Privacy policy

Splitly is built so that using it requires giving up as little as possible. Most of the product works with no account at all. This page explains exactly what is stored, why, and who else ever sees it.

The short version

  • Using a group needs no account, no email and no phone number.
  • A group stores the names people type and the amounts they enter. Nothing else.
  • Anonymous usage statistics are collected, with group links and expense details stripped out before anything is sent.
  • Anyone holding a group's invite link can read that group. That is the trade-off for having no accounts, and it means a group is not the place for anything sensitive.
  • An account is needed only for the personal ledger, the Ria assistant and expense sheets.
  • Nothing is sold. There is no data broker, no profile built about you, and no tracking of you across other websites.

Using Splitly without an account

When you first open Splitly, your browser generates a random identifier and keeps it in local storage on your device. It is sent with each request so the server knows which member of a group you are. It is not derived from anything about you or your device — it is a random value, and clearing your browser storage discards it permanently.

That identifier is the whole of the no-signup model. It is why a group remembers you between visits without ever being told who you are.

What a group stores

A group holds its name, the display names of its members, and the expenses entered into it: an amount, a description, a date, who paid and who it was split between. Optional notes are stored if you write them. Balances are not stored at all — they are recalculated from the expenses each time they are shown.

Deleting an expense keeps a hidden record of it so the group's history remains auditable and a deletion can be explained. It stops affecting any balance immediately.

Invite links are the credential

A group's link contains a code, and possession of that code grants access to the group. It is treated accordingly: those pages are excluded from search engines, the code is kept out of page metadata, out of referrer headers and out of anything sent to a third party, and no link preview is generated for them.

The consequence for you is simple. Share a group link only with the people who should see the group, in the same way you would treat a shared document link.

Accounts, and the three things that need one

An account stores your email address, a display name, and either a password hash or the fact that you signed in with Google. Passwords are never stored in a readable form.

Accounts exist for the personal ledger (money you lent, borrowed or spent alone), the Ria assistant, and expense sheets shared by email address. Groups never require one, and signing in does not change how a group works.

The Ria assistant

Ria is optional and acts only when you ask her something. Typing an expense by hand, or using the microphone in the expense form, sends nothing to any AI provider.

When you do send Ria a message, that message and a summary of the figures needed to answer it are sent to an external AI provider to generate the reply. Your conversation is kept so it survives reloading the page — the most recent exchanges only, and they are deleted automatically after a period. You can clear the whole conversation at any time from the panel itself.

Voice input is separate and worth stating plainly: speech recognition is your browser's own feature, and in most browsers it works by sending the audio to the browser vendor's servers. That happens under your browser's privacy policy, not Splitly's, and it is why the microphone is never the only way to enter anything.

Notifications

If you turn on notifications, your browser issues a token that identifies that browser to the messaging service, and Splitly stores it so it can send you a notification. It identifies the browser, not you. Turning notifications off, or clearing site data, invalidates it.

Advertising

Splitly shows ads on some public pages to pay for running it. These are served by Google AdSense, which sets its own cookies and receives the address of the page the ad appeared on. Splitly never passes your expenses, balances, group names or invite codes into an ad request.

If you are in a region requiring consent for personalised advertising, you should see a consent prompt before any personalised ad is served, and declining leaves you with non-personalised ads rather than none.

Usage analytics

Splitly records anonymous usage statistics through Google Analytics so it is possible to tell which parts of the product people actually use — how often an expense is added, whether voice entry works, whether a page loads fast enough.

What is recorded is the shape of an action, never its content. An expense being created records how many people it was split between and which split rule was used; it does not record the amount, the description, the notes, or anyone's name. Voice entry records that speech happened and how many words were heard, never what was said.

Page addresses are stripped before they are sent. A group's web address contains its invite code, so the code is removed and the page is recorded only as "a group page" — and the same is done for join links, shared sheets, and the parts of a link that carry an amount or a description. Nothing that could identify your group or reconstruct an expense leaves in an analytics event.

No identifier that follows you is attached to these events, and the statistics are not used to build a profile of you or to target advertising.

Who else receives data

  • The hosting and database providers that run the service.
  • Google, for sign-in if you choose it, for notification delivery, for advertising, and for the anonymous usage statistics described above.
  • The AI provider behind Ria, and only for messages you send her.
  • Nobody else. Your data is not sold, rented, or shared for anyone else's marketing.

How long things are kept

Groups and their expenses are kept while the group exists, because a shared ledger that forgets is not a ledger. Assistant conversations expire automatically. Account data is kept while the account exists.

You can delete a group you created, and you can clear your Ria conversation. To have an account and its ledger deleted, write to the address below.

Your rights

Depending on where you live you may have the right to ask what is held about you, to have it corrected, to have it deleted, or to receive a copy. Requests can be sent to [CONTACT EMAIL] and will be answered within the period the applicable law requires.

Because groups need no account, a request about a group needs to identify it — the invite link is usually the only way to do that.

Children

Splitly is not directed at children and should not be used by anyone under the age at which consent for online services is required where they live.

Changes, and who to contact

If this policy changes materially, the change will be published here before it takes effect. Splitly is operated by [COMPANY / OPERATOR NAME], and questions about privacy can be sent to [CONTACT EMAIL].

Frequently asked questions

Do I have to give an email address to split expenses?
No. Creating a group, adding expenses, splitting them and settling up all work with no account and no email address. An account is only needed for the personal ledger, the Ria assistant and expense sheets.
Can anyone with the link see my group?
Yes, and that is deliberate — the link is what replaces a signup. Treat a group link like a shared document link, and do not use a group for anything you would not want a link-holder to read.
Does Splitly sell my data?
No. There is no sale or sharing of your data for anyone else's marketing. The service is paid for by ads on public pages, which never receive your expenses or balances.
What happens if I clear my browser data?
The random device identifier is discarded, so Splitly stops recognising you as a returning member. The groups themselves are unaffected — reopening the invite link gets you back in.