Privacy policy
Last updated 2026-05-13
This policy describes how Split (“we,” “us”) collects, uses, and shares information when you use the Split web app at split.foundrystudiolabs.com or the Split mobile apps on iOS and Android. Split is operated by Foundry Studio Labs.
What we collect
- Account data — email address, optional display name, and optional phone number you choose to add. Authentication is handled by Supabase.
- Expense data — the groups, expenses, settlements, and notes you create in the app, plus receipt images you upload.
- Payment-method handles — if you enter a Venmo, Cash App, or PayPal handle, we store it on your profile so other members of your group can pay you. We do not store actual card numbers; web subscription payments are handled directly by Stripe.
- Subscription state — the current plan tier (free, starter, pro), the source (Stripe for web; Apple or Google for mobile), and renewal/cancellation status.
- Request logs — standard HTTP metadata (IP address, user agent, request timestamp) retained by Vercel for operational purposes.
Receipt images and AI processing
When you upload a receipt photo, the image is sent to Anthropic’s Claude API for automatic line-item extraction (merchant, items, totals, currency, date). The structured JSON is cached on the expense record so we do not reprocess the same receipt later.
Per Anthropic’s data-processing terms, images submitted via API are not used to train models and are retained only briefly for abuse prevention. We send only the receipt image — no account email, name, or other personal data accompanies it.
Receipt images themselves are stored in our Supabase Storage bucket and are visible only to members of the group the expense belongs to.
Third-party processors
Split shares limited data with the following sub-processors to provide app functionality. Each is bound by their own data-protection terms.
- Supabase, Inc. — hosts the database and authentication system. Receives all user data described above.
- Vercel, Inc. — hosts the web application. Receives HTTP request metadata for logging.
- Anthropic, PBC (Claude API) — receives receipt images you upload, returns structured data. Does not receive any other personal data.
- Stripe, Inc. — payment processing for web subscriptions. Receives the email address linked to the subscription. Card details are entered directly with Stripe and never touch our servers.
- RevenueCat, Inc. — receipt verification and entitlement management for in-app purchases on iOS and Android. Receives your Supabase user ID (an anonymous random UUID), platform receipt data, and subscription state.
- Apple, Inc. — App Store In-App Purchases on iOS. Receives transaction data per Apple’s standard IAP flow.
- Google LLC — Google Play Billing on Android. Receives transaction data per Play Billing’s standard flow.
- Resend — transactional email delivery (signup confirmations, password resets, group invitations). Receives the recipient email address and the message body.
- Twilio, Inc. — transactional SMS delivery for phone-based authentication only (one-time login codes). Receives the recipient phone number and the message body.
- frankfurter.app — public foreign-exchange rate API. Receives only currency-pair codes and a date; no personal data.
We do not sell user data. We do not share data with advertisers. We do not use third-party analytics or tracking SDKs.
How we use your data
- To provide the core expense-splitting features.
- To send transactional email and SMS related to your use of the app (group invitations, login verification codes, password resets, receipts).
- To process subscription payments and enforce plan limits.
- To investigate abuse, fraud, or violations of our terms.
- To comply with legal obligations (e.g. responding to lawful requests).
SMS messaging
Split sends SMS through one explicitly user-initiated flow:
- Phone-based sign-in. When you choose to sign in by phone, you receive a single SMS containing a one-time 6-digit verification code. Frequency: one SMS per login attempt.
Split does not send SMS to anyone other than the account owner who initiates a sign-in. Quick Split shares via a link that you copy or share through your own messaging app (iMessage, WhatsApp, email, etc.) — Split itself does not send any messages to Quick Split participants.
Message and data rates may apply to login SMS; rates are determined by your carrier, not by Split.
Opt-out. Reply STOP to any Split SMS to immediately opt out of all further messages. Reply HELP for support information. Opt-out is processed by our SMS provider (Twilio) at the carrier level.
We do not share, sell, or rent your mobile phone number to third parties for advertising, marketing, or any other purpose. We provide your number to Twilio (our SMS sub-processor) only as required to deliver the message you requested, and to Supabase (our database host) for the purpose of associating your account with your phone number. Both parties act under written data-processing agreements as sub-processors of Foundry Studio Labs LLC, not as independent controllers, and may not use the data for their own advertising or marketing purposes.
Mobile-app permissions
- Camera — only when you tap a button to scan a receipt or pick a photo. Images stay on your device unless you attach them to an expense.
- Photo library — only when you choose “Choose from library” in a receipt-picker prompt.
- Contacts — only when you tap “Add from contacts” while creating a Quick Split. The contact you pick fills a name and phone or email field locally; Split does not upload your address book.
- Biometric (Face ID / fingerprint) — only if you opt into biometric unlock in Settings. The biometric check is performed by your device’s OS; no biometric data is sent to our servers.
Account deletion
You can delete your account at any time from Settings → Delete account in the app. Deletion is immediate and removes your profile, expenses, settlements, and group memberships. Some records may be retained in encrypted backups for up to 90 additional days; backups are not actively accessed.
If you cannot access your account, email support@foundrystudiolabs.com from the address on the account. We will delete the data within 30 days.
Data retention
We retain account and expense data for as long as your account is active. After deletion, primary records are removed immediately; encrypted backups roll off within 90 days. Audit and billing records required by law may be retained longer.
Users under 18
Split is intended for users aged 13 and older.
Users under 13. We do not knowingly collect data from children under 13. If we learn we have collected personal information from a user under 13, we will delete it. If you believe a child under 13 has signed up, email support@foundrystudiolabs.com and we will delete the account.
Users aged 13–17. Split treats users in this age range the same as adults except as noted below. We do not show personalized advertising or behavioral profiling to any user; the app contains no third-party advertising of any kind. We do not sell or rent personal information to third parties for advertising or marketing purposes. Sub-processors listed above (Supabase, Vercel, Stripe, Anthropic, RevenueCat, Resend, Twilio) receive only the data needed to provide the product feature described and process it under their respective DPAs as sub-processors of Foundry Studio Labs LLC, not as independent controllers. Where laws like the GDPR (EU/UK), the UK Age Appropriate Design Code, or US state laws (e.g. CCPA/CPRA, COPPA) grant additional rights to minors and their guardians, those rights take precedence over this policy. Email support@foundrystudiolabs.com to exercise any such right.
Paid features. Subscriptions to paid tiers (Pro) require an 18+ payment-account holder to complete checkout, in line with our payment processors’ terms of service. The free tier of Split is available to any user 13 or older.
Changes to this policy
We will update the “last updated” date above when this policy changes. Material changes will be communicated via email or in-app notice.
Contact
Questions or requests: support@foundrystudiolabs.com.
See also our Terms and Conditions.