Privacy Policy

Splendo · last updated 7 August 2026

Splendo lets a group of people record shared expenses and see who owes whom. This policy describes exactly what the app stores, why, and who else sees it. It covers the iOS app and the service behind it.

What we collect

DataWhy
Display name So the people in your groups can tell who added an expense. Chosen by you; it does not have to be your legal name.
Email address (optional) Only if you sign in by email. It is used to send you a one-time sign-in code, and to recognise you when you sign in again. If you continue as a guest, or sign in with Apple using Hide My Email, we never hold your real address.
Profile picture (optional) Shown to the members of your groups. You can pick one of our built-in characters instead of uploading a photo.
Groups, expenses, settlements and comments The content of the app. Visible to the members of the group the entry belongs to, and to nobody else.
Receipt and expense photos (optional) Attached to an expense so the group can check it. See “Scanning a receipt” below.
A device identifier Sent on every sign-in, whichever way you sign in, so that a session can be tied to the device it was issued to — which is what lets us notice a stolen token being replayed somewhere else. It also lets a guest account survive being closed and reopened. It is Apple's per-vendor identifier, not an advertising identifier, and it is not shared with anyone.
Contacts' email addresses (optional) Only if you grant contacts access, and only to check which of them already have an account. See “Finding people you know” below.
How the app is used Counts and timings — which screens open, which steps finish, which failures people meet. See “How we count usage” below.

What we do not do

Finding people you know

If you tap “Find contacts on Splendo” and allow access, the app sends us the email addresses from your contacts — nothing else. Not names, not phone numbers, not anything else on the card. We compare them against the accounts we hold and answer, for each one, whether it has an account.

Nothing about a non-match is kept. No table is written, addresses are never logged at any level, and the answer carries back only the addresses you sent us. An address with no account leaves no trace of having been asked about.

The feature is an accelerator, never a requirement: everything on that screen works without it, and declining costs you nothing. Most address-book entries have no email saved, so this finds only a fraction of the people you know — the app says so on the screen rather than letting a thin result read as a small user base.

How we count usage

The app reports what people do with it, so we can see which parts work and which fail. These reports carry no account identifier — not your user id, not your email, nothing that joins a row back to you. They are grouped by a session, which is a fresh random value each time the app starts.

An event cannot contain free text, and that is a property of how it is built rather than a promise to remember: a group's name, an expense description, a merchant, a note and an amount are all impossible to put in one. What an event can carry is a count, a duration, a yes/no, and a word from a fixed list we wrote in advance.

The honest cost of that choice: because no row names an account, we cannot delete one person's usage records on request. There is nothing to find. We think rows nobody can attribute to a person are the better position, and we would rather say so than leave it out.

These reports are kept for 90 days and then removed.

What stays on your phone

So the app opens and works without a connection, some of what you have already seen is kept on the device itself:

WhatWhy
Your own name, photo and account id So the app can open while you are offline instead of asking you to sign in again. Your sign-in tokens are kept separately, in the iOS Keychain.
Expenses you enter with no connection Held on the phone until there is a signal, then sent. Until then they exist nowhere else — not on our servers, and not for anyone else in the group.
A copy of what you last loaded Your groups and their expenses, so those screens still work with no signal. It is a copy of what the app had already shown you.

None of this is sent anywhere; it is on your phone. It is removed when you sign out, and it goes with the app if you delete it.

Scanning a receipt

If you photograph a receipt, that image is sent to Anthropic, which reads the amount, the merchant and the date and sends them back. The result is filled into the form as a draft for you to check — nothing is saved until you confirm it.

The image is sent for that one request and is not used to train models. If you never use the scan button, no image ever leaves your device for this purpose.

Who else processes your data

Each of these acts on our instructions and for no other purpose.

How long we keep it

Your account and its content are kept until you delete them. Sign-in codes expire within minutes.

Deleting your account

In the app: Profile → Settings → Delete Account. This removes your account and your personal details.

One thing it cannot remove: expenses you added to a group stay in that group's history, because they are part of other people's balances. An expense you paid for is also a record of what everyone else owes, and erasing it would silently change what they owe. Your name is removed from those entries.

Children

Splendo is not directed at children under 13, and we do not knowingly collect their data.

Changes

If this policy changes, the date at the top changes with it.

Contact

Questions, or a request to see or delete your data: info@splendo.app.