Your data, explained
Privacy Policy
Effective and last updated: 22 September 2026
Splitin helps people keep track of shared group expenses. This policy explains how Splitin collects, uses, shares, retains and deletes information when you use the app or splitinapp.com.
Information we use
We receive information directly from you, from a sign-in provider you choose, and through your use of Splitin. This may include:
- Account and profile information, such as your display name, email or sign-in details where available, profile photo and settings. Guest accounts use the name provided by the guest.
- Group and expense information, such as group and member details, expenses, items, splits, balances, payments, notes, invitations and other information people add to shared records.
- Optional getting-paid information, such as a reusable payment link or UK account-holder name, sort code, account number and suggested payment reference that you choose to save.
- Images you choose to add, including receipt images, profile photos and group photos selected from your device or captured with the camera.
- Safety reports you choose to submit, including the selected reason, optional context and the account that submitted the report. Reports about a group, member or expense are private to authorised Splitin moderators.
- Receipt-scanning information, when you choose Create from receipt, including a compressed receipt image and extracted merchant, date, currency, total, item and adjustment information.
- Optional location information you add, such as a place name or map link and the place details or coordinates obtained from that link. Splitin does not read your device's current location.
- Notification information, when notifications are enabled, including the information needed to deliver notifications, your preferences and limited delivery information.
- Crash diagnostics, including an unexpected error or crash type, technical stack trace, app version and build, operating-system and device-model information, and a limited app operation or screen category.
- Optional usage analytics, only if you choose to enable them, including basic feature interactions, app sessions, coarse location derived by Google from a masked IP address, and a pseudonymous identifier for that installation of Splitin.
- Support information, such as your email address, message and any account or group details you choose to provide when contacting us.
How we use information
- Provide and protect Splitin accounts.
- Create shared groups, record expenses and payments, and calculate balances.
- Show your chosen getting-paid details to signed-in group members who currently owe you, so they can make a payment outside Splitin.
- Provide features you choose, such as adding images, locations and shared links.
- Send notifications you have allowed.
- Diagnose crashes and unexpected errors and improve Splitin's reliability.
- Understand feature use and general engagement, and improve product and user-experience priorities, if you enable optional usage analytics.
- Respond to support, privacy and account-deletion requests.
- Review reports of suspected spam, abuse, offensive content, scams or privacy concerns and protect the Splitin community.
- Maintain the security and reliability of Splitin.
Getting paid
If you choose to save receiving details, Splitin encrypts sensitive bank, Pix, MB WAY, SPIN and TWINT information. Depending on the method, this can include an account-holder name, sort code and account number, IBAN, BIC/SWIFT, optional reference, Pix key and key type, or phone number. Splitin does not collect a Pix merchant name or city, a separate recipient name for MB WAY/SPIN/TWINT, or NIF/NIPC for phone-only SPIN. The encryption key is held separately from the database. Reusable payment links and a Wise Wisetag remain access-controlled but are not field-encrypted because they are intentionally shared receiving identities.
A signed-in member can retrieve your getting-paid details only while Splitin's current settlement calculation shows that member owes you in the selected group. Being a group organiser or another group member is not enough. Splitin checks that relationship each time payment details are prepared and does not keep another member's details in persistent app storage.
Splitin validates formats but does not verify an account, Pix key, Wisetag or phone-number registration. It does not query Pix DICT, contacts or payment-provider accounts. PayPal.Me can receive the exact current settlement amount using its documented link format; other methods show the amount for the payer to enter manually. Splitin does not generate Pix QR/BR Code/Copia e Cola data, provider payment requests, or currency conversions, and it does not process, initiate, hold, route or confirm money.
Copying details or opening a payment provider is an explicit action. Information you copy is then controlled by your device clipboard and any app you paste it into, and information sent to an external provider is governed by that provider. Splitin cannot revoke a copy after an authorised member has viewed or copied it. Viewing or copying details does not mark a payment as complete.
Receipt scanning
Receipt scanning is available only to signed-in, non-guest accounts. Before the first scan for each disclosure version, Splitin explains the processing and asks you to accept or cancel.
When you choose to process a receipt, Splitin normalises and compresses the selected image on your device and sends that JPEG through Splitin's secure server function to Mistral AI for document processing. The OCR-processing image is held only for the request and is not written to Splitin's database or Supabase Storage. Splitin does not submit a user-provided URL, follow links found in a receipt or decode receipt QR codes.
Splitin temporarily stores the structured extraction and validation result for up to 24 hours so you can review or resume it. That temporary content is cleared after confirmed expense creation, explicit discard or expiry. Creating the expense automatically stores a separate, smaller compressed receipt image as an ordinary private expense attachment, which remains subject to the normal receipt and expense deletion lifecycle.
The imported result is only a draft. You must review and confirm it through Splitin's normal expense-creation flow before it affects balances, settlements or activity.
Optional usage analytics
Some versions of Splitin may offer optional usage analytics using Google Analytics. Analytics is off by default. No Analytics data is sent until you explicitly choose Allow in the consent prompt or enable Usage analytics in Account → Privacy & data. Choosing No thanks, dismissing the prompt or pressing Back does not give consent and leaves Analytics off.
If enabled, Splitin uses Analytics to understand which features are used, measure general app engagement, improve Splitin and guide product and user-experience priorities through aggregate usage patterns. Splitin's custom events are limited to coarse interactions such as opening a static app screen, creating or joining a group, creating or editing an expense, recording a payment, sharing an invite, or linking a guest account to Google. Their parameters are limited to basic categories or yes/no values, such as the join method, split method, whether a receipt was used, or the kind of invite shared.
Splitin does not intentionally send names, email addresses, phone numbers, group or member names, expense descriptions, item names, notes, amounts, receipts or receipt text or images, locations or coordinates, invite links, codes or tokens, push tokens, Supabase user, group, member or expense identifiers, access or refresh tokens, or OAuth credentials to Google Analytics.
Google Analytics nevertheless processes its own measurement information when Analytics is enabled. This includes a pseudonymous app-instance identifier, basic app and device information, app lifecycle and session events, and coarse location derived from a masked IP address. The app-instance identifier can distinguish an installation, so we do not describe Analytics as anonymous. Splitin does not set a Google Analytics user ID and does not map your Splitin or Supabase account identifier to Google Analytics.
Google processes this information as Splitin's analytics service provider. Splitin does not use this integration for advertising, remarketing or ad personalisation, and Advertising ID collection is disabled in the app configuration. You can change your choice at any time in Account → Privacy & data → Usage analytics. Turning it off stops future Analytics collection from Splitin; it does not automatically delete Analytics data that Google has already processed.
For more information, see Google's Privacy Policy and Google Analytics data safeguards.
Crash diagnostics
Released versions of Splitin may automatically send privacy-minimised crash and unexpected-error diagnostics to Sentry so we can identify and fix reliability problems. These reports can include the error type and technical stack trace, app version and build, operating-system and device-model information, and a limited operation, feature, screen, component or status category.
Splitin does not attach your Splitin account, user, group, expense or request identifiers to these reports. It disables default personal information, screenshots, view hierarchy, session replay, performance tracing and failed-request capture. Before a report leaves the app, Splitin removes credentials, email addresses, private invite and expense links, request bodies, and receipt or image fields. Crash diagnostics are used for app functionality and reliability, not advertising or tracking.
Sharing
Information added to a shared group is visible to the relevant group members. Getting-paid details use the narrower eligibility described above. Information may also be processed by trusted service providers where needed to operate Splitin, such as providing sign-in, hosting, image storage, moderation storage and notification delivery. Reports are not shown to the reported person; authorised Splitin moderators can review the report and reporter identity. When you choose receipt scanning, Mistral AI processes the compressed scanning copy and extracted document information on Splitin's behalf. Sentry processes the privacy-minimised crash diagnostics described above. If you enable optional usage analytics, Google also processes the measurement information described above. We require these providers to protect information consistently with this policy and applicable requirements.
Splitin does not sell personal information and does not use it for advertising, attribution or tracking across other companies' apps or websites.
Security
We use reasonable technical and organisational safeguards to protect information, including access controls and encrypted connections. No online service can guarantee complete security, so you should also protect your device and sign-in method.
Retention and deletion
We keep account information while your account is active and keep shared records while they remain part of a group's history. Safety reports are retained for moderation history and are not removed merely because a report is resolved or dismissed; a fixed timed purge for this operational record has not yet been defined.
When you delete your account, your Splitin account, profile and personal account data are removed. Some shared group history may remain where needed so other members' expenses, payments and balances continue to make sense. Retained shared information may still include a displayed member name and surrounding group or transaction context, so it is not necessarily anonymous.
You can remove a saved getting-paid method at any time. Removing the method deletes its encrypted sensitive payload. Deleting your account also deletes all saved payment methods and their encrypted payloads; they are not retained as shared group history.
Temporary receipt-scanning extraction and validation content is cleared after confirmed expense creation, explicit discard or expiry and is not retained beyond 24 hours. A receipt image retained with a created expense is an ordinary private expense attachment and follows the existing expense, receipt, group and account deletion rules.
Crash diagnostics do not contain a Splitin account identifier, so deleting an account cannot be used to identify an individual crash report. Diagnostic reports remain subject to Splitin's configured Sentry retention and Sentry's applicable service practices.
Account deletion disables future Analytics collection, removes the local Analytics consent preference and resets the local Analytics app instance. Because Splitin does not set a Google Analytics user ID, account deletion does not automatically identify and erase measurement data that Google has already processed. Previously collected Analytics data remains subject to the Google Analytics property's retention settings and Google's applicable retention practices. Splitin will verify the property's exact retention setting before Analytics is released.
See Delete your Splitin account for the in-app steps and the email option available if you cannot access the app.
Your choices
You can update supported profile information, choose whether to add images or locations, control device permissions and notification preferences, turn optional usage analytics on or off in Account → Privacy & data → Usage analytics, and delete your account. You can withdraw optional device permissions in your device settings.
You may also contact us to ask about access, correction or deletion of your personal information. We may need to verify that the request relates to your account.
Contact us
For privacy questions or requests, email support@splitinapp.com.