Skip to the content
tabtada

Privacy policy

Effective: [[ OWNER: effective date ]]

1. Who is responsible

The controller of personal data in tabtada is: [[ OWNER: name of the person or company acting as controller ]], [[ OWNER: address ]], [[ OWNER: legal form and registration number, if any ]].

Contact for privacy questions and the requests in section 11: [email protected].

2. What we collect

We use no analytics, no advertising and no tracking tools, and we load nothing from third-party sites, so there is no cookie consent banner: we set only essential cookies (section 9). If we ever add analytics we will ask for consent and update this text first.

3. Why, and on what legal basis

4. Who receives your data (processors)

These companies process data on our behalf under data processing agreements (art. 28 GDPR) that include standard contractual clauses where the company is outside the EU. Fly.io, Neon, Cloudflare are US companies, but the processing takes place in the EU.

Backups never leave the EU. Our uptime monitor receives only "alive" pings and no personal data. We do not sell data and do not pass it to anyone but the processors above, unless the law requires it.

5. If someone added you to a group

A group member may have added you by typing your name and, optionally, your email address. If they gave an address we sent you an invitation: that is our notice under GDPR art. 14. It says who added you and to which group, what we keep and why, where this document is, and how to object with one click.

6. Shared content, and what deleting an account does

Group names and expense descriptions are kept in a separate content table, never in the event journal, and belong to the group.

7. Your data as a file (export)

On your account page you can download a ZIP file: your account data, every group you were in, the expenses and payments you took part in or recorded, the text you typed and the people you added, your sessions (when each started and when it expires) and the emails sent on your behalf (when, for which group, and the recipient as the keyed digest we store, not the address), plus one CSV per group in Splitwise's layout. The export includes the display names of other members and every live entry of the groups you belong to, because you can already see them in the app (GDPR art. 15(4)), but never another person's email address. We email you when a copy is downloaded.

8. How long we keep data

9. Cookies

We use four cookies, all first-party and essential. The language comes from your account setting, from a choice remembered in tt_lang, or from your browser's language header.

On your device, besides cookies. So that the app works on a poor connection, your browser keeps on your phone or computer (in this site's own storage, which other sites cannot read):

On iPhone and iPad, Safari may delete all of this if you do not open the app for 7 days, unless you added it to the Home Screen; a waiting write is then lost. iOS sends nothing in the background: waiting writes are sent when you open the app.

10. Age

You must be at least [[ OWNER: confirm the minimum age, e.g. 16 ]] years old to use the service. The sign-up form does not check age.

11. Your rights and how to use them

You have the right of access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interests, and to complain to a supervisory authority (in Poland: the President of the Personal Data Protection Office, uodo.gov.pl).

12. Changes

When we change this text materially we will change the effective date and, where the change affects you, tell you.