Privacy Policy for the "Split" App
Last updated: September 4, 2026 · Version 1.6
This English translation is provided for convenience. The German version is legally binding.
1. Controller
The controller within the meaning of Art. 4 No. 7 GDPR is the provider of the "Split" app:
Email: info@trysplit.de
Phone: +49 160 96698542
Data protection officer: No data protection officer has been appointed, as the requirements of § 38 of the German Federal Data Protection Act (BDSG) are not met.
2. Principles
We process personal data only insofar as this is necessary for providing the app or you have consented. We do not sell data, we do not operate advertising tracking, and we do not integrate advertising networks.
By its nature, Split processes data that also concerns other people, such as the names of the people you split a bill with. The same principles apply to this data.
3. Processing in Detail
3.1 User Account and Sign-In
Data: Email address, self-chosen username, display name, optionally a profile picture, password hash (when registering with email and password), technical identifiers of the account.
Purpose: Setting up and managing your account, authentication, assignment of your data, protection against misuse.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract).
System emails: If you register with an email address and password, we send you a message with a confirmation link; the account only becomes usable after you click this link. If you request a new password, we send you a message with a one-time, time-limited link. We do not send any other emails, in particular no advertising.
For sending, we use the mailbox of our provider Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. In the process, your email address and the content of the respective message are processed. The basis is a data processing agreement pursuant to Art. 28 GDPR; the processing takes place in Germany.
Legal basis: Art. 6 (1) (b) GDPR (confirmation email as part of account setup) and Art. 6 (1) (f) GDPR for the password reset; our legitimate interest lies in being able to restore access to the account securely.
Profile picture: If you upload a profile picture, we store it as an image file on our server (Hetzner Online GmbH, server location Nuremberg). It is displayed exclusively to people you are friends with or with whom you share at least one group; this authorization is checked again on every single retrieval. A profile picture is voluntary. You can remove it in the app at any time, in which case the file is deleted.
Sign in with Apple: If you use "Sign in with Apple", Apple transmits an identifier to us and, depending on your selection, your name and an email address. If you choose "Hide My Email", we receive only an anonymized forwarding address from Apple. Provider: Apple Inc. or Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland.
Storage period: Until your account is deleted. After that, the data is deleted without delay, insofar as no statutory retention obligations prevent this.
3.2 Groups, Expenses, and Bills
Data: Group names, names and usernames of the participants, expense descriptions, amounts, dates, splits, balances, payment status, activity history.
Purpose: The core function of the app, namely recording, splitting, and settling shared expenses.
Legal basis: Art. 6 (1) (b) GDPR.
Recipients: This data is visible to the other members of the respective group. This is the purpose and functional principle of the app. If you add people who do not use Split, we process their names exclusively for display within your group.
Storage period: Until the group or your account is deleted. Since bills concern several people, entries remain in place for the other group members; in this case your name is replaced with a neutral designation.
3.3 Receipt Scanning and AI-Assisted Analysis
This is the most sensitive processing in Split from a data protection perspective. Please read this section particularly carefully.
Data: The photo you take, or the stored image, of a receipt, as well as the information recognized from it (item descriptions, quantities, prices, total, date, and, where applicable, the name of the establishment).
Purpose: Automatic recognition of the receipt items so that you don't have to type them in.
Process: For recognition, the photo is transmitted from your device to our server and forwarded from there to the AI service Claude by Anthropic PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, USA. Only the recognition result is returned to your device. The photo is not stored permanently.
Legal basis: Art. 6 (1) (b) GDPR. The analysis is the service you requested.
Third-country transfer: The processing takes place in the USA. Anthropic is our processor pursuant to Art. 28 GDPR on the basis of a data processing agreement (Data Processing Addendum). The transfer is based on the EU Commission's standard contractual clauses pursuant to Art. 46 (2) (c) GDPR. Despite these safeguards, processing in the USA carries the risk that US authorities may demand access on the basis of local laws. A level of protection fully equivalent to the European one cannot be guaranteed for third-country transfers.
Important, what you should do: If possible, photograph only the receipt itself. Make sure that no credit card slips, identity cards, names of third parties, or other unneeded information appear in the picture.
Storage period and technical implementation: The photo exists exclusively for the duration of the analysis. This is technically ensured:
- On your device: The photo is held only in the working memory of the scan step. When you leave this step, whether after the analysis is complete, when proceeding manually, or upon cancellation, all image references are deleted. The photo is not transferred into the expense draft, not written to the device storage, and the app's camera function does not save it to your photo library either.
- On our server: The image is passed through to the recognition exclusively in working memory. It is not written to a storage medium, not logged, and not stored in a database. Once the request ends, it no longer exists.
Only the recognized information in your bill is retained, namely item descriptions, quantities, and amounts.
Under our contractual agreements, Anthropic does not use transmitted content to train its models.
Translation feature (subscription only): If you enable the translation of item descriptions, these descriptions are additionally transmitted to the same service. Without the feature enabled, no translation takes place.
Alternative without transmission: You can always enter expenses and bills manually. In this case, no image leaves your device and no transmission to the USA takes place.
3.4 Payment Details (IBAN, BIC, Account Holder)
Data: IBAN, BIC, name of the account holder, optionally a payment link you have stored.
Voluntariness: Providing this is voluntary. Without it, you can use Split fully; only the automatic display of your bank details to others is omitted.
Purpose: So that people who owe you money from a shared bill can transfer it to you. From your information, their device generates a transfer QR code according to the EPC standard ("Girocode"), which common banking apps can read.
Legal basis: Art. 6 (1) (b) GDPR. Providing your bank details to co-payers is the feature you requested.
Storage and encryption: Your information is transmitted to our server and stored there (Hetzner Online GmbH, server location Nuremberg). Payment details are transmitted encrypted (TLS) and stored encrypted (AES-256). The key required for decryption is held exclusively on the server and is protected against third-party access. In addition, a local cache of your own entries is kept on your device in the iOS keychain, so that you don't have to fill in the form again.
Circle of recipients: Your payment details are displayed exclusively to people with whom you share at least one group. Our server checks this shared membership on every single retrieval. Requests from accounts without a shared group are rejected. If you leave a group or are removed from it, the other members' access lapses automatically as a result.
Transparency in the app: Already when you fill in the form, we point out that the data is visible to members of your groups and stored on our server for this purpose.
Storage period and deletion: You can change or delete your payment details at any time in the app's settings. Upon deletion, the display for everyone else ends immediately. At the latest when your account is deleted, the data is removed completely.
Express note: Split does not execute payments, does not hold money, and is not a payment service within the meaning of the German Payment Services Supervision Act. We exclusively display information. You make the transfer yourself with your bank.
Important for you: Bank details are sensitive data. Store them only if you actually want to make them accessible to the members of your groups.
3.5 Friends and Contacts
Data: Friend relationships you have added; when using the invitation feature, the contact details you have individually selected.
Purpose: Finding friends and inviting them to groups.
Legal basis: Art. 6 (1) (a) GDPR (consent, given via the iOS permission prompt).
Expressly not: We do not read your address book in full and do not transmit it to our server. Only the contacts you yourself select in the operating system's selection dialog are processed.
Withdrawal: At any time in the iOS settings under Privacy → Contacts.
3.6 Push Notifications
Data: Device-specific push token, your app's language setting (German or English), content of the notification.
Purpose: Notices of incoming payments, reminders of open amounts, invitations to groups. We store the language setting so that notifications sent at a later time also arrive in the language in which you use the app; it is stored with your account together with the push token and deleted with the account.
Legal basis: Art. 6 (1) (a) GDPR (consent via the iOS prompt).
Recipient: Apple Push Notification service (Apple Inc./Apple Distribution International Ltd.) as the technical transmission channel.
Withdrawal: At any time in the iOS system settings or in the app's settings.
Purely local reminders do not leave your device.
3.7 Purchases and Subscription
The paid services, namely Split Pro as a monthly and as an annual subscription and the one-time Vacation Pass, are handled exclusively via Apple's in-app purchase system. Apple is the seller. We never receive payment data such as credit card numbers at any time.
We only receive a signed purchase receipt from Apple. From this, we store with your account which product was purchased, until when the service runs, and a transaction identifier. This unlocks the purchased features, and the same receipt cannot be redeemed more than once. For the Vacation Pass, we additionally store the date on which the seven days end.
Legal basis: Art. 6 (1) (b) GDPR.
Referral program: If you redeem a referral code, we store the link between the referring and the referred account. If you subsequently take out a subscription, we additionally store that this resulted in a free month for the referring account, as well as the time and duration of the credit. Without this information, the reward could not be granted and could not be checked against multiple credits.
3.8 No Usage Analytics, No Ad Tracking
We do not measure your usage behavior. The app contains no analytics or statistics function: no screens opened, no flows, and no events are recorded or transmitted. A previously available, voluntary usage analytics feature was removed entirely on 17 August 2026; the events stored until then were deleted.
No ad tracking: We use no advertising identifier (IDFA), no cross-device tracking, and no advertising networks. A prompt under Apple's App Tracking Transparency framework is therefore not required.
Independent of us: Apple provides us with aggregated, anonymized statistics on crashes and usage in App Store Connect. We do not receive this data in a personally identifiable form; its collection is governed by Apple's privacy provisions.
3.9 Widgets on the Home and Lock Screen
Data: If you place a Split widget on the home or lock screen, the app stores the information needed for it in a shared storage area of the app and widget on your device: your total balance, the sum of open amounts, and, for the next steps, the display name of the person involved and the amount in each case.
This data does not leave your device. It is not transmitted to us and not passed on to third parties; it comes from the data that is displayed for your account anyway. On the lock screen, amounts are automatically hidden while the device is locked.
Purpose: Displaying the widget without the app having to be open for it.
Legal basis: Art. 6 (1) (b) GDPR.
Storage period: Until the widget's next update. If you remove all widgets or delete the app, the area is removed with it.
3.10 Server Log Data
No access log: The HTTPS proxy in front of our server is deliberately configured so that it keeps no access log. Therefore no IP addresses of users are logged.
Data: Only technical application logs arise, in particular the time and type of an error, the endpoint concerned, the status code, and the app version.
Purpose: Operation, troubleshooting, and defense against abusive use.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in the secure and trouble-free operation of the app.
Storage period: At most 7 days. In addition, the log volume is limited to a total of 300 MB; older entries are automatically overwritten when this limit is reached.
Hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The servers are located in Nuremberg, Germany. The basis is a data processing agreement pursuant to Art. 28 GDPR. No transfer to a third country takes place for the hosting.
3.11 Our Website trysplit.de
No cookies: Our website sets no cookies. No analytics tools, no advertising networks, and no fonts, maps, or videos loaded from third-party servers are integrated.
Data: If you dismiss the privacy notice at the bottom of the page, your browser stores a single entry in local storage with the name split-hinweis-gesehen and the value 1. We do not create any other entries.
Purpose: So that the notice does not appear again on every page view.
Legal basis: § 25 (2) No. 2 TDDDG. The storage is strictly necessary to take your decision into account; no consent is required for this. No personal data is processed in the process.
No transmission: The entry remains exclusively on your device and is never transmitted to us or to third parties.
Storage period: Until you delete it. You can remove it at any time via your browser settings by deleting the website data for trysplit.de. The notice will then appear again.
Not in the app: The app itself uses neither cookies nor this entry. This section concerns exclusively visits to the website.
Visiting the website: Section 3.10 applies to the delivery of the pages; here too, no access log is kept and no IP addresses are logged.
3.12 Badges and Your Map
What happens: If you settle a scanned receipt, you can collect badges for it: for the venue, the country and the currency. For this we store:
- the name and address of the venue as printed on the receipt, and the country derived from it,
- which badges you have reached and at which tier, and how often you have been to a place,
- a checksum of the receipt made from merchant, date, total and receipt number, so that the same receipt cannot count twice. This value allows no conclusions about the contents of the bill.
The receipt itself is still not stored. Section 3.3 continues to apply without change: the image never leaves working memory and is discarded after analysis. Only the venue details listed above are stored.
The venue is not personal data: Once a venue exists, it applies to everyone. Anyone who later submits the same address receives the same badge. The only person recorded on the venue itself is whoever first registered it.
Purpose: The collecting feature. It is part of the app and included in every plan.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Visible to friends, only if you switch it on: By default nobody sees your badges. If you enable sharing in your collection, your confirmed friends see only which badges you hold and at which tier. They do not learn how often you were where, or in how many venues or countries you have collected. Those figures are not transmitted at all for other people's collections. You can switch sharing off again at any time.
Groups: Within a group you also collect together. These badges are visible to all members of that group.
Your map: On request we show your venues on a map. The points are derived exclusively from the address on the receipt. Split never requests your device location and needs no location permission for this. Converting the address into coordinates is done by your iPhone's map service (Apple); the venue's address is transmitted to Apple in the process, not your identifier. The map is visible to you alone and only appears after you have confirmed it once.
Retention: Until you delete your account. Your badges and checksums are deleted with it. The venues themselves remain, as they no longer relate to you.
4. Recipients at a Glance
| Recipient | Purpose | Location | Basis |
|---|---|---|---|
| Hetzner Online GmbH | Server operation, database | Germany (Nuremberg) | Art. 28 GDPR |
| Strato AG | Sending system emails (account confirmation, password reset); the email address is processed | Germany (Berlin) | Art. 28 GDPR |
| Anthropic PBC | AI analysis of receipt images | USA | Art. 28 GDPR, standard contractual clauses Art. 46 GDPR |
| Apple Distribution International Ltd. | Sign-in, purchases, push | Ireland | Art. 6 (1) (b) GDPR |
No disclosure to other third parties takes place unless we are legally obliged to do so.
5. Storage Period and Deletion
We store personal data only for as long as is necessary for the respective purposes. If you delete your account in the settings, your data is deleted without delay. Exceptions are:
- data we must retain due to commercial or tax law provisions (§ 147 AO, § 257 HGB),
- billing data concerning other group members; there, your name is anonymized.
Separate periods apply to technical access data:
- Session tokens are deleted when they have not been used for 90 days, and immediately as soon as you sign out.
- Password reset tokens are valid for 24 hours and are deleted afterwards. As soon as the new password has been set, they are deleted immediately.
6. Your Rights
You have the right at any time to:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7 (3) GDPR)
To do so, contact info@trysplit.de. We respond within one month.
Data portability in detail. You have the right to receive the data you have provided to us in a common, machine-readable format. Write to us at info@trysplit.de for this. We will send you the data within one month. Included are your account, your group memberships, your expenses and shares, your settlements, and your payment details. Not included is data of other people: for shared expenses, the names and shares of the participants are included, but none of their account details. We never store receipts anyway.
Erasure. You can delete your account and all associated data at any time directly in the app: Settings → Account → Delete Account. This is final. An active subscription does not end as a result. You cancel it separately via your Apple account.
Right to lodge a complaint: You can complain to a data protection supervisory authority, in particular in the member state of your place of residence. The authority responsible for us is:
Bayerisches Landesamt für Datenaufsicht (BayLDA)
Promenade 18, 91522 Ansbach
www.lda.bayern.de
7. Minimum Age
Split is not aimed at children. Use requires a minimum age of 16 years (Art. 8 (1) GDPR in conjunction with its German implementation). If we become aware that an account was created by a younger person without the consent of their legal guardians, we will delete it.
8. No Automated Decision-Making
No automated decision-making, including profiling with legal effect on you within the meaning of Art. 22 GDPR, takes place. The AI-assisted receipt analysis serves exclusively for text recognition; you can check and change all results before saving.
9. Data Security
We secure transmission through encryption (TLS). Access credentials and session tokens are stored on your device exclusively in the iOS keychain. Passwords are never stored in plain text, only as a hash using a recognized method.
Payment details are additionally stored encrypted at rest (AES-256). Even in the event of unauthorized access to the database or a backup copy, the bank details cannot be read from it.
10. Changes to This Privacy Policy
We adapt this policy when the app or the legal situation changes. The current version is available in the app under Settings → About → Privacy. In the event of significant changes, we will inform you in the app.