Chitipay
Legal

Privacy Policy

This policy applies to the Chitipay app and the Chitipay website (including the web-based splitting tool). We try to collect as little data as possible and be clear about what it's used for.

1. What is Chitipay

Chitipay is an offline-first group expense-splitting app. Core data (groups, members, expenses, balances, settlement plans) is stored in a SQLite database right on your device. The app works fully without a network connection.

2. Data we collect (app)

  • Display name (optional, entered by you) — shown within your expense groups.
  • Email address or Google account (only when you enable backup or link an account) — used to sign in (emailed code or Google) for cloud backup and restoring your data on another device.
  • Group/expense/settlement data you create — this is the app's core feature; it's synced to the cloud when you enable backup.
  • Receiving-account details (bank name, account number, QR code) you enter — stored only on your device (not synced to the cloud in v1) and shown locally when you share the QR code or account number with group members.
  • Content you actively submit to AI features (expense description text, receipt photos, voice recordings, reminder context including names and amounts) — used to generate expense/reminder drafts; processed by Google Gemini (see "Data sharing").

Chitipay v1 does not collect: location, contacts, photos (other than a group avatar you choose yourself, stored on-device, and receipt photos/voice recordings you actively submit when using AI features), advertising data, or in-app behavioral analytics, and there is no advertising.

3. Storage and sync

  • The primary data source is on-device SQLite. The app works fully offline from first launch <b>without an account</b>; a fresh install creates no account of any kind (not even an anonymous one) until you choose to enable backup.
  • An account (email or Google) is created only when you opt into "protect your data" to enable backup/restore. Group data is then backed up/synced via Supabase (Postgres, hosted on Supabase's infrastructure). Data access is restricted with Row Level Security: only group members can read a group's data.
  • Sign-in identities are managed by Supabase Auth. We don't sell or share your email or sign-in identity with third parties.

4. Data sharing

Group data is visible to other members of the same group (display name, expenses, balances, settlement status, receiving-account details you've added to the group).

AI features (Google Gemini). When you actively use an AI feature (text to expense, receipt scan, voice to expense, debt-reminder drafting), the content you submit — description text, receipt photo, voice recording, or reminder context (debtor/creditor names and amount, possibly including group member names for payer matching) — is sent to Google Gemini for processing. We use Gemini's paid tier only: under Google's terms this data is not used to train models. Our servers do not store the photo, the recording, or Gemini's raw response — only the validated result draft for up to 30 days (to serve retries) plus usage audit metadata.

Beyond Supabase as our infrastructure provider and Google Gemini (for the AI features above, only when you actively use them), we don't share data with any other third party in v1.

5. Website analytics

The Chitipay website uses PostHog in cookieless mode: no personal profiling, no advertising cookies, and no session replay. We also use Vercel Speed Insights to measure page performance. Since no tracking or advertising cookies are set, the website doesn't need a cookie-consent banner.

6. Beta signup email

If you sign up for beta updates, your email is stored in a separate Supabase project and used only to notify you about the beta program. You can request deletion of this email at any time.

7. Web calculator data

When you use the web splitting tool, the member list and expenses live only in your browser (localStorage) and are never sent to any server. Clearing your browser data or clicking "Reset" deletes all of this data.

8. Deleting your account and data

In the app, you can delete your own account under Profile → Delete account:

  • Solo groups: permanently deleted from the cloud.
  • Shared groups: ownership transfers to another member; expense history is kept for the remaining members, and your display name is kept but no longer tied to any account.
  • Your sign-in account (email) is removed from the authentication system.
  • All on-device data is deleted.

If you never linked an account (offline-only on this device), the "Delete on-device data" option clears all local data with equivalent effect. To request deletion of your beta signup email or any other data, email realdoan.dev@gmail.com.

9. Contact

For any privacy questions, contact realdoan.dev@gmail.com.

The app-policy section is synced from the app's documentation — keep it in sync.