Legal
Privacy policy
Last updated: March 2026
Information we collect
- Account: name, email, and optionally phone number and profile photo.
- Expenses: descriptions, amounts, currencies, categories, dates, split details, and receipt images you upload.
- Game sessions: game names, player buy-ins, rebuys, final amounts, and settlement records.
- Connections: who you share expenses with.
- Device: push notification tokens (if you enable notifications), device type for crash reporting.
- Usage: login timestamps and feature usage. No third-party analytics.
How we use your data
- Operating the service: balances, splits, notifications.
- Receipt processing: images sent to Anthropic's Claude Vision API for text extraction. Anthropic does not store or use these images beyond processing your request.
- Improving the service via aggregated, anonymized usage patterns.
- We never sell, rent, or share personal information with advertisers or data brokers.
Data storage and security
- Hosted on Supabase (AWS us-west-2 region).
- Row-level security policies ensure users can only access their own data and data shared with them.
- All communication encrypted via TLS/HTTPS.
- Passwords hashed using bcrypt via Supabase Auth.
- Receipt images stored in private Supabase Storage buckets with authenticated access only.
Data retention
- Active account data is retained as long as your account exists.
- Deleted expenses are soft-deleted and permanently purged after 30 days.
- Account deletion permanently removes all data within 30 days.
- Push notification tokens removed when you log out or unregister.
Your rights
- Access: view all your data in the app at any time.
- Export: download a complete JSON copy of your data (Profile → Data).
- Deletion: permanently delete your account and all associated data.
- Correction: update your profile information at any time.
- These rights apply regardless of your location (GDPR, CCPA, PIPEDA compliance).
Third-party services
- Supabase (database, auth, storage).
- Anthropic Claude (receipt scanning AI — images processed on demand, not stored).
- No Google Analytics, Facebook Pixel, or ad networks.
Children's privacy
FairSlice is not directed at children under 13. We do not knowingly collect data from children.
Changes to this policy
We'll update the "Last updated" date when changes are made. Continued use constitutes acceptance.
Contact
Questions about this policy? Reach us via the Contact page.