Splitto

Privacy Policy

Last updated: 7 September 2026

Splitto is a shared-expense tracker. It needs an account and the expenses you record — nothing else. We do not sell your data, we do not show ads, we do not use your data to train AI models, and we never touch your money.

1. Who we are

Splitto is operated jointly by Edoardo Bertoli and Simone Bervicato, both private individuals resident in Italy. Together we are the joint data controllers for the personal data described here, under the EU General Data Protection Regulation (GDPR).

You can reach us for any privacy question, or to exercise any of the rights in section 7, at bertoliedoardo99@gmail.com. We answer within 30 days.

This policy covers the Splitto mobile apps for iOS and Android, the API at api.splitto.dev, and this website.

2. What we collect

Your account

We never see or store your password. Sign-in is handled entirely by our authentication provider (see section 4).

What you record in the app

Everything in a group is visible to every member of that group. That is the point of the product, but it is worth stating plainly: if you record that you paid €40 for dinner, the other members see it.

Collected automatically

What we never collect

Your contacts, your location, your calendar, your microphone or camera beyond a photo you explicitly pick, your health data, or your card and bank credentials. There is no paid tier, so we process no payments at all.

3. Why we are allowed to use it

DataPurposeLegal basis (GDPR Art. 6)
Account, groups, expenses, balancesProviding the service you asked forPerformance of a contract
Payment handlesLetting others pay you backContract — and you choose to add them
Push tokenTelling you about new expenses and paymentsYour consent, given in the OS permission prompt
Server logs, crash reportsKeeping the service up, secure and debuggableLegitimate interest
Usage analyticsUnderstanding which parts of the app get usedLegitimate interest

4. Who else processes it

We use a small number of service providers. They act on our instructions and may not use your data for their own purposes.

ProviderWhat it doesWhere
SupabaseSign-in and the database holding your account, groups and expensesEU region
HetznerThe server running the Splitto APIGermany
CloudflareThis website, traffic protection, and storage of profile and group photos (R2, EU jurisdiction)EU
Google (Firebase)Push notification delivery and usage analyticsEU and United States
SentryCrash reportsEU and United States
Google, AppleSign-in, only if you use those buttons; app distributionUnited States

Where a provider processes data outside the EU, the transfer relies on the European Commission's Standard Contractual Clauses.

Beyond these, we share nothing. No advertising networks, no data brokers, no sale of personal data under any definition, including the CCPA's. We would disclose data to authorities only where a valid legal order compels us to.

5. How long we keep it

6. Deleting your account

Settings → Delete account, in the app. Immediately and without further confirmation from us:

One thing does survive, and you should know it before you delete: the expenses, payments and comments you created stay in the groups you shared them with, attributed to "Deleted user". Removing them would silently change what everyone else in those groups owes each other, and we are not willing to rewrite other people's records. If you want a specific entry gone, delete it in the app before deleting your account, or write to us.

7. Your rights

Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to another provider. You can withdraw consent for push notifications at any time in your device settings.

Most of this is available directly in the app: edit your profile to correct it, delete your account to erase it. For anything else, email bertoliedoardo99@gmail.com.

If you think we have handled your data badly, you can complain to your national data protection authority. In Italy that is the Garante per la protezione dei dati personali.

8. Security

All traffic is encrypted in transit with TLS. Passwords are hashed and held by our authentication provider, never by us. Every API request is authenticated with a short-lived signed token. Photos live in a private bucket and are served through time-limited links, not public URLs.

No system is perfectly secure. If you find a vulnerability, please write to bertoliedoardo99@gmail.com before disclosing it publicly.

9. Children

Splitto is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has an account, write to us and we will delete it.

10. Changes

When this policy changes we update the date at the top of this page. For a change that materially affects how we use your data, we will also tell you in the app before it takes effect.