Zippity-Split has no accounts and no sign-in, and we never ask for your name, email address or phone number. Your bills stay on your own device. Three things can leave it: a receipt image is sent for parsing when you scan one (and is not kept); on Android the app reports anonymous usage and crash statistics so we can tell what is working; and on Android's free tier the advert banner sends Google the kind of data adverts run on, including your device's advertising ID. All three are described in full below. Where the Android and iPhone apps differ, this page says so.
This policy describes what the app does today. If it changes, this page changes with it.
Bill data — items, prices, who claimed what, and totals — lives on the host's device. That is the only copy that outlasts the meal: there is no cloud backup and no sync, and we never build a record of your bills.
Getting it to your guests takes one of two routes. On the same Wi-Fi, the host's phone serves them directly and nothing touches our servers at all. From further away, the bill travels through our relay, which keeps the latest copy while the table is open so that a guest whose phone drops out has something to come back to. That copy goes when the table closes. It is held as a block of text we never open, and nothing in it is read, indexed or used for anything.
The current session is cleared whenever the app's server restarts. Separately, the host device keeps a receipt history of past bills so you can look them up later. That history is stored on the host device only, and stays there until you delete it or uninstall the app.
A guest's tip is a special case: it is kept only in that guest's own browser. It is never sent to the host or to any other guest, and never reaches us.
When you scan a receipt, the image is sent over an encrypted connection to our server (running on Cloudflare), which passes it to Google's Gemini models to read the line items and prices. The parsed text comes back to your phone.
We ask first. Before the first receipt photograph ever leaves your device, the app shows you a disclosure naming Google's Gemini and saying exactly what is sent, and nothing is sent until you agree. If you decline, nothing is sent and no scan happens.
This applies to online mode, which is what sends the photo. To scan without sending anything, switch the app to offline mode using the mode pill at the top of the screen: the receipt is then read entirely on your phone. Offline scanning needs on-device AI, which not every phone has — where it is missing, the app tells you so rather than pretending.
The image is not stored. Our server holds it only in memory for the length of that one request and writes it to no database, bucket or log. We keep no copy, and we cannot look at your receipts. Google processes it under their terms of service.
On Android devices with built-in on-device AI, scanning while offline is handled entirely on the phone and no image leaves it at all.
Zippity-Split requests camera permission for one purpose only: scanning receipts. The camera is never used for any other purpose. Photos are used for the parsing step described above and are not stored by us.
Each guest is given a name automatically — an "{adjective} {animal}" pair such as "Brave Otter" — generated on their own device and remembered in their browser's localStorage. You can change it to whatever you like, and some people type their real first name.
Whichever name you end up with travels with the bill, because the point of it is that everyone at the table can see who claimed what. When guests reach the host through our relay rather than over your own Wi-Fi, that means the name passes through our server and is held there, alongside the rest of the bill, for as long as the table is open. It is deleted with the table. We do not read it, we never link it to anything else, and nothing about it reaches our usage analytics. If you would rather we never saw a name at all, keep the one you were given or type something that is not yours.
The host device holds guest identifiers only for the duration of the active bill session.
The Android app includes Google Firebase Analytics and Firebase Crashlytics. The iPhone app does not include them and sends us no usage analytics or crash reports of its own; Apple may share anonymised crash reports with us only if you have opted in to that on your device. On Android, these record anonymous information about how the app is used and when it breaks:
What the app itself sends never includes: your name or email, receipt images, restaurant names, item names, prices, totals, or guest names. That is enforced in code, by rejecting any analytics value whose name suggests it carries that kind of content. Be clear about the limit of that guarantee: it governs what we send, not the identifiers in the list above, which Google's SDKs generate and handle for themselves. The advertising ID in particular is Google's, not ours.
Our own server also records anonymous statistics about receipt parsing — how long a parse took, how many items came back, and which model answered. These carry no identifier of any kind and cannot be linked to a person or a device.
On Android, the free tier shows a banner advert supplied by Google AdMob. The iPhone app shows no advertising at all. To serve and measure that banner, Google collects your device's advertising ID, its app set ID, your IP address, what you tap in the app and basic diagnostics, and uses them for advertising, analytics and fraud prevention under their policies. This is the one place where data about you goes to a third party for that third party's own purposes. Buying Pro removes the banner, and with it this entire paragraph.
The web page your guests see currently carries no third-party advertising. The space at the bottom shows a link to download the app, served by us.
We do not sell your data, and we do not share bill contents or receipt images with advertisers.
The Pro upgrade is a one-time in-app purchase handled entirely by the store you bought it from: Google Play Billing on Android, or Apple's App Store on iPhone. We never see or store your payment details. The app asks the store whether this device owns the upgrade; that answer is held for the session and is not written to disk.
To keep the free tier honest, the Android app stores an encrypted record of how many receipts you have scanned in your device's own storage, where it survives uninstalling and reinstalling the app. It contains the scan count and a random install identifier. The file itself stays on your device and is never transmitted to us; the identifier inside it is the same random one the anonymous analytics above use, so that a reinstall does not look like a new person. The exact count never leaves the device — only the range described above. On iPhone the count is kept in the app's own storage and is removed when you delete the app.
Our server sees the IP address of any request made to it, as every internet server does. We use it in two ways: to count parsing requests per hour so no one can overload the service (that count is discarded after an hour), and it is recorded alongside any feedback you choose to send. We do not attach it to the usage analytics above, and we do not use it to build a profile of you. Google's own SDKs see your IP separately, as the Analytics and Advertising sections describe.
Sending feedback is entirely optional. If you choose to send it, that submission — the message you write, basic technical context (app version, device model, platform, and how the most recent receipt was parsed), your IP address, and any receipt image you explicitly choose to attach — is sent to and stored on our backend (Cloudflare) so we can diagnose and fix the problem.
Feedback is deleted after 90 days — both the record itself and any image you attached. Feedback is used only to improve the app, and is never sold or given to advertisers.
When used in offline hotspot mode, bill data remains entirely on the local network created by your device and none of it reaches the internet. On devices with on-device AI, receipt parsing in this mode also happens entirely on the phone.
Hotspot mode is available on supported Android devices only. Analytics and crash reports gathered while offline are stored on the device by the Firebase SDK and sent the next time you have a connection.
When guests are not on the same Wi-Fi, the guest page is served through our relay service, or from the host's phone through a Cloudflare tunnel, so it can be reached from anywhere. Both run on Cloudflare, and the relay holds the bill only for as long as the table is open. Cloudflare carries that traffic under their privacy policy. The lasting copy of the bill is the one on the host's phone; what the relay keeps is a working copy for the length of the table, as described under Bill Data.
In summary, the third parties involved are:
There is no one else. We do not sell data to anybody.
If you enter your email address on our beta sign-up page, we store that address for 90 days so we can add you to the tester list. It is used for nothing else.
Most of what Zippity-Split holds never leaves your own device, so deleting it is something you do rather than something you ask us for. Here is every category, in one place.
.zs_scan_tracker in your device's Downloads folder, holding a scan count and a random install identifier. It deliberately survives uninstalling the app; delete that file to remove it. On iPhone it lives in the app's own storage and deleting the app removes it. The file is never sent to us, though the identifier in it is the one the anonymous analytics use.This policy is linked inside the app, under Privacy in the bottom bar, as well as from our store listing.
For anything else, or if a request here does not work, email support@zippitysplit.app and we will deal with it.
Zippity-Split does not knowingly collect personal information from children under 13. The app does not require an account or any personal information.
If we make material changes to this privacy policy, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
Questions about this privacy policy? Reach us at support@zippitysplit.app.