Privacy Policy
Split Sage ("the App", "we", "us") is an expense-splitting app. This policy explains what data we collect, why, and how we handle it, in accordance with the General Data Protection Regulation (GDPR).
In plain English
- Split Sage needs an account. You sign in either with Google, or with an email address and a password you choose. With Google we store the email address, display name and profile photo Google gives us, and the account identifier that links them. With email and password we store the email address (as your login identifier) and the display name you pick. Your password is only ever stored as a salted, one-way scramble (a PBKDF2 derivation, with an optional extra server-side secret applied first): we never keep the password itself and cannot recover it.
- We store the expenses, groups, balances and settlements you record, because syncing them between you and your group members is the whole point of the app.
- Everything you put in a group is visible to the other members of that group. That is a feature, not a leak.
- Receipt photos are optional. If you attach one, we store it and show it to your group.
- The only email Split Sage sends you is a password reset link, and only if you use email and password sign-in and ask to reset. There is no marketing mail, no verification mail and no invite mail: an invite is a link or a code that you share yourself, however you like.
- We run on Cloudflare's infrastructure, which also sends that one reset email. If you choose Google, Google signs you in; Google also distributes the app. That is the full list of companies that touch your data.
- No ads, no trackers, no analytics, no crash reporting, no selling data. Ever.
- You can export your data (a whole-account JSON file, or a single group as CSV), correct it, or delete your account at any time, in the app or through a public web page that needs no sign-in.
- If you delete your account, your personal details are erased, but expenses you added to shared groups are anonymized rather than deleted, because they determine what other people owe each other. The name you were using inside those groups stays on the entries you took part in, as history with no account behind it, so the remaining members can still read their own ledger.
1. Data Controller
The data controller responsible for your personal data is the individual developer of Split Sage, established in Greece. For any privacy-related enquiry, contact christos@sudo-ezekiel.com.
2. Data We Collect
- Account data: Your email address and display name, and, for Google sign-in, your profile photo URL, so that we can sign you in and identify you to your groups. With Google, these come from your Google account when you first sign in, along with the Google account identifier that links your sign-ins to your account. With email and password, your email address is the login identifier you register with and your display name is the one you choose.
- Password credential (email and password sign-in only): If you sign in with an email address and a password, we store the password only as a salted one-way derivation (PBKDF2-HMAC-SHA256, with a unique random salt for your account and an optional additional secret held in our server configuration, never in the database). We never store the password itself, in any form we can read, and it cannot be recovered from what we hold. The email address in this case is a login identifier only: it is not treated as a verified claim and is never used to link or merge accounts.
- Session records: A hashed session token and its expiry per signed-in device, so you stay signed in without signing in again on every request.
- Expense data: Expense descriptions, amounts, currencies, dates, categories, notes, comments, who paid, and how each expense is split. This is the core content of the app.
- Group data: Group names, membership lists, invite records, and the relationships between members that follow from shared expenses (who owes whom, and how much).
- Settlement and balance records: Records of settle-up payments you log and the running balances computed from them.
- Receipt photos (optional): If you attach a photo to an expense, we store it on our servers and display it to the members of that group. Attaching photos is always your choice; the app works fully without them.
- Activity data: An activity feed of changes in your groups (for example "Alex added Dinner, 40 EUR"), derived from the data above.
- Push notification tokens: If you enable notifications, we store the device token needed to deliver them. You can disable notifications at any time in system settings or in the app.
- Support email content: If you email us, we keep the correspondence for as long as needed to resolve your request.
3. Data We Do NOT Collect
- We do not use analytics or tracking services
- We do not use crash reporting
- We do not collect advertising identifiers
- We do not display ads or use ad-related SDKs
- We never sell or monetize your data in any way
- We do not track your location
- We never store your password in a readable form. Email and password sign-in keeps only a salted, one-way PBKDF2 derivation (plus an optional server-side secret); the plaintext is never stored and cannot be recovered.
- We do not collect payment card details or bank credentials. Split Sage records who owes whom; it never holds, moves, or processes money.
If a future version ever adds an analytics or crash-reporting feature, it will be opt-in and this policy will be updated first.
4. Legal Basis for Processing
Under GDPR Article 6, we process your personal data on the following legal bases:
- Contract performance (Article 6(1)(b)): Processing your account data, your password credential (for email and password sign-in), expense data, group data, and settlement records is necessary to provide the app's core functionality: authentication, multi-device sync, and shared group ledgers. Sending a password reset link when you ask for one is part of providing that sign-in service.
- Legitimate interest (Article 6(1)(f)): Push notifications about changes in groups you participate in, keeping a free service available (limits on how much one account can write and create, per-address limits on sign-in attempts, and the platform-level protections Cloudflare applies in front of our API), and answering support mail you send us. You can object to notifications by muting or disabling them at any time.
- Consent (Article 6(1)(a)): Receipt photos are strictly optional. You give consent by attaching a photo and can withdraw it by deleting the photo or the expense.
5. How We Use Your Data
- Authentication: To sign you in and identify your account
- Sync: To keep your groups and expenses consistent across your devices and your group members' devices
- Group functionality: To compute balances, simplify debts, record settlements, and show the activity feed
- Push notifications: To notify you when an expense, a settlement, a membership or a group you share changes, if you have enabled them. The message itself carries no amounts and no names: it wakes the app, which then loads the change behind your own sign-in
- Password reset: If you use email and password sign-in and ask to reset your password, to email a single-use reset link to your address
- Support: To answer questions you email us
The only email we send you is that password reset link, and only when you ask for one; we send no marketing or promotional mail. We do not use your data for advertising, profiling, or any automated decision-making with legal effect.
6. Data Sharing
We never sell your data. Data is visible to or handled by:
- Other group members (by design): When you join a group, the other members of that group can see the display name you joined with, the expenses you add or are part of (descriptions, amounts, dates, payer), receipt photos attached to those expenses, your balances within the group, and your settlement history. Your email address and your profile photo are not shown to other members: the member list carries a name and nothing else. Do not put anything in an expense description that you would not want the whole group to read.
- Service providers (processors): The companies listed in section 7, which host and deliver the service under our instructions and their data processing terms.
- Legal requirements: We may disclose data if required by law or to protect our legal rights. We have never received such a request.
7. Third-Party Processors
Cloudflare, Inc.
Hosting and storage: Workers (the API and this website), D1 (database), R2 (receipt photos) and KV (caches), plus Email Sending for the one password reset email. Touches all server-stored data listed in section 2, and your email address for a reset link you request.
Google LLC
Sign-in (Google is the identity provider that authenticates you and tells us your email, name and photo), app distribution through Google Play, and, if push is enabled, notification delivery through Firebase Cloud Messaging. Touches your Google account identity at sign-in, under Google's own privacy policy; install and update handling by Play; and FCM device tokens if push is enabled.
Buy Me a Coffee
The optional donation page. Not a processor for us: it receives nothing unless you go there yourself. The link opens in your system browser, and any data you enter there is governed by Buy Me a Coffee's own privacy policy. Donating grants no in-app benefit and we receive no personal data back from it.
The one email the app sends, the password reset link, goes through Cloudflare's own Email Sending, so it adds no new processor: there is no separate mail company. No other third parties receive your data.
8. International Data Transfers
Your data is stored on Cloudflare's infrastructure, which may process and store data on servers located outside the European Economic Area (EEA), including in the United States. Cloudflare's Data Processing Addendum incorporates the EU Standard Contractual Clauses (SCCs) as the legal mechanism for these transfers, ensuring your data receives an equivalent level of protection. Signing in involves Google, which processes your Google account data under its own privacy policy and transfer mechanisms.
9. Data Retention
- Active accounts: We retain your data for as long as your account is active.
- Account deletion: When you delete your account, your personal data (email address, your account's display name and photo, your password credential and any outstanding password reset links, the link to your Google account, session records, push tokens, and receipt photos you uploaded) is permanently deleted from our servers within 30 days, and immediately when you delete from inside the app. See section 13 for what happens to shared group records.
- Support correspondence: Kept only as long as needed to resolve your request.
- Backups: Deleted data may persist in encrypted backups for up to 30 additional days before those backups rotate out.
10. Data Storage and Security
- All traffic between the app and our servers is encrypted in transit (TLS).
- Data at rest in Cloudflare D1 and R2 is encrypted by Cloudflare.
- Every API request is authenticated, and every read or write is checked server-side against your group membership. You can only access groups you belong to.
- Passwords are never stored in a form we can read. If you sign in with an email address and a password, the password is kept only as a salted PBKDF2-HMAC-SHA256 derivation (64,000 iterations, a unique random salt for your account), with an optional additional secret applied before derivation that lives in our server configuration and never in the database. The plaintext is never stored and cannot be recovered from what we hold. For Google sign-in, Google's identity tokens are verified against Google's published signing keys on every sign-in.
- Session tokens are stored on our side as hashes, never in readable form, and on your device in the operating system's secure storage rather than in plain text.
- If you forget a password, resetting it is self-service: you request a link at splitsage.whataboutalist.app/reset, which is single-use, expires after 60 minutes, and on success signs you out of every device. The reset token is stored only as a hash, the same as a session token.
- Our API sits behind Cloudflare, which applies its platform-level protections to every request.
- We do not write personal data (emails, names, expense text, amounts) to server logs.
No system is perfectly secure, but we keep the amount of data we hold to the minimum the app needs.
11. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights:
- Right of access (Article 15): Request a copy of the personal data we hold about you.
- Right to rectification (Article 16): Request correction of inaccurate or incomplete data.
- Right to erasure (Article 17): Request deletion of your personal data.
- Right to restriction (Article 18): Request that we limit how we process your data in certain circumstances.
- Right to data portability (Article 20): Request your data in a structured, machine-readable format.
- Right to object (Article 21): Object to processing based on legitimate interest, including push notifications.
- Right to withdraw consent: Where processing is based on consent (receipt photos), you may withdraw it at any time without affecting the lawfulness of prior processing.
12. How to Exercise Your Rights
- Access and portability: For a full copy of everything we hold for your account, across all your groups, use the in-app export (Settings, then Account, then Export my data). It downloads one JSON file, structured and machine-readable, with amounts exactly as they are stored. For a single group as a spreadsheet, open the group and use Export as CSV. Both work at any time and neither needs to be requested. If you cannot reach the app, email christos@sudo-ezekiel.com.
- Rectification: Expense content (descriptions, amounts, dates, splits, payers) is editable in the app by any member of the group it belongs to. For Google sign-in, your display name, email and photo come from your Google account as it was when you first signed in; for email and password sign-in, your display name and login email are what you entered when you registered. To have any of them corrected, email christos@sudo-ezekiel.com.
- Erasure: Delete your account in the app (Settings, then Account, then Delete account), or without signing in, and even after uninstalling, via the public account deletion page.
- Objection and consent withdrawal: Mute or disable notifications in the app or in system settings; delete receipt photos from the relevant expenses.
- Anything else: Email christos@sudo-ezekiel.com. We respond within 30 days.
13. Data Deletion and Shared Group Data
Deleting your account permanently removes:
- Your user profile: your account's display name becomes "Deleted user" and your photo is erased
- Your email address, and your password credential and any outstanding password reset links (email and password sign-in), or the link between your account and your Google account (Google sign-in)
- Your session records on every device, so every signed-in device is signed out
- Your push notification tokens and devices
- All receipt photos you uploaded, both the images and their records
- All groups with no one left in them but you. Placeholder members (people added to a group who have never signed in themselves) do not count as anybody left, so a group holding only you and placeholders goes too
Deletion is never refused because of what you owe or are owed, and there is nothing to pay or settle first. Signing in again later, whether with the same Google account or the same email address, creates a brand-new, empty account rather than restoring the old one.
Shared groups are different. Expenses you added to a group with other people determine those people's balances: deleting the expenses outright would silently change what other members owe each other and corrupt their records. So when you delete your account:
- Your account is anonymized and closed: no email, no photo, no password credential, no link to Google, no way to sign in again, and everything written from that moment on names you as "Deleted user".
- The name you were using inside each shared group stays on the entries you took part in, and in that group's past activity entries, as a historical snapshot. A ledger in which every past payer reads "Deleted user" is one the remaining members cannot reconcile. Behind that name there is no account, no email address and no way to contact you.
- The financial records themselves are retained (amounts, dates, splits, settlements), tied to that snapshot and to nothing else about you.
This partial retention exists so that other users' data stays correct, and is the disclosure Google Play requires for retaining data after account deletion for legitimate reasons. If you want specific expenses gone as well, delete or edit them in the app before deleting your account (group members can see those changes in the activity feed).
The full explanation, including how to request deletion without signing in, is on the public account deletion page.
14. Breach Notification
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it (GDPR Article 33) and, where the risk is high, notify affected users directly without undue delay (GDPR Article 34), describing what happened, what data was involved, and what we are doing about it.
15. Cookies and Local Storage
The Split Sage app is not a tracking website and sets no advertising or analytics cookies.
- On your device, the app stores your session token (in secure storage), your preferences (light or dark theme, your notification choice, whether you have seen the introduction, an identifier for this install), and cached group data so the app opens quickly.
- Our web pages (this policy, the terms, the deletion page, the invite page) set no cookies. Cloudflare may set strictly technical cookies or headers needed to serve and protect the site (for example bot-protection challenges); these are not used to track you across sites.
16. Children's Privacy
Split Sage is a finance tool for adults and is listed on Google Play with a target audience of 18 and over. It is not directed at children under 13, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact christos@sudo-ezekiel.com and we will delete it promptly.
17. California Privacy Rights
Split Sage does not meet the thresholds that make the CCPA/CPRA apply to it. Regardless, for California residents: the categories of personal information we collect are identifiers (name, email), financial information (expense amounts and balances), user-generated content (descriptions, group names), and photos (optional receipts). We do not sell or share personal information as those terms are defined in the CPRA. You can exercise rights to know, correct, and delete through the same mechanisms described in section 12, without discrimination.
18. Right to Lodge a Complaint
If you believe we are handling your data unlawfully, you have the right to lodge a complaint with your local supervisory authority. In Greece, this is the Hellenic Data Protection Authority (HDPA):
- Website: www.dpa.gr
- Address: Kifissias 1-3, 115 23 Athens, Greece
- Phone: +30 210 6475 600
19. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated effective date. For significant changes, we will notify signed-in users in the app before the changes take effect.
20. Contact
Questions? Reach us at christos@sudo-ezekiel.com.