Privacy policy
Last updated 25 August 2026. This policy covers the Spliteso Android app and the service behind it.
The short version. Spliteso holds what it needs to share out costs between the people in your groups, and nothing else. There is no advertising, there are no third-party trackers or analytics SDKs in the app, and nothing about you is sold or handed to anybody for their own purposes. You can export everything you have, and delete your account, from inside the app.
Who is responsible
Jaume Mora Vines operates Spliteso and decides what happens to the data described here. Write to [email protected] about anything on this page.
What is held, and why
- Your account. Email address, the name you chose to show other people, and — if you set one — a profile picture. The password is never stored: what is kept is an Argon2 hash it cannot be recovered from. If you sign in with Google, Google tells us your address and name and we keep those; we never see your Google password.
- Confirming your address. Signing up sends a link to your address and gives you no session until you open it, because an unconfirmed address plus a password-reset flow is a way into somebody else's account.
- Your groups and their money. Group names and currencies, who is in them, and every expense and payment: the amount, the description, the category, the date, who paid, and each person's share. Comments you write on an expense, and the record of what was changed and when.
- Receipt photographs, when you attach one. They are stored in object storage and served over a content delivery network. Anyone holding the link to a receipt can read it, which is what lets a shared cache serve it at all — links can be time-limited, and a deleted receipt stops being served once the cache expires.
- Profile pictures are decoded and re-encoded before storage, so nothing of the original file survives: no EXIF metadata, and so no GPS coordinates of the room you took it in.
- Devices. A notification token per device, so the group's activity can reach you. Delete the app or sign out and the token goes.
- Sessions. Which sign-ins are current, so you can end them.
- Server logs. Ordinary request records: the time, the route, the method, the response, and a request identifier. They exist to find faults and abuse.
- Counts of use. How many people used the service on a given day and how many times each kind of action happened. These are totals: there is no per-person series and no profile.
- Subscription state, if you buy Spliteso Pro: which plan you have, until when, and the purchase token Google gives us to check it. Payment itself is Google's — no card number ever reaches us.
What is never collected
No location. No contacts. No advertising identifier. No card or bank details. No microphone, camera roll, or file access beyond the photograph you deliberately pick for a receipt or a profile picture.
Why we are allowed to hold it
Everything in the first four points above is what performing the contract with you requires: without it there is no group and no balance. Server logs, security throttling and the counts of use rest on our legitimate interest in running a service that works and is not abused. Notifications rest on the permission you grant on your device, which you can take back at any time.
Who else sees it
- The other people in your groups see your display name, your profile picture, and the expenses, payments and comments you share with them. That is the point of the app.
- Google, for two things only: delivering push notifications to your device, and processing a Spliteso Pro subscription through Google Play.
- Our hosting, storage and email providers, who process data on our instructions to run the servers, hold receipts, and send the account emails.
Nobody buys this data, and it is not used to advertise anything. Data is processed in Europe.
How long it is kept
Your account and your groups are kept while the account exists. Records that only exist to make the app work — the change log clients catch up from, keys that stop a retry becoming a second expense, expired tokens, idle rate-limit counters — are pruned on a schedule. Deleted receipts are removed from storage. Server logs are short-lived.
Your rights
- See everything. Settings → export gives you a complete file: your account, your sign-in methods, your devices, and every group's expenses, payments, comments and receipt records.
- Correct it. Your name, your address, your picture and your expenses are all editable in the app.
- Delete it. Settings → delete my account, or the web page for it. What deletion does, and the one case where it is refused, is set out there.
- Object, restrict, or complain. Write to [email protected]. If you are in the European Union you may also complain to your national data protection authority.
Security
Everything travels over TLS. Passwords are hashed with Argon2. Sign-in, sign-up, password reset and confirmation attempts are rate limited per address and per account. Session tokens rotate, and signing out or changing your password ends the other sessions.
Children
Spliteso is not intended for anyone under 16, and accounts are not knowingly created for them.
Changes
If this policy changes in a way that matters, the date at the top changes and the app says so before the change takes effect.
Esta página también está en castellano.