The short version
Settle The Tab is operated by the individual developer identified as its seller in the App Store. The service handles the information needed to create accounts, share expenses with the people you choose, calculate balances, attach receipts, synchronize devices, provide support, and protect the service.
We do not sell personal information, show behavioral ads, use expense details for advertising, or track you across other companies' apps and websites. Group information is private from the public, but it is intentionally visible to authorized members of that group.
Information we collect
| Category | Examples and source |
|---|---|
| Account information | Name, email address, password hash, account settings, verified-email status, and Apple or Google account identifier when you choose that sign-in method. We do not receive your Apple or Google password. |
| Expenses and financial records | Groups, members, invitations, descriptions, categories, notes, dates, currencies, amounts, payers, participants, splits, balances, cash-settlement records, and change history entered by you or another group member. |
| Receipts and other content | Receipt images you choose to upload, file and processing details, and information you include in a support request. Visible receipt content may contain personal information even after image metadata is removed. |
| App and device activity | Session identifiers, app or browser version, operating system, synchronization operations, record revisions, conflict details, and upload status needed to operate the app and make retries safe. |
| Service and security information | IP address, request time, user agent, response status, rate-limit events, session activity, and security audit events. Ordinary service logs are designed not to contain passwords, authentication tokens, receipt contents, or full expense notes. |
Information from other people
A group member may add your name as a provisional member, invite your email address, or include your name in an expense before you create an account. Contact us if you believe someone added your information improperly.
Information stored on your device
The web app uses first-party cookies for sign-in and IndexedDB for app records and pending changes. The iOS app uses SwiftData for app data and Keychain for protected session credentials. We do not use third-party advertising cookies or advertising identifiers.
How we use information
- Authenticate accounts, maintain groups, calculate balances, synchronize changes, store receipts, and create available exports.
- Show shared records to authorized group members and deliver account, invitation, security, and support messages.
- Detect duplicate operations and conflicts, preserve an accurate history, prevent abuse, and enforce account and group permissions.
- Diagnose failures, maintain backups, test recovery, and improve the service's reliability and accessibility.
- Comply with applicable law and respond to valid legal requests.
Depending on where you live, these uses rely on providing the service you requested, your consent for an optional feature, legitimate interests in operating and securing the service, or a legal obligation.
Who receives information
People in your groups
Authorized group members can see the names, expenses, splits, balances, settlements, receipts, and history available to their role. They may save or export information they can see. Removing a member stops later access after revocation synchronizes, but cannot retrieve copies that person already made.
Providers used to run the service
| Provider | Purpose |
|---|---|
| Privately operated hosting | Runs the application, database, and private receipt storage. |
| Cloudflare | Provides DNS, edge delivery, encrypted transport, and abuse protection for the public service. |
| Apple and Google | Provide optional sign-in when you select the corresponding provider. |
| Email and backup providers | Deliver requested service messages and hold encrypted disaster-recovery copies when those services are configured. This policy will name the selected production providers before they receive user information. |
Providers may use information only to perform the services requested from them and must protect it consistently with this policy. We may also disclose information when reasonably necessary to comply with law, protect a person or the service, investigate abuse, or complete a transfer of the service with notice and comparable protections. We do not sell personal information or share it for cross-context behavioral advertising.
Retention and deletion
| Information | Retention |
|---|---|
| Account and active-group data | Kept while your account is open or while the group needs the record. We do not automatically delete an account merely because it has been inactive. |
| Shared ledger and audit history | Kept while needed to preserve an affected group's accounting history, synchronization integrity, security, or a legal obligation. If you delete your account, required shared records are disconnected from the account and your identity is replaced with a de-identified participant label. |
| Receipt images | Kept until an authorized person removes the receipt or its related record no longer requires it. Deletion from active storage is queued promptly and normally completes within seven days. A receipt needed by remaining group members is not erased solely because its uploader deletes an account. |
| Sessions and temporary links | Sessions normally expire after 30 days. Verification links expire after 24 hours, password-reset links after 30 minutes, and group invitations after seven days. Revoked or expired credentials cannot be used even if a minimal security record remains. |
| Operational logs | Kept for no more than 30 days, unless a specific security incident or legal obligation requires a limited record for longer. |
| Encrypted backups | Deleted data may remain in restricted backup generations for up to 12 months before aging out. Backups are used only for disaster recovery and are not used to restore a deleted account as an active account. |
Account deletion revokes sessions and delegated API keys, removes the active account, and deletes or de-identifies personal information that is no longer needed. Shared facts may remain so another member's payment and balance history is not silently rewritten.
Your choices and rights
The app lets you review shared records, export available device data as CSV or JSON, manage group access where your role permits, and permanently delete your account from Settings. You can also email us to ask for access, correction, deletion, restriction, portability, or help with a privacy request. We may need to verify your identity and authority over a group before acting.
Rights vary by location and may be limited by another person's rights, security needs, shared accounting history, or applicable law. To make a request, email support@settlethetab.com. Do not send identity documents unless we specifically request them through a verified process.
Children and teens
Settle The Tab is not directed to children under 13, and we do not knowingly collect their personal information. A person who is 13 but below the age of legal adulthood where they live should use the service only with permission from a parent or guardian. Contact us if you believe a child provided information improperly.
Security and data location
We use HTTPS, protected cookies and iOS Keychain storage, memory-hard password hashing, server-side authorization, private database and receipt services, restricted administrative access, encrypted backups, and receipt re-encoding that removes embedded image metadata. No service can guarantee absolute security; review group membership, protect your devices, and report unexpected access.
Primary systems are privately operated. Cloudflare, sign-in, email, and backup providers may process limited information in the United States and other countries where they operate. Applicable data protection rights continue to apply when information is processed across borders.
Changes and contact
We will update this policy when the product, providers, or legal requirements materially change and will change the date above. When appropriate, we will also provide notice in the service or by email.
Settle The Tab is operated by an individual developer. The privacy and support contact is support@settlethetab.com. If a formal request requires the operator's legal identity or postal contact, request it through that address. The developer's legal name is also displayed as the seller on the App Store listing.