Privacy Policy

  • shape image
  • shape image

Last updated: September 16, 2026

This privacy policy explains which personal data we process when you use the mobile app "SplitBuddies", for what purposes, and which rights you have as a data subject. It applies to all versions of the app available in the Apple (iOS) and Google (Android) app stores within the European Union.


1. Controller according to Art. 4 No. 7 GDPR

Name / Provider
Simon Buchholz
Füssener Str. 11
87600 Kaufbeuren
Germany
E-Mail: splitbuddies.appbench@gmail.com


2. Categories of Data, Purposes, and Legal Bases


Processing Activity Categories of Data Purpose Legal Basis
Account Registration & Login (via Auth0) Email address; Auth0 account identifier; if applicable, social login provider identifier; public handle (username); profile picture URL Provision and management of your user account; authentication (passwords are processed exclusively by Auth0 and are not stored by SplitBuddies) Art. 6(1)(b) GDPR (Contract)
App Usage (managing expenses) Expenses, amounts, group and contact names entered by you Core function of the app: recording, calculating, and displaying shared expenses Art. 6(1)(b) GDPR
Placeholder Buddies (third-party names) A label entered by you for a person who does not have a SplitBuddies account. It is not a public username and is not unique. Representing an offline participant in shared-expense records. The name is private to you unless you add the placeholder to a group, in which case all group members can see it. Art. 6(1)(f) GDPR (legitimate interest in maintaining shared-expense records)
Connecting with other users (handle, QR code, share link) A public username (handle); a share code contained in your personal QR code and share link; whether others can find you by your handle Letting you add other people as buddies, and be added by them, without exchanging email addresses. You can regenerate your share code at any time in the app, which makes previously shared codes and QR images stop working. Art. 6(1)(b) GDPR (Contract)
Continue without an account A temporary account; when you accepted the Terms; the handle and share code described in the row above, where discovery by handle is on by default (you can turn it off in the app). Your session stays on this device and is tied to a key stored only on your device. There is no email or other identity we can use to verify a later request. Let you use the app and save your expenses without creating an account. You can create an account later and keep your data. While the session still exists on this device you can delete it in the app or upgrade it to a registered account. If you lose the device or the key (for example after a reinstall that does not restore it), you cannot trigger erasure or export yourself (see § 5). Art. 6(1)(b) GDPR (Contract)
Blocks Who blocked whom, and when Hide the blocked person from your buddy list and stop them finding or adding you by handle, QR, or email. Blocking does not remove either of you from a group you share; expenses, balances, and settlements stay intact. Art. 6(1)(f) GDPR (legitimate interest in user safety)
User reports Who filed the report; who it is about; the reason you typed (up to 80 characters); whether it is still open; and when it was filed Receive and retain notices about other users. Reports are stored and available to us for review. We then try to notify our contact mailbox by email via AhaSend. Delivery is best-effort: a failed send does not prevent the report from being stored. If the person who filed it later deletes their account, we keep the report text as it was written but no longer store who filed it. The report stays attached to the person it is about (see § 5). Art. 6(1)(f) GDPR (legitimate interest in user safety and moderation); Art. 17(3)(e) GDPR for keeping the allegation after the reporter's erasure
System Logs & Error Reports IP addresses, device type, operating system, timestamps, request identifiers, error messages Stability, error analysis, abuse detection Art. 6(1)(f) GDPR (legitimate interest in app security)
Contact via Email Email address, content of your message Support, response to inquiries Art. 6(1)(f) GDPR
Transactional Emails (via AhaSend) Recipient email address (for invitations: provided by another user), sender public handle Delivering transactional emails: account verification, password reset, and invitation emails. If an invitation is not accepted, we may send up to two reminders over the following days and then stop. Every invitation email includes a link to this privacy policy and a link to stop receiving them. Art. 6(1)(b) GDPR (Contract) for verification/password reset; Art. 6(1)(f) GDPR for invitations


We do not use tracking or analytics tools for advertising purposes and do not integrate any advertising networks.


3. Minors

SplitBuddies is not specifically directed at children. Users under the age of 16 may only use the app with the consent of their legal guardians (Art. 8 GDPR). We will request proof of age or consent if we become aware that an account is operated by a minor without the necessary consent.


4. Storage Location and Recipients of Data


Service Role Processing Location Safeguards
Google Cloud Hosts the app and access logs Data centers in Belgium Data processing agreement
CockroachDB Cloud Stores the app's data Data centers in Belgium Data processing agreement
Auth0 (Okta) Sign-in service EU region Data processing agreement
AhaSend B.V. Sends account, invitation, and report-notification emails EU (Hetzner data centers in Germany and Finland; DA International Group in Bulgaria) Data processing agreement; email content deleted after 14 days


The app is hosted in the European Economic Area (Belgium). Where a provider's contract includes EU Standard Contractual Clauses, those clauses apply as a safeguard.


5. Storage Period and Deletion

Account data is stored as long as your user account exists. You can delete your account at any time via the app settings.

If you use the app without an account: while the key stored only on your device still exists, you can delete your data in the app. If you lose the device or that key, we cannot verify that a later request is yours — there is no email to check against — so you cannot erase or export the data yourself. You can avoid that by creating a registered account while the session still exists. Unused accounts without registration are deleted after one year unless money is still open; if money is still open, we keep the session until it is settled.

After account deletion, we remove personal data from our active systems within 30 days. If you change your handle or delete your account, neither you nor anyone else can use the released handle for 60 days.

Blocks are kept until you unblock, and are not deleted when an account is deleted (Art. 6(1)(f) GDPR, user safety).

Reports are kept while they are open. After a report is closed, it is kept for 24 months and then deleted. If the person who filed it deletes their account, we keep the report text as it was written but no longer store who filed it. If the person it is about deletes their account, the report stays attached to that account for the same period, under an internal reference that no longer identifies them by name or email. Reports are stored and available to us for review.

If you write to us by email, we keep your message in our support mailbox until we delete it there. That mailbox is not emptied automatically.

To keep group balances correct, expense entries stay in the shared group records under an internal reference that no longer identifies you by name or email.

For placeholder buddies, we warn the creator after about one year without use and automatically anonymize the third-party placeholder label after about 18 months if it remains unused. Choosing Keep in the app renews the retention clock and we will ask again later if the buddy remains unused. You can remove that name earlier by deleting the placeholder buddy. Deleting your account also removes placeholder names you created. Numeric expense amounts may remain so balances stay correct.

Server logs and backup copies are automatically deleted after a maximum of 90 days.


5a. Local Storage on Your Device (§ 25 TDDDG)

The following items are stored on your device and are strictly necessary for the service you explicitly requested (§ 25(2) No. 2 TDDDG) and do not require separate consent:

  • Signed-in state: The app remembers on this device that you are signed in, so you do not have to sign in again each time you open it.
  • Last-used currency: The most recently selected currency per friend or group, so the app can pre-fill the correct currency when you add an expense.
  • Sign-in details: What the app needs to keep you signed in, including if you continue without an account, stored only on your device.
  • Profile pictures: Images are stored temporarily on your device and are removed after seven days.

None of this data is shared with third parties. You can clear all locally stored data by deleting the app from your device.


6. Security of Processing (Art. 32 GDPR)

We protect your data with appropriate technical and organisational measures.


7. Rights of Data Subjects

You have the right at any time to:

  • Obtain information about the data we store about you (Art. 15 GDPR),
  • Request rectification of inaccurate data (Art. 16 GDPR),
  • Request erasure or exercise the "right to be forgotten" (Art. 17 GDPR),
  • Request restriction of processing (Art. 18 GDPR),
  • Object to processing based on legitimate interest for reasons arising from your particular situation (Art. 21 GDPR); this applies in particular to the processing described in § 2 under Art. 6(1)(f) GDPR,
  • Request data portability (Art. 20 GDPR),
  • Withdraw consent at any time (Art. 7(3) GDPR).

To exercise these rights, please contact splitbuddies.appbench@gmail.com.

You can also download a copy of your data in the app under Settings → Download my data (Art. 15 and Art. 20 GDPR). The export is a machine-readable file. If you use the app without an account, that download and in-app deletion are only possible from the device while the session exists (see § 2). For identity-verified requests, upgrade to a registered account while the session still exists.

You can correct your public handle yourself in the app, without contacting us. After you change it, you cannot change it again for 30 days, and neither you nor anyone else can use the handle you released for 60 days.

If you received an invitation email from us, you can object to any further invitation emails without contacting us first: use the "Stop invitation emails" link at the bottom of the email, or the unsubscribe button offered by your email program. We will then stop sending them.


8. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement. The competent authority for the provider is:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 27, 91522 Ansbach, Germany
https://www.lda.bayern.de


9. Obligation to Provide Data

Providing an email address is contractually required to create a registered SplitBuddies account. Without it, a registered account cannot be operated. A public handle is assigned as part of providing the service. All other data (for example a profile picture) is voluntary.


10. Automated Decision-Making / Profiling

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.


11. Changes to this Privacy Policy

We reserve the right to amend this privacy policy if the app or the legal situation changes. We will inform you of any material changes in the app or by email.


12. Language

The German version of this privacy policy is legally binding. Translations into other languages are provided solely for convenience. In case of discrepancies, the German version shall prevail.