I knew you would look for this. I made a privacy policy just for you.
Privacy policy
1. Who we are
"We" is Kyle, who built this app for the two of you. That makes Kyle the data controller, the data processor, the data protection officer and the whole engineering team. Questions about any of those roles are welcome over dinner.
2. Who this covers
The app has exactly two users, Kyle and Eunice. It's a small user base, but a very good one.
3. What we collect
- Expenses. The amount, a description of up to 60 characters, the date, who paid and who added it, plus when it was created and last edited. That's what the app needs to work out who owes whom. Both of you can see every description.
- Your password, sort of. The database only stores a salted scrypt hash. In the spirit of full disclosure, Kyle sets the passwords when deploying the app, so please pick one you don't use anywhere else.
- Your IP address, briefly. If a sign-in attempt fails, your IP address is kept in memory for about a minute to slow down password guessing. It is never written to disk.
4. Card statements
When you import a CSV from your card, the file is read on your device and is never uploaded. Only the charges you tick are saved, and only the same four details as an expense you type in yourself: amount, description, date and who paid. Card numbers, categories, the rest of the file and the charges you didn't pick stay with you. Closing the import screen clears the file from the page.
5. What we don't collect
No analytics, ads, tracking pixels, fingerprinting, location or contacts. Nothing is stored in your browser apart from the sign-in cookie below. We have no idea how many times you checked the balance.
6. Cookies
There's one cookie, called sid. It's HTTP-only and signed, and it lasts 30
days. It holds your user number, a fingerprint of your password hash (so a new password
signs old sessions out) and when you signed in. It's strictly necessary, so there's no
banner. Sadly, it is not the chocolate chip kind.
7. Who else sees it
- Each other. Kyle and Eunice both see every expense. That's the point of a shared list.
- Railway, the hosting provider, runs the server and stores the database on its disk, under its own terms and policies.
- Google Fonts serves the rounded typeface, so your browser asks Google for a copy of Nunito when the page loads.
We don't sell or share your personal information, and never will.
8. How long we keep it
Until the trip is wrapped up and the database is deleted. Deleted expenses are removed from the database right away, with the usual caveat that SQLite doesn't physically overwrite freed pages until it's compacted. You probably knew that already.
9. Your rights
- Access. Granted in full, in real time, on the home screen, and refreshed every ten seconds.
- Rectification. Tap any expense you added to fix it.
- Erasure. You can delete any expense you added. Expenses Kyle added are Kyle's to delete, so just ask. Sadly, debts don't fall under the right to be forgotten.
- Portability. Screenshots are supported on all major platforms.
- Objection. Raise it with Kyle, in person, ideally over ice cream.
- Human review of automated decisions. The app makes exactly one: it divides by two. You're welcome to ask for a human review, and the human will also divide by two.
10. Security
Hashed passwords, HTTPS, signed cookies, and a server that refuses edits once the trip is marked settled. That's plenty for two people splitting pizza, though it isn't built to stop a determined attacker.
11. Breach notification
If anything ever goes wrong, Kyle will tell you without undue delay, which here means leaning over and saying something.
12. Children
This service is not directed at children. It is directed at Eunice.
13. Changes to this policy
Changes go through a Git commit with a descriptive message, and you're welcome to review the diff.
14. Contact
Kyle is usually within arm's reach.