Draft: final legal details are being confirmed.

Privacy Policy

Last updated: 11 October 2026 · Version 2026-10-11

Splitkia helps groups of people track shared costs. This policy explains what personal data we collect, why, who sees it, how long we keep it and the choices you have. It works with our Terms of Service. We never sell your data, there are no ads, and Splitkia never moves money.

1. Who is responsible

Splitkia ((to be confirmed)) is the data controller. Contact for anything about your data: [email protected].

2. What we collect

We do not collect your contacts, location, photos, card or bank details.

3. Why we use it, and on what legal basis

PurposeLegal basis (GDPR / UK GDPR)
Providing Splitkia: your account, storing and syncing your groups and balances, sending invites you ask us to sendContract
Keeping a record that you agreed to these termsLegal obligation and legitimate interests (showing agreement if there is ever a dispute)
Security, preventing abuse (rate limits), backups, crash reportsLegitimate interests (a safe, working service). You can turn crash reports off.
Anonymous usage statistics to improve the appConsent: off unless you opt in, and you can withdraw at any time in Account
Responding to legal requestsLegal obligation

4. Who can see your data

Your groups: people in a group see its members, expenses, payments, history and the payment usernames of its members. People outside a group cannot see anything in it.

Our service providers (processors), who handle data only on our instructions and under data processing agreements:

Exchange rates are fetched from a public service (frankfurter.app, European Central Bank data); no personal data is sent. When you use "Settle up" with PayPal, Monzo or a UPI app, you leave Splitkia and that service's own privacy policy applies.

We share data with authorities only when the law requires it, and would tell you unless the law forbids it. If Splitkia were ever transferred to another organisation, your data would only go with it under this policy, and we would tell you first.

5. Where your data is stored

Our database is in the European Union. Some providers (for example Google, Sentry and GitHub) may process data outside your country, including in the United States. Where they do, we rely on safeguards recognised by law, such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum and the EU–US Data Privacy Framework.

6. How long we keep it, and how it is deleted

DataKept for
Your account (name, email, sign-in, payment usernames)Until you delete your account; then removed straight away
Groups, expenses, payments and their historyWhile the group is in use. If you delete your account, entries you were part of stay in your groups under "Former member", with no name, email or payment details, so everyone else's balances still add up
Email addresses of people you invitedDeleted 30 days after the invite is accepted, cancelled or expires
Record of your agreement to the Terms and Privacy PolicyWhile your account exists and for 6 years after it is deleted (contains only a random id, versions and dates), then deleted
Security and anti-abuse records (rate limits, duplicate-request checks)2 to 120 days
Encrypted backups30 days, then automatically deleted. A deleted account disappears from backups within 30 days
Crash reports and usage statisticsUp to 90 days. Usage statistics are deleted when you delete your account
Server request logsA few days
Data on your phoneUntil you sign out (which wipes it) or uninstall the app

We may delete accounts unused for 24 months, after at least 30 days' notice (see the Terms).

7. Your rights and choices

Depending on where you live, these rights come from the EU/EEA and UK GDPR, California's CCPA/CPRA, India's Digital Personal Data Protection Act 2023 or similar laws. We do not sell or "share" personal information for advertising, and we do not use it for automated decisions about you. You can complain to your data protection authority (in the UK, the ICO at ico.org.uk), but please contact us first so we can help.

8. Security

Data is encrypted in transit (TLS) and at rest. On your phone, the local database is encrypted and its key is kept in the Android Keystore; cloud backups of the app are disabled. On our servers, access is restricted so each person can only read their own groups, every change is checked by the server, and backups are encrypted. No system is perfectly secure: if a breach affects your data we will tell you and the authorities as the law requires.

9. Children

Splitkia is for people aged 18 and over. If you believe a child has created an account, contact us and we will delete it.

10. Changes to this policy

When this policy changes, the date and version above change. For significant changes we tell you in the app and ask you to agree to the new version before you continue. We keep a record of each version you agreed to.

Contact

Splitkia · (to be confirmed) · [email protected]