Privacy
Last updated 10 October 2026
SplitMe helps groups share costs. This page explains what data that takes, who sees it, how long it's kept and how to get it removed. In short: we only keep what splitting costs needs, there are no ads and no tracking, and you can delete your data from inside the app.
Who is responsible
SplitMe is run by Glauk IA, the data controller for the personal data described here. For any privacy question or request, write to privacy@split-me.xyz.
What we keep
- What people put into a group: names, optional email addresses, expenses, payments, restaurant bills and who had what, comments, and a log of who changed what.
- Optional monthly income, used only for income-based splits. Only the person it belongs to sees the amount; other members see just the resulting share, as a percentage.
- Kids: a parent can add a child's first name and age so their share is weighted fairly. Children don't use SplitMe themselves.
- Receipt photos you choose to scan are sent to OpenAI to read the items, and are not stored by SplitMe.
- A sign-in cookie that remembers which groups you belong to on this device; the app needs it to work. Until you pick a language, the language is chosen from your browser's language or the country your IP address indicates, and neither is stored. A language cookie, splitme_locale, is only set when you choose a language in the menu: it holds just that choice and expires after 1 year. We use no advertising or analytics cookies, so there's no cookie banner.
- IP addresses are only kept by our hosting provider, in technical logs (with details such as your browser) kept briefly to run and protect the service. To limit abuse, such as how many groups one address can create in an hour, SplitMe stores a one-way keyed hash of your IP address, never the address itself, for up to 2 days (and in backups until they expire).
Why, and on what legal basis
- To provide the service you asked for: keeping your group's shared costs (contract, GDPR Art. 6(1)(b)).
- When you add someone else to a group, such as a friend or your child, it's in everyone's legitimate interest to split shared costs fairly (Art. 6(1)(f)). Please only add what's needed.
- Security logs and abuse protection: legitimate interest in keeping the service safe (Art. 6(1)(f)).
Who sees it
Only the members of a group see that group. Nobody else can read or change it, and we never sell data or show ads. These providers process data for us, under data processing agreements:
- Vercel: hosts the app (servers in Paris, France; company in the USA).
- Supabase: stores the database (in Frankfurt, Germany).
- OpenAI: reads scanned receipts (USA). It may keep API data for up to 30 days to detect abuse and doesn't use it for training.
- GitHub: holds encrypted nightly backups, deleted after 30 days.
Where data leaves the EU, it is protected by the providers' Standard Contractual Clauses or the EU-US Data Privacy Framework. The exchange-rate services we use receive no personal data.
How long we keep it
- A group is kept until a member deletes it: it is erased 7 days after the request, unless a member keeps it.
- Groups with no activity for 24 months are deleted automatically.
- Backups expire after 30 days, so deleted data is gone from them within a month.
Your rights
You can do most of this yourself in the app:
- See and correct your details: tap your name in a group.
- Get a copy of a group's data: ⋯ menu → Export CSV.
- Remove yourself: ⋯ menu → Remove me from group. Your name, email and income are erased, including from the activity log, and you're signed out of the group on every device. If you have expenses there, they stay under “Former member” so the others' balances still add up.
- Delete a whole group: ⋯ menu → Delete group.
You also have the right to restrict or object to processing, and to complain to the data protection authority where you live. For anything else, write to privacy@split-me.xyz; we answer within one month.
Security
The database can only be reached by SplitMe's own server, sign-in cookies are cryptographically signed, every group is sealed off from every other, and backups are encrypted. If a breach ever puts your data at risk, we will tell the authority within 72 hours and tell you without delay.
Changes
If this policy changes, we'll update the date at the top and explain anything important in the app.