Cookies Policy
Last updated: September 29, 2026
1. What this policy covers
This page explains the cookies and similar storage technologies (localStorage, sessionStorage) that Split The Bill sets when you use the Service. It complements our Privacy Policy, which covers how we handle the personal information stored alongside these identifiers.
2. What is a cookie?
A cookie is a small text file your browser stores on your device when you visit a website. We also use the related browser APIs localStorage and sessionStorage, which work the same way for the purposes of this policy. The categories below apply to all of them.
3. Cookies we use
We do not use advertising or cross-site tracking cookies. The full list:
3.1 Strictly necessary (always on)
These cookies are required for the Service to work. You cannot disable them without breaking sign-in or basic page rendering.
fb_sessionโ httpOnly session cookie, set after a successful sign-in via Firebase Authentication. Lifetime: 7 days. Without this cookie you are signed out.anon_sessionโ httpOnly, signed, issued the first time you use a "try it now" tool without an account. Lifetime: 30 days. Lets us apply the free-try limit without requiring sign-up.wishlist_sessionโ httpOnly, issued when you open or claim an item on a shared wishlist. Lifetime: 90 days. Remembers which items you already claimed.CF_AppSession,CF_Authorizationโ set by Cloudflare on staging environments only, used for access control. Not present on the production site.
3.2 Functional (preferences)
These store your preferences across visits. They never leave your browser; nothing is sent to us.
themeโ remembers light/dark/system preference. Stored inlocalStorage.languageโ remembers your interface language when set explicitly. Stored inlocalStorage.- Wizard / split-bill drafts โ drafts of bills you are still editing, persisted to
localStorageso a refresh does not lose work. Cleared when the bill is saved or discarded. uiVersion,app_v2โ remember whether your account uses the current or the newer app layout. Not httpOnly (read by the page to route you correctly); not a secret. Lifetime: 7 days, refreshed on sign-in.active_workspaceโ remembers which workspace you were last viewing, if you use more than one. Not httpOnly; every request is still re-checked against your real membership server-side, so this cookie cannot grant access on its own. Lifetime: 7 days, refreshed regularly while signed in.
3.3 Analytics (only with your consent)
We use Google Analytics 4 to understand how the app is used (which pages are visited, broad device/region breakdowns) so we can improve it. These cookies are off by default and are only set after you enable the Analytics category in our cookie banner. If you do not consent, Google Analytics is never loaded and none of the cookies below are set.
_gaโ distinguishes visitors. Lifetime: up to 2 years. Set by Google Analytics._ga_<container-id>โ persists session state for a specific GA property. Lifetime: up to 2 years.- Turning this category on also stores, on our own server (not a cookie): a coarse country from your network location, a coarse device type (mobile/tablet/desktop), and the Google Analytics identifiers needed to link a payment to your session. Never your exact location, IP address, or a device fingerprint. See our Privacy Policy ยง2 and ยง6.
- You can withdraw consent at any time by reopening the cookie settings and turning Analytics off; the cookies stop being set, the server-side fields above are deleted immediately, and you can clear existing cookies from your browser.
- Separately, whichever choice you make in this banner increments an anonymous daily counter (e.g. "accepted", "rejected") with no cookie, IP address, or other identifier attached โ this is aggregate statistics, not personal data, so it is not itself a use that requires consent.
3.4 Third-party cookies
We integrate two third parties whose cookies you may encounter:
- Firebase Authentication (Google) โ sets cookies on
accounts.google.comduring the sign-in popup. These are subject to Google's cookie policy. - Our payment provider (Merchant of Record for paid plans) โ sets cookies on its checkout domains during the upgrade overlay only. Required for the checkout flow to render and complete. See the cookies policy linked from the checkout window.
3.5 What we do NOT use
- No advertising cookies.
- No cross-site tracking cookies.
- No third-party analytics without consent. Google Analytics (ยง3.3) is the only analytics tool and it stays off until you opt in.
- No social-media share-button cookies.
4. How to control cookies
When you first visit, a cookie banner lets you accept or reject non-essential cookies, or open Customize to choose per category (Functional, Analytics). Strictly-necessary cookies cannot be switched off because sign-in and basic rendering depend on them. You can reopen these settings at any time from the cookie link in the footer to change or withdraw your choices.
You can also clear cookies and localStorage at any time from your browser's privacy settings. Doing so will sign you out and reset your stored preferences.
Analytics cookies (ยง3.3) are only ever set after you opt in; until then Google Analytics is not loaded at all.
5. Changes to this policy
If we add or change cookie usage, we will update this page and adjust the "Last updated" date above. Material changes will be communicated via the in-app What's New page where appropriate.
6. Contact
Questions about this policy? [email protected].


