Privacy Policy
Last updated: October 8, 2026
1. Who we are
Split The Bill ("we", "us", "our") operates the website split-the-bill.app and the related web application (together, the "Service"). This policy explains what personal information we collect, why we collect it, and the choices you have.
For the purposes of the EU General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act ("CCPA"), we act as the data controller for the personal information described here. You can contact us at [email protected].
2. What we collect
When you sign up
When you create an account we collect:
- Your email address (required)
- Your name (optional)
- Your browser language preference (to personalise the interface)
- The page or referrer you signed up from (so we can tell which channels are working)
- The timestamp of your signup
When you use the app
- Account data: email, display name, hashed password, preferences
- Content you create: receipts (including photos you upload), bill line items, the names you assign to people in a split, and the splits themselves
- Billing data (Pro subscribers): our payment provider (merchant of record) handles your card details directly โ we never see or store them. We receive your subscription status, plan, and billing period from them.
- Technical data: IP address, browser user-agent, and error logs โ retained for up to 30 days for abuse prevention and debugging
- Visit activity: the date you last used the Service, kept server-side so we can measure retention and improve the product. This is first-party and does not use a cookie โ see ยง3 for the legal basis.
- Country and device type (only with analytics consent): if you turn on the Analytics cookie category, we also store a coarse country (from your network location) and device type (mobile/tablet/desktop) on your account, plus the Google Analytics identifiers needed to link a purchase to your session. Turning Analytics off deletes this immediately โ see our Cookies Policy ยง3.3.
- Push notification subscription (optional): if you turn on push notifications, your browser or device gives us a subscription endpoint and the encryption keys needed to deliver them. We use this only to send notifications you asked for, and delete it when you turn notifications off or sign out of that device.
When you invite someone
If you invite another person to a group, bill, or split, we process the email address or phone number you give us on your instruction, solely to deliver that invitation. We are not responsible for the accuracy of contact details you provide. The invite tells the recipient who invited them and how to stop receiving invitations from the Service.
When you try it without an account
Our homepage lets you try scanning up to three bills before you sign up, and split one with friends. We collect the photo you upload, the extracted result, and basic technical data (a hashed IP address and your browser user-agent) to prevent abuse of the free try and to debug and improve parsing. If you split the bill, we store the names you add and any email addresses you choose to add for the people you split with; only when you press "email everyone" do we send each of them one email with their share and an unsubscribe link. We do not ask for your own name or email unless a scan fails and you choose to leave an email so we can send you the result by hand โ see ยง6.
When you email us a receipt
If you (or someone forwarding a receipt on your behalf) send an email to your personal inbound address, we process the sender address, subject, body, and attachments to extract a bill the same way as our other AI features (see ยง4). If the sender is not a registered user, we hold that email only long enough to extract and deliver the result, plus the same debugging retention described in ยง6, and we do not use it to contact that address for any other purpose.
Children
The Service is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
3. Why we use it (legal basis)
Under the GDPR we rely on the following legal bases:
- Consent (Art. 6(1)(a)) โ for sending optional product-update emails, for push notifications (only after you explicitly opt in), and for analytics cookies and the country/device profiling tied to them (see our Cookies Policy).
- Contract (Art. 6(1)(b)) โ for providing the account and features (Free or Pro) you sign up for, and for sending an invite you ask us to send on your behalf.
- Legitimate interests (Art. 6(1)(f)) โ for basic security logging, spam prevention, aggregate service metrics, and measuring when accounts were last active (visit/retention analytics) so we can maintain and improve the Service. You can object to this at any time โ see ยง7.
4. Who we share it with
We do not sell your personal information. We do not share it with advertisers. We share it only with:
Shared links are served with noindex and X-Robots-Tag: noindex headers so search engines do not index them. Links use long random tokens that are not guessable and can be revoked at any time from your account.
- Our infrastructure and email providers, strictly as processors acting on our instructions under a data processing agreement (DPA)
- Cloudflare โ our network and security provider. The free try on our homepage is protected by Cloudflare Turnstile, which checks in the background that a visitor is a person and not a bot, without showing a puzzle. Cloudflare processes the technical data this needs as described in the Turnstile Privacy Addendum.
- Google (Gemini API) and Anthropic โ AI providers we use to read and understand the content you submit for extraction: receipts, bills, invoices, wishlists, menus, official notices, and chat messages. They process this content as our processor, under their own data processing terms, solely to return the extracted result to our servers โ never to train their models on your data, and never to contact you directly. All calculations (totals, splits, balances) are performed by our own code, never by an AI model.
- TypeSafe AI (Jev) โ an AI provider we use to classify a bill we have already read into a fixed set of options (bill type, spending category, item categories), and to help route and match items in messages you type to our chat assistant, with a confidence score. It receives only the already-extracted bill fields (merchant name, item names, total, currency) and the text of messages you type to the assistant โ truncated, with email addresses and phone numbers removed. It never receives your receipt image, email attachments, or your contacts. It generates no text and acts as our processor under its own data processing terms, solely to return the classification to our servers.
- BugLens โ our issue-tracking widget, present on every page, so you can report a bug or request straight from the app. If you submit a report, we receive its content and basic technical context (page, browser). It acts as our processor and does not use your data for anything else.
- Government authorities where we are legally required (court order, lawful subpoena, or equivalent)
- People you explicitly share a bill or collection with โ via a shareable link or a private invite you send from inside the app
5. International transfers
Our servers are located in the European Union. If your data needs to leave the EU (for example, to a support tool based elsewhere), we rely on the European Commission's Standard Contractual Clauses or an equivalent lawful transfer mechanism.
6. How long we keep it
When you delete a bill, or your whole account, we delete the files you uploaded for it (receipt photos, PDFs, item photos) along with the record.
- Product-update emails: until you unsubscribe.
- Account data and receipts: while your account is active, plus up to 90 days after account deletion to complete backups and handle disputes.
- Billing records: kept as required by tax and accounting law after a subscription ends, handled by our payment provider as merchant of record.
- Server logs: up to 30 days, then deleted automatically.
- Visit activity (last-used date): kept while your account is active, deleted with the account.
- Country, device type, and Google Analytics identifiers: kept only while Analytics consent is granted โ turning Analytics off deletes them immediately (see our Cookies Policy).
- Content you send to our AI features (receipts, bills, invoices, wishlists, menus, official notices, and chat messages โ from a signed-in account or the anonymous "try it now" tool on our homepage) is retained so we can debug and improve parsing quality, along with basic technical metadata about the request (timestamps, success/failure, processing time). We do not use it for advertising or sell it. You can ask us to delete any of it at any time โ email [email protected] and we will remove it.
- The anonymous "try it now" tool does not require an account, so we have no way to contact you about your upload except an email address you choose to leave us. Anonymous tries and splits that are never saved to an account โ including the names and email addresses added to a split โ are deleted after 90 days; we keep only aggregate counts with no personal data. If you sign up afterward, your free try or split becomes a normal bill in your account and follows the retention rules above instead. If someone unsubscribes from split emails, we keep only a one-way hash of their address so we never email it again.
7. Your rights
If you are in the EU, UK, Switzerland, or California, you have the following rights in relation to your personal information. You can exercise any of them by emailing [email protected].
Under the CCPA, California residents have the right to know, delete, and opt out of the sale of their personal information. We do not sell personal information.
- Access โ ask for a copy of the data we hold about you
- Rectification โ correct inaccurate data
- Erasure โ ask us to delete your data ("right to be forgotten")
- Restriction โ temporarily limit how we use your data
- Portability โ receive your data in a machine-readable format
- Objection โ object to processing based on legitimate interests
- Withdrawal of consent โ withdraw consent at any time
- Complaint โ lodge a complaint with your local data protection authority
8. Cookies & similar technologies
The Service uses only strictly necessary cookies โ a session cookie to keep you signed in, and a theme preference in your browser's local storage. We do not use advertising or cross-site tracking cookies. No consent banner is required for these essential cookies under ePrivacy rules. See our Cookies Policy for the full list.
9. Security
We use industry-standard measures โ TLS in transit, hashed passwords, encrypted backups, and least-privilege access for our team. No system is perfectly secure, so we encourage you to choose a strong, unique password.
10. Changes to this policy
We may update this policy to reflect changes in the Service or the law. When we do, we will change the "Last updated" date at the top and, if the change is material, notify you by email or a banner inside the app.
11. Contact us
Questions or requests? Email [email protected]. We respond within 30 days.


