● Legal
Privacy Policy
Last updated 22 September 2026 · Effective 22 September 2026
This policy explains what SplitChamp collects, why it is collected, who else processes it, how long it is kept, and how to get it deleted. SplitChamp is a shared-expense app: it records who paid what within a group and works out who owes whom.
Contents
1. Who we are
SplitChamp is built and operated by Adel Ashraf Hamouda and Ahmed Tarek, trading together as beanvoid ("we", "us"), a product studio based in Egypt — see beanvoid.com. For data protection purposes we are jointly the controllers of the personal data described below.
Contact: support@beanvoid.com. Write to us there for anything in this policy, including requests about your data; we will give a postal address on request.
2. What we collect
| Category | What exactly | Where it comes from |
|---|---|---|
| Account | Your email address, your display name, and the account identifier Google gives us when you sign in. | Google, when you choose to sign in |
| What you create in the app | Groups and their members, expenses (amount, currency, description, date, who paid, how it is split), settlements you record, recurring expense rules, invite codes and the email addresses you use to invite people. | You and the people in your groups |
| Sign-in state | Session records so the app can keep you signed in. Refresh tokens are stored only as a one-way hash, never in a readable form. | Created by us |
| Technical logs | IP address, request time, endpoint, response status and error details, produced when the app talks to our servers and by the security layer in front of them. | Automatic |
We do not collect your Google password, contacts, calendar, photos or location, and we do not ask Google for anything beyond your basic profile and email address. We do not use advertising or analytics trackers, and we do not store bank details or card numbers, because no money moves through SplitChamp.
3. Why, and our legal basis
- To run the service — create your account, show your groups, calculate balances and settlements. Legal basis: performance of a contract with you.
- To keep the service secure and working — abuse and rate-limit protection, error diagnosis, backups. Legal basis: legitimate interests in keeping a service available, correct and safe.
- To answer you when you email support. Legal basis: legitimate interests in responding to enquiries.
- To meet legal obligations where they apply. Legal basis: legal obligation.
We do not sell personal data, and we do not use it to profile you or to target advertising.
4. Data about other people
When you invite someone by email, we store that email address so the invitation can be matched to them when they sign in, and so their share of expenses can be tracked in the meantime. Only invite people who expect to be in the group. If someone would like their address removed before they ever sign in, email us and we will remove it.
Anyone in a group can see the group's expenses, who paid, how each expense is split, and the balances and settlements that follow from it. That is the point of a shared ledger — treat what you put in a group as visible to that group.
5. Who else processes it
We keep the list of processors deliberately short:
| Processor | What for |
|---|---|
| Google (Google Sign-In) | Verifying who you are when you sign in. Google's own handling of your account is covered by Google's privacy policy. |
| Railway | Hosting the SplitChamp service and its database. |
| Cloudflare | DNS, TLS, and the security layer in front of the service; also object storage for encrypted database backups. |
| Firebase App Distribution (Google) | Only for pre-release test builds given to our own testers, not for public releases. |
Each processes data on our instructions, for the purpose above, and nothing else.
6. Where it is stored
We are based in Egypt, and our service, database and backups are hosted by the providers above, so data is processed in countries outside your own, including the United States. Where a transfer is subject to EU or UK data protection law, it relies on the safeguards those providers offer, such as the European Commission's standard contractual clauses.
7. How long we keep it
- Account and app content: for as long as your account exists.
- Sign-in sessions: refresh tokens expire within 30 days, and a session ends immediately when you sign out.
- Technical logs: kept for a short period for diagnosis and security, then discarded.
- Backups: encrypted database backups are kept for 30 days and then deleted automatically. Deleted data can persist in a backup until that window passes.
8. Your rights
You can ask us to: give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. Email support@beanvoid.com and we will respond within 30 days. There is no charge.
These rights are given by Egypt's Personal Data Protection Law (Law No. 151 of 2020), and, if you are in the EU or the UK, by the GDPR. You can also complain to your local data protection authority.
9. Deleting your account
Email us from the address you signed in with and ask for deletion. We remove your account, your display name and email, and your session records within 30 days, and backups age out within 30 days after that.
One limit worth stating plainly: expenses you were part of belong to a shared group ledger. If we removed your side of a shared expense, the other members' balances would stop adding up. Where that is the case we anonymise your entries instead of erasing them, so the group's history stays correct but is no longer linked to you.
10. Security
- All traffic between the app and our servers uses TLS 1.2 or newer.
- The service sits behind Cloudflare, with rate limiting on sign-in endpoints, and it accepts traffic only through that layer.
- The database is not exposed to the public internet.
- Refresh tokens are stored hashed; access tokens are short-lived.
- Backups are encrypted at rest, access-controlled, and protected against deletion for a rolling period.
No system is perfectly secure, but if a breach ever affects your data we will tell you and the relevant authority as the law requires.
11. Children
SplitChamp is not intended for children under 16. We do not knowingly collect their data; if we learn that we have, we delete it.
12. Changes and contact
If this policy changes materially we will update the date at the top and, where the change matters to you, tell you in the app. Questions, requests, or anything that looks wrong: support@beanvoid.com.
This policy is governed by the laws of the Arab Republic of Egypt, without affecting any rights you have under the data protection law of the country you live in.