Privacy Policy
Effective 3 October 2026
BillShare is a free app for splitting shared expenses with friends, flatmates and travel groups. It has no ads, no premium tier and no tracking for advertising. We collect only what the app needs to work, we never sell personal data, and we never move money: BillShare only records who owes whom.
What we collect
Account details.
- Your first and last name and your email address (required to create an account).
- A password, if you sign up with email. We store only a salted scrypt hash, never the password itself.
- If you sign in with Google: your Google account ID, name, email address and the link to your Google profile picture, as provided by Google.
- Optional profile fields you choose to fill in: city of residence, UPI ID and a payment note.
- Preferences: language, theme, default currency, notification settings and whether you opted in to product updates.
- Technical account data: when you signed up, when you were last active, and sign-in tokens.
What you enter in lists.
- List names, member names (including people you add by name who do not use BillShare yet), expenses, income, transfers, amounts, dates, categories, descriptions, notes and settlements.
- Photos you attach to expenses (receipts) or use as a list cover. You pick these with the Android photo picker or take them with your camera; we only see the photos you choose. Our server re-encodes every photo before storing it, which removes the metadata inside the file (such as the time it was taken, the camera model, or a GPS location your camera may have recorded).
Device and diagnostic data.
- If you allow notifications: a Firebase Cloud Messaging push token and the app version, so we can send notifications to your phone.
- Crash reports from the Android app via Firebase Crashlytics: the stack trace, device model, Android version, app version and a random installation identifier. We do not attach your name, email or user ID to crash reports.
- Server error reports (only if error monitoring is switched on): technical details of the failed request, used to fix bugs.
- Your IP address, which our hosting provider sees with every request and which we use briefly to limit abusive traffic.
Support messages. If you contact us, we keep your email address and what you wrote.
What we do not collect: your phone's contacts or address book (the "BillShare contacts" you see are only people you already share a list with), your location, microphone, browsing history, or any bank, card or UPI PIN details. There are no advertising or analytics SDKs in the app.
Why we use it
- To run the service: keep your lists in sync, calculate balances and show them to list members.
- To manage your account: sign-in, password reset, email verification and email changes. These emails are always sent when you ask for them.
- To send notifications about activity in your lists, payment reminders and occasional service announcements. You can turn these off per list in the app or in Android settings.
- To keep the service secure: rate limiting, preventing abuse and investigating problems.
- To fix crashes and bugs, and to answer support requests.
We do not use your data for advertising, and we do not build profiles of you.
Who can see your data
- Members of your lists see your name as it appears in the list, the expenses and settlements in that list, attached photos and, when they owe you money, your UPI ID and payment note (so their UPI app can pay you).
- Anyone with a photo's link. Attached photos are stored at long, random web addresses. They are not listed anywhere, but anyone who has the exact link can open the image.
- Our administrators can see account and list data to provide support and keep the service running. Every admin view of a user's details is recorded in an audit log.
- Service providers that host and run BillShare for us (below). They process data only to provide their service to us.
We do not sell, rent or share your personal data with anyone for their own purposes.
Service providers
- Vercel: hosting of the API and website, and file storage (Vercel Blob) for photos and private backups.
- Neon: the main Postgres database.
- Google / Firebase: Sign in with Google, push notifications (Firebase Cloud Messaging, which carries the notification text) and crash reports (Firebase Crashlytics).
- Resend: sending account emails and receiving replies to support emails.
- Upstash: short-lived rate-limit counters keyed by IP address, user ID or email address; they expire within an hour.
- Sentry: server error reports, only when error monitoring is enabled.
- Frankfurter (frankfurter.app): currency exchange rates. Only currency codes are sent, never personal data.
These providers may store and process data on servers outside your country.
How long we keep data
- Your account data is kept while your account is open.
- Expenses and lists you delete are hidden from everyone but kept in the database so list history and balances stay consistent.
- Push tokens for devices that have not been seen for 180 days are deleted automatically.
- Used or expired sign-in, reset and verification tokens are deleted automatically.
- We make a weekly backup of the database in private storage, used only to recover from data loss. We keep the 8 most recent weekly backups (about two months) and delete older ones automatically, so data from a deleted account disappears from backups within about two months.
Deleting your account
In the app, go to Account → Delete account and confirm with your password or Google sign-in. You are signed out on every device straight away. If you can no longer use the app, email privacy@billshare.in from the address on your account and we will delete it for you.
Seven days after your request, your account is anonymized. If you change your mind, contact us within those seven days. Anonymization:
- removes your email address, name, city, UPI ID, payment note, profile picture link, password hash, Google account link and all sign-in tokens;
- deletes your registered devices and your in-app notification history, so you get no further notifications;
- removes your email address, ticket subjects and opening messages from support tickets.
What stays: BillShare is a shared ledger, so expenses and settlements you were part of stay in your lists and are shown under "Deleted user". Otherwise other members' balances would break. Text you or others typed into a list (for example expense descriptions and notes), photos attached to expenses, older activity entries and support conversation replies are not rewritten and may still contain your name. Backups follow the rule above. If you want specific content removed, email us and we will help.
Your rights and choices
- See and correct your profile at any time in the app (Account → Your profile, Login details, UPI / payment info).
- Export the expenses of any list as CSV or PDF from the list's Exports screen.
- Download a copy of all the data we hold about you, in a machine-readable (JSON) format, from Account → Download my data.
- Ask us to correct or delete your data, or delete your account yourself as described above.
- Turn notifications off per list in the app, or entirely in Android settings.
- Withdraw consent for optional data by clearing those fields.
To use any of these rights, email privacy@billshare.in. We will reply within 30 days. You may also complain to the data protection authority where you live.
Security
- All traffic between the app and our servers is encrypted with HTTPS.
- Passwords are stored only as salted scrypt hashes. Access tokens expire after 15 minutes; longer-lived sign-in tokens are stored only as hashes and are replaced each time they are used.
- On the web (billshare.in/app), signing in sets two strictly necessary cookies that keep you signed in:
bs_session(15 minutes) andbs_refresh(up to 60 days, removed when you sign out). They can't be read by page scripts, and we use no advertising or analytics cookies. - The admin console requires two-factor authentication, and admin actions are audited.
- Backups are stored privately and are not publicly accessible.
No system is perfectly secure, but we work to protect your data and will tell you if a breach affects you.
Children
BillShare is for people aged 18 and over. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has created an account, email us and we will delete it.
Changes to this policy
If we change how we handle your data, we will update this page and its effective date. For significant changes we will also tell you in the app.
Contact
Questions or requests about privacy: privacy@billshare.in