Split Today is a mobile app for splitting shared expenses with friends — trips, flats, and everyday groups. It keeps a shared ledger of who paid what and who owes whom, plus a private tracker for your own spending. It does not move money. This policy explains what data the app collects, why, who it is shared with, and the choices and rights you have.
01Who we are
Split Today (“the app”, “we”, “us”) is operated by Speed Develop, an independent developer based in India, who acts as the data controller for the personal data described here. For anything in this policy — including privacy requests and grievances — contact speeddevelop.dev@gmail.com.
02Data we collect
- Account data. You sign in with Google. We receive and store your name, email address, and profile photo URL from your Google account. We never see your Google password.
- Group & expense data. The content you and your group enter: group names, member display names, expense titles, amounts, dates, categories, splits, and settlement records. This is the product — it is stored on our backend (Supabase) and is visible to the other members of your group, and in read-only preview to anyone who has that group’s invite link.
- Personal expenses. If you use the private personal tracker, your own income and spending entries (amounts, categories, notes, dates). These are private to your account and are not shown to any group.
- Settlement & payment references. When you settle up, we store the record that a settlement was claimed and confirmed. If you use pay-via-UPI or send a payment request, we store the UPI ID or reference you enter so the request can be shown to the other person. We do not process or hold the money (see Payments & UPI).
- Subscription status. If you buy Premium, we store your entitlement status (active / expired) via RevenueCat and the app store. We never receive your card or bank details (see Subscriptions & purchases).
- Device & technical data. To run and maintain the app we process basic technical data such as your app version, build number, platform (Android / iOS), and coarse timestamps of activity, plus diagnostic and crash information if something goes wrong.
- Push notification token. When you allow notifications, we store your device’s messaging token (from Google Firebase Cloud Messaging) against your account, together with the platform and app version. It is how a reminder reaches the right phone — without it we can address a notification to you but never deliver it. We delete it when you sign out, when Google tells us the token is no longer valid, after 270 days without use, and when you delete your account. We never share it, and no other member of your groups can see it or learn whether you have one.
- What we send to it. Two separate things, each with its own switch under Account › Notifications. Payment reminders are transactional — someone you split with nudging you about an open amount, or telling you a payment was confirmed. They are on by default because they are part of the service you asked for, and you can turn them off. News & offers are promotional. They are off until you turn them on, and you can turn them off again at any time. Turning notifications back on in your device settings never opts you into News & offers.
- Usage analytics. We use PostHog (hosted in the EU) and Google Analytics for Firebase to understand how the app is used — which screens are opened and which features are used (for example “expense added”) — so we can improve it. These records carry a random account ID and basic device details (such as app version and platform), never your name, email, or the amounts, titles, or payment details you enter, and we don’t use them for advertising. We do not collect them in regions where the law requires your consent first, such as the EU, UK, and Switzerland.
- Advertising identifiers. The app includes Google AdMob, but ads are currently not shown. If ads are enabled in the future, ad delivery is gated by a consent prompt (Google UMP), and on iOS by Apple’s App Tracking Transparency. If you decline, any ads shown are non-personalized.
03Camera, photos & receipts
The app asks for camera access when you scan a group’s invite QR code or scan a receipt, and photo access when you pick a QR image or a receipt from your gallery. QR frames are processed on your device and are never stored or uploaded.
Receipt scanning. When you scan a receipt to fill in an expense, the text is read on your device first using on-device recognition. Only when the amount can’t be read on the device is the receipt image sent to Google’s Gemini API to extract the total. Receipt images are used only to fill in the expense you are creating; they are not kept after processing and are not used for advertising.
Shared content. If you share a payment message or image from another app into Split Today, that shared text or image is used only to pre-fill the expense you are adding.
04Payments & UPI
Split Today does not move, hold, or process money. “Mark as settled” only records that a payment happened outside the app.
Pay-via-UPI opens your own UPI app with the details pre-filled; the actual payment happens inside that app and your bank, not inside Split Today. We store the UPI ID or reference you enter so a settle-up or payment request can be shown to the other person. We never see your bank credentials, UPI PIN, or transaction confirmation from your bank.
05Subscriptions & purchases
Premium is billed through Google Play or the Apple App Store and managed for us by RevenueCat. The store handles your payment; we only receive an anonymized entitlement (whether Premium is active) tied to your account ID. We do not receive or store your card number, billing address, or bank details.
06How we use your data
- To run the service: showing your groups, balances, activity, and personal tracker to you and — for group content — your group members.
- To unlock and enforce Premium features you have purchased.
- To send payment reminders about your own open balances, and promotional notifications only if you opted in.
- To understand which screens and features are used, via usage analytics, so we can improve the app.
- To keep the service secure and reliable — diagnosing crashes, preventing abuse, and enforcing rate limits.
- To comply with legal obligations where they apply.
We do not sell your data, and we do not use your expense content for advertising.
07Our legal bases
Where data-protection law requires a legal basis, we rely on: performance of a contract (running the app you asked to use), consent (promotional notifications and any future personalized ads — each of which you can give or withdraw), legitimate interests (keeping the service secure and reliable, and improving it through usage analytics outside the regions where analytics needs consent), and legal obligation where applicable.
08Who we share data with
- Your group. Group content is shared with the members of that group by design, and shown read-only to people who open the group’s invite link.
- Supabase — hosts our database and authentication.
- Google — Sign-In (authentication), Firebase (analytics and push messaging), the Gemini API (receipt fallback reading), and AdMob (ads, if ever enabled).
- PostHog — usage analytics, hosted in the European Union.
- RevenueCat and the app stores (Google Play, Apple) — subscription billing and entitlement.
These providers process data on our behalf under their own terms and security commitments. We do not sell personal data or share it with data brokers.
09International transfers
Our service providers may process data on servers outside your country, including in the United States and the European Union. Where required, such transfers are covered by the providers’ standard contractual safeguards.
10Retention & deletion
Your account data is kept while your account exists. You can delete your account inside the app at Account → Delete account (see how deletion works). Deletion removes your account, sign-in identity, and profile immediately. Expenses and settlements you recorded in shared groups are kept but anonymized — your name is detached so other members’ balances stay correct. Backups and logs are retained for a short period and then rotated out.
11Your rights & choices
Depending on where you live, you can:
- Access & correct your profile and content from inside the app.
- Delete your account and data yourself, at any time (how deletion works).
- Withdraw consent for promotional notifications from Account settings, without affecting the core app.
- Opt out of analytics or have your analytics records deleted, by emailing us.
- Object to or restrict certain processing, and request a copy of your data, by emailing us.
To exercise a right we can’t action in-app, email speeddevelop.dev@gmail.com from the address on your account. If you are unhappy with our response, you may complain to your local data-protection authority.
12Security
Data is encrypted in transit (HTTPS). Access to group data is enforced per-membership on the server, so you can only reach data for groups you belong to, and locally cached data on your device is stored encrypted. No system is perfectly secure, but we work to protect your data and to respond quickly if something goes wrong.
13Children
Split Today is not directed at children. You must be at least 18 (or the age of majority where you live) to use the app. If you believe a child has provided us data, contact us and we will delete it.
14This website
This website (splittoday.com) hosts our marketing pages and these legal documents. It does not set advertising or tracking cookies and does not build a profile of you. Our hosting provider may keep standard, short-lived server logs (such as IP address and request time) to deliver and secure the site.
15Changes & contact
We will update this page when the policy changes and adjust the effective and updated dates above; significant changes will be highlighted in the app. This policy is governed by the laws of India. Questions or requests: speeddevelop.dev@gmail.com.