Privacy Policy
Last updated: August 10, 2026


Content
1. Introduction
This Privacy Policy explains how Tabsnap B.V. ("Tabsnap", "we", "us", "our") collects, uses, and protects your personal data when you use the Tabsnap iOS app and the tabsnap.app website, including the split.tabsnap.app and pay.tabsnap.app pages. Tabsnap B.V. is a private limited company (besloten vennootschap) registered in the Netherlands (Berkenweg 11, 3941 JA Doorn, KvK 42128754) and is the Data Controller for the personal data described here.
Tabsnap is a bill-splitting app. You scan a restaurant receipt, split the items between the people at the table, and everyone pays the host through the host's own payment link. Tabsnap does not handle money itself.
If you have questions about this policy, email contact@tabsnap.app.
1. Introduction
This Privacy Policy explains how Tabsnap B.V. ("Tabsnap", "we", "us", "our") collects, uses, and protects your personal data when you use the Tabsnap iOS app and the tabsnap.app website, including the split.tabsnap.app and pay.tabsnap.app pages. Tabsnap B.V. is a private limited company (besloten vennootschap) registered in the Netherlands (Berkenweg 11, 3941 JA Doorn, KvK 42128754) and is the Data Controller for the personal data described here.
Tabsnap is a bill-splitting app. You scan a restaurant receipt, split the items between the people at the table, and everyone pays the host through the host's own payment link. Tabsnap does not handle money itself.
If you have questions about this policy, email contact@tabsnap.app.
2. Data we collect
We collect only the data we need to run the app. We do not sell data. We do not use advertising SDKs. We do not track you for marketing.
Account data
A user ID.
Your phone number. It is your account identifier, because sign-in works with a one-time SMS code.
A display name (up to 40 characters).
An avatar colour, and an avatar photo if you set one. Avatar photos are stored in a publicly readable storage bucket: anyone who has the direct image link can view the photo. Choose your avatar photo with that in mind.
An optional email address, only if you choose to add one in your profile. It is used only so we can reach you about your account. It is never used for sign-in, marketing, or account recovery.
App preferences: language and currency.
Notification settings: the in-app push switch and the automatic payment reminders switch.
Your Tabsnap Pro status (whether Pro is active and until when).
A marketing opt-in flag that defaults to off. We send no marketing today.
Account timestamps (created, last sign-in).
Bill data
Venue name, bill date, currency, totals, tax, tip, and service charge.
The items on the bill, with prices and quantities.
Who ordered what (the split).
The participants you add: a name, an avatar colour, and, when you add them from your contacts, their phone number. A participant entry can also contain an email address.
The payment link you paste as host (for example a Tikkie link). We also derive the link's provider and domain and run an automatic check that flags suspicious links, to protect participants from phishing.
Payment-status markers (requested, paid) with timestamps and who set them. A marker can also be set automatically when someone opens your payment link; the host can always correct it.
Extra payment requests when leftover items are assigned to someone after the bill was first shared.
For collaborative splitting: the split method, the expected number of participants, and a join code that powers the link.
For bills in a foreign currency: the exchange rate to EUR, frozen when the bill is created.
An audit log of changes to the bill (edits, participants added, payments marked), with timestamps. Participants on the bill can read it. Entries are deleted after 12 months.
In-app notifications about your bills (for example "X paid their share"), visible only to you, deleted after 90 days.
Saved groups
If you save a group of people you often split with, we store the group name and each member's name and optional phone number. Only you can see your saved groups.
Receipt images
The photo you take of the receipt, stored as a compressed image (up to 3 MB) in a private storage bucket.
Readable in the app by you and by the participants on that bill.
If you share a split or payment link, people with the link see the receipt photo through a short-lived signed link: about 1 hour on the web pages, up to 7 days inside the app.
Contacts matching
Contacts access is off until you grant the iOS Contacts permission.
On your phone, the app reads names and phone numbers only. No photos, no email addresses, no postal addresses.
To check who already uses Tabsnap, the app sends those phone numbers (in standard international format, as the numbers themselves, not as hashes) to our backend in Europe, in batches of at most 200.
The server compares them against existing accounts and returns the matches. It does not store the numbers you submitted. The only thing it writes is a counter on your account that limits how often the check can run.
The match result is kept in the app's memory for at most 1 hour and is never written to disk.
We never upload or store your address book as a whole.
When you add a matched contact to a bill, their name and phone number are stored on that bill as a participant entry. That is what routes the bill to their own Tabsnap account.
Push notification token
If you allow notifications, iOS gives the app a push token and we store it with your account.
We use it to notify you about your bills: for example when someone pays their share, and for payment reminders on open bills.
The content that passes through Apple's push service is a title, a short text, and the bill reference. Nothing else.
The token is deleted when you delete your account, and automatically when Apple reports that the app is no longer on the device.
You control pushes with the notification switch inside the app and with the standard iOS notification settings. Turning notifications off in iOS always stops delivery.
Product analytics
We use PostHog, hosted in the EU, to understand how the app is used and to improve it.
Analytics is on by default in this version. You can switch it off at any time in the app's Settings under "Anonymous analytics". Opting out stops collection and resets the analytics identity.
Your account is referenced only by a one-way hash of your account ID, never the ID itself, and never your name, phone number, or email.
Events are product actions: app opened, sign-up completed, receipt scanned, bill created, bill shared, bill settled, and similar. Amounts appear only as coarse ranges. Item names and venue names are never sent to analytics.
There is no autocapture, no screen recording, and no session replay.
Crash reporting
We use Sentry, hosted in the German region, to detect and fix crashes and errors.
Reports contain technical context: the error, stack trace, iOS version, and device model, plus anonymous session counts for release health.
Crash reports contain no receipt content and no phone numbers. There is no performance tracing.
Service counters and technical records
Scan records: for each receipt scan we record your account ID, whether it succeeded, how long it took, and an internal cost estimate. No receipt content. These records enforce the free scan limit (5 successful scans per calendar month on the free plan; Pro has no monthly limit) and our abuse limits. We keep them as cost records even after account deletion; once your account is deleted, the ID in them no longer links to any profile.
Link statistics: per share link we count opens and App Store taps per invited person. Deliberately no IP address, no browser details, no name. These rows are deleted together with the bill.
Rate-limit counters per account, kept for about 48 hours, plus overall daily limits across the service.
A daily internal cost digest is emailed to ourselves (via Resend) with aggregate usage per internal account ID. Operations only, never marketing.
What we do not collect, and what we never do
No location data. The app never asks for GPS and stores no place data beyond the venue name on the receipt.
No email address at sign-up. Your phone number is the identifier; the profile email is optional and contact-only.
No storage of your contact list (see Contacts matching above).
No credit card numbers and no stored IBANs. Payment runs through the host's own payment link; Tabsnap does not process money.
No advertising identifiers, no ad SDKs, no third-party marketing trackers.
No selling of personal data, to anyone, for any purpose.
No session replay and no screen recording.
No device fingerprinting and no IP-based linking of web visitors to accounts.
No profiles of your eating or spending habits. We store your bills so the app works. We do not analyse them to build taste, habit, or behaviour profiles.
The only SMS we ever send is the sign-in code you request yourself.
No marketing email today. If we ever introduce it, it will be opt-in and off by default.
2. Data we collect
We collect only the data we need to run the app. We do not sell data. We do not use advertising SDKs. We do not track you for marketing.
Account data
A user ID.
Your phone number. It is your account identifier, because sign-in works with a one-time SMS code.
A display name (up to 40 characters).
An avatar colour, and an avatar photo if you set one. Avatar photos are stored in a publicly readable storage bucket: anyone who has the direct image link can view the photo. Choose your avatar photo with that in mind.
An optional email address, only if you choose to add one in your profile. It is used only so we can reach you about your account. It is never used for sign-in, marketing, or account recovery.
App preferences: language and currency.
Notification settings: the in-app push switch and the automatic payment reminders switch.
Your Tabsnap Pro status (whether Pro is active and until when).
A marketing opt-in flag that defaults to off. We send no marketing today.
Account timestamps (created, last sign-in).
Bill data
Venue name, bill date, currency, totals, tax, tip, and service charge.
The items on the bill, with prices and quantities.
Who ordered what (the split).
The participants you add: a name, an avatar colour, and, when you add them from your contacts, their phone number. A participant entry can also contain an email address.
The payment link you paste as host (for example a Tikkie link). We also derive the link's provider and domain and run an automatic check that flags suspicious links, to protect participants from phishing.
Payment-status markers (requested, paid) with timestamps and who set them. A marker can also be set automatically when someone opens your payment link; the host can always correct it.
Extra payment requests when leftover items are assigned to someone after the bill was first shared.
For collaborative splitting: the split method, the expected number of participants, and a join code that powers the link.
For bills in a foreign currency: the exchange rate to EUR, frozen when the bill is created.
An audit log of changes to the bill (edits, participants added, payments marked), with timestamps. Participants on the bill can read it. Entries are deleted after 12 months.
In-app notifications about your bills (for example "X paid their share"), visible only to you, deleted after 90 days.
Saved groups
If you save a group of people you often split with, we store the group name and each member's name and optional phone number. Only you can see your saved groups.
Receipt images
The photo you take of the receipt, stored as a compressed image (up to 3 MB) in a private storage bucket.
Readable in the app by you and by the participants on that bill.
If you share a split or payment link, people with the link see the receipt photo through a short-lived signed link: about 1 hour on the web pages, up to 7 days inside the app.
Contacts matching
Contacts access is off until you grant the iOS Contacts permission.
On your phone, the app reads names and phone numbers only. No photos, no email addresses, no postal addresses.
To check who already uses Tabsnap, the app sends those phone numbers (in standard international format, as the numbers themselves, not as hashes) to our backend in Europe, in batches of at most 200.
The server compares them against existing accounts and returns the matches. It does not store the numbers you submitted. The only thing it writes is a counter on your account that limits how often the check can run.
The match result is kept in the app's memory for at most 1 hour and is never written to disk.
We never upload or store your address book as a whole.
When you add a matched contact to a bill, their name and phone number are stored on that bill as a participant entry. That is what routes the bill to their own Tabsnap account.
Push notification token
If you allow notifications, iOS gives the app a push token and we store it with your account.
We use it to notify you about your bills: for example when someone pays their share, and for payment reminders on open bills.
The content that passes through Apple's push service is a title, a short text, and the bill reference. Nothing else.
The token is deleted when you delete your account, and automatically when Apple reports that the app is no longer on the device.
You control pushes with the notification switch inside the app and with the standard iOS notification settings. Turning notifications off in iOS always stops delivery.
Product analytics
We use PostHog, hosted in the EU, to understand how the app is used and to improve it.
Analytics is on by default in this version. You can switch it off at any time in the app's Settings under "Anonymous analytics". Opting out stops collection and resets the analytics identity.
Your account is referenced only by a one-way hash of your account ID, never the ID itself, and never your name, phone number, or email.
Events are product actions: app opened, sign-up completed, receipt scanned, bill created, bill shared, bill settled, and similar. Amounts appear only as coarse ranges. Item names and venue names are never sent to analytics.
There is no autocapture, no screen recording, and no session replay.
Crash reporting
We use Sentry, hosted in the German region, to detect and fix crashes and errors.
Reports contain technical context: the error, stack trace, iOS version, and device model, plus anonymous session counts for release health.
Crash reports contain no receipt content and no phone numbers. There is no performance tracing.
Service counters and technical records
Scan records: for each receipt scan we record your account ID, whether it succeeded, how long it took, and an internal cost estimate. No receipt content. These records enforce the free scan limit (5 successful scans per calendar month on the free plan; Pro has no monthly limit) and our abuse limits. We keep them as cost records even after account deletion; once your account is deleted, the ID in them no longer links to any profile.
Link statistics: per share link we count opens and App Store taps per invited person. Deliberately no IP address, no browser details, no name. These rows are deleted together with the bill.
Rate-limit counters per account, kept for about 48 hours, plus overall daily limits across the service.
A daily internal cost digest is emailed to ourselves (via Resend) with aggregate usage per internal account ID. Operations only, never marketing.
What we do not collect, and what we never do
No location data. The app never asks for GPS and stores no place data beyond the venue name on the receipt.
No email address at sign-up. Your phone number is the identifier; the profile email is optional and contact-only.
No storage of your contact list (see Contacts matching above).
No credit card numbers and no stored IBANs. Payment runs through the host's own payment link; Tabsnap does not process money.
No advertising identifiers, no ad SDKs, no third-party marketing trackers.
No selling of personal data, to anyone, for any purpose.
No session replay and no screen recording.
No device fingerprinting and no IP-based linking of web visitors to accounts.
No profiles of your eating or spending habits. We store your bills so the app works. We do not analyse them to build taste, habit, or behaviour profiles.
The only SMS we ever send is the sign-in code you request yourself.
No marketing email today. If we ever introduce it, it will be opt-in and off by default.
3. Who can see what
Only you: your saved groups, your in-app notifications, your settings, your usage counters, your push token.
Participants on your bill who use the app: the bill, its items, the split, the amounts, the receipt photo, the other participants' names and avatar colours, and the bill's audit log.
Anyone who has a share or join link: a bill summary, the host's display name, the items with their claim status, and the receipt photo through a link that works for about 1 hour. Web visitors do not see other guests' names; every other claimer is shown anonymised. Links expire automatically (currently after 14 days). Anyone holding the link can open it, so share it only with the people at the table.
Who can see your phone number
Tabsnap never displays your phone number, or any other participant's phone number, on any screen. A host who added you from their own contacts keeps the number they themselves supplied. Contact matching answers only whether a number already uses Tabsnap; it does not reveal numbers to anyone. Phone numbers are never included in what web visitors receive.
Our backend currently allows the app of another participant on your bill to request records that include a phone number: the participant entry the host created, and your profile record including your optional email. The app never shows this data. We are rolling out a backend change that removes this access entirely, so that other participants can technically retrieve only your display name and avatar, and participant phone numbers become readable by the host alone. Until that change is fully applied we do not claim that this data is technically inaccessible, only that it is never displayed or used.
3. Who can see what
Only you: your saved groups, your in-app notifications, your settings, your usage counters, your push token.
Participants on your bill who use the app: the bill, its items, the split, the amounts, the receipt photo, the other participants' names and avatar colours, and the bill's audit log.
Anyone who has a share or join link: a bill summary, the host's display name, the items with their claim status, and the receipt photo through a link that works for about 1 hour. Web visitors do not see other guests' names; every other claimer is shown anonymised. Links expire automatically (currently after 14 days). Anyone holding the link can open it, so share it only with the people at the table.
Who can see your phone number
Tabsnap never displays your phone number, or any other participant's phone number, on any screen. A host who added you from their own contacts keeps the number they themselves supplied. Contact matching answers only whether a number already uses Tabsnap; it does not reveal numbers to anyone. Phone numbers are never included in what web visitors receive.
Our backend currently allows the app of another participant on your bill to request records that include a phone number: the participant entry the host created, and your profile record including your optional email. The app never shows this data. We are rolling out a backend change that removes this access entirely, so that other participants can technically retrieve only your display name and avatar, and participant phone numbers become readable by the host alone. Until that change is fully applied we do not claim that this data is technically inaccessible, only that it is never displayed or used.
4. When someone sends you a Tabsnap link (web guests, no account)
You can open a Tabsnap split or payment link in your browser without creating an account.
What we receive from you: the items you claim, an optional display name (up to 80 characters), a random token your browser generates so you can return to your own claim, a paid marker if you mark your share as paid (including how you paid: via the payment link or directly), and a tap on the App Store banner if you use it.
What your browser stores: local storage only. Your random claim token, your last-used name, and a device-local record of any extra charges assigned to you, so a returning visitor still sees what they owe. No cookies. No analytics. No trackers of any kind on these pages.
What you can see: the bill, the host's display name, the items and their claim status (other claimers anonymised), your own share and items, and the receipt photo through a link that works for about 1 hour. The payment page shows only your own share. It never shows other participants' names or amounts.
Server-side: the split page records when your join link was first and last opened; the payment page records only when it was first opened. If you tap the host's payment link, your share can be marked as paid automatically; the host can always correct it. If the host later assigns leftover items to you, an extra payment request is created for exactly those items, and the page shows you that amount before you pay.
What we never do with web guests: no IP logging to identify you, no fingerprinting, no linking of your guest activity to any Tabsnap account behind your back. If you later create an account, your guest claims are not attached to it automatically.
Legal basis and retention: our legitimate interest (Art. 6(1)(f) GDPR) in letting invited people split a bill without an account. Your claim data lives as long as the host keeps the bill and is permanently deleted at most about 30 days after the host deletes it. Expired payment links are deleted 90 days after they expire. None of it is used for marketing or advertising.
The controller is Tabsnap B.V. The pages are served from Vercel's hosting infrastructure (see Sections 6 and 11). Questions: contact@tabsnap.app.
4. When someone sends you a Tabsnap link (web guests, no account)
You can open a Tabsnap split or payment link in your browser without creating an account.
What we receive from you: the items you claim, an optional display name (up to 80 characters), a random token your browser generates so you can return to your own claim, a paid marker if you mark your share as paid (including how you paid: via the payment link or directly), and a tap on the App Store banner if you use it.
What your browser stores: local storage only. Your random claim token, your last-used name, and a device-local record of any extra charges assigned to you, so a returning visitor still sees what they owe. No cookies. No analytics. No trackers of any kind on these pages.
What you can see: the bill, the host's display name, the items and their claim status (other claimers anonymised), your own share and items, and the receipt photo through a link that works for about 1 hour. The payment page shows only your own share. It never shows other participants' names or amounts.
Server-side: the split page records when your join link was first and last opened; the payment page records only when it was first opened. If you tap the host's payment link, your share can be marked as paid automatically; the host can always correct it. If the host later assigns leftover items to you, an extra payment request is created for exactly those items, and the page shows you that amount before you pay.
What we never do with web guests: no IP logging to identify you, no fingerprinting, no linking of your guest activity to any Tabsnap account behind your back. If you later create an account, your guest claims are not attached to it automatically.
Legal basis and retention: our legitimate interest (Art. 6(1)(f) GDPR) in letting invited people split a bill without an account. Your claim data lives as long as the host keeps the bill and is permanently deleted at most about 30 days after the host deletes it. Expired payment links are deleted 90 days after they expire. None of it is used for marketing or advertising.
The controller is Tabsnap B.V. The pages are served from Vercel's hosting infrastructure (see Sections 6 and 11). Questions: contact@tabsnap.app.
5. How we use your data
Each type of processing has a legal basis under the GDPR.
Creating and running your account, storing your bills, splitting them, storing receipt photos, sharing bills with participants, and sending push notifications about your bills when you enable them: performance of a contract (Art. 6(1)(b)).
Parsing the receipt photo with Anthropic's Claude model to turn it into structured items: performance of a contract (Art. 6(1)(b)).
Contacts matching, which runs only after you grant the iOS Contacts permission and use the feature: consent (Art. 6(1)(a)). You can withdraw it at any time in iOS Settings.
Crash reporting: our legitimate interest in keeping the app stable (Art. 6(1)(f)).
Rate limiting, usage caps, the phishing check on payment links, and fraud prevention: our legitimate interest in protecting the service and controlling costs (Art. 6(1)(f)).
Product analytics with a hashed identifier: our legitimate interest in improving the service (Art. 6(1)(f)), with an opt-out in Settings under "Anonymous analytics".
Processing for web guests: our legitimate interest as described in Section 4 (Art. 6(1)(f)).
Future marketing email (none today): your consent, withdrawable at any time (Art. 6(1)(a)).
Receipt scanning (what actually crosses the wire)
When you scan a receipt, your phone first runs a quick on-device pre-fill step. That step never leaves your phone. The photo itself, downscaled and size-capped, is then sent to our backend, which forwards it to Anthropic's Claude model to read it into structured items, totals, tax, and tip. Anthropic processes the image for the duration of the request. We do not train any model on your receipts, and Anthropic does not use them for training under its commercial terms. The original photo stays in our private storage bucket so the host and participants can re-open it.
Free accounts get 5 successful scans per calendar month; Tabsnap Pro removes that monthly limit. Hourly and daily abuse caps apply to everyone.
Currency conversion
For receipts in a foreign currency we fetch exchange rates from a public rate service (Frankfurter, based on European Central Bank data). Only currency codes are requested. No personal data and no receipt content is sent to it.
5. How we use your data
Each type of processing has a legal basis under the GDPR.
Creating and running your account, storing your bills, splitting them, storing receipt photos, sharing bills with participants, and sending push notifications about your bills when you enable them: performance of a contract (Art. 6(1)(b)).
Parsing the receipt photo with Anthropic's Claude model to turn it into structured items: performance of a contract (Art. 6(1)(b)).
Contacts matching, which runs only after you grant the iOS Contacts permission and use the feature: consent (Art. 6(1)(a)). You can withdraw it at any time in iOS Settings.
Crash reporting: our legitimate interest in keeping the app stable (Art. 6(1)(f)).
Rate limiting, usage caps, the phishing check on payment links, and fraud prevention: our legitimate interest in protecting the service and controlling costs (Art. 6(1)(f)).
Product analytics with a hashed identifier: our legitimate interest in improving the service (Art. 6(1)(f)), with an opt-out in Settings under "Anonymous analytics".
Processing for web guests: our legitimate interest as described in Section 4 (Art. 6(1)(f)).
Future marketing email (none today): your consent, withdrawable at any time (Art. 6(1)(a)).
Receipt scanning (what actually crosses the wire)
When you scan a receipt, your phone first runs a quick on-device pre-fill step. That step never leaves your phone. The photo itself, downscaled and size-capped, is then sent to our backend, which forwards it to Anthropic's Claude model to read it into structured items, totals, tax, and tip. Anthropic processes the image for the duration of the request. We do not train any model on your receipts, and Anthropic does not use them for training under its commercial terms. The original photo stays in our private storage bucket so the host and participants can re-open it.
Free accounts get 5 successful scans per calendar month; Tabsnap Pro removes that monthly limit. Hourly and daily abuse caps apply to everyone.
Currency conversion
For receipts in a foreign currency we fetch exchange rates from a public rate service (Frankfurter, based on European Central Bank data). Only currency codes are requested. No personal data and no receipt content is sent to it.
6. Who we share data with
We use a small number of third-party processors. Each processes data only to deliver its part of the service.
Supabase Inc. (data processor). Hosts our database, file storage, sign-in, and server functions. All of it runs in Supabase's eu-central-2 region in Europe. Purpose: the app's backend. Contract: Supabase's data processing agreement.
Anthropic PBC (data processor). Provides the Claude model that parses receipt photos. We send the photo you scan; Anthropic processes it for the duration of the request and does not use it for training under its commercial terms. Location: United States. Transfer mechanism: Standard Contractual Clauses (SCCs) included in Anthropic's Commercial Terms of Service.
Twilio Inc. (data processor). Delivers the one-time sign-in code to your phone number by SMS. Data shared: your phone number and the code message. The code is single-use and expires after 2 minutes. Location: United States, with some routing via EU infrastructure. Transfer mechanism: SCCs under Twilio's Data Processing Addendum. This is the only SMS Tabsnap ever sends.
PostHog (data processor). Product analytics, hosted in the EU. Receives events tied to a one-way hashed account ID only; never your name, phone number, email, item names, or venue names. You can opt out in Settings under "Anonymous analytics".
Sentry (data processor). Crash and error reporting, hosted in the German region. Receives technical error context only.
Apple Inc. (platform, purchase provider, push delivery). Tabsnap is distributed through the App Store under Apple's own privacy terms. Tabsnap Pro is sold through Apple In-App Purchase, so Apple processes the purchase and subscription. Apple's push service (APNs) delivers our notifications to your device. We do not use Sign in with Apple.
Vercel Inc. (data processor, hosting). Hosts and serves the split.tabsnap.app and pay.tabsnap.app pages. Like any web host, Vercel processes standard request data, including IP addresses, in its server logs. We run no trackers on those pages. Location: United States company with a global edge network. Transfer mechanism: Vercel's Data Processing Addendum with SCCs.
Resend Inc. (data processor). Used only to send an internal daily operations digest to ourselves. It sends no email to users today. If we ever use it for user-facing email, we will update this policy first.
Frankfurter (exchange-rate service). Receives no personal data at all; listed for completeness. Only currency codes are requested.
Framer B.V. (data processor, website host; Amsterdam, the Netherlands). The tabsnap.app marketing and legal pages are built and hosted on Framer. Like any web host, Framer sees standard request data such as IP addresses.
We share data with no other third parties. We do not sell your data. We do not share your data for advertising.
6. Who we share data with
We use a small number of third-party processors. Each processes data only to deliver its part of the service.
Supabase Inc. (data processor). Hosts our database, file storage, sign-in, and server functions. All of it runs in Supabase's eu-central-2 region in Europe. Purpose: the app's backend. Contract: Supabase's data processing agreement.
Anthropic PBC (data processor). Provides the Claude model that parses receipt photos. We send the photo you scan; Anthropic processes it for the duration of the request and does not use it for training under its commercial terms. Location: United States. Transfer mechanism: Standard Contractual Clauses (SCCs) included in Anthropic's Commercial Terms of Service.
Twilio Inc. (data processor). Delivers the one-time sign-in code to your phone number by SMS. Data shared: your phone number and the code message. The code is single-use and expires after 2 minutes. Location: United States, with some routing via EU infrastructure. Transfer mechanism: SCCs under Twilio's Data Processing Addendum. This is the only SMS Tabsnap ever sends.
PostHog (data processor). Product analytics, hosted in the EU. Receives events tied to a one-way hashed account ID only; never your name, phone number, email, item names, or venue names. You can opt out in Settings under "Anonymous analytics".
Sentry (data processor). Crash and error reporting, hosted in the German region. Receives technical error context only.
Apple Inc. (platform, purchase provider, push delivery). Tabsnap is distributed through the App Store under Apple's own privacy terms. Tabsnap Pro is sold through Apple In-App Purchase, so Apple processes the purchase and subscription. Apple's push service (APNs) delivers our notifications to your device. We do not use Sign in with Apple.
Vercel Inc. (data processor, hosting). Hosts and serves the split.tabsnap.app and pay.tabsnap.app pages. Like any web host, Vercel processes standard request data, including IP addresses, in its server logs. We run no trackers on those pages. Location: United States company with a global edge network. Transfer mechanism: Vercel's Data Processing Addendum with SCCs.
Resend Inc. (data processor). Used only to send an internal daily operations digest to ourselves. It sends no email to users today. If we ever use it for user-facing email, we will update this policy first.
Frankfurter (exchange-rate service). Receives no personal data at all; listed for completeness. Only currency codes are requested.
Framer B.V. (data processor, website host; Amsterdam, the Netherlands). The tabsnap.app marketing and legal pages are built and hosted on Framer. Like any web host, Framer sees standard request data such as IP addresses.
We share data with no other third parties. We do not sell your data. We do not share your data for advertising.
7. How long we keep data
Account data (phone number, name, avatar, email, preferences): as long as your account exists. Deleted with your account.
Bills, items, splits, participants, and receipt images: until you delete the bill or your account. A deleted bill disappears from the app immediately and the underlying records and receipt files are permanently purged within about 30 days. The receipt files are removed first.
Share and join links: expire automatically (currently after 14 days). A link created for an extra payment request is not cut off at 14 days; it stays usable while that charge is open. The link records are deleted 90 days after their recorded expiry.
In-app notifications: deleted after 90 days.
Bill audit log: deleted after 12 months.
Rate-limit counters: about 48 hours.
Free-scan counter: covers the current calendar month.
Contact match results: at most 1 hour, in the app's memory only, never on disk.
Push token: until you delete your account, or sooner if Apple reports the app is gone from the device.
Analytics events: kept by PostHog under our configured retention, tied only to a hashed ID.
Crash events: kept under Sentry's standard retention period.
Sign-in codes: single-use, expire after 2 minutes. Twilio may retain SMS delivery logs for a short period under its own terms.
Scan cost records: kept for cost accounting, also after account deletion. Once your account is deleted, the ID in them no longer links to any person.
Encrypted backups: kept on a 7-day rolling window.
7. How long we keep data
Account data (phone number, name, avatar, email, preferences): as long as your account exists. Deleted with your account.
Bills, items, splits, participants, and receipt images: until you delete the bill or your account. A deleted bill disappears from the app immediately and the underlying records and receipt files are permanently purged within about 30 days. The receipt files are removed first.
Share and join links: expire automatically (currently after 14 days). A link created for an extra payment request is not cut off at 14 days; it stays usable while that charge is open. The link records are deleted 90 days after their recorded expiry.
In-app notifications: deleted after 90 days.
Bill audit log: deleted after 12 months.
Rate-limit counters: about 48 hours.
Free-scan counter: covers the current calendar month.
Contact match results: at most 1 hour, in the app's memory only, never on disk.
Push token: until you delete your account, or sooner if Apple reports the app is gone from the device.
Analytics events: kept by PostHog under our configured retention, tied only to a hashed ID.
Crash events: kept under Sentry's standard retention period.
Sign-in codes: single-use, expire after 2 minutes. Twilio may retain SMS delivery logs for a short period under its own terms.
Scan cost records: kept for cost accounting, also after account deletion. Once your account is deleted, the ID in them no longer links to any person.
Encrypted backups: kept on a 7-day rolling window.
8. Deleting your account
You can delete your account directly in the app: Settings, then Delete Account. This is immediate and cannot be undone. There is no grace period and no way to restore the account afterwards.
Deletion removes your profile (name, phone number, optional email, avatar photo and files), your bills with their items and splits, your receipt images, your saved groups, your notifications, and your push token. Your analytics consent flag on the device is reset as well.
Where you appeared as a participant on someone else's bill, that entry is detached from your account at the same moment: the link to your account is removed, any phone number or email on the entry is erased, and your name on it is replaced with a neutral "Deleted user" placeholder. The entry itself remains, because it is part of the host's own record of their bill and their totals must keep adding up. Audit-log entries are deleted after 12 months at the latest. Anonymous scan cost records remain without any link to you (see Section 7).
The deletion endpoint is rate-limited against abuse, but it is built so that a technical failure of the limiter can never block a deletion request.
8. Deleting your account
You can delete your account directly in the app: Settings, then Delete Account. This is immediate and cannot be undone. There is no grace period and no way to restore the account afterwards.
Deletion removes your profile (name, phone number, optional email, avatar photo and files), your bills with their items and splits, your receipt images, your saved groups, your notifications, and your push token. Your analytics consent flag on the device is reset as well.
Where you appeared as a participant on someone else's bill, that entry is detached from your account at the same moment: the link to your account is removed, any phone number or email on the entry is erased, and your name on it is replaced with a neutral "Deleted user" placeholder. The entry itself remains, because it is part of the host's own record of their bill and their totals must keep adding up. Audit-log entries are deleted after 12 months at the latest. Anonymous scan cost records remain without any link to you (see Section 7).
The deletion endpoint is rate-limited against abuse, but it is built so that a technical failure of the limiter can never block a deletion request.
9. Your rights
Under the GDPR you have the following rights.
Right of access (Art. 15): ask for a copy of the personal data we hold about you.
Right to rectification (Art. 16): correct data that is wrong or incomplete.
Right to erasure (Art. 17): ask us to delete your data.
Right to restriction (Art. 18): ask us to pause processing in specific cases.
Right to object (Art. 21): object to processing based on legitimate interest.
Right to data portability (Art. 20): receive your data in a structured, machine-readable format (JSON).
Right to withdraw consent (Art. 7): withdraw consent at any time where consent is the legal basis, for example the Contacts permission in iOS Settings or the analytics toggle in the app.
How to use these rights
Contact us at contact@tabsnap.app. Because your phone number is your account identifier, write from an email address you can be reached at and include the phone number tied to your account, so we can verify the request. We respond within one calendar month (extendable by up to two further months for complex requests, per Art. 12(3) GDPR, in which case we will tell you why). No fee applies to reasonable requests.
You can also act directly in the app: delete your account under Settings, switch off analytics under "Anonymous analytics", and control notifications with the in-app switch and iOS Settings. Data-portability requests run through email; there is currently no in-app export of your full account data.
9. Your rights
Under the GDPR you have the following rights.
Right of access (Art. 15): ask for a copy of the personal data we hold about you.
Right to rectification (Art. 16): correct data that is wrong or incomplete.
Right to erasure (Art. 17): ask us to delete your data.
Right to restriction (Art. 18): ask us to pause processing in specific cases.
Right to object (Art. 21): object to processing based on legitimate interest.
Right to data portability (Art. 20): receive your data in a structured, machine-readable format (JSON).
Right to withdraw consent (Art. 7): withdraw consent at any time where consent is the legal basis, for example the Contacts permission in iOS Settings or the analytics toggle in the app.
How to use these rights
Contact us at contact@tabsnap.app. Because your phone number is your account identifier, write from an email address you can be reached at and include the phone number tied to your account, so we can verify the request. We respond within one calendar month (extendable by up to two further months for complex requests, per Art. 12(3) GDPR, in which case we will tell you why). No fee applies to reasonable requests.
You can also act directly in the app: delete your account under Settings, switch off analytics under "Anonymous analytics", and control notifications with the in-app switch and iOS Settings. Data-portability requests run through email; there is currently no in-app export of your full account data.
10. Data security
We take reasonable technical and organisational measures to protect your data.
Data in transit is encrypted using TLS.
Data at rest is encrypted on the database and on file storage.
Access to bills and receipt images is enforced with row-level security, so only the host and the bill's participants can read them in the app.
Receipt photos shared through links use short-lived signed URLs instead of public files.
Pasted payment links are automatically checked and flagged when they look suspicious.
You can additionally protect the app with Face ID / Touch ID (App Lock).
Backups are encrypted.
We do not hold ISO 27001, SOC 2, or similar certifications. We rely on the security posture of Supabase, Anthropic, Twilio, PostHog, Sentry, Vercel, and Apple for the parts of the stack they operate.
10. Data security
We take reasonable technical and organisational measures to protect your data.
Data in transit is encrypted using TLS.
Data at rest is encrypted on the database and on file storage.
Access to bills and receipt images is enforced with row-level security, so only the host and the bill's participants can read them in the app.
Receipt photos shared through links use short-lived signed URLs instead of public files.
Pasted payment links are automatically checked and flagged when they look suspicious.
You can additionally protect the app with Face ID / Touch ID (App Lock).
Backups are encrypted.
We do not hold ISO 27001, SOC 2, or similar certifications. We rely on the security posture of Supabase, Anthropic, Twilio, PostHog, Sentry, Vercel, and Apple for the parts of the stack they operate.
11. International data transfers
Your data is stored primarily in Europe: the backend in Supabase's eu-central-2 region, crash reporting in Sentry's German region, analytics in PostHog's EU cloud.
Some processing involves transfers outside the EU:
Anthropic PBC processes receipt photos in the United States, covered by SCCs in Anthropic's Commercial Terms of Service.
Twilio Inc. delivers SMS sign-in codes from the United States, with some EU routing, covered by SCCs in Twilio's Data Processing Addendum.
Vercel Inc. serves the web split and payment pages from a global edge network operated by a US company, covered by Vercel's Data Processing Addendum with SCCs.
Apple Inc. operates the App Store, In-App Purchase, and push delivery under its own terms and safeguards.
Supabase Inc. is a US company; the data itself is hosted in Europe as described above, and Supabase's data processing agreement applies.
11. International data transfers
Your data is stored primarily in Europe: the backend in Supabase's eu-central-2 region, crash reporting in Sentry's German region, analytics in PostHog's EU cloud.
Some processing involves transfers outside the EU:
Anthropic PBC processes receipt photos in the United States, covered by SCCs in Anthropic's Commercial Terms of Service.
Twilio Inc. delivers SMS sign-in codes from the United States, with some EU routing, covered by SCCs in Twilio's Data Processing Addendum.
Vercel Inc. serves the web split and payment pages from a global edge network operated by a US company, covered by Vercel's Data Processing Addendum with SCCs.
Apple Inc. operates the App Store, In-App Purchase, and push delivery under its own terms and safeguards.
Supabase Inc. is a US company; the data itself is hosted in Europe as described above, and Supabase's data processing agreement applies.
12. Children's privacy
Our digital-consent threshold for creating an account is 16, in line with the default age under the GDPR and the age set by Dutch law (our primary market). You must also have a phone number you are entitled to use, on a line you control, to complete SMS verification. If you are under 16, you need permission from a parent or legal guardian to use Tabsnap and to agree to this Privacy Policy, wherever you live. If we learn that we hold data for a user under 16 without parental consent, we will delete that data.
12. Children's privacy
Our digital-consent threshold for creating an account is 16, in line with the default age under the GDPR and the age set by Dutch law (our primary market). You must also have a phone number you are entitled to use, on a line you control, to complete SMS verification. If you are under 16, you need permission from a parent or legal guardian to use Tabsnap and to agree to this Privacy Policy, wherever you live. If we learn that we hold data for a user under 16 without parental consent, we will delete that data.
13. What we may build next
Tabsnap will grow. Features we are considering include in-app payments and personal insights based on your own bills. None of that exists today, and this policy covers only what the app does now. If we build such features, we will update this policy first, explain exactly what changes, and, where the law requires it, ask for your explicit opt-in consent before your data is used in any new way. Anything that would analyse your bills beyond running the service will be off by default. Two things stay fixed regardless: we do not sell personal data, and we do not use your data for third-party advertising.
13. What we may build next
Tabsnap will grow. Features we are considering include in-app payments and personal insights based on your own bills. None of that exists today, and this policy covers only what the app does now. If we build such features, we will update this policy first, explain exactly what changes, and, where the law requires it, ask for your explicit opt-in consent before your data is used in any new way. Anything that would analyse your bills beyond running the service will be off by default. Two things stay fixed regardless: we do not sell personal data, and we do not use your data for third-party advertising.
14. Changes to this policy
We may update this policy as the app and the law evolve. When we make a material change we will:
Update the "Last updated" date at the top.
Notify you inside the app or by email before the change takes effect.
Continued use of Tabsnap after the change means you accept the new policy.
14. Changes to this policy
We may update this policy as the app and the law evolve. When we make a material change we will:
Update the "Last updated" date at the top.
Notify you inside the app or by email before the change takes effect.
Continued use of Tabsnap after the change means you accept the new policy.
15. Contact
For any privacy question, data request, or complaint, contact us first.
Email: contact@tabsnap.app
Controller: Tabsnap B.V., Berkenweg 11, 3941 JA Doorn, the Netherlands, KvK 42128754
15. Contact
For any privacy question, data request, or complaint, contact us first.
Email: contact@tabsnap.app
Controller: Tabsnap B.V., Berkenweg 11, 3941 JA Doorn, the Netherlands, KvK 42128754
16. Supervisory authority
If you feel we have not handled your data properly, you have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or with the supervisory authority in your EU country of residence.
16. Supervisory authority
If you feel we have not handled your data properly, you have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or with the supervisory authority in your EU country of residence.