Last updated August 30, 2026
Privacy Policy
This policy explains what data SharingBill collects, why it is processed, which providers support the service, and how users can exercise privacy rights.
This page is provided for transparency for an early-stage MVP. It is not legal advice and may be updated as SharingBill evolves.
1. Controller and contact
SharingBill is currently operated as a personal MVP project. For privacy requests or questions, contact [email protected].
2. Data collected
SharingBill may process your email address, display name, password hash, pending registration and email-verification records, session records, password reset records, books, invite codes, members, placeholder members, roles, expenses, participant splits, balances, settlement records, and technical data needed to operate, secure, and debug the service.
3. Purposes of processing
Data is processed to provide account registration, login, sessions, password resets, shared book collaboration, invites, expenses, settlements, service messages, security, abuse prevention, debugging, and reliability.
4. Legal basis
For users in the EU or Germany, processing is primarily based on providing the requested service, legitimate interests in operating and securing the service, and compliance with applicable legal obligations where relevant.
5. Service providers
SharingBill uses infrastructure and communication providers to operate the service, including Railway and PostgreSQL hosting for application and database infrastructure, Resend for production email delivery, and Cloudflare or DNS services for domain routing.
6. Cookies and sessions
SharingBill uses an HTTP-only session cookie that is necessary to keep users logged in. The service does not currently use advertising cookies or third-party tracking cookies.
7. Retention
Unverified registration records expire after 24 hours and are deleted during later registration or verification activity. Account and book data is generally retained while the account or book remains active. For accountability, an administrator-only deletion record containing the former email address, display name, deletion reason, operator, and time may be retained for up to 365 days. Completed administrative audit, deletion-request, and legal-notice delivery records are also generally retained for up to 365 days. Some shared ledger records may be retained where needed for service integrity, the rights of other members, dispute handling, or legal obligations.
8. Your rights
Depending on your location and applicable law, especially under GDPR in the EU, you may have rights to access, rectify, erase, restrict, or receive your personal data, and to object to certain processing. Signed-in users can request account deletion from the Account page, or contact us for exceptional review. On approval, login identifiers are removed. A shared book may continue to show the member name with a deleted marker, together with expenses and settlements needed by its other members. You may also have the right to lodge a complaint with a data protection supervisory authority.
9. Security
SharingBill uses password hashing, HTTP-only sessions, and managed infrastructure providers. No online service can be guaranteed to be perfectly secure, so users should avoid storing unnecessary sensitive information in expense titles, member names, or notes.
10. Changes
This policy may be updated as SharingBill changes. Material updates will be reflected on this page with a new last-updated date.