Privacy Policy

Last updated: April 5, 2026

1. Introduction

BillBuddies ("we", "our", or "us") is a personal expense splitting application. This Privacy Policy explains how we collect, use, and protect your information when you use our mobile app or website. We are committed to protecting your privacy and being transparent about our data practices.

By using BillBuddies, you agree to the collection and use of information as described in this policy.

2. Information We Collect

Account Information

  • Name (first and last name) — optional, used for display
  • Email address — used for account login and friend invitations
  • Phone number — optional, used for account login and friend search
  • Username — chosen by you, visible to your friends on the app
  • Password — stored as a secure, one-way hash; never readable by us

Financial Data

  • Expense descriptions, amounts, and dates you enter
  • How expenses are split among group members
  • Payment records you log to settle balances
  • Group names and membership

BillBuddies is a record-keeping tool, not a payment processor. We store the amounts you record — we do not handle, move, or hold any actual money.

Device Contacts (Mobile Only)

If you tap "Sync Contacts" in the app, we read your device's contact list to match phone numbers against existing BillBuddies users. Contact data is only used in that moment to find matches — it is never stored on our servers, never shared, and not accessed again unless you explicitly tap Sync Contacts again.

Information We Do NOT Collect

  • Location data or GPS coordinates
  • Device identifiers or advertising IDs
  • Browsing history or cross-app activity
  • Biometric data
  • Any analytics or crash reporting data

3. How We Use Your Information

  • To provide the service — create your account, track expenses, calculate balances, and manage groups
  • To send friend invitations — when you invite someone by email, we use Resend (resend.com) to deliver a one-time invitation email on your behalf
  • To enable friend discovery — your email and phone number (if provided) allow other users to find and add you
  • To verify your identity — we may send a one-time code to confirm your email address

We do not use your data for advertising, profiling, or any purpose beyond operating the app.

4. Third-Party Services

We use a minimal set of third-party services, all for infrastructure purposes only:

ServicePurposeData Shared
Resend (resend.com)Sends invitation emailsRecipient email address only
Amazon Web Services (EC2)Hosts our backend serverInfrastructure only; data not sold to AWS
PostgreSQL DatabaseStores all app dataEncrypted at rest

We do not use any advertising networks, analytics platforms (Google Analytics, Mixpanel, etc.), social login providers (Facebook, Google), or crash reporting services.

5. Data Storage and Security

  • All data is transmitted over HTTPS (TLS encryption in transit)
  • Passwords are hashed using industry-standard algorithms and never stored in plain text
  • Database is encrypted at rest
  • Authentication uses short-lived JWT tokens (1-day access tokens, 7-day refresh tokens)

6. Data Retention

  • Your account data and expense history are retained as long as your account is active
  • If you request account deletion, your personal details (name, email, phone, password) are removed immediately. Expense and settlement records shared with other users are retained in anonymized form so their balances remain accurate; you will appear to them as "Deleted User"
  • Invitation emails sent via Resend may be retained by Resend per their own retention policy

7. Your Rights

You have the right to:

  • Access your data — contact us and we will provide a summary of data we hold about you
  • Correct your data — update your profile directly in the app (Account → Edit Profile)
  • Delete your account — delete it yourself from Account → Delete my account in the mobile app or website, or contact us at the email below. Your personal details are removed immediately; shared expense history is retained in anonymized form so other users' balances remain accurate
  • Withdraw consent — you may stop using the app and request deletion at any time

To exercise any of these rights, email us at [email protected].

8. Children's Privacy

BillBuddies is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for significant changes, notify you via the email address on your account.

10. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us: