Privacy Policy
Splitto is a shared-expense tracker. It needs an account and the expenses you record — nothing else. We do not sell your data, we do not show ads, we do not use your data to train AI models, and we never touch your money.
1. Who we are
Splitto is operated jointly by Edoardo Bertoli and Simone Bervicato, both private individuals resident in Italy. Together we are the joint data controllers for the personal data described here, under the EU General Data Protection Regulation (GDPR).
You can reach us for any privacy question, or to exercise any of the rights in section 7, at bertoliedoardo99@gmail.com. We answer within 30 days.
This policy covers the Splitto mobile apps for iOS and Android, the API at
api.splitto.dev, and this website.
2. What we collect
Your account
- Email address. Either the one you sign up with, or the one released to us by Google or Apple when you use those sign-in buttons. If you use Apple's Hide My Email, we only ever see the relay address.
- First and last name, as you type them. Other members of your groups see this name.
- Profile photo, only if you choose to upload one.
- Preferences: display language, default currency, whether push notifications are on.
- Payment handles, only if you choose to add them: a Revolut link, a PayPal link, or an IBAN with its account-holder name. These exist so people who owe you money can pay you back in their own banking app. They are visible to members of groups you share.
We never see or store your password. Sign-in is handled entirely by our authentication provider (see section 4).
What you record in the app
- Groups: name, currency, optional group photo, and who is a member.
- Expenses: description, amount, currency, the exchange rate applied, category, date, who paid, and how the cost is split.
- Payments and forgiven debts you record between members.
- Comments you write on an expense.
- Invite codes and links you generate.
Everything in a group is visible to every member of that group. That is the point of the product, but it is worth stating plainly: if you record that you paid €40 for dinner, the other members see it.
Collected automatically
- Push token. A device identifier issued by Apple or Google, stored only if you allow notifications, and deleted when you turn them off or delete your account.
- Server logs. IP address, browser or app user agent, the request path and a timestamp. Used to debug failures and block abuse.
- Crash reports (Sentry): the stack trace, device model, OS version and app version. Configured not to attach your name, email or account id.
- Usage analytics (Firebase Analytics): which screens are opened, how often the app is launched, device type and coarse country-level region, tied to a pseudonymous app-instance identifier rather than to your account. On Android, Firebase may also read the device Advertising ID; we do not use it for advertising and we run no ad networks.
What we never collect
Your contacts, your location, your calendar, your microphone or camera beyond a photo you explicitly pick, your health data, or your card and bank credentials. There is no paid tier, so we process no payments at all.
3. Why we are allowed to use it
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Account, groups, expenses, balances | Providing the service you asked for | Performance of a contract |
| Payment handles | Letting others pay you back | Contract — and you choose to add them |
| Push token | Telling you about new expenses and payments | Your consent, given in the OS permission prompt |
| Server logs, crash reports | Keeping the service up, secure and debuggable | Legitimate interest |
| Usage analytics | Understanding which parts of the app get used | Legitimate interest |
4. Who else processes it
We use a small number of service providers. They act on our instructions and may not use your data for their own purposes.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Sign-in and the database holding your account, groups and expenses | EU region |
| Hetzner | The server running the Splitto API | Germany |
| Cloudflare | This website, traffic protection, and storage of profile and group photos (R2, EU jurisdiction) | EU |
| Google (Firebase) | Push notification delivery and usage analytics | EU and United States |
| Sentry | Crash reports | EU and United States |
| Google, Apple | Sign-in, only if you use those buttons; app distribution | United States |
Where a provider processes data outside the EU, the transfer relies on the European Commission's Standard Contractual Clauses.
Beyond these, we share nothing. No advertising networks, no data brokers, no sale of personal data under any definition, including the CCPA's. We would disclose data to authorities only where a valid legal order compels us to.
5. How long we keep it
- Your account and content: until you delete your account.
- Push tokens: until notifications are turned off, the token is replaced, or the account is deleted.
- Server logs: held in the hosting platform's rolling buffer. We do not archive or back them up.
- Duplicate-request keys (used so a tapped button can't create the same expense twice): deleted automatically after 24 hours.
- Database backups: kept on a short rolling window by our database provider, then overwritten.
6. Deleting your account
Settings → Delete account, in the app. Immediately and without further confirmation from us:
- your name is replaced with "Deleted user" and your email with an unusable placeholder;
- your profile photo is deleted from storage;
- your payment handles — Revolut, PayPal, IBAN — are erased;
- your push tokens are deleted;
- your sign-in identity is deleted, so the account can never be used again.
One thing does survive, and you should know it before you delete: the expenses, payments and comments you created stay in the groups you shared them with, attributed to "Deleted user". Removing them would silently change what everyone else in those groups owes each other, and we are not willing to rewrite other people's records. If you want a specific entry gone, delete it in the app before deleting your account, or write to us.
7. Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to another provider. You can withdraw consent for push notifications at any time in your device settings.
Most of this is available directly in the app: edit your profile to correct it, delete your account to erase it. For anything else, email bertoliedoardo99@gmail.com.
If you think we have handled your data badly, you can complain to your national data protection authority. In Italy that is the Garante per la protezione dei dati personali.
8. Security
All traffic is encrypted in transit with TLS. Passwords are hashed and held by our authentication provider, never by us. Every API request is authenticated with a short-lived signed token. Photos live in a private bucket and are served through time-limited links, not public URLs.
No system is perfectly secure. If you find a vulnerability, please write to bertoliedoardo99@gmail.com before disclosing it publicly.
9. Children
Splitto is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has an account, write to us and we will delete it.
10. Changes
When this policy changes we update the date at the top of this page. For a change that materially affects how we use your data, we will also tell you in the app before it takes effect.