SharingBill
Back to homeLog in
TermsPrivacyCookiesContact

Last updated August 30, 2026

Privacy Policy

This policy explains what data SharingBill collects, why it is processed, which providers support the service, and how users can exercise privacy rights.

This page is provided for transparency for an early-stage MVP. It is not legal advice and may be updated as SharingBill evolves.

1. Controller and contact

SharingBill is currently operated as a personal MVP project. For privacy requests or questions, contact [email protected].

2. Data collected

SharingBill may process your email address, display name, password hash, pending registration and email-verification records, session records, password reset records, books, invite codes, members, placeholder members, roles, expenses, participant splits, balances, settlement records, and technical data needed to operate, secure, and debug the service.

3. Purposes of processing

Data is processed to provide account registration, login, sessions, password resets, shared book collaboration, invites, expenses, settlements, service messages, security, abuse prevention, debugging, and reliability.

4. Legal basis

For users in the EU or Germany, processing is primarily based on providing the requested service, legitimate interests in operating and securing the service, and compliance with applicable legal obligations where relevant.

5. Service providers

SharingBill uses infrastructure and communication providers to operate the service, including Railway and PostgreSQL hosting for application and database infrastructure, Resend for production email delivery, and Cloudflare or DNS services for domain routing.

6. Cookies and sessions

SharingBill uses an HTTP-only session cookie that is necessary to keep users logged in. The service does not currently use advertising cookies or third-party tracking cookies.

7. Retention

Unverified registration records expire after 24 hours and are deleted during later registration or verification activity. Account and book data is generally retained while the account or book remains active. For accountability, an administrator-only deletion record containing the former email address, display name, deletion reason, operator, and time may be retained for up to 365 days. Completed administrative audit, deletion-request, and legal-notice delivery records are also generally retained for up to 365 days. Some shared ledger records may be retained where needed for service integrity, the rights of other members, dispute handling, or legal obligations.

8. Your rights

Depending on your location and applicable law, especially under GDPR in the EU, you may have rights to access, rectify, erase, restrict, or receive your personal data, and to object to certain processing. Signed-in users can request account deletion from the Account page, or contact us for exceptional review. On approval, login identifiers are removed. A shared book may continue to show the member name with a deleted marker, together with expenses and settlements needed by its other members. You may also have the right to lodge a complaint with a data protection supervisory authority.

9. Security

SharingBill uses password hashing, HTTP-only sessions, and managed infrastructure providers. No online service can be guaranteed to be perfectly secure, so users should avoid storing unnecessary sensitive information in expense titles, member names, or notes.

10. Changes

This policy may be updated as SharingBill changes. Material updates will be reflected on this page with a new last-updated date.