AI Tip & Split

Privacy Policy

Effective date: May 28, 2026 · Last updated: August 5, 2026

Who we are

AI Tip & Split (“we,” “us,” “our”) operates the AI Tip & Split mobile application and browser-based split experience under that name.

Contact: aitipsplit@protonmail.com

Summary

AI Tip & Split helps you calculate tips and split restaurant bills. We do not require an account. We collect only what is needed to run the app, enforce free-tier OCR limits, sync live splits, and (optionally) improve reliability through crash and analytics services.

  • We do not collect payment card numbers.
  • Receipt photos sent only for OCR are not retained by us after processing. If a host shares a split, a separate copy may be stored temporarily for participants.
  • We do not sell your personal information.

Information we collect

On your device

  • Anonymous device ID — generated on first launch, stored locally until uninstall.
  • Tip calculator inputs — stay on device unless you start a shared split.
  • Pro tip and split history (Pro only) — up to 50 entries. Auto-delete after 30 days is enabled by default and can be turned off.
  • Local receipt image copies (Pro history) — when available to that device, a receipt source file is copied into app storage and displayed with its history entry. Host/scanner devices can retain this copy independently of server deletion. Receipt images opened from a guest’s temporary signed link are not copied into local history.

Android cloud backup and device transfer are disabled. An iOS device backup may contain local app data captured before a later Delete My Data action.

On our servers (Supabase)

  • Shared split sessions — restaurant name, totals, line items, nicknames, session code and anonymous membership. Guests can join or change claims for 72 hours; metadata remains available to the host for recovery for up to 30 days, then is deleted.
  • Shared receipt images — uploaded only when a host shares a split. Private storage; short-lived signed URLs (~30 minutes); deleted after the 72-hour shared-session access period expires, normally within about one hour.
  • OCR scan logs — device ID, success/failure, error code, scan quality, and timestamp. Not the receipt image. Purged after ~90 days.
  • Subscription status — device ID and Pro active/expiry for server-side OCR limits. Inactive or expired rows are purged after approximately 90 days.
  • Anonymous authentication — supports private split membership. Delete My Data removes it; orphan identities are purged after approximately 30 days.
  • Abuse-prevention records — expired temporary device bans are removed after approximately 365 days. Permanent bans remain while needed to protect the service and can be reviewed on request.

Receipt scanning (OCR)

When you scan, you grant camera or photo access. The image may be compressed on device, sent to our Supabase Edge Function, and processed by OpenAI’s vision API. Extracted data returns to the app for review. The image is not retained on our servers after processing. We do not use your receipt data to train our own models.

Free tier: 1 successful scan per rolling 3-day window. Pro: unlimited quota (spam rate limits still apply). You may skip scan and enter manually anytime.

Subscriptions

Purchases are processed by Apple or Google through Superwall. When configured, the app sends its anonymous device ID to check subscription status, including before purchase or restore. We receive subscription status — not payment card numbers.

App integrity

Apple App Attest and Google Play Integrity help us confirm that OCR requests come from an authentic app installation and prevent abuse. We process short-lived integrity challenges and verification tokens. For iOS, we also retain the App Attest key ID, public key, verification counters, and anonymous device association while needed to validate future requests. Apple and Google process integrity data under their own policies.

Analytics and crash reporting (optional and off by default)

You can opt in independently in Settings. PostHog receives product events without session codes, receipt content, names, or totals. Sentry receives crashes, stack traces, device/OS and app version, automatic session state, and sampled performance traces.

Information we do not collect

  • Email or password (unless you contact support)
  • Payment card numbers
  • Precise location
  • Contacts, calendar, or microphone
  • Advertising identifiers for ad targeting — we do not show ads

Shared splits

Anyone with the session code or share link can join and see session totals, nicknames, items, and the receipt image (if uploaded) during the 72-hour access period. When server access ends, it does not delete a separate receipt copy already stored in a host or scanner device’s Pro history. Guest history keeps the saved totals but normally does not keep a copy of an image viewed through a temporary signed link.

Third-party providers

Supabase, OpenAI, Superwall, Apple, Google, and optionally PostHog and Sentry. Each processes data under their own policies.

Your choices and privacy rights

Depending on where you live — including under the GDPR (EEA, UK, Switzerland) and CCPA/CPRA (California) — you may have rights to access, delete, or port personal information. The App has no login; data is mostly tied to an anonymous device ID.

In the app (Settings → Privacy & Data)

  • Export My Data — JSON export through the share sheet containing local Pro history, privacy preferences, and server-side counts/status.
  • Delete My Data — removes Pro history and receipt photos on this device; deletes OCR logs, subscription cache, and split sessions you hosted (including receipt images), guest memberships, and anonymous auth identity on our servers; clears saved session info and managed receipt/cache copies; resets telemetry and device identities. Pro users should tap Restore Purchases afterward.

Delete My Data does not remove

  • Purchase records held by Apple, Google, or Superwall
  • Previously sent provider analytics/crash records, which follow provider retention
  • Permanent abuse-prevention records where needed to protect the service

Other controls

  • Skip OCR and enter totals manually
  • Auto-delete Pro History after 30 days
  • Opt in or out of Product Analytics and Crash Reporting
  • Use Delete browser data on the browser split page
  • Manage subscriptions via Apple/Google or in-app Customer Center
  • Email aitipsplit@protonmail.com if in-app tools fail or for verified requests

We do not sell or share personal information for cross-context behavioral advertising. We will not discriminate against you for exercising privacy rights.

Children

Not directed at children under 13. We do not knowingly collect data from children.

Changes

We may update this policy. The “Last updated” date will change accordingly.

AI Tip & Split

aitipsplit@protonmail.com

Terms of Service · Help