← Back to Splitiz

Privacy Policy

Last updated: 11 September 2026

Splitiz is a bill-splitting app. This policy explains what personal data we collect, why, and what you can do about it.

Who is responsible for your data

Splitiz is operated from the United Kingdom. For data protection law, the operator of Splitiz is the "data controller". If you need our registered details — for a complaint, a data request, or anything else — write to us and we will provide them.

Contact: contact@splitiz.app

What we collect

  • Your account: email address, display name, and a one-way encrypted form of your password. We never store your actual password and cannot see it.
  • What you put in the app: trips, expenses, amounts, currencies, dates, categories, who paid, how things are split, budgets and settlements.
  • Receipt photos and trip photos you choose to upload.
  • Payment names you choose to add (for example a Monzo.me or PayPal.Me username). These are public-style usernames. We never ask for or store bank account numbers, sort codes or card details.
  • Technical data needed to run the service: your login session, and ordinary web server logs which may include your IP address.

We do not use advertising trackers, and we do not sell your data to anyone.

Why we use it

  • To provide the service — showing your trips, calculating who owes what, and keeping you signed in.
  • To send you service emails, such as a password reset you asked for.
  • To keep the service working and secure, including preventing abuse.

Data protection law asks us to say which legal basis each of those rests on:

What forLegal basis
Running the app — your trips, balances, keeping you signed in Performing our contract with you
Reading a receipt when you ask us to Performing our contract with you
Service emails, such as a password reset Performing our contract with you
Keeping the service working, secure and free of abuse Our legitimate interests
News about Splitiz Your consent

Nothing in Splitiz makes an automated decision about you. The receipt reader suggests line items; what to keep is always your choice.

Receipt scanning

If you use the optional "analyse and itemise" feature, the receipt photo is sent to Google Cloud Document AI to read the line items. Google processes it on our behalf as a data processor. This only happens when you switch that option on for a given receipt.

We also keep a copy of the receipt and of what the reader made of it for up to 30 days, so that mistakes can be found and the reading improved. After 30 days that copy is deleted. It is separate from the receipt photo attached to your expense, which stays with the expense. If you would rather we did not keep that copy at all, email us and we will remove yours.

Cookies, and what is stored on your device

Splitiz sets one cookie: the session cookie that keeps you signed in. It contains nothing but a random identifier, it is marked secure and HTTP-only so other sites and scripts cannot read it, and signing out clears it.

The app also keeps a small amount of data in your browser's own storage, on your device: an expense you have started but not yet saved. It never reaches our servers, we cannot see it, and clearing your browser data removes it.

We use no advertising cookies, no tracking pixels and no third-party analytics.

Emails we send you

Service emails — a password reset you asked for, or something you need to know about your account. These are part of running the service.

News about Splitiz — only if you have asked for it. There is a tick box when you sign up, off by default, and on the home page you can leave your address to be told when Pro goes on sale. Those are two separate permissions, and neither is implied by anything else: an address given so that you can join a trip is not permission to email you news.

You can withdraw either at any time, from your Account screen or by writing to us, and every such email carries an unsubscribe link. If you registered interest in Pro and nothing else, your address is used for that one email and is not kept for anything further.

How we protect it

Everything travels over an encrypted connection. Passwords are stored as a one-way hash, so nobody here can read yours. Receipt and trip photos are held outside the public web folder and are served only to people signed in to a trip that includes them. Access to the servers is limited to those who need it.

No service can honestly promise perfect security. If something does go wrong with your personal data and it is likely to affect you, we will tell you, and the Information Commissioner's Office where the law requires it.

Sharing with other people

Splitiz is shared by design. Anyone in a trip with you can see the expenses, amounts, and your display name within that trip, and any payment name you chose to add. Only share trips with people you are happy to share that with.

Paying people

Splitiz never handles, holds or transfers money. When you tap a "Pay" button we simply open that provider's own page or app. Whatever happens after that is between you and them, under their terms and privacy policy.

Where your data is kept

On servers in the United Kingdom, provided by our hosting company. Receipt scanning is processed by Google in the European Union.

Who else handles your data

We keep this list as short as we can. Each one handles only what it needs to, and only on our instructions:

  • Our hosting company — runs the servers your data sits on, in the United Kingdom.
  • Google Cloud Document AI — reads a receipt photo when you ask for it to be analysed, in the European Union.
  • Our payment provider — once Splitiz sells subscriptions, takes the payment. We never see your card details.

We do not sell your data, and we share it with nobody for advertising.

How long we keep it

  • Your account, and what you put in the app — for as long as you have an account. If you delete it, see below.
  • Receipt photos on a free account — 90 days, after which the photo is deleted and the expense itself is untouched.
  • The copy kept to improve receipt reading — 30 days.
  • Web server logs — kept briefly by our hosting company and then overwritten.
  • Backups — up to 30 days, so deleted data may sit in a backup for that long before being overwritten.

Deleting your account

You can delete your account at any time from the Account screen in the app.

When you do, we remove your email address, display name, password and payment names. Expenses on trips you shared with other people are kept, because they are also those people's records and removing them would break their balances. You appear as "Deleted user" in those trips. Trips that only ever involved you are deleted entirely.

Backups are kept by our host for up to 30 days, so deleted data may sit in those backups for that period before being overwritten.

Your rights

Under UK data protection law you can ask us to give you a copy of your data, correct it, delete it, or restrict how we use it. Email contact@splitiz.app and we will respond within one month.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk.

Children

Splitiz is not intended for children under 13, and we do not knowingly collect their data.

Changes

If we change this policy we will update the date at the top. Significant changes will be announced in the app.