Privacy Policy
This policy applies to the Chitipay app and the Chitipay website (including the web-based splitting tool). We try to collect as little data as possible and be clear about what it's used for.
Last updated: September 23, 2026
1. What is Chitipay
Chitipay is an offline-first group expense-splitting app. Core data (groups, members, expenses, balances, settlement plans) is stored in a SQLite database right on your device. The app works fully without a network connection.
2. Data we collect (app)
- Display name (optional, entered by you) — shown within your expense groups.
- Email address or Google account (only when you enable backup or link an account) — used to sign in (emailed code or Google) for cloud backup and restoring your data on another device.
- Group/expense/settlement data you create — this is the app's core feature; it's synced to the cloud when you enable backup.
- Receiving-account details (bank code/name, account number, account holder name, QR payload) you enter — used to show a QR code or account number so members can transfer money to you; synced to the cloud when you enable backup. While direct or collection payment routing is active, active members of the same group may read the receiving account used by another active member; non-members cannot read it. When a settlement plan is activated, the snapshot of the receiving details for each transaction is readable only by the two parties of that transaction (payer and payee).
- Expense category suggestion. When you are signed in and type a title for an expense, that title may be sent out to pre-fill a category (food, transport, shopping...). It is only sent when you leave the title field, when the title is at least 3 characters long, and when you have not picked a category yourself. Only the title leaves your device: no amount, group name, member name, photo or audio. You can always change the category back with one tap. Nothing is sent if you are not signed in.
- Photos you attach yourself — receipt photos on an expense, plus avatars and group cover images. With backup on, each photo is downscaled on your device and uploaded to a private Supabase Storage bucket (never public); every view goes through a signed, expiring link issued only to someone already allowed to read the matching data.
Chitipay v1 does not collect: location, contacts, your photo library (beyond the specific photos you attach yourself, above), voice recordings, advertising data, or in-app behavioural analytics (the only in-app measurements are the crash and performance diagnostics and the anonymous category-suggestion quality record, both described in section 4), and there is no advertising.
3. Storage and sync
- The primary data source is on-device SQLite. The app works fully offline from first launch without an account; a fresh install creates no account of any kind (not even an anonymous one) until you choose to enable backup.
- An account (email or Google) is created only when you opt into "protect your data" to enable backup/restore. Group data is then backed up/synced via Supabase (Postgres, hosted on Supabase's infrastructure). Data access is restricted with Row Level Security: only group members can read a group's data.
- Sign-in identities are managed by Supabase Auth. If you choose Google sign-in, Google provides an ID token for that authentication flow. We do not sell your email or sign-in identity.
4. Data sharing
Group data is visible to other members of the same group (display name, expenses, balances, settlement status). While direct or collection payment routing is active, receiving-account details are readable by active members of that same group. When a settlement plan is activated, the receiving details snapshot for each transaction is readable only by its payer and payee.
Automatic category suggestion. The expense title is relayed through a Supabase Edge Function to the Vercel AI Gateway, and from there to the classification provider TypeSafe. To measure suggestion quality, our server records only the length of the title and whether it carries diacritics, together with the suggested category, how confident it was and whether you kept it: the title itself is not stored, and that measurement record carries no identity. The request travels with your signed-in session so the server can apply a per-account hourly limit; that counter keeps your account ID for up to two days. The other AI features — AI expense entry, receipt scanning, voice input and AI reminders — are not enabled in the v1 store build; receipt photos are sent to no AI provider and the app makes no audio recordings.
Crash reporting. The app sends error reports and a small sample of performance data to Sentry so we can fix crashes and slowdowns. A report contains the error type and message, its stack trace, the app version, the device model and operating system version, and a trail of recent app events such as taps, network requests and log messages. Sentry's option to attach personally identifying information is turned off, and we do not deliberately add your group, expense or receiving-account content to reports; an error message or a recent log line can occasionally contain text you entered.
We do not sell your data. We share data with the named service providers below when their service is enabled, and with other members of a group where the app shows group data. Push notifications are optional and can be disabled on your device.
Service providers. For transparency, these are the parties that process data in the roles described in this policy: storage, authentication and cloud sync — Supabase; Google ID-token authentication — Google, only when you choose Google sign-in; delivery of the emailed sign-in code — Resend, which receives your email address and the code; crash reporting — Sentry; gateway and expense-category classification — Vercel AI Gateway and TypeSafe; push delivery — Expo Push Service, which hands notifications to Apple Push Notification service or Firebase Cloud Messaging and receives a device push token and the notification title/body, which may include a group name, member name, expense title or amount when detailed notifications are enabled; website performance and cookieless analytics — Vercel and PostHog. This list is updated whenever it changes.
5. Website analytics
The Chitipay website uses PostHog in cookieless mode: no personal profiling, no advertising cookies, and no session replay. We also use Vercel Speed Insights to measure page performance. Since no tracking or advertising cookies are set, the website doesn't need a cookie-consent banner.
6. Beta signup email
If you sign up for beta updates, your email is stored in a separate Supabase project and used only to notify you about the beta program. You can request deletion of this email at any time.
7. Web calculator data
When you use the web splitting tool, the member list and expenses live only in your browser (localStorage) and are never sent to any server. Clearing your browser data or clicking "Reset" deletes all of this data.
8. Deleting your account and data
In the app, you can delete your own account under Profile → Delete account:
- Solo groups: permanently deleted from the cloud.
- Shared groups: ownership transfers to another member; expense history is kept for the remaining members, and your display name is kept but no longer tied to any account.
- Your sign-in account (email) is removed from the authentication system.
- All on-device data is deleted.
If you never linked an account (offline-only on this device), the "Delete on-device data" option clears all local data with equivalent effect. To request deletion of your beta signup email or any other data, email realdoan.dev@gmail.com.
9. Contact
For any privacy questions, contact realdoan.dev@gmail.com.
The app-policy section is synced from the app's documentation — keep it in sync.