Splitzy — Privacy Policy
This Privacy Policy describes how Splitzy (the “App”, “we”, “us”) collects, uses, stores and shares your personal data when you use the App on Android or any related services. The App is published by Yannick Badoual, acting as an individual developer based in France, who is the data controller within the meaning of the EU General Data Protection Regulation (“GDPR”).
1. Who we are & how to contact us
Data controller: Yannick Badoual, individual developer, France.
Contact for any privacy request (access, deletion, etc.):
splitzy.app.support@gmail.com
If you live in the EU/EEA, you can also lodge a complaint with your local supervisory authority. In France, this is the Commission Nationale de l’Informatique et des Libertés (CNIL — cnil.fr).
2. What data we collect
2.1 Account data (from Google Sign-In)
You sign in to Splitzy with your Google account. Through this sign-in, we receive from Google and store on Firebase Authentication:
- your email address;
- your display name;
- your profile picture URL;
- a unique Google/Firebase user identifier.
We do not receive your Google password, contacts, calendar, or any other Google data beyond the basic profile listed above.
2.2 Trip and expense data
When you use the App, you create and store content such as:
- trip names, descriptions and currency;
- members you add to a trip (their display name and, where applicable, their Splitzy user ID);
- expenses (amount, category, date, who paid, who participates, optional notes);
- settlements between members;
- scanned receipts/bills (image files) — see section 2.3.
2.3 Bill / receipt images
When you scan a bill, the image is:
- uploaded to Google Firebase Cloud Storage (region
us-east1, United States); - sent to the Google Gemini API (Google AI) so the model can extract the total, currency, line items and merchant from the photo;
- kept in storage for approximately 90 days while the trip is active, after which it is automatically deleted. Images linked to a trip are also deleted when the trip itself is deleted, or when you delete your account.
2.4 Push notifications
If you allow notifications, we register a Firebase Cloud Messaging (FCM) device token so we can send you trip-related notifications (e.g. a new expense was added, someone settled with you). The token is not used for advertising.
2.5 Crash and diagnostic data (Firebase Crashlytics)
We use Firebase Crashlytics to be notified when the App crashes or hits a serious error, so we can fix it. When a crash happens, Crashlytics automatically collects and sends to Google’s servers:
- the crash stack trace and the thread state at the moment of the crash;
- device information: brand, model, OS version, available RAM/storage, orientation, whether the device is rooted;
- app information: app version, build number, time since launch;
- a Firebase-generated Crashlytics Installation UUID (a per-install identifier, not your name or email), which lets us count how many distinct users are affected by a given crash;
- your IP address, used transiently by Google to derive a coarse country/region and then discarded;
- optional breadcrumb logs we add in code (e.g. “opened trip details”, “tapped scan bill”) to help us reproduce the crash. These logs do not include the content of your expenses, trip names, or other personal data.
Crashlytics data is used solely for stability monitoring and debugging. It is not used for advertising, profiling, or any other purpose.
2.6 Subscription data (Google Play Billing & RevenueCat)
Splitzy offers a freemium model with optional paid subscriptions that unlock higher limits (more trips, more bill scans, more expenses per trip, etc.). Subscriptions are billed by Google Play Billing and managed on our side by RevenueCat, a subscription-management platform.
For this purpose, the following data is processed:
- by Google Play: your purchase, payment method and billing history — we do not see your card or bank details, only that you have an active entitlement;
- by RevenueCat: your Splitzy user ID, the purchase receipt issued by Google Play, the resulting subscription status (active, paused, expired), country, app version and platform. RevenueCat acts as our data processor under a Data Processing Addendum and uses this data only to manage entitlements on our behalf;
- by us: the resulting subscription status, mirrored in Firestore so the App can enforce limits offline.
2.7 Product analytics (Firebase Analytics)
We may use Firebase Analytics to log a limited set of anonymised events — for
example trip_created, expense_added, bill_scanned,
subscription_started — together with non-identifying context (app version, OS version,
country derived from IP, language). This helps us understand which features are used and where the
App can be improved.
Where applicable law requires consent before any non-essential tracker is activated — in particular Article 82 of the French Loi Informatique et Libertés (transposing the ePrivacy Directive) and equivalent rules in other EU/EEA countries, the UK and Switzerland — we ask for your consent on first launch, and Firebase Analytics stays disabled by default until you opt in. You can change your choice at any time from Settings → Privacy. If you do not consent, no analytics events are sent.
We may also log a small number of events without your consent where this is strictly necessary to comply with a legal obligation we are subject to (Art. 6(1)(c) GDPR) — for example to keep an auditable record of subscription transactions for tax purposes, to detect and document fraud or abuse, or to be able to answer a lawful request from a competent authority. These events are limited to what is necessary for that purpose and are not used for product analytics.
Firebase Analytics is never used for advertising, ad targeting, profiling, or sharing data with third parties beyond Google as our processor.
2.8 If someone else added you to a Splitzy trip
Splitzy lets users add other people to a trip — for example to record that “Alice paid 60€ for the group” — even if those people don’t have a Splitzy account. The data that ends up in Splitzy in that case is limited to what the inviter typed in (typically a name, sometimes a contact identifier such as an email).
In this scenario, the person who added you is the data controller for the information they entered about you; we act as their service provider. If you are concerned about the way your information appears in a trip, you can:
- contact the person who added you and ask them to remove or correct the entry;
- write to us at splitzy.app.support@gmail.com — we will inform you of who added you (where we can identify them) and, in line with our obligations under Articles 12 and 14 GDPR, help you exercise your rights vis-à-vis that person.
2.9 Data we do not collect or share
- We do not access your phone contacts, calendar, microphone or precise location.
- We do not embed third-party advertising or attribution SDKs.
- We do not sell, rent or trade your personal data.
- We do not share your data with any third party other than the processors listed in section 4 (Google for Firebase and Gemini, Google Play for billing, and RevenueCat for subscription management), and only to the extent strictly needed for them to provide their service to us.
3. Why we use your data (purposes & legal bases)
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Authenticate you and create your account | Google account info, user ID | Performance of a contract (Art. 6(1)(b)) |
| Provide the core service (trips, expenses, balances, settle-up) | Trip and expense data | Performance of a contract (Art. 6(1)(b)) |
| Analyse bill images to pre-fill expenses | Receipt image, extracted text | Performance of a contract (Art. 6(1)(b)) — feature you actively trigger |
| Send trip notifications | FCM token, trip event | Performance of a contract (Art. 6(1)(b)) and your OS-level consent |
| Fix bugs, prevent abuse, secure the service | Crash logs, diagnostic data | Legitimate interest (Art. 6(1)(f)) — keeping the App reliable and secure |
| Understand how the App is used (Firebase Analytics) | Anonymised in-app events, app/OS version, country | Your consent (Art. 6(1)(a) GDPR + Art. 82 LIL), collected on first launch in the EU/EEA, UK and Switzerland |
| Comply with a legal obligation that requires logging (e.g. transaction records, fraud reporting, lawful authority requests) | The minimum events strictly necessary for the obligation | Legal obligation (Art. 6(1)(c)) |
| Manage subscriptions and entitlements | Subscription status from Google Play | Performance of a contract (Art. 6(1)(b)) |
| Prevent abuse of free trials and freemium limits (e.g. someone deleting and recreating accounts to keep restarting the trial) | A one-way salted hash of your email address only | Legitimate interest (Art. 6(1)(f)) — protecting the App’s economic viability against abuse, recognised by Recital 47 GDPR |
| Comply with legal obligations (e.g. tax, lawful requests) | Whatever is strictly required | Legal obligation (Art. 6(1)(c)) |
4. Who has access to your data (sub-processors)
We rely on the following processors. They act on our documented instructions, only for the purposes described below, and are bound by data-protection agreements (DPAs):
-
Google Ireland Ltd. / Google LLC — Firebase Authentication, Cloud Firestore
(region
europe-west), Cloud Storage (regionus-east1), Cloud Messaging, Crashlytics, Firebase Analytics (only when you have consented, or where logging is required by law), and the Gemini API. - Google Play Billing (Google LLC) — billing and payment processing when you purchase a subscription.
- RevenueCat, Inc. (United States) — subscription management: validating receipts, keeping track of your entitlement, and notifying our backend when your subscription state changes. RevenueCat does not receive your name, email, profile picture, trips or bill images.
Apart from these processors, we do not share your personal data with any third party, except where strictly required by law (e.g. a valid request from a competent authority) or to establish, exercise or defend legal claims.
5. Where your data is stored (international transfers)
Splitzy stores most documents (trips, expenses, members, balances) on Cloud Firestore in the
European Union (europe-west). Bill/receipt images are stored on Cloud
Storage in the United States (us-east1), and bill images are processed
by the Gemini API on Google’s global infrastructure, which may include the United States.
Subscription receipts and entitlement records processed by RevenueCat are also
hosted in the United States.
These transfers outside the EEA rely on the European Commission’s Standard Contractual Clauses and, where applicable, on Google’s certification under the EU-U.S. Data Privacy Framework, which together provide appropriate safeguards under Articles 45–46 GDPR.
6. How long we keep your data
| Category | Retention |
|---|---|
| Account profile (email, name, picture) | Until you delete your account. |
| Trips, expenses, balances, settlements | Until you delete the trip or your account. After account deletion, residual copies in backups are purged within 30 days. |
| Bill / receipt images | Approximately 90 days from upload while the trip is active, then automatically deleted. Sooner if you delete the expense, the trip, or your account. |
| Push notification tokens | Until you sign out or uninstall the App. |
| Crash logs and diagnostic data (Crashlytics) | Up to 90 days for individual crash reports; aggregated, non-identifying stability metrics may be kept longer for trend analysis. |
| Firebase Analytics events (when consented, or when retained under a legal obligation) | Up to 14 months for user-level events (Google’s default for EU-configured projects); aggregated, non-identifying reports may be kept longer. Events retained on a legal-obligation basis are kept for the period required by that obligation (typically up to 10 years for tax-related records) and then erased. |
| Subscription entitlement data on RevenueCat | For as long as you have an active or recently expired subscription, plus the period required by RevenueCat’s own retention policy and any tax-law obligations. |
| Subscription / billing records | Up to 10 years where French/EU tax or accounting law requires it. |
| Anti-abuse record (salted hash of your email) | Up to 12 months after you delete your account, then automatically erased. We never keep the plaintext email after deletion — only an irreversible hash that lets us detect if the same email tries to claim a new free trial within that window. |
7. About Gemini / Google AI processing
When you scan a bill, the image is sent to the Google Gemini API (Google AI) so the model can read the receipt and return structured data (total, currency, line items, merchant). According to Google’s terms applicable to paid Gemini API usage, prompts and responses sent via the paid API are not used to train Google’s general-purpose models. Google may, however, retain the data for a limited period for abuse-prevention purposes. We do not send any additional personal data (such as your name or email) with the image.
AI extraction is provided as a convenience to help you fill expenses faster. You should always review the extracted amount before saving — see also the Terms of Use.
8. Your rights
Under the GDPR and French Loi Informatique et Libertés, you have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”);
- restrict or object to certain processing, including profiling;
- data portability — receive your data in a structured, commonly-used and machine-readable format (we provide a JSON export on request, sent to your registered email address);
- withdraw any consent you have given, at any time;
- define directives on what happens to your data after your death;
- lodge a complaint with the CNIL or another supervisory authority.
To exercise any of these rights, contact us at splitzy.app.support@gmail.com.
8.1 Deleting your account from the App
The simplest way to exercise your right to erasure is directly from the App:
- open Splitzy and go to Settings;
- tap Delete my account;
- confirm the action.
Deletion is immediate and irreversible. It removes:
- your profile (email, name, profile picture, user ID);
- the trips you own, including expenses, members, balances and uploaded bill images;
- your FCM push notification token.
Trips you are only a member of (not the owner) remain available to the other members, but your participation is anonymised so that historical balances stay correct.
8.2 What we keep after deletion, and why
Even after you delete your account, we retain two limited items:
- a salted, one-way hash (SHA-256) of your email address, for up to 12 months, solely to detect abuse of the free trial and freemium limits (Art. 6(1)(f) GDPR, legitimate interest — see also Recital 47);
- any billing records we are required to keep under French/EU tax and accounting law (typically up to 10 years).
The hash is irreversible (the salt is stored only on our server and is not derivable from the hash) and is not used for marketing, analytics or any purpose other than anti-abuse.
How the hash is used at sign-up. When a new account is created, we hash the sign-up email with the same server-side salt and check whether that hash matches one of the hashes we kept. If it does, we flag the new account as “restored”, which means the App treats the free tier (number of trips, bill scans, expenses, etc.) as already consumed. The user can still use the App, but they cannot start a new free trial or claim a fresh freemium allowance. We do not recover any data from the previous account — your trips, expenses and bill images remain permanently deleted. After the 12-month window expires, the hash is removed and a new sign-up with the same email starts with a fresh free tier.
You can object to this processing at any time by writing to splitzy.app.support@gmail.com; we will weigh your objection against the anti-abuse interest as required by Art. 21 GDPR.
9. Security & data breaches
We rely on Google Firebase’s infrastructure, which provides encryption in transit (TLS) and at rest. Access to Firestore and Cloud Storage is controlled by per-user security rules so that you can only read or write trips you are a member of. We restrict administrative access to data to what is strictly necessary to operate and troubleshoot the App.
Despite these measures, no system is 100% secure. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the CNIL within 72 hours of becoming aware of it (Article 33 GDPR). If the breach is likely to result in a high risk, we will also notify you directly without undue delay (Article 34 GDPR), describing the nature of the breach, its likely consequences, and the measures taken or proposed to address it.
10. Children
Splitzy is not directed to children. You must be at least 16 years old to create an account, or older if your country requires a higher age of digital consent. If we learn that we have collected data from a child below that age without parental consent, we will delete it.
11. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be highlighted in the App before they take effect. The “Effective date” at the top of this page always reflects the latest version.
12. Contact
Questions or requests? Email splitzy.app.support@gmail.com.