Privacy Policy
1. Introduction & Overview
At SplitLedger AI (“we”, “our”, or “us”), your privacy and financial security are our foundational commitments. This Privacy Policy details how we collect, process, protect, and handle your information when you use our web platform, mobile experiences, and associated APIs.
SplitLedger AI is built specifically for personal expense tracking, group bill sharing, roommate budgets, trip ledgers, and intelligent debt settlements. We adhere to the highest international data privacy standards and the Digital Personal Data Protection Act (DPDPA).
2. Information We Collect
To provide seamless shared expense calculations and intelligent financial features, we collect the following categories of information:
A. Personal Information
When you create an account via Clerk authentication, we securely record your full name, email address, avatar image, phone number (if provided for WhatsApp reminders), and user ID.
B. Financial Transaction Data
Transaction amounts, currencies (primarily INR ₹), expense dates, merchant or payee descriptions, payment modes (UPI, Card, Cash), category classifications, and settlement records.
C. Group & Social Data
Group titles, member email associations, split percentages, debt graph balances, and trip itinerary associations.
D. Financial Notes & Journal Entries
User-created notes, markdown memos, expense reminders, and custom tags created within the Financial Notes module.
E. Attachments & Receipt Images
Images and PDF documents uploaded for receipt scanning or document vault storage. Optical Character Recognition (OCR) extracts text strictly for transaction creation.
F. Cookies & Local Storage
Essential authentication session tokens, theme state preferences (dark/light mode), and temporary client-side form caches. We do NOT use invasive advertising tracking cookies.
G. Analytics & Diagnostic Logs
Aggregated telemetry, API latency measurements, and error stack traces to diagnose system crashes and optimize database performance.
3. How Data Is Used
We process your data strictly to deliver and enhance SplitLedger AI features:
- Compute multi-member greedy debt settlements and optimal repayment graphs.
- Generate pre-filled NPCI compliant UPI QR payment codes (`upi://pay`).
- Provide AI-powered transaction categorization and OCR receipt item extraction.
- Send critical security notifications, settlement balance updates, and payment alerts.
- Calculate personal spending metrics, category budgets, and financial health trends.
4. Security & Encryption
SplitLedger AI implements enterprise-grade security protocols across all infrastructure tiers:
Every byte transmitted between your browser and our servers is secured using modern TLS 1.3 encryption with strict HSTS headers.
All database tables, attachments, and backups are stored using 256-bit Advanced Encryption Standard (AES-256) on Neon PostgreSQL.
5. Third-Party Services & Subprocessors
We work with trusted enterprise cloud vendors to deliver platform functionality:
6. Data Retention Policies
We retain personal and financial records for as long as your account remains active. Upon your explicit request to delete your account, your data is completely purged from production databases within 30 days and permanently deleted from backup rotation within 60 days.
7. User Rights & Data Export
You maintain full sovereignty over your personal and financial information:
Export your complete financial transaction history, notes, and group ledgers anytime in structured JSON or CSV format directly from your Account Settings.
Permanently delete your profile, transactions, notes, and group associations with a single confirmation in Account Settings or by emailing support.
8. Children's Privacy
SplitLedger AI is not intended for use by individuals under 13 years of age. We do not knowingly solicit or collect personal information from children. If we discover that a minor under 13 has provided personal data, we will promptly delete it.
9. Changes to This Policy
We may periodically revise this Privacy Policy to reflect feature additions or regulatory requirements. Whenever significant changes occur, we will provide conspicuous notice via email and update the “Last updated” timestamp at the top of this document.
10. Contact & Privacy Office
If you have questions, inquiries, or grievance requests concerning this Privacy Policy or our data handling practices, reach our Data Protection Officer directly: