SplitMate Privacy Policy
Effective Date: August 14, 2026 • Published by Fyndra Labs
Fyndra Labs ("we", "us", or "our") built SplitMate as a secure, shared expense management mobile application. We do not sell, rent, or trade your personal information to third parties or data brokers. All data collection is strictly tied to providing group bill splitting, balance calculations, push notifications, and diagnostics.
1. Introduction & Overview
This Privacy Policy describes how Fyndra Labs collects, uses, processes, and protects your information when you use the SplitMate mobile application ("App") and associated web endpoints. SplitMate helps users create groups, track shared expenses, compute settlements, and maintain balance records.
By creating an account or using SplitMate, you consent to the collection and use of information in accordance with this policy.
2. Information We Collect
We collect personal and technical information strictly necessary to operate SplitMate's features:
A. Account Information (Email & Name)
When registering or editing your profile, we collect your full name and email address. Email addresses are authenticated securely via Firebase Authentication to verify identity, manage sessions, and facilitate account recovery.
B. Phone Numbers
Phone numbers may be provided voluntarily to facilitate member invitations and user lookup within groups. Phone numbers are stored securely in Firebase Authentication/Firestore and are never shared with external telemarketers or advertisers.
C. Profile Photos & Media
If you choose to upload a profile avatar or attach images (such as receipts or expense proofs), these images are transmitted over TLS/SSL encryption and stored in Firebase Storage. Image data is strictly used for display inside your shared groups.
D. Expense & Group Data
We collect group names, member assignments, expense titles, bill amounts, currency preferences, split ratios, payment settlement logs, and activity timeline entries stored securely in Cloud Firestore.
E. Notifications & Device Tokens
To deliver push notifications when a group member adds an expense or settles a balance, we collect push notification tokens via Expo Notifications and Firebase Cloud Messaging (FCM), alongside basic device model and OS version information.
F. Crash Reporting & Diagnostics (Sentry)
We utilize Sentry to capture real-time crash logs, exception stack traces, and app stability metrics. Diagnostic logs may include device model, CPU architecture, OS version, app version, memory usage, and the state of the app at the exact moment of a crash.
3. Firebase Infrastructure & Third-Party Service Disclosures
We do not sell personal data. We disclose data to trusted cloud infrastructure and diagnostics providers under strict confidentiality and security terms:
Firebase Authentication (Google LLC)
Manages secure user sign-in, token generation, and account authentication states.
Cloud Firestore (Google LLC)
Stores real-time database documents including group memberships, balances, settlement logs, and user profile metadata with AES-256 encryption at rest.
Firebase Storage (Google LLC)
Stores user-uploaded profile pictures and receipt images with granular access rules.
Firebase Cloud Messaging (FCM) & Expo Notifications
Delivers real-time transactional push notifications to device push tokens.
Sentry (Functional Software, Inc.)
Captures real-time stack traces, crash diagnostics, and performance metrics to ensure app stability.
4. Explicit Service Boundaries
- No Financial Services: SplitMate is a mathematical balance tracking tool. We do not act as a bank, financial institution, lender, money transmitter, payment processor, credit issuer, or investment advisor. We do not process bank transfers or credit card transactions directly.
- No Advertising: SplitMate currently contains no third-party advertisements, ad trackers, or advertising SDKs.
- No Health Data: We do not collect, process, or request any health, biometric, or medical data.
- No Location Tracking: We do not collect real-time background or precise GPS location data.
5. How We Use Information
We process collected data exclusively for the following operational purposes:
- To authenticate user identity and prevent unauthorized access.
- To calculate group balances, split logic, and settlement summaries.
- To send transactional push notifications (e.g., "Alex added a $40 expense").
- To render user profiles and receipts within group views.
- To detect, prevent, and fix technical bugs or crashes via Sentry.
- To enforce our Terms of Service and maintain platform integrity.
6. Data Security Measures
We employ industry-standard administrative, physical, and technical safeguards. All data in transit between the SplitMate mobile app and server infrastructure is encrypted using Transport Layer Security (TLS 1.2/1.3). Data at rest in Firebase Cloud Firestore and Cloud Storage is encrypted using AES-256. Firestore Security Rules enforce strict authorization access control so users can only access groups and expenses they belong to.
7. Data Retention & Deletion Rights
We retain your personal data for as long as your account remains active. You have full right and control to request the deletion of your account and personal data at any time.
To delete your account:
- In-App: Go to Settings > Account > Delete Account and confirm.
- Web Request: Visit our dedicated Account Deletion Portal to submit a deletion request.
Effect of Account Deletion:
- Your Firebase Authentication account record is permanently removed.
- Your user profile (Name, Email, Phone Number, Profile Photo URL) is permanently deleted from Firestore and Cloud Storage.
- Historical expense records created in shared groups may retain an anonymized placeholder ("Deleted User") to maintain exact accounting balances for remaining group members.
8. User Rights (GDPR / CCPA Compliance)
Depending on your jurisdiction, you possess the following rights regarding your personal information:
- Right of Access: Request a copy of the personal data held about you.
- Right to Rectification: Request correction of inaccurate profile data via in-app settings.
- Right to Erasure: Request permanent deletion of your profile and data.
- Right to Restrict Processing: Withdraw consent for non-essential push notifications.
9. Children's Privacy
SplitMate is not directed to children under the age of 13 (or 16 in certain European jurisdictions). We do not knowingly collect personal information from children. If we discover that a child under 13 has provided personal data, we will immediately delete such information. If you believe a child has provided us with personal information, please contact us.
10. Google Play Data Safety Reference Table
| Data Category | Data Type | Collected / Shared | Purpose |
|---|---|---|---|
| Personal Info | Name, Email, Phone | Collected (Encrypted) | App functionality & Auth |
| Photos & Videos | Profile Photo, Receipt Images | Collected (Encrypted) | App functionality |
| Financial Info | Group Bills & Expenses | Collected (Encrypted) | App functionality (Splitting) |
| App Diagnostics | Crash logs, Diagnostics (Sentry) | Collected (Encrypted) | Analytics & App Performance |
| Device IDs | Push Token (FCM / Expo) | Collected (Encrypted) | Push Notifications |
11. Policy Changes & Contact Information
We may update our Privacy Policy periodically. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top.
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us at: