Privacy Policy
Effective August 19, 2026 · Last updated August 19, 2026
1. Introduction
This Privacy Policy explains how Settle (“we”, “us”) collects, uses, shares, and protects personal information when you use the Settle mobile application, the website at https://joinsettle.app, and the guest bill pages served from it (together, the “Service”).
We have written this policy to be read, not to be skimmed past. If anything is unclear, contact us at privacy@joinsettle.app.
2. Three things to know up front
We never receive your money. Settle does not process, hold, or transmit funds. We have no access to your bank accounts or payment app balances, and we never see any transaction you make. See Section 4.3 for what this means for the payment identifiers you do give us.
We never sell your personal information, and we do not share it for cross-context behavioural advertising. There is no advertising in Settle.
We do not use your content to train machine learning models. Your receipts, expense descriptions, and bill data are used to operate the Service for you and no one else.
3. Information you give us
Website waitlist
When you join the waitlist, we store your email address and the time and version of your consent in Supabase. We use it to send launch news and occasional Settle updates. We retain your subscription until you opt out or the list is discontinued. To opt out or request deletion, email privacy@joinsettle.app. We store a signup flag in your browser to avoid showing the invitation again, and a session flag when you dismiss it.
3.1 Account information
- Your name and email address, from Sign in with Apple, Google, or email registration
- If you use Sign in with Apple with the “Hide My Email” option, we receive an Apple private relay address (
@privaterelay.appleid.com) instead of your real address, and that is all we ever have - Your chosen handle, which is public within the Service
- A profile photo, if you add one
3.2 Payment identifiers
If you choose to add them, we store identifiers for third-party payment services — for example a Venmo username, Cash App cashtag, PayPal.me link, Zelle email or phone number, UPI VPA, GCash mobile number, Pix key (which may be a CPF, phone number, email address, or random key), Mercado Pago alias, or an 18-digit CLABE for SPEI bank transfers.
These are addressing information, not credentials. They tell someone where to send money, in the same way a postal address tells someone where to send a letter. We never ask for and never store bank account numbers used for withdrawal, card numbers, CVVs, PINs, passwords, or login credentials for any payment service.
We nevertheless treat these identifiers as sensitive. Note that a Brazilian CPF used as a Pix key is a national identification number, and a CLABE identifies a specific bank account. Section 4.3 explains exactly who can see them.
3.3 Expense and bill content
- Expense descriptions, amounts, currencies, dates, and categories
- Who participated in a bill and how it was divided
- Group names, cover images, and membership
- Notes you add
- Whether you or another user has marked something as paid
3.4 Receipt images
If you use receipt scanning, we receive the photograph you take and the data extracted from it. See Section 5.
3.5 Communications
Messages you send us for support, and any feedback you submit.
4. Information collected automatically
4.1 Device and usage information
- Device type, operating system version, and app version
- Device region and language settings, used to select your default currency and language
- Crash reports and diagnostic logs
- Basic usage events, such as which screens are opened, used to fix problems and improve the app
- IP address, used for security, abuse prevention, and rate limiting, and retained only briefly
4.2 We do not collect your location
Settle never requests location permission and does not collect GPS, precise location, or approximate location data.
To pre-select your currency we read the region setting configured on your device — the same setting that determines your date format. This is a device preference, not a location measurement, it requires no permission, and it is never transmitted for the purpose of determining where you physically are.
4.3 How your payment identifiers are shared
This is the most important disclosure in this policy.
When you add a payment identifier, you are instructing us to show it to people who need to pay you. Specifically, it becomes visible to:
- Other Settle users on a bill where you are owed money, and
- Any person holding a valid share link to such a bill, including people who do not have a Settle account and whom we cannot identify.
Share links are unguessable but are not otherwise access-controlled. Anyone the link is forwarded to can see it.
We limit this in two ways. Only the identifiers of the person who is owed money on a given bill are returned to a share link — not those of every participant. And the guest page is served with Referrer-Policy: no-referrer, so that when a visitor taps through to a payment app, the share link itself is not leaked to that third party.
Do not add a payment identifier you are not willing to have seen by everyone your bills are shared with.
5. Receipt scanning
When you photograph a receipt, the image is uploaded to our storage and sent to OpenAI, which extracts the merchant, line items, and totals and returns them to us.
5.1 Retention
- Images attached to a bill are retained for as long as that bill exists, as a record of what was spent. They are deleted when you delete the expense or your account.
- Unprocessed or unused photos — images uploaded but never attached to a bill, including abandoned or failed scans — are deleted after 24 hours.
- Extracted text remains attached to the expense until the expense is deleted.
5.2 How OpenAI handles the images
- Your receipts are not used to train any model. Data submitted through OpenAI's API is not used for model training by default, and we have not entered into any arrangement that changes this.
- OpenAI retains API inputs and outputs for up to 30 days for abuse monitoring, after which they are deleted, unless longer retention is required by law. This is OpenAI's standard API retention policy.
- OpenAI acts as our processor and is restricted to processing the images for the purpose of returning extracted text to us.
5.3 Your responsibility
A receipt may contain information beyond the purchase itself — the last four digits of a card, a server's name, a loyalty number, or a table number. Only photograph receipts you are comfortable uploading, and only ones you have the right to upload.
6. How we use information
| Purpose | Examples |
|---|---|
| Providing the Service | Creating your account, recording expenses, calculating splits, generating share links, showing balances |
| Payment facilitation | Displaying your payment identifiers to people who owe you; building deep links and payment codes |
| Receipt processing | Extracting line items from images you submit |
| Notifications | Bill invitations, friend requests, group invites, payment confirmations, and — for Settle Pro — automatic reminders |
| Subscriptions | Determining whether your account has an active Settle Pro entitlement |
| Support | Answering your questions and investigating problems |
| Security and abuse prevention | Rate limiting, fraud detection, enforcing our Terms |
| Improvement | Diagnosing crashes and understanding which features are used |
| Legal compliance | Responding to lawful requests and meeting our obligations |
7. Legal bases (EEA, UK, and Switzerland)
Where the GDPR or UK GDPR applies, we rely on:
- Performance of a contract — operating the Service, maintaining your account, processing bills and receipts you submit
- Legitimate interests — security, abuse prevention, service improvement, diagnostics, and defending legal claims, balanced against your rights
- Consent — push notifications and any optional analytics, which you may withdraw at any time
- Legal obligation — responding to lawful requests and retaining records where required
8. Who we share information with
We do not sell personal information. We share it only as described here.
8.1 Other users
Your handle, display name, profile photo, expense entries, and — where you are owed money — your payment identifiers are visible to people you split with and to holders of a share link.
8.2 Service providers (processors)
| Provider | Role | Data |
|---|---|---|
| Supabase | Database, authentication, file storage, serverless functions | All account and bill data, receipt images |
| OpenAI | Receipt text extraction | Receipt images |
| RevenueCat | Subscription management and entitlement | An anonymized user identifier and subscription status |
| Apple (APNs) / Google (FCM) | Push notification delivery | Device push token, notification content |
| Transactional email provider | Transactional email | Email address, message content |
| Crash reporting provider | Crash reporting and diagnostics | Device and crash data |
Each is bound by contract to process data only on our instructions and to protect it appropriately.
Transactional emails never contain payment identifier values. A notification may tell you that someone added a payment method; it will not include the identifier itself.
8.3 Legal and safety
We may disclose information where we reasonably believe it is required by law, or necessary to protect the rights, safety, or property of any person, or to investigate fraud or a breach of our Terms.
8.4 Business transfer
If we are involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction. We will notify you and this policy will continue to apply until replaced.
9. International transfers
We operate globally and your information may be processed in countries other than your own, including the United States, which may not provide the same level of data protection as your home jurisdiction. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards including the European Commission's Standard Contractual Clauses. Contact privacy@joinsettle.app for details.
10. Retention
| Data | Retained |
|---|---|
| Account and profile | Until you delete your account |
| Payment identifiers | Until you remove them or delete your account |
| Bills and expenses | Until deleted; shared bills persist for other participants in anonymized form |
| Receipt images attached to a bill | Until the expense or account is deleted |
| Unprocessed or unused receipt photos | 24 hours |
| Receipt images held by OpenAI | Up to 30 days for abuse monitoring, then deleted |
| Extracted receipt text | With the expense, until the expense is deleted |
| IP addresses and rate-limit logs | Up to 30 days |
| Crash and diagnostic logs | Up to 90 days |
| Backups | Up to 30 days after deletion from live systems |
11. Deleting your account
You may delete your account at any time from within the app.
- Deletion is subject to a 7-day grace period, during which signing in restores your account.
- After the grace period, your personal information is deleted or irreversibly anonymized.
- Bills you shared with others are not removed from their accounts. Your participation remains visible to them in anonymized form, so their own records stay accurate. This is unavoidable in shared record-keeping and cannot be reversed.
- Backups are purged on the schedule in Section 10.
- Deleting your account does not cancel a subscription. Cancel that in your App Store or Google Play settings.
12. Your rights
Subject to your jurisdiction, you may have the right to access your information, correct it, delete it, receive a portable copy, object to or restrict processing, withdraw consent, and be free from discrimination for exercising these rights.
To exercise any of these, email privacy@joinsettle.app. We will respond within the period required by applicable law — generally 30 days, extendable where permitted. We may need to verify your identity, which we will do using information already associated with your account.
12.1 EEA, UK, and Switzerland
You have the rights above under the GDPR and UK GDPR, and the right to lodge a complaint with your local supervisory authority.
12.2 Brazil (LGPD)
You have the rights under the Lei Geral de Proteção de Dados, including confirmation of processing, access, correction, anonymization or deletion of unnecessary or excessive data, portability, information about entities with whom we share data, information about the consequences of refusing consent, and revocation of consent. You may petition the Autoridade Nacional de Proteção de Dados (ANPD).
Note on Pix keys: if you use your CPF as a Pix key, that is a national identification number and will be visible to people who owe you money and to holders of a share link. Consider using a random key, phone number, or email address as your Pix key instead.
12.3 California (CCPA/CPRA)
You have the right to know, delete, correct, and opt out of sale or sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We do not use or disclose sensitive personal information beyond what is necessary to provide the Service. We will not discriminate against you for exercising your rights.
12.4 India (DPDP Act)
You have the right to access a summary of your personal data and our processing, to correction and erasure, to nominate another person to exercise your rights, and to grievance redressal. Contact privacy@joinsettle.app.
12.5 Other jurisdictions
Residents of other jurisdictions with applicable privacy laws — including Mexico, Indonesia, the Philippines, Nigeria, Kenya, Canada, and Australia — may have comparable rights. Contact us and we will honour any right the law affords you.
13. Security
We protect your information using:
- Encryption in transit (TLS) and at rest
- Row-level security in our database, so records are only accessible to authorized users
- Guest access mediated exclusively by security-definer functions that return only the specific bill a share token references; the anonymous role has no direct table access
Referrer-Policy: no-referreron guest pages, so share tokens are never leaked to third parties- Scoped queries that return only the payment identifiers of the person owed money on a bill
Our public API key is public by design; it grants no access on its own, and all access is controlled by the policies above.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any relevant regulator as required by law.
14. Children
The Service is not intended for anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact privacy@joinsettle.app and we will delete it and terminate the account.
15. Notifications
We send push notifications and emails for bill invitations, friend and group activity, payment confirmations, and — for Settle Pro users — automatic payment reminders. You can control push notifications in your device settings and in the app, and unsubscribe from non-essential emails using the link in each message.
We will still send essential service messages, such as account security notices and changes to these terms.
16. Guest visitors
If you open a shared bill link without a Settle account, we process:
- The share token in the URL, to retrieve the bill
- Your IP address, briefly, for rate limiting and abuse prevention
- Any payment confirmation you submit
We do not create an account for you, do not set advertising cookies, and do not track you across sites. Guest bill pages are marked noindex so they are not listed by search engines.
17. Changes to this policy
We may update this policy. If we make material changes we will notify you through the Service or by email before they take effect, and update the date above. Continued use after that constitutes acceptance.
18. Contact
Privacy enquiries and rights requests: privacy@joinsettle.app
Settle is operated as a sole proprietorship by Settle in Oregon, United States. Settle is the data controller for the purposes of the GDPR and UK GDPR, and the data fiduciary for the purposes of India's DPDP Act.