Privacy policy
Effective: [[ OWNER: effective date ]]
1. Who is responsible
The controller of personal data in tabtada is: [[ OWNER: name of the person or company acting as controller ]], [[ OWNER: address ]], [[ OWNER: legal form and registration number, if any ]].
Contact for privacy questions and the requests in section 11: [email protected].
2. What we collect
- Your account. Email address, display name, password (we keep only an Argon2 hash of it, never the password itself), your chosen language, when you registered and whether your address is confirmed. While you change your address we also hold the new one until it is confirmed.
- Sessions. A hash of a random session code, your account id, and when the session started and expires. A session lasts a fixed 30 days from sign-in and is never extended.
- Group data. Group names, members' display names, expenses (amount, currency, date, category, who paid, who owes what, who recorded it), payments that settle up, and the descriptions members type.
- People added by others. A group member can add a person by name alone, or by name and email address (see section 5).
- The email send log. To limit abuse we record that a mail was sent: a keyed digest of the recipient's address (not the address), the sender's account id, the group id and the time.
- The objection list. A keyed digest of the address of everyone who objected to our emails, so that we do not write to them again.
- Technical logs. Our logs carry request ids and outcomes and, by design, no names, email addresses or passwords. A client's IP address is held only in the process's memory to count request limits and is lost on restart. Our hosting provider (Fly.io) may keep its own network logs, including IP addresses, under its own retention rules.
We use no analytics, no advertising and no tracking tools, and we load nothing from third-party sites, so there is no cookie consent banner: we set only essential cookies (section 9). If we ever add analytics we will ask for consent and update this text first.
3. Why, and on what legal basis
- Your account and sessions
- Performing our contract with you to provide the service (GDPR art. 6(1)(b)). Kept until you delete the account, then up to 30 days in backups.
- Account emails (address confirmation, password reset, address change, confirmation of account deletion and of a data download)
- Performing the contract (art. 6(1)(b)). The links in them expire: address confirmation after 3 days, password reset after 1 hour, address change after 1 day, the link that reverts a change after 7 days.
- The ledger between members after one member's account is deleted
- The other members' legitimate interest in an accurate record of who owes whom (art. 6(1)(f)), and for the balances the establishment and defence of claims between members (art. 17(3)(e)). It is kept for the life of the group, but once the account is deleted it is pseudonymous: ids, amounts and dates remain, not your name, email or password.
- The name and email of a person added by a group member
- The group's legitimate interest in recording who shares a cost and in inviting that person (art. 6(1)(f)). The data is minimal, the address is never shown to other members, the person is told at first contact and can object with one click. The address is deleted when the person claims their place, or objects, or 90 days after the last invitation, or 30 days after it was added if no invitation could be sent. The name stays while the member exists, as the group's label for them.
- Shared content (group names, expense descriptions)
- The members' legitimate interest in their shared record (art. 6(1)(f)). Kept for the life of the group; descriptions you typed can be erased with your account (section 6).
- Invitations sent by members
- The legitimate interest of the group and of the member who invites (art. 6(1)(f)).
- The email send log
- Our legitimate interest in preventing abuse and mail flooding (art. 6(1)(f)). Rows older than 24 hours are removed when the next mail is sent, so during a quiet spell a row can sit a little longer. When an account is deleted we delete the rows it sent and those about its address. When the address of a person added by a member is deleted, the rows of the invitations sent to it are not deleted with it: they go after 24 hours, like every other row.
- The objection list
- A legal obligation to honour an objection (art. 6(1)(c) with art. 21(3)). Kept indefinitely, because that is what keeps the objection honoured. It is a digest, not the address.
- Backups
- Security of processing (art. 32), on the basis of art. 6(1)(f). See section 8.
- Essential cookies
- Needed to provide the service you asked for, so no consent is required (art. 5(3) of Directive 2002/58/EC).
4. Who receives your data (processors)
These companies process data on our behalf under data processing agreements (art. 28 GDPR) that include standard contractual clauses where the company is outside the EU. Fly.io, Neon, Cloudflare are US companies, but the processing takes place in the EU.
- Fly.io: application hosting, Frankfurt region (
fra), including the machines that make backups. - Neon: the PostgreSQL database, Frankfurt.
- Cloudflare R2: encrypted backups, in the EU jurisdiction (
eu). - Scaleway (Scaleway SAS, France): sending email through its Transactional Email service in Paris. It receives the recipient's address, the subject and the body (including links that carry single-use codes) and keeps sending logs. According to the provider the service runs entirely in the EU with no non-EU sub-processors, so the data does not leave the EEA. Scaleway's retention of its logs: [[ OWNER: Scaleway's log retention period, from its DPA ]].
Backups never leave the EU. Our uptime monitor receives only "alive" pings and no personal data. We do not sell data and do not pass it to anyone but the processors above, unless the law requires it.
5. If someone added you to a group
A group member may have added you by typing your name and, optionally, your email address. If they gave an address we sent you an invitation: that is our notice under GDPR art. 14. It says who added you and to which group, what we keep and why, where this document is, and how to object with one click.
- What data: your name (the group's label for you) and your email address if one was given. Source: the person who added you.
- Purpose and basis: to invite you and let you take your place in the group; the group's legitimate interest (art. 6(1)(f)).
- How long: as in section 3. An objection deletes the address from every group that holds it, adds its digest to the objection list and stops any further mail to it. The group keeps only the name it gave you.
- A person added by name alone has no contact data with us, so we cannot notify them (art. 14(5)(b)). That name is a label the group uses. Names imported from a file are treated the same way.
6. Shared content, and what deleting an account does
Group names and expense descriptions are kept in a separate content table, never in the event journal, and belong to the group.
- When you delete your account we delete your email address, display name, password, sessions and email send-log rows. Nobody can sign in to that account again.
- Your place in every group stays, shown to the other members as a "Deleted user", and balances and expenses do not change, so that what members owe each other still adds up.
- The descriptions you typed are erased by default along with the account: the box "Also erase the descriptions I typed" is ticked (privacy by default). The expenses stay, shown as "Description removed". Untick the box if you want the group's history to stay readable.
- Group names stay: they belong to the group. Descriptions imported from a file belong to the group and are erased with it or on request.
- The objection list stays, because it records an objection.
- Deletion happens at once; if something fails it is finished the next time the service starts. We send a confirmation to your address.
- Deleting the account also clears the device you delete it on: the saved pages, your expenses and payments still waiting to be sent, and the codes remembered for your account (section 9). Other devices you were signed in on keep their saved pages until someone signs out there or another account signs in, for 30 days at most: sign out on them first if you can.
7. Your data as a file (export)
On your account page you can download a ZIP file: your account data, every group you were in, the expenses and payments you took part in or recorded, the text you typed and the people you added, your sessions (when each started and when it expires) and the emails sent on your behalf (when, for which group, and the recipient as the keyed digest we store, not the address), plus one CSV per group in Splitwise's layout. The export includes the display names of other members and every live entry of the groups you belong to, because you can already see them in the app (GDPR art. 15(4)), but never another person's email address. We email you when a copy is downloaded.
8. How long we keep data
- Account: until deletion, then up to 30 days in backups.
- A person added by a member: email address as in section 3 (90 days after the last invitation if they have not taken their place).
- Email send log: 24 hours (see section 3). Objection list: indefinitely.
- Sessions: 30 days from sign-in, or until you sign out. An expired session's record is deleted the next time anyone signs in.
- What is kept on your device: see section 9.
- Backups: the database provider keeps point-in-time recovery for the short window of our plan (at most a few days), and we keep daily encrypted logical backups for 30 days in the EU. After a restore we re-apply the recorded deletions, so a deleted account does not come back.
9. Cookies
We use four cookies, all first-party and essential. The language comes from your account setting, from a choice remembered in tt_lang, or from your browser's language header.
tt_session(over HTTPS__Host-tt_session)- Keeps you signed in. Set when you sign in; HttpOnly, Secure, SameSite=Lax; lasts 30 days, removed when you sign out.
tt_csrf(over HTTPS__Host-tt_csrf)- Protects forms against forged requests. Holds a random code; Secure, SameSite=Lax; a session cookie that disappears when the browser closes.
tt_theme- Remembers the theme (light or dark) only if you choose one. Holds no personal data; Secure, SameSite=Lax; lasts one year. Choosing "system" removes it.
tt_lang- Remembers the language (
enorpl) only if you choose one with the language switch. Holds no personal data; Secure, SameSite=Lax; lasts one year.
On your device, besides cookies. So that the app works on a poor connection, your browser keeps on your phone or computer (in this site's own storage, which other sites cannot read):
- Saved pages
- Copies of up to 50 pages you opened recently (the dashboard, group pages with their expenses, balances and member names), to show them without a connection. Each copy is kept at most 30 days; all are removed when you sign out, and when another account signs in on the device.
- Writes waiting to be sent
- An expense or payment you saved without a connection, with what you typed (description, amount, currency, the people), until it is sent; at most 30 days. They are not removed when you sign out, so they can still be sent after your next sign-in, and they are sent and shown only for the account that saved them. Deleting your account on this device removes yours.
- Refused writes
- When the server refuses a waiting write, the device keeps a notice of it with what you typed (description, amount, currency, the form's fields), to show it to you and let you fix the form ("Fix it"). It is removed once you see it on your account, and when you sign out or delete your account on this device.
- Preferences
- A small store: the page language, the current form security code and the ids of the accounts it was issued to (the last 8 sign-ins on the device), so that a waiting write only ever goes to the account that made it. Deleting an account on this device removes its ids and codes.
- App files
- The app's scripts, styles and icons and the "You are offline" page, with no personal data; replaced with each new version.
On iPhone and iPad, Safari may delete all of this if you do not open the app for 7 days, unless you added it to the Home Screen; a waiting write is then lost. iOS sends nothing in the background: waiting writes are sent when you open the app.
10. Age
You must be at least [[ OWNER: confirm the minimum age, e.g. 16 ]] years old to use the service. The sign-up form does not check age.
11. Your rights and how to use them
You have the right of access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interests, and to complain to a supervisory authority (in Poland: the President of the Personal Data Protection Office, uodo.gov.pl).
- Access and portability: "Download your data" on your account page (/account/export).
- Rectification: change your name and language on the account page, and your email address in its address section.
- Erasure: "Delete your account" on your account page (/account/delete).
- Objecting to our emails: the link in the invitation, one click.
- Any other request, including from people without an account: write to [email protected]. We answer within one month.
12. Changes
When we change this text materially we will change the effective date and, where the change affects you, tell you.