DiviSum

Privacy Policy

Last updated: 13 August 2026

DiviSum helps groups of people track shared expenses and work out who owes whom. This policy explains what we collect, why, how long we keep it, and what you can do about it.

The short version. We collect the minimum needed to run a shared-expense ledger: who you are, what you spent, and who you shared it with — plus a crash report when the app breaks, so that it can be fixed. We do not sell your data, we do not show ads, and we do not use it for advertising or profiling. There is no usage analytics, and nothing records which screens you open or what you tap.

Who is responsible

DiviSum is operated by Mihir Bavisi, the developer named on the Google Play listing. For any privacy question, or to exercise any right described below, email divisum.review@gmail.com.

What we collect

DataWhy
Name, email address and profile picture Supplied by Google when you sign in. Identifies you to the other members of your groups so they know whose expense is whose.
Expenses, splits and settlements The core function of the app. Includes amounts, currency, descriptions, dates, optional notes and category.
Groups and membership Determines who can see which expenses.
Notification token A per-installation identifier issued by Firebase Cloud Messaging, used only to deliver notifications to your device. Stored against your account so we know where to send them.
Crash diagnostics When the app crashes or hits an error, Firebase Crashlytics records what went wrong: the error and its stack trace, your device model and operating system version, the app version, device state such as free memory and storage, and an identifier for this installation. Your account ID is attached, so that one person hitting a fault forty times can be told apart from forty people hitting it once. Your expenses, balances, group names and the contents of your ledger are not included.

We do not collect your location, contacts, photos, calendar, or any advertising identifier. There is no advertising SDK and no analytics SDK in the app — nothing records which screens you open or what you tap. Firebase Crashlytics is the only diagnostic tool we use, and it reports faults, not usage.

Legal bases

Who else processes your data

ServiceRole
Supabase Hosts the database and handles authentication. Your data is stored in the European Union (Frankfurt region).
Google — Sign-In Authenticates you. We receive your name, email address and profile picture. We never see your Google password.
Google — Firebase Cloud Messaging Delivers push notifications. Google may process the notification token and message content outside the EU, including in the United States, under their standard contractual clauses.
Google — Firebase Crashlytics Receives crash reports so that faults can be found and fixed. Google may process this data outside the EU, including in the United States, under their standard contractual clauses.

We do not sell your data or share it with anyone for marketing.

Who can see your expenses

Only members of a group can see that group's expenses. That is enforced at the database level, not just in the app. When you add an expense, the people you split it with can see the amount, the description, and your share of it, because that is the point of a shared ledger.

How long we keep it

Your account data is kept for as long as your account exists. Expenses and settlements are kept for as long as the groups they belong to exist.

Crash reports are kept by Firebase Crashlytics for 90 days, after which Google begins removing them from its live and backup systems.

Deleting your account

You can delete your account from the Account tab inside the app, or by emailing divisum.review@gmail.com. Full instructions are on the account deletion page.

When you delete your account, your name, email address, profile picture, sign-in and notification tokens are permanently erased, and you are removed from every group.

Expenses you took part in are kept, but anonymised. They are also part of other people's records of what they owe and are owed. Erasing them outright would silently change other members' balances, leaving them with debts that no longer add up and no record of why. So your name is replaced with “Deleted user” and nothing personally identifying stays attached to them.

We act on email deletion requests within 30 days and confirm by email when it is done.

Your rights

If you are in the European Economic Area or the UK, you have the right to:

Email divisum.review@gmail.com to exercise any of these. You also have the right to complain to your local data protection authority.

Children

DiviSum is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, email us and we will delete it.

Security

Data is encrypted in transit. Access to expenses is restricted at the database level so that only group members can read them. No system is perfectly secure, but we do not store passwords at all — sign-in is handled entirely by Google.

Changes

If this policy changes materially we will update the date at the top and, where the change affects how your data is used, tell you in the app.