Privacy Policy
Last updated 1 October 2026
OpenSplit is an expense splitter. It exists to answer one question — who owes whom — and it collects what it needs to answer that, and nothing else. There is no analytics SDK in the app, no advertising identifier, no crash reporting, no location access and no access to your contacts. We do not sell anything to anybody.
What we collect
Your account
- Email address, if you sign in with email or with Google.
- A Google account identifier, if you sign in with Google. We never receive your Google password.
- An anonymous account identifier if you continue as a guest. A guest account has no email or other recovery credential until you add one.
Your profile
- A display name — the one people in your groups see.
- A UPI ID, if you choose to add one, so people in your groups can open their own payment app to pay you. OpenSplit never handles, holds, moves or processes money, and is not a payment service.
Your groups and expenses
- Group names, and the names you type for people who do not have the app.
- Expenses: description, amount, currency, date, category, any notes you add, and who paid and who owes what.
- A record of changes to an expense — what was edited, by which member of the group, and when — so a group can see how a figure came to be what it is.
- Invite links you create: which group and member slot they are for, who created them, and who redeemed them.
Notifications
- A Firebase Cloud Messaging registration token and whether this device is Android or the web, and only if you turn notifications on. The messages we send carry identifiers, not amounts: your device fetches the detail and writes the notification text itself.
What stays on your device
OpenSplit is local-first. The complete record of your groups and expenses is stored on your device in a local database, and every balance, search and chart is computed there. The app is fully usable with no connection at all, and the server is never asked to compute anything.
Guest accounts use the same synchronization service as other accounts, so their groups and expenses are stored on the server and shared with group members. Until you attach an email address or Google account, the session on that device is the only way to return to the account. Losing it, reinstalling, clearing browser data, or not opening OpenSplit for a year (when the session lapses) can therefore leave the server data in place while you lose access to it.
If a guest signs in to an account that already exists, the two are treated as the same person: the guest's places in its groups, with everything paid and owed, move to that account, and the guest account is deleted. In a group that account was already in, the guest's place stays as a separate entry under the guest's name.
Who can see what
Access is enforced by the server, not by the app asking politely. Each group is a separate store with its own copy of its membership list, and a request for a group is answered by that store after it has checked its own list — so there is no query anybody can write that reaches a group they are not in.
- People who share a group with you can see your display name, your UPI ID if you set one, and the expenses in that group.
- Nobody can read a group they are not a member of.
- Somebody holding an invite link can see the group's name, the member slot the link is for, who sent it, and how many people are in it — before deciding whether to join. Nothing else.
Who we share it with
We do not sell your data and we do not share it for advertising. It is processed on our behalf by:
- Cloudflare — the server: storage, authentication, and hosting for the website and the web app.
- Resend — sending the sign-in code, if you sign in with an email address. They process the address and the message, nothing else.
-
Google Firebase
— Cloud Messaging, and only if you turn notifications on. Also Firebase Hosting, which only redirects the old
opensplit.web.appandopensplit-app.web.appaddresses here. - Google Sign-In — only if you choose to sign in that way.
We may also disclose data if the law genuinely requires it.
How long we keep it
- Your account and its data are kept until you delete them.
- A sign-in lasts a year from the last time you opened the app. After that you sign in again; a guest, having nothing to sign in with, cannot.
- A group with no activity for three months is archived. This changes nothing about it — it still opens, still adds up, and adding an expense brings it back — it simply moves out of your main list.
- An archived group in which every balance has been settled to zero, and which has had no activity for a year, is deleted. A group with money still outstanding is never deleted automatically, however old it is.
- When a group is deleted this way, it is also removed from every member's device the next time the app synchronizes, with all of its expenses and history. If you want to keep a record, export it as CSV or JSON from the group's screen before then.
- A guest account that never joined a group and was never used again is deleted after 90 days.
Deleting your account
You can delete your account from inside the app: Account → Delete account. There is no waiting period and no email to send.
What that removes: your account, your sign-in identities, your profile, your push registrations, and every group that nobody else has an account in — along with every expense in those groups.
What it deliberately does not remove: your side of a shared group. What you paid and what you owe stays, under your name. That record belongs to your co-members as much as to you — it is how their own balances add up — and erasing it would leave their figures wrong with nothing to explain it. The account behind the name is gone; nobody can sign in as you, and you no longer appear as a person with an account.
If you cannot reach the app, see Delete your account.
Security
Everything between the app and the server travels over HTTPS. Every request carries your session or it carries nothing — the app ships with no key, and there is no anonymous credential to leak. Each group's data is held in its own store, which checks its own membership list before answering, so being signed in is not the same as being able to read a group.
Children
OpenSplit is not directed at children under 13, and we do not knowingly collect data from them.
Your rights
You can see and edit your profile in the app at any time, export a group's full data as CSV or JSON from the group's own screen, and delete your account as described above. For anything else — including a copy of what we hold or a correction — write to hello@eigeninteractive.com.
Changes
If this policy changes materially we will update the date at the top and say so in the app before the change takes effect.