Last updated: 13 August 2026
DiviSum helps groups of people track shared expenses and work out who owes whom. This policy explains what we collect, why, how long we keep it, and what you can do about it.
DiviSum is operated by Mihir Bavisi, the developer named on the Google Play listing. For any privacy question, or to exercise any right described below, email divisum.review@gmail.com.
| Data | Why |
|---|---|
| Name, email address and profile picture | Supplied by Google when you sign in. Identifies you to the other members of your groups so they know whose expense is whose. |
| Expenses, splits and settlements | The core function of the app. Includes amounts, currency, descriptions, dates, optional notes and category. |
| Groups and membership | Determines who can see which expenses. |
| Notification token | A per-installation identifier issued by Firebase Cloud Messaging, used only to deliver notifications to your device. Stored against your account so we know where to send them. |
| Crash diagnostics | When the app crashes or hits an error, Firebase Crashlytics records what went wrong: the error and its stack trace, your device model and operating system version, the app version, device state such as free memory and storage, and an identifier for this installation. Your account ID is attached, so that one person hitting a fault forty times can be told apart from forty people hitting it once. Your expenses, balances, group names and the contents of your ledger are not included. |
We do not collect your location, contacts, photos, calendar, or any advertising identifier. There is no advertising SDK and no analytics SDK in the app — nothing records which screens you open or what you tap. Firebase Crashlytics is the only diagnostic tool we use, and it reports faults, not usage.
| Service | Role |
|---|---|
| Supabase | Hosts the database and handles authentication. Your data is stored in the European Union (Frankfurt region). |
| Google — Sign-In | Authenticates you. We receive your name, email address and profile picture. We never see your Google password. |
| Google — Firebase Cloud Messaging | Delivers push notifications. Google may process the notification token and message content outside the EU, including in the United States, under their standard contractual clauses. |
| Google — Firebase Crashlytics | Receives crash reports so that faults can be found and fixed. Google may process this data outside the EU, including in the United States, under their standard contractual clauses. |
We do not sell your data or share it with anyone for marketing.
Only members of a group can see that group's expenses. That is enforced at the database level, not just in the app. When you add an expense, the people you split it with can see the amount, the description, and your share of it, because that is the point of a shared ledger.
Your account data is kept for as long as your account exists. Expenses and settlements are kept for as long as the groups they belong to exist.
Crash reports are kept by Firebase Crashlytics for 90 days, after which Google begins removing them from its live and backup systems.
You can delete your account from the Account tab inside the app, or by emailing divisum.review@gmail.com. Full instructions are on the account deletion page.
When you delete your account, your name, email address, profile picture, sign-in and notification tokens are permanently erased, and you are removed from every group.
We act on email deletion requests within 30 days and confirm by email when it is done.
If you are in the European Economic Area or the UK, you have the right to:
Email divisum.review@gmail.com to exercise any of these. You also have the right to complain to your local data protection authority.
DiviSum is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, email us and we will delete it.
Data is encrypted in transit. Access to expenses is restricted at the database level so that only group members can read them. No system is perfectly secure, but we do not store passwords at all — sign-in is handled entirely by Google.
If this policy changes materially we will update the date at the top and, where the change affects how your data is used, tell you in the app.