SplitEasy

Legal

Privacy policy

In force from 12 August 2026. This policy explains what SplitEasy does with personal data, in the plainest terms we can manage.

The short version. Trips you keep on your phone stay on your phone. If you sign in, your trips are stored on our servers in the UK so they can reach your other devices and the people you share a trip with. We never sell anything to anyone, and nothing about your trips, expenses or the people on them is used for advertising or sent to an analytics service.

Who we are

SplitEasy is operated by Enrico Rossini, a sole trader based in the United Kingdom, who is the data controller for the personal data described here.

For anything in this policy — a copy of your data, a correction, an erasure, or a complaint — write to privacy@spliteasy.app. It is a monitored address and the fastest route to a person.

Where your data actually lives

This is the part most policies leave vague, and it decides most of the rest, so it comes first.

  • The mobile app works offline, on your device. Trips, expenses, the people you add and any cover photos are written to a database inside the app's own storage. Without an account, none of it is sent to us — deleting the app deletes it, and we cannot recover it for you.
  • Signing in moves a copy to us. The web app at spliteasy.app, and syncing between devices, both need your trips on our servers. That copy is what other people on a shared trip can see, and what you can ask us to export or erase.

What we collect, and why we are allowed to

Under UK GDPR every use of personal data needs a lawful basis. Ours are in italics below. Where the basis is consent you can withdraw it at any time; where it is our legitimate interests you can object, and we will stop unless there is a compelling reason not to.

Your account
Email address, a display name, and your password — which is stored only as a hash, so nobody here can read it. We also keep the technical flags an account needs: whether the address is confirmed, and a count of failed sign-in attempts so an account can be locked after repeated guesses. Basis: performance of our contract with you. Lock-out counting: legitimate interests in keeping accounts secure.
Your trips and expenses
Trip names, dates, currencies and cover photos; expense descriptions, amounts, dates, exchange rates, who paid and how it was split; payments you record between people. These are the service — there is nothing to show you without them. Basis: performance of our contract with you.
The people you add to a trip
Names, and email addresses or phone numbers where you enter them. Most of these people never have an account: they exist so a share of a bill can be tracked against them, and so they can be invited later. Basis: our legitimate interests, and yours, in running a shared expense record. See below for what this asks of you.
Share links
When you invite somebody to a trip we store the link's token as a SHA-256 hash rather than the token itself, along with which participant it names and when it expires. A link works once and dies after seven days. Basis: performance of our contract with you.
Technical data from requests
Your IP address, the time of a request, and the usual server log lines. The IP address is what our rate limiter counts against, which is how sign-in, sign-up and invitation endpoints are protected from being hammered. Basis: legitimate interests in the security and availability of the service.
Emails we send you
Confirmation links, password resets and sign-in links go through our mail server on the spliteasy.app domain. We do not send marketing email, and there is no tracking pixel in anything we send. Basis: performance of our contract with you.
Website analytics
Counts of page visits, via Google Analytics, and only if you accept — see cookies. Basis: consent.
Advertising in the free mobile app
The free tier of the phone app shows banner ads through Google AdMob — see advertising. Basis: consent where the ad SDK asks for it, otherwise our legitimate interests in funding a free tier.

Details you enter about other people

Adding a friend by name and email means you are handing us someone else's personal data, and it is worth being straight about what that involves.

  • We use it for one thing: showing that person on the trip, working out their share, and — if you send them a share link — inviting them. It is never used to market anything to them, and they are not signed up for anything.
  • Everyone on a trip can see the names of the others on it, and the expenses, shares and payments recorded against them. That is the point of a shared record, but it means adding somebody makes their name visible to the rest of the group.
  • Please only add details you were given for this sort of purpose, and tell the person if they would not expect it. If someone contacts us asking to be removed from a trip they are not part of, we will act on it.

Cookies, and the choice at the bottom of the page

The website sets two kinds of cookie, and they are not treated the same way.

  • Strictly necessary — set without asking. A sign-in cookie that keeps you signed in, and an anti-forgery cookie that stops a form on another site being submitted as you. There is no version of a signed-in account that works without these, so the law does not require consent for them. Alongside them, your answer to the cookie question itself is kept in a cookie for a year — so that you are asked once rather than on every page.
  • Analytics — only if you accept. Google Analytics, which counts visits and tells us which pages people actually read. It loads with storage denied by default and writes nothing to your device unless you press Accept; if you decline, it stays denied and only an anonymous, cookieless page count is registered. No account details, trip content or expense data is ever sent to it.

Changed your mind? — this clears the stored answer and brings the choice back.

Google's own handling of analytics data is described in their privacy policy, and their browser add-on opts you out of Google Analytics on every site at once.

Advertising in the free app

The phone app's free tier carries a banner from Google AdMob at the foot of some pages. To fill it, Google's ad SDK receives technical information from the device — IP address, device and app details, and an advertising identifier — and Google acts as its own controller for that.

What it does not receive is anything from inside the app. Your trips, the amounts, the names of people you split bills with: none of it is passed to the ad SDK, and nothing you enter is used to target an ad at you.

You can reset or limit the advertising identifier in your phone's settings — under Privacy in iOS, and Ads under Google settings on Android. Pro is ad-free, and no ad SDK is loaded at all for a Pro subscriber.

Photos

A cover photo for a trip is chosen from your device's library, which is the only reason the app asks for library access. We never browse the library ourselves — you pick one image and only that image is used.

When a photo reaches our servers it is checked by its actual contents rather than by its file name, stored as ordinary bytes, and served only to people on that trip through a URL that checks who is asking. Photos are never public.

Who else sees your data

We do not sell personal data, and we do not share it for anyone else's marketing. It is passed on in only three ways:

  • Other people on your trips, as described above.
  • Suppliers who run part of the service for us, under contract and only on our instructions: our hosting and database provider in the UK, the mail provider that delivers confirmation and reset messages, Google Analytics for website visit counts, and Google AdMob for advertising in the free app.
  • Where the law requires it — a court order, or a legal obligation we cannot refuse.

When paid plans launch, payment will be handled by Apple, Google or Stripe depending on where you buy, and card details will not reach our servers at any point. There is nothing to buy yet, and this policy will be updated before there is.

Where your data is kept

Accounts and trip data are stored in the United Kingdom. Our own systems do not move your data outside the UK.

Two of the suppliers above are global: Google Analytics and Google AdMob may process data outside the UK, including in the United States. Those transfers rely on the UK extension to the EU–US Data Privacy Framework and on the standard contractual clauses in Google's terms. Declining analytics, or subscribing to the ad-free tier, removes each of those transfers respectively.

How long we keep it

  • Your account and trips — for as long as the account exists. Ask us to delete it and they go with it.
  • Deleted trips and expenses — marked as deleted rather than removed instantly, and kept as a marker for up to 90 days. This is not evasion: an offline device that never hears about a deletion cannot tell the difference between a record that was removed and one it has simply never seen, and would restore what you deleted on its next sync.
  • Someone removed from your address book — the entry is marked as removed rather than erased, because their name appears in the split of every expense they were part of. Erasing the person outright would silently change the balances on trips other people rely on. If you want the entry itself gone, ask and we will do it once we can do so without corrupting anyone else's record.
  • Share links — expire after seven days and are spent on first use. Only the hash was ever stored.
  • Server logs — kept for up to 30 days for security and debugging, then discarded.

Your rights

Under UK GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, hand it over in a portable form, or object to processing we do on the basis of legitimate interests. Where we rely on consent — analytics, and ad personalisation where it is asked for — you can withdraw it at any time without affecting what was done beforehand.

Write to privacy@spliteasy.app. We will answer within one month, and we will not charge you for it. There is no automated decision-making in SplitEasy that produces legal or similarly significant effects.

To close your account entirely, see deleting your account.

If you think we have got this wrong, please tell us first — but you have every right to complain directly to the Information Commissioner's Office, the UK's supervisory authority, at ico.org.uk or on 0303 123 1113.

How your data is protected

  • Everything travels over HTTPS, and the site refuses plain HTTP.
  • Passwords are stored as salted hashes, never in a readable form.
  • Share-link tokens are stored as hashes, so a copy of the database does not hand anybody a working invitation.
  • An account locks temporarily after repeated failed sign-ins, and the endpoints that accept credentials are rate-limited per address.
  • Every request for a trip is checked against whether you are actually on that trip, rather than trusting the identifier in the request.

No system is perfect. If you find a security problem, please report it to privacy@spliteasy.app before disclosing it publicly, and we will work with you.

Children

SplitEasy is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will remove it.

Changes to this policy

When this changes we update the date at the top. If a change materially affects what we do with your data — a new purpose, a new supplier, a new kind of collection — we will tell account holders by email before it takes effect.

An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.