Privacy policy
Last updated 29 September 2026
SplitBase helps a group of people record shared expenses and work out who owes whom. This policy describes exactly what the app stores, why, and what you can do about it. It describes the app as built — every item below corresponds to a field the app actually writes.
The short version
- SplitBase never touches your money. It records what people tell it and does the arithmetic. There is no payment processing and no bank connection.
- The app shows ads from Google AdMob. They are non-personalised — never chosen from a profile of you — and nothing you enter in SplitBase is ever given to Google or anyone else for advertising. There is no analytics, and nothing is sold.
- What you enter is visible to the members of the groups you are in, and to nobody else.
What is stored
- Your account
- Your name, email address and profile photo, provided by the sign-in you chose, plus your preferred currency. Authentication itself is handled by Clerk; SplitBase keeps a copy of these fields so group screens can show who is who.
- Your groups
- The group's name, emoji, currency, who is a member, and an invite code. Also join requests, including who asked and who approved.
- Expenses
- A description, amount, date, category, who paid, how it was split, and each person’s share. Optionally a receipt image, which is stored as a file and visible to that group.
- Settlements and advances
- Amount, who paid whom, when, an optional note, and whether the recipient has confirmed it.
- Shared pots
- The pot's name, who holds it, contributions and what has been spent from it.
- One-to-one ledgers
- You can split an expense with a person instead of a group. That opens a private ledger between the people involved, holding the same kinds of records as a group: expenses, shares, settlements and activity. It is visible only to the people on it.
- Personal expenses
- Spending you record for yourself alone. It is kept in a ledger that holds only you, is visible only to you, and never affects what anyone owes.
- Notification addresses
- If you allow notifications, the app registers an anonymous token that identifies this installation to Apple’s and Google’s notification services, and stores it so the people in your groups can reach you. It says nothing about you or your device beyond how to deliver a message to it. Signing out removes it, and so does deleting your account.
- Comments and activity
- Comments you write on an expense, and a log of group actions (an expense added, a member joined, a payment confirmed) so the group can see what changed and when.
What stays on your device
- A copy of what you last saw
- Balances and lists are cached on the device so a cold start or a phone with no signal can show something rather than an empty screen. The cache lives only on your device, is kept separately for each account, and is erased when you sign out.
- Spreadsheets you export
- Exporting writes an .xlsx file into a SplitBase folder in your device’s Downloads. The file contains the expenses, balances and settlements it names, and stays on your device until you delete it. If you choose to share it, it goes wherever you send it — that copy is outside SplitBase and outside this policy.
- Your export count
- On Android, how many spreadsheets you have exported this month, so the app knows when the free allowance described under “Advertising” is used up. It is a month and a number, and nothing else.
- Export messages
- The “export saved” message telling you where a file went is composed and shown by the app itself. It never leaves the device, and it appears whether or not you have allowed the notifications described below.
What is not stored
- No bank details, card numbers, or account credentials.
- No location, contacts, calendar, or device identifiers.
- No advertising or analytics identifiers. The app contains no analytics SDK. The advertising SDK described below is Google’s, and what it collects goes to Google, not to SplitBase.
- No password. Sign-in is handled by Clerk; SplitBase never sees a password.
Advertising
SplitBase shows banner ads from Google AdMob on Home, Groups, Activity and Insights. Never on the screens where you enter an expense, settle up, or manage your account. On Android, exporting a spreadsheet is free a few times a month, and past that you can choose to watch an ad to export again. If no ad is available, the export goes ahead anyway. On iPhone, exporting is always free.
The ads are non-personalised. Google chooses them from the app they appear in and your approximate location, worked out from your IP address. They are not chosen from a profile built from your activity in other apps or on the web. Your SplitBase data is never shared for advertising: that includes names, email addresses, groups, expenses and amounts.
Delivering any ad still involves Google’s software on your device. To show ads, limit how often you see the same one, count them and detect fraud, it collects information about the device and how ads on it are used. That means your IP address, the device model and operating system, ad views and taps, and the device’s advertising identifier. Google handles this under its own privacy policy: https://policies.google.com/technologies/partner-sites
In the European Economic Area, the UK and Switzerland, the app asks for your choice through Google’s consent form before any ad is requested. You can change that choice at any time from Profile → Ad privacy choices. On any phone, you can reset or delete the advertising identifier in the device’s own settings.
Notifications
When someone adds an expense, settles up or comments, everyone else on that group or ledger is notified. The message carries the same words the activity feed shows — the group, who acted, what they did and the amount — because a notification that withholds them says nothing worth reading.
Delivering it means handing that text to Expo, and then to Apple or Google, who pass it to your phone. Those services see the message in transit. This is how notifications work on every app on your phone, but it does mean the one thing on the device that group members can put in front of you is also the one thing a third party carries — so it is worth knowing before you switch them on.
Notifications are optional in three places, any of which is enough: declining the permission your phone asks for, the Notifications switch in Profile, and your device’s own settings for the app. Turning them off changes nothing else — the same events still appear in the app.
Who can see it
Anything you add to a group is visible to the members of that group, and anything on a one-to-one ledger is visible to the people on that ledger. That is the point of a shared ledger: the people splitting a bill can all see the bill.
An invite code on its own grants nothing. Someone entering a code creates a request that an existing member must approve before they can see anything. When a member is removed, the group’s invite code is rotated so the old one stops working.
A one-to-one ledger can only be opened with someone you already share a group with, and it has no invite code of its own. There is no way to start one with a stranger.
Nobody outside your groups can see your data. It is not sold, rented, or shared for advertising, and there is no third-party analytics SDK in the app. The one advertising SDK, Google’s, never receives any of it.
Who processes it
| Service | Role | What it handles |
|---|---|---|
| Clerk | Authentication | Your sign-in identity, email, name and profile photo |
| Convex | Database and file storage | Everything listed under "What is stored" |
| Expo | Notification delivery | The text of a notification, and the address it is sent to — only if you allow notifications |
| Apple, Google | Notification delivery | The same message, on its last step to your phone |
| Google AdMob | Advertising | The device and ad information described under “Advertising” — never your SplitBase data |
Clerk, Convex and Expo are processors acting on our instructions. Google handles advertising data under its own privacy policy. Data may be stored on any of these services’ infrastructure outside your country.
Deleting your account
Profile → Delete account. This removes your name, email address, profile photo and your ability to sign in. It cannot be undone.
Your personal expenses are deleted outright, receipts included, since they are nobody else’s record. Your entries in a group or one-to-one ledger remain, attributed to "Former member". This is deliberate and worth understanding before you delete: every expense you added or were part of is simultaneously a record belonging to the other members of that group. Removing those rows would change what your former groups believe everyone is owed. Rather than silently rewriting other people’s balances, SplitBase keeps the amounts and removes you from them.
Before you confirm, the app shows any group where you still owe money or are owed money. Settling first is kinder to the people you shared with, but it is not required and will not block deletion.
Changes
If this policy changes materially, the app will say so before the change takes effect.
Contact
Questions about this policy, or a request about your data: manojkumarsahu97@gmail.com