Legal
Privacy Policy
Last updated: July 5, 2026. Effective: July 5, 2026.
TL;DR — We collect only what we need to run SplitEase. We do not sell or "share" your personal information for cross-context behavioural advertising. You have strong rights over your data — including access, correction and deletion — that we honour globally. Contact hello@splitease.ai for any request.
1. Who we are and the scope of this Policy
This Privacy Policy explains how KAIVON TECHNOLOGIES PRIVATE LIMITED, a company incorporated in India with its registered office at 3314, Ropa, Bajaura, Kullu, Himachal Pradesh 175125, India ("SplitEase", "we", "us", "our"), collects, uses, discloses and safeguards personal data (also referred to as "personal information") when you use the SplitEase mobile application, our website at splitease.ai, our APIs and any related services (collectively, the "Service").
For users located in the European Economic Area (EEA), the United Kingdom (UK) or Switzerland, SplitEase is the "controller" of your personal data. For users in California and other US states with comprehensive privacy laws, SplitEase is a "business" that determines the purposes and means of processing. For users in India, SplitEase is a "data fiduciary" under the Digital Personal Data Protection Act, 2023 (DPDP Act).
Depending on where you live, additional region-specific rights and disclosures apply. Those appear in Section 13.
For users located in the European Economic Area (EEA), the United Kingdom (UK) or Switzerland, SplitEase is the "controller" of your personal data. For users in California and other US states with comprehensive privacy laws, SplitEase is a "business" that determines the purposes and means of processing. For users in India, SplitEase is a "data fiduciary" under the Digital Personal Data Protection Act, 2023 (DPDP Act).
Depending on where you live, additional region-specific rights and disclosures apply. Those appear in Section 13.
2. Personal data we collect
2.1 Information you give us
- Account data: name, mobile number, email address, password or one-time password, profile photo, country, preferred currency and language.
- Expense and group data: the amounts, descriptions, categories, dates, participants, notes, receipts, comments, reactions and splits you record.
- Communication data: messages you send to us (support tickets, feedback) and messages you exchange with other Group members through in-app chat.
- Media: images and receipts you choose to upload, and voice recordings you choose to submit for voice-expense entry.
- Contacts: if you grant permission, the names and phone numbers or email addresses of contacts you invite to a Group. We use this information only to look up existing SplitEase users and to send the invitation you request.
2.2 Information we collect automatically
- Device data: device model, operating system and version, app version, language, time zone, unique installation identifier, push-notification token, approximate location derived from IP address (country / region level).
- Usage data: the screens you view, the actions you take, session duration, feature interactions and referring URLs.
- Log and diagnostic data: IP address, crash logs, performance metrics, error traces and other technical information required to keep the Service running.
- Cookies and similar technologies: on the website only — see the Cookie Policy.
2.3 Information we receive from third parties
- Identity providers (Apple, Google) when you sign in using them — a unique identifier, your name and email.
- Payment Providers (Stripe, Razorpay, UPI, PayPal, Apple, Google) — transaction status, subscription status, refund status, and a limited masked instrument identifier. We do not receive or store full card numbers, UPI PINs, CVV codes or bank credentials.
- App stores — subscription entitlements, purchase receipts and refunds.
- Analytics and crash reporters — pseudonymous device and session identifiers.
2.4 Sensitive personal information
We do not knowingly collect biometric data, information about your health, racial or ethnic origin, religious beliefs, sexual orientation, precise geolocation, genetic data, or information about your children. Please do not upload such information into free-text fields (e.g., expense descriptions or chat messages).3. Voice and receipt processing
Voice-expense entry: audio you record is transmitted securely to our servers, transcribed and interpreted in real time, and the resulting text is used to pre-fill your expense form. We do not retain the raw audio after processing.
Receipt scanning: images you capture are processed through optical-character-recognition and category-inference models. Unless you explicitly save the receipt image to a Group, the raw image is deleted after parsing.
Receipt scanning: images you capture are processed through optical-character-recognition and category-inference models. Unless you explicitly save the receipt image to a Group, the raw image is deleted after parsing.
4. How we use your personal data
We use your personal data for the following purposes:
- to create and maintain your Account, authenticate you, and provide the Service;
- to record expenses, calculate splits and balances, and coordinate settlements between users;
- to enable in-app chat, notifications, invitations and shared Groups;
- to provide customer support and respond to your requests;
- to prevent, detect and investigate fraud, abuse and security incidents, and to enforce our Terms of Service;
- to comply with legal, regulatory, audit, accounting and tax obligations, and to respond to lawful requests from public authorities;
- to send you transactional communications (settlement reminders, security alerts, service updates) — you cannot opt out of essential communications while your Account is active;
- to send you marketing communications about SplitEase where permitted, from which you can unsubscribe at any time;
- to measure, understand and improve the Service (using pseudonymised or aggregated data where possible);
- to develop new features, including through the use of machine-learning models trained on aggregated, de-identified data — we do not use the content of your chats, expense descriptions or receipts to train third-party foundation models; and
- to enable corporate transactions (financing, merger, acquisition, reorganisation, sale of assets), subject to appropriate confidentiality.
5. Legal bases for processing (EEA, UK, Switzerland)
If you are in the EEA, the UK or Switzerland, we rely on one or more of the following legal bases under the General Data Protection Regulation (GDPR) and UK GDPR:
- Performance of a contract (Article 6(1)(b)) — to provide the Service to you under our Terms;
- Legitimate interests (Article 6(1)(f)) — to secure the Service, prevent fraud, understand usage, improve the product, and communicate with you about the Service, where those interests are not overridden by your rights;
- Consent (Article 6(1)(a)) — for optional analytics or marketing cookies on our website, for access to your contacts, microphone or camera on the mobile app, and for marketing emails. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal;
- Legal obligation (Article 6(1)(c)) — to comply with tax, accounting, anti-money-laundering and other legal duties;
- Vital interests (Article 6(1)(d)) — in rare emergencies where a life is at risk.
6. Who we share personal data with
We do not sell your personal data. We share it only with:
- Other users you choose to share with: the members of the Groups you join see your name, avatar and the expense entries you record in that Group.
- Cloud and infrastructure providers: Amazon Web Services (AWS), Google Cloud, Cloudflare — hosting, storage, delivery, DNS and DDoS protection.
- Payment Providers: Stripe, Razorpay, UPI networks, PayPal, Apple, Google — to enable settlements and subscriptions. These providers act as independent controllers of their own data.
- Analytics and crash-reporting: Firebase Analytics, Firebase Crashlytics, Sentry — configured to minimise personal data and to disable advertising identifiers.
- Communications: providers we use to deliver push notifications, email, and, where applicable, SMS OTPs.
- Professional advisers: lawyers, auditors, accountants and consultants, bound by confidentiality.
- Authorities and third parties for legal reasons: where we believe in good faith that disclosure is required by law, legal process, court order or lawful request from a public authority; to enforce our Terms; or to protect the rights, property or safety of SplitEase, our users or others.
- In connection with a corporate transaction: as part of a merger, acquisition, financing, insolvency, reorganisation or sale of assets, in which case we will use reasonable efforts to notify affected users and to require the recipient to honour this Policy.
7. International data transfers
SplitEase is headquartered in India, and personal data is primarily stored in India and Singapore. When we transfer personal data from your country to another country, we put in place appropriate safeguards required by applicable law, which may include:
- the European Commission's or the UK Information Commissioner's Standard Contractual Clauses (or International Data Transfer Agreement / UK Addendum) for transfers from the EEA / UK;
- reliance on adequacy decisions where one applies;
- additional technical, contractual and organisational measures such as encryption in transit and at rest, access controls, and confidentiality obligations.
8. How long we keep your data
We retain your personal data for as long as your Account is active, and for as long as reasonably necessary to fulfil the purposes described in this Policy. When you delete your Account:
- Profile data, device tokens, chat messages, voice recordings and receipt images are deleted or anonymised promptly (typically within 30 days).
- Settled transaction records and invoices are retained in a restricted-access archive for up to 7 years to comply with tax, accounting and financial-recordkeeping obligations in India and other jurisdictions where required.
- Anonymised, aggregated statistics may be kept indefinitely.
- Backup copies age out on a standard rolling schedule (typically 30 days).
9. How we protect personal data
We implement industry-standard technical and organisational measures to protect personal data, including:
- encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent);
- strong access control, principle of least privilege and multi-factor authentication for our staff;
- network segmentation, hardened cloud configurations and continuous monitoring;
- regular third-party security assessments and penetration testing;
- staff training on privacy and information security;
- an incident-response programme that includes notification of authorities and affected users within the timeframes required by applicable law.
10. Automated decision-making and profiling
We do not make decisions about you that produce legal or similarly significant effects using solely automated means. We may use models to suggest expense categories, detect duplicate entries or highlight suspected fraud, but these suggestions are advisory only and can be reviewed and overridden by you.
11. Children
The Service is not directed at children under the age of 13, or under the higher minimum age of digital consent in your country (for example, 16 in some EEA member states). We do not knowingly collect personal data from children below that age. If we learn that we have inadvertently done so, we will delete the account and the associated data. If you believe a child has provided personal data to us, please contact hello@splitease.ai.
12. Marketing and communications
We may send you marketing communications where permitted by applicable law. You can opt out at any time by using the unsubscribe link in the message, changing your notification preferences in-app, or contacting us. Even after opting out, we will continue to send you transactional and service messages, such as security alerts and settlement reminders, while your Account is active.
13. Your privacy rights
You have the rights described below. To exercise any right, email hello@splitease.ai from the address associated with your Account, or use the in-app self-service tools where available. We may need to verify your identity before acting on a request. We aim to respond within 30 days (or shorter where required by law).
We do not "sell" personal information for money, and we do not "share" personal information for cross-context behavioural advertising. We do not knowingly sell or share personal information of consumers under 16.
Verifiable requests: send an email to hello@splitease.ai with the subject "CCPA request". We will confirm receipt within 10 business days and respond substantively within 45 days (extendable by a further 45 days where reasonably necessary). We honour Global Privacy Control (GPC) signals as an opt-out preference signal for the sale and sharing of personal information.
13.1 Global rights
Regardless of where you live, you can:- access, correct or update the personal data in your Account;
- delete your Account and associated personal data (subject to legal retention);
- opt out of marketing communications.
13.2 EEA, UK and Switzerland
Under the GDPR / UK GDPR / Swiss FADP, you additionally have the right to:- request access to and a copy of your personal data;
- request rectification of inaccurate or incomplete data;
- request erasure ("right to be forgotten");
- request restriction of processing;
- object to processing based on legitimate interests, including profiling and direct marketing;
- data portability — receive your data in a structured, commonly used and machine-readable format;
- withdraw consent at any time, without affecting prior processing;
- lodge a complaint with your local supervisory authority (e.g., the Irish Data Protection Commission, the UK Information Commissioner's Office, or the Federal Data Protection and Information Commissioner in Switzerland).
13.3 India (DPDP Act, 2023)
If you are in India, you are a "data principal" and have the rights of access, correction, erasure, grievance redressal and nomination as described on our DPDP Compliance page. Our Grievance Officer / Data Protection Officer can be reached at hello@splitease.ai. You may also file a complaint with the Data Protection Board of India once constituted.13.4 California (CCPA / CPRA)
If you are a California resident, you have the right to:- know what categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties we disclose it to;
- request deletion of your personal information;
- request correction of inaccurate personal information;
- opt out of the "sale" or "sharing" of your personal information (as those terms are defined by the CCPA/CPRA);
- limit our use and disclosure of sensitive personal information to what is necessary to provide the Service;
- non-discrimination for exercising your rights;
- designate an authorised agent to submit requests on your behalf.
We do not "sell" personal information for money, and we do not "share" personal information for cross-context behavioural advertising. We do not knowingly sell or share personal information of consumers under 16.
Verifiable requests: send an email to hello@splitease.ai with the subject "CCPA request". We will confirm receipt within 10 business days and respond substantively within 45 days (extendable by a further 45 days where reasonably necessary). We honour Global Privacy Control (GPC) signals as an opt-out preference signal for the sale and sharing of personal information.
13.5 Other US state privacy laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Delaware, Montana, New Jersey, Iowa, Tennessee, New Hampshire, Kentucky, Maryland, Minnesota, Rhode Island and Nebraska have rights of access, correction, deletion, portability and opt-out of targeted advertising, sale, or profiling in furtherance of decisions producing legal or similarly significant effects. We do not engage in targeted advertising and do not sell personal information under these laws. To exercise a right or appeal a decision, contact hello@splitease.ai.13.6 Canada (PIPEDA and provincial laws)
Canadian residents may access and correct their personal information, withdraw consent (subject to legal or contractual restrictions) and complain to the Office of the Privacy Commissioner of Canada or the applicable provincial regulator (e.g., Quebec CAI).13.7 Brazil (LGPD)
Brazilian data subjects have the rights of confirmation of processing, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent under the Lei Geral de Proteção de Dados. Complaints may be filed with the Autoridade Nacional de Proteção de Dados (ANPD).13.8 Australia (Privacy Act 1988)
Australian residents may access and correct their personal information and complain to the Office of the Australian Information Commissioner (OAIC).13.9 Singapore (PDPA), Malaysia (PDPA), Thailand (PDPA), Philippines (DPA), Vietnam (PDPD), UAE (PDPL) and other jurisdictions
Residents of these jurisdictions have local rights of access, correction, withdrawal of consent, deletion and complaint to the relevant regulator (e.g., PDPC Singapore, PDPC Thailand, National Privacy Commission Philippines). Contact us and we will process your request in accordance with applicable local law.13.10 South Africa (POPIA)
South African data subjects have the rights set out in the Protection of Personal Information Act, 2013, and may complain to the Information Regulator (South Africa).14. Cookies and similar technologies
The SplitEase website uses cookies and similar technologies as described in our Cookie Policy. The SplitEase mobile app does not use browser cookies; it stores session tokens in the operating-system-provided secure storage.
15. Third-party links and services
The Service may contain links to third-party websites or services (e.g., a Payment Provider or a support article). This Policy does not apply to those third-party services. We encourage you to review their privacy notices.
16. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you at least 14 days before they take effect through email, in-app notification or a banner on the Service, unless a shorter period is required by law. The "Last updated" date at the top reflects the most recent revision. Continued use of the Service after the effective date constitutes your acknowledgment of the updated Policy.
17. Contact us and complaints
For any question, request or complaint about this Policy or our processing of your personal data, please contact:You may also lodge a complaint with your local data-protection or privacy regulator. We would appreciate the chance to address your concern before you do.
Data Protection Officer / Grievance Officer
KAIVON TECHNOLOGIES PRIVATE LIMITED
Email: hello@splitease.ai
Address: 3314, Ropa, Bajaura, Kullu, Himachal Pradesh 175125, India