Google’s Firebase Cloud Messaging, to the installation you enabled notifications on. They carry enough to make sense of them without opening the app — who acted, in which group, the amount, and what it means for your balance. Everyone who receives one can already see those details inside the app, but a lock screen can be read by anyone holding the phone: if you would rather they stayed hidden until you unlock, both Android’s and iOS’s own notification settings can hide them. An invitation from someone you are not already connected to is deliberately vague — it says only that an invite is waiting, because nothing about a stranger who has your email address is verified.
Notifications are entirely optional and off until you turn them on. Declining them changes nothing else: your changes still send.
This on-device copy:
- is stored in your app’s private storage, which other apps cannot read;
- is excluded from Android’s automatic backup, so it is not copied to your Google account;
- is kept separately for each account, and is erased when you sign out or switch accounts, so a shared phone never shows one person’s groups to another;
- is deleted entirely when you uninstall the app.
Details we consider sensitive are deliberately never saved this way — payment handles, profiles, your friends list and pending invitations are always fetched fresh, so anything you stop sharing stops being visible.
When the app starts it asks our server for the minimum supported app version, so it can tell you when an update is required to keep working. That request happens before you sign in and contains no personal data — no name, no email, no device identifier — and nothing is stored as a result of it.
Scanning a receipt
Section titled “Scanning a receipt”If you tap Scan a receipt, the photo you take is sent to Google’s Gemini service, which reads it and sends back the total, the date, the merchant name and a suggested category. We use that only to fill the expense form in for you.
Three things are worth being clear about:
- It is entirely optional. Every expense can be typed in by hand, and the app asks you first — the explanation appears before your first receipt is ever sent, and nothing is sent if you decline.
- Nothing is saved until you say so. What comes back only fills in the form. You see it, correct anything wrong, and the expense exists only once you tap Save.
- Google does not use your receipts to train their models. We use the paid Gemini API, whose terms exclude the content we send from product improvement. Google may retain it briefly for abuse monitoring.
The photo itself is stored with the expense in our own storage in the EU, and the people in that group can see it, in the same way they can see the amount.
Saying an expense
Section titled “Saying an expense”If you tap Say it, the recording is sent to Google’s Gemini service, which listens to it and sends back the amount, the date, a description, a category, who paid and how it is split. We use that only to fill the expense form in for you.
Four things are worth being clear about:
- It is entirely optional. Every expense can be typed in by hand, and the app explains this before your first recording is ever sent. Nothing is sent if you decline, and your phone asks separately for permission to use the microphone.
- The recording is never kept. It is held only for as long as it takes to send, and it is deleted from your phone the moment it has been. Neither we nor Google store it afterwards.
- What you said becomes part of the expense. The words are written into the expense’s notes so you can check what was heard — which means the other people in that group can read them. They are shown to you, and you can edit or delete them, before you save anything.
- Nothing is saved until you say so. What comes back only fills in the form. You see it, correct anything wrong, and the expense exists only once you tap Save.
As with scanning, we use the paid Gemini API, whose terms exclude the content we send from product improvement. Google may retain it briefly for abuse monitoring.
How we use it
Section titled “How we use it”- To provide the service: track shared expenses, compute per-currency balances, and help you settle up.
- To authenticate you and keep your account secure.
- To send transactional and invitation emails you or your group-mates trigger.
- To notify you about activity in your groups, if you turn notifications on.
- To read a receipt you have chosen to scan, so we can fill the expense form in for you.
- To understand an expense you have chosen to say out loud, so we can fill the expense form in for you.
Our legal basis (UK GDPR / GDPR) is performance of our contract with you to provide the app; your consent for optional items such as payment handles, notifications, receipt scanning and saying an expense out loud; and our legitimate interest in keeping the service secure and reliable (for the technical logs described above).
Who can see your data
Section titled “Who can see your data”- Other members of your groups can see that group’s shared content, and can see your payment handles once you have confirmed you are in that group. This visibility is the point of the app; only share groups with people you trust. If a friend adds you to a group, you become a member straight away, but your profile and payment details stay hidden from that group until you tap the confirmation shown at the top of it — so you can leave first if you’d rather not be there.
- People you are connected to can see your display name and picture in their friends list, and can add you to a group. They stay connected to you until either of you removes the connection, even after a shared group ends.
- Service providers (processors) acting on our instructions:
- Supabase — the database and authentication service that hosts your data.
- Cloudflare — hosting and content delivery for our website.
- Google (Firebase Cloud Messaging) — delivers notifications to your device, if you enable them. It receives your installation’s notification token and the contents of each notification.
- Apple (Push Notification service) — on an iPhone or iPad, the final delivery hop. Firebase hands the notification to Apple, which passes it to your device.
- Google (Gemini API) — reads a receipt you have chosen to scan, or listens to an expense you have chosen to say out loud, and returns the details so the app can fill the form in. It receives only that photo or that recording, and only when you scan or say one. Neither is used to train Google’s models, and the recording is not kept.
- The Android app is distributed through Google Play, which processes install and diagnostics data under Google’s own privacy policy. The iPhone and iPad app is distributed through the Apple App Store, which does the same under Apple’s.
We do not sell your personal data, and we do not share it with anyone else for their own purposes.
Payments
Section titled “Payments”Splitini does not process payments or hold any money. When you settle up, you pay the other person directly through their own payment provider (for example PayPal or Satispay) or their bank details — we only display the payment handle they chose to share with the group. We never see, handle, or store the payment itself.
Where your data is stored
Section titled “Where your data is stored”Your Splitini account and group data is stored in the EU (our database is hosted in Ireland). Our website is served through Cloudflare’s global network, which may process basic request data such as your IP address. If you enable notifications, their contents pass through Google’s Firebase Cloud Messaging infrastructure, which operates globally. If you scan a receipt or say an expense out loud, that photo or recording is sent to Google’s Gemini service, which processes it globally — the stored copy of a photo stays in the EU with everything else, and a recording is not stored at all. Any processing outside the UK/EEA relies on the safeguards those providers offer.
How long we keep it
Section titled “How long we keep it”We keep your data while your account is active. You can delete your account and associated data yourself, in the app, at any time — Profile → Delete account, which takes effect immediately. If you cannot sign in you can email us instead and we will complete the deletion within 30 days. See Delete your account for the steps and what is deleted or kept. Some group content you authored may remain visible to that group as part of its shared history unless the group removes it; your name is removed from it. A receipt photo is kept for as long as the expense it is attached to; if you scan a receipt and then leave without saving the expense, the photo is deleted. A voice recording is never kept at all — it is deleted from your phone as soon as it has been sent, and there is nothing to delete afterwards. The words it produced live in the expense’s notes, like anything else you type there.
After a deletion we keep one small record that it happened, so we can show we honoured the request if it is ever queried. It holds the date we received the request, the date we completed it, and how it reached us — plus a one-way cryptographic fingerprint of the email address, not the address itself. The fingerprint lets us check whether a particular address was deleted; it cannot be turned back into an address or used to contact anyone. We keep this record longer than the account data it refers to, because its whole purpose is to evidence the deletion after the fact.
Your rights
Section titled “Your rights”Subject to law, you can ask to access, correct, delete, or export your data, and to withdraw consent. Email privacy@splitini.com and we will respond. If you are in the UK you may also complain to the Information Commissioner’s Office (ico.org.uk); in the EEA, to your local data-protection authority.
Security
Section titled “Security”Access to your data is restricted by row-level security so you only ever reach data for groups you belong to, and data is encrypted in transit and at rest. No system is perfectly secure, but we take reasonable measures to protect your information.
Children
Section titled “Children”Splitini is not directed at children and is not intended for anyone under 18.
Changes to this policy
Section titled “Changes to this policy”We may update this policy as the app evolves or the data we collect changes. We will revise the “Last updated” date above; significant changes will be made clear in the app or on this page.