1. Executive Summary
SplitSmart is built on a single principle: your financial data belongs to you, and only you. We do not have servers, we do not have user accounts, and we do not sell information. All your groups, expenses, receipts, and settlements are stored exclusively in a local database on your device. What happens on your phone, stays on your phone unless you deliberately choose to share it.
2. Data You Store in SplitSmart
All records you enter are stored directly in a local database on your device. This includes:
- Your "Me" profile: the name, phone number, and optional photo you set up for yourself.
- Group members: names, phone numbers, and optional photos for people you add, either typed manually or imported from your device contacts.
- Expenses and receipts: titles, amounts, line items, receipt photos, and how you split them.
- Settlements: records of who paid whom and when, carrying a tamper-evident signature.
We cannot access, read, edit, or delete any of this data. It never leaves your phone unless you export a backup or deliberately send a reminder or settlement message.
3. On-Device Receipt Scanning (OCR)
SplitSmart's receipt scanner is built on Google's ML Kit and runs entirely on your device. It needs a one-time internet connection, via Google Play Services, to download its text-recognition model the first time you scan a receipt. Outside of that one-time download, SplitSmart makes no network requests of its own -- no analytics, no sync, no telemetry.
4. When Data Leaves Your Device
SplitSmart has no server to send data to, so the only ways information ever leaves your device are actions you take yourself:
- WhatsApp: tapping "WhatsApp" on a reminder or settlement opens a pre-filled link in the WhatsApp app, containing the recipient's phone number and your message. That handoff is the only time a phone number leaves SplitSmart, and it only happens when you tap that button. From there, WhatsApp's own privacy policy applies.
- Share sheet: tapping "Share" hands the same kind of message to your phone's native share menu, so you can send it through whichever app you choose.
- Contact Developer: an entirely optional, user-initiated email (see Section 6).
5. Device Permissions
To deliver its core features, the app may request specific system permissions:
- Contacts (optional): used only to let you pick a name and phone number when adding a group member. Read locally, never transmitted.
- Camera / Photos: used for scanning receipts and for optionally picking a profile photo. Images are processed on your device.
- Notifications and exact alarms: used only to schedule the optional local reminders (Settlement Reminder, Expense Nudge) you turn on in Settings. Generated entirely on-device; nothing is pushed from a server.
- Biometric: used only for the optional app lock. Your fingerprint or face data is handled entirely by your phone's operating system -- SplitSmart never sees or stores it.
6. Contact Developer Feature
Settings includes an optional "Contact Developer" form. It only sends data when you explicitly tap Send Email, and only the technical details you individually check a box for (e.g. app version, Android SDK level, local performance metrics). It never includes your expenses, contacts, phone numbers, or financial data.
7. Third-Party Services
SplitSmart contains no third-party advertisements, no advertising-network SDKs, and no analytics software. The only third parties it ever talks to are WhatsApp (Section 4, only when you tap it) and Google ML Kit / Play Services (Section 3, for on-device OCR only). Your usage remains anonymous to us.
8. Security
- Backup encryption: if you choose to create a backup, it is encrypted using a key derived from your specific device, so a backup file is unreadable without your phone.
- Biometric lock: you can optionally lock the app with your fingerprint or face ID.
- Tamper-evident settlements: recorded settlements carry a cryptographic signature so they cannot be silently altered after the fact.
9. Children
SplitSmart is not directed at children and we do not knowingly collect information from anyone under 13.
10. Changes and Contact
If this policy changes, the updated version will be posted at this URL with a revised effective date. For privacy questions, feedback, or concerns, email us at supportanubis@gmail.com.