Privacy Policy
Last updated: 2026-06-16
Draft template - legal review required before publication.
This Privacy Policy explains how SplitNinja App Ltd ("we", "us", or "our") processes personal data when you use Split Ninja at splitninja.app and related API services (the "Service").
Split Ninja helps registered users manage shared expenses, groups, quick tabs, balances, and settlement records. The Service records financial information entered by users, but it does not move money, provide payment processing, or connect to bank accounts.
1. Controller and Contact
The data controller is:
- Legal name: SplitNinja App Ltd
- Registered address: Ukraine, Kyiv
- Support contact: splitninja.app@gmail.com
2. Personal Data We Process
We process the following categories of personal data, depending on how you use the Service.
Account and Profile Data
- Email address.
- Display name.
- Public user identifier.
- Account settings, such as theme, color scheme, density, tips, closed-group visibility, and application mode.
- Account creation and update timestamps.
Authentication and Security Data
- Password hashes. We do not store plain-text passwords.
- Refresh token hashes and authentication version data.
- Access tokens issued to your client app.
- HttpOnly refresh cookies used for token refresh and logout.
- Password reset token hashes, expiry timestamps, and consumption state.
- Pending registration records, including verification channel, hashed verification codes, attempt counts, expiry timestamps, and completion state.
- Security logs and diagnostic records needed to protect the Service and investigate problems.
Optional Verification Channel Data
If you choose Telegram-based registration or verification, we may process:
- Telegram user ID.
- Telegram chat ID.
- Telegram username.
- Hashed Telegram link token.
- Telegram webhook/debug information if enabled for operational troubleshooting.
If you choose email verification or password reset, we process the email data needed to send the message through our email provider.
Shared Expense and Collaboration Data
When you use groups, quick tabs, invite links, expenses, approvals, balances, settlements, or money records, we process:
- Group and quick-tab names, descriptions, currencies, roles, membership, and status.
- Invite link records, including hashed tokens, expiry, use limits, use counts, and creator.
- Expense titles, optional descriptions, dates, payer, creator, amount in minor currency units, currency code, split method, participant shares, and status.
- Approval actions, comments, timestamps, and member references.
- Settlement records, including debtor, creditor, amount in minor currency units, currency code, note, settlement date, creator, and status.
- Immutable money records, including event type, source type, balance deltas, currency code, related expense or settlement, metadata, and timestamps.
- Quick-tab settlement markers and settlement payments.
Information you enter into group names, expense titles, descriptions, notes, comments, and metadata may be visible to other authorized members of the same group or quick tab. Do not enter sensitive personal data unless it is necessary.
Technical, Device, and Usage Data
We may process technical data needed to operate and secure the Service, such as:
- IP address.
- Browser or device information.
- Request timestamps.
- API endpoint usage.
- Error, audit, and security logs.
The exact technical data depends on the hosting, frontend, logging, and monitoring tools used in production.
Support Communications
If you contact us, we process the information you provide in the support request and the related correspondence.
3. Data We Do Not Intend to Collect
Based on the current Service design, we do not intend to collect:
- Bank account details.
- Payment card details.
- External payment provider account details.
- Precise location data.
- Identity documents.
- File attachments.
- Special-category personal data, such as health, biometric, religious, political, or trade-union information.
Users may still enter sensitive information into free-text fields. Please avoid doing that.
4. Why We Process Data and Legal Bases
This section uses GDPR-style legal bases as examples. The final legal bases must be confirmed for the operating entity and jurisdictions.
| Purpose | Example legal basis |
|---|---|
| Create and manage user accounts | Contract performance |
| Authenticate users and keep sessions secure | Contract performance; legitimate interests |
| Send verification, password reset, and service emails | Contract performance; legitimate interests |
| Provide groups, quick tabs, expenses, balances, approvals, settlements, invite links, and money records | Contract performance |
| Show shared records to authorized group or quick-tab members | Contract performance; legitimate interests |
| Preserve financial audit trails and ledger consistency | Legitimate interests; legal obligation where applicable |
| Detect abuse, protect accounts, prevent unauthorized access, and debug incidents | Legitimate interests |
| Respond to support requests | Contract performance; legitimate interests |
| Comply with law, court orders, regulatory requests, or enforce legal claims | Legal obligation; legitimate interests |
| Optional marketing or non-essential analytics, if added later | Consent, where required |
| Optional Telegram-based registration or verification | Consent or contract performance, depending on implementation |
5. Cookies and Local Storage
The API uses an HttpOnly refresh-token cookie for authentication refresh and logout. In production, this cookie should be configured with appropriate security attributes, such as Secure and SameSite settings.
The access token is returned to the client app. The client app must document where it stores access tokens and any other local data.
Strictly necessary cookies or storage may be used to provide login, security, and user-requested functionality. If non-essential cookies, analytics, advertising, or tracking technologies are added later, this policy and the client cookie notice must be updated and consent must be collected where required.
6. How We Share Data
We share personal data only where necessary for the Service or where legally required.
Other Users in Your Groups or Quick Tabs
Group and quick-tab members can see shared records needed for collaboration, such as member display names, expenses, shares, balances, approvals, settlements, and audit records.
Invite link recipients may see limited preview information needed to decide whether to accept an invite. Full financial details should be visible only after authentication and authorization.
Service Providers
We may use processors and service providers for:
- Hosting and database infrastructure.
- Email delivery, such as Resend if configured.
- Telegram delivery if you choose Telegram verification.
- Logging, monitoring, diagnostics, and security tooling.
- Customer support tooling.
Processors must process personal data only under our instructions and with appropriate safeguards.
Legal and Safety Reasons
We may disclose data where necessary to comply with law, enforce our terms, protect users, investigate abuse, or defend legal claims.
We do not sell personal data.
7. International Transfers
If personal data is transferred outside the EU/EEA, the transfer should rely on an appropriate legal mechanism, such as an adequacy decision, Standard Contractual Clauses, or another lawful transfer tool. The actual transfer details depend on the production hosting, email, logging, and support providers.
8. Retention
We keep personal data only for as long as needed for the purposes described in this policy, unless a longer period is required or permitted by law.
Example retention approach:
- Account data: kept while your account is active and for a limited period after deletion where needed for security, legal claims, backups, or audit integrity.
- Pending registration data: kept until registration is completed, expires, or is cleaned up.
- Refresh token hashes: kept until logout, rotation, expiry, account revocation, or cleanup.
- Password reset token hashes: kept until expiry, use, or cleanup.
- Group, quick-tab, expense, settlement, approval, and money-record data: kept while needed to provide the shared ledger, preserve financial integrity, and protect the rights of other members.
- Security and operational logs: kept for 1 year after deletion or overwritten on the normal log rotation.
- Backups: kept for 1 year and deleted or overwritten on the normal backup cycle.
Because Split Ninja is a shared ledger, deletion of one account may not remove every record from a group or quick tab if that would corrupt financial history, audit records, or other members' records. In those cases, we may delete, minimize, anonymize, or restrict personal identifiers where practical while preserving the shared financial record.
9. Your Rights
Depending on your location and applicable law, you may have rights to:
- Access your personal data.
- Correct inaccurate or incomplete data.
- Delete personal data.
- Restrict processing.
- Object to processing based on legitimate interests.
- Receive a portable copy of certain data.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a supervisory authority.
To exercise rights, contact splitninja.app@gmail.com. We may need to verify your identity before responding.
10. Security
We use technical and organizational measures designed to protect personal data, including password hashing, hashed refresh tokens, JWT-based authentication, role and membership authorization, validation, transactional writes for money-impacting operations, and database-level relational integrity.
No system is perfectly secure. You are responsible for keeping your login credentials safe and for using a secure device.
11. Children
The Service is not intended for children under 16 unless a lower age is permitted by local law and valid parental consent is obtained where required. If you believe a child has provided personal data without proper consent, contact us at [privacy contact email].
12. Automated Processing
The Service calculates balances and suggested settlement information deterministically from records entered by users. We do not intend to make automated decisions that produce legal or similarly significant effects about users.
13. Changes to This Policy
We may update this Privacy Policy when the Service, law, or our processing changes. We will update the "Last updated" date and, where required, provide additional notice.
14. Publication Checklist
Before publication, replace all placeholders and confirm:
- Legal entity and controller details.
- Privacy and support contacts.
- Production hosting, database, email, Telegram, logging, monitoring, support, and analytics providers.
- Cookie names, paths, retention periods, and security attributes.
- Token storage behavior in the client app.
- Actual retention schedule.
- Account deletion and data export behavior.
- Supervisory authority and governing jurisdiction.
- Whether a DPO, EU representative, cookie banner, or consent-management flow is required.