Privacy Policy
Effective September 17, 2026
What changed
- You can sign in with your email address, and add, change or confirm the email on your account in Settings → Profile.
- Someone who adds you to a group can only offer you a place in it. You choose whether to join.
- The App asks to read your contacts so you can search them. Only the people you pick are sent to us.
- We now describe board and statement links, the phone number on your profile, and using the camera to scan a group's QR code.
- Resend, which sends our emails, is now listed as a service provider.
This Privacy Policy explains what information NthCube LLC (“NthCube,” “we,” “us”) collects when you use the Zplity iOS app (“Zplity” or the “App”) and the marketing site at zplity.com (the “Site”), why we collect it, who else sees it, and the choices you have. We built Zplity to handle the minimum data needed to make shared-expense math work; nothing more.
1. Information we collect
1.1 Information you give us directly
- How you sign in. You sign in with Apple or with your email address. With Apple, we receive an opaque user identifier from Apple plus, if you choose to share them, your name and (a real or relay) email address. Apple releases your name only on your first sign-in; if it does, we save it as your profile name so you don’t have to type it. With email, we send a sign-in link and a 6-digit code to the address you type, and you sign in to the account that address belongs to, or a new one if none does.
- Your email address. The address Apple shared with us, or the one you signed in with. Under Settings → Profile you can add one, change it, or confirm one Apple passed on without vouching for: we email a 6-digit code to the address, and nothing changes until you type it into the App. The address on your account is the one a sign-in link opens your account with, the one the matching described below compares against, and the one a group sees if you turn on Show my email for that group — no group sees it otherwise. An address another account already uses can’t be added. The only emails we send are sign-in links and these codes; we don’t send marketing email.
- Your phone number. Optional, added under Settings → Profile. It is private: a group sees it only if you turn on Show my phone for that group. Nobody verifies a number, so it is never treated as proof of who you are — when it matches a number somebody saved for a person they added to a group, we ask them whether it’s really you, as described below.
- Your profile name. A single display name on your account, which you can add, change, or correct at any time under Settings → Profile in the App. If Apple never shared a name with us, this stays empty until you enter one — we don’t substitute a placeholder. Its only purpose is to fill in your name when you create or join a group; each group then keeps its own name for you, and changing your profile name does not rewrite the name people in your existing groups already see. You are free to use a nickname or initials.
- Your currency preference. Optional. New groups start in the currency your device’s region uses; if that isn’t the one you want, the choice you make under Settings → Preferences is stored on your account so it follows you to a new phone. We derive it from your device’s own region setting, never from your IP address or any other location signal.
- Your profile photo. Optional. If you add one under Settings → Profile, the image you crop is uploaded and stored privately in Cloudflare R2 at
avatar/<your id>.jpg. It is visible only to people you share a group with: every request goes through our server, which checks that the requester is an active member of a group you’re also an active member of before returning the image. Leaving or being removed from a group ends that access. We do not run face recognition or any other analysis on it, and it is never sent to an AI provider or any other processor. Remove it at any time from the same screen — that deletes the file from R2 and members see your initials again. - Group and expense content. The groups you create, the members you add (including shadow members entered as a name only), expenses, item-level splits, settlements, notes, and timestamps. The name you use in a group is visible to the other members of that group, as are the expenses and settlements you record there — the note on an expense included, which everyone on that expense can read. The one exception is the private note described next.
- The private note on an expense. An expense can carry a second note that only the account which entered the expense can read. Our server returns it to that account and to no one else: every other member of the group receives the field empty, so it never reaches their device, and an edit they make to the expense leaves your note where it was. It is not in the spreadsheet export, not on a shared statement link, and not in any notification. It is stored as ordinary text rather than encrypted, so it is private from the people you share a group with rather than from us — please don’t put passwords or full card numbers in it. Deleting your account deletes it (Section 5), and it is never copied on to the occurrences a recurring expense generates, because those have no author to read them back.
- Receipt scans you submit for parsing. When you tap “Scan receipt,” the image is uploaded to our server, forwarded to an AI processing provider for parsing, and the parsed JSON is returned to your device. The upload itself is discarded once parsing finishes — we keep no separate copy of the scan. Keeping that photo on the expense afterwards is a different choice, and it does store the image; see the next item. Section 4 covers what the AI provider may do with it.
- Receipt photos you attach to an expense. If you choose to keep a photo on an expense, it is stored privately in Cloudflare R2 at
expense/<id>.jpg. Only members of that expense’s group can fetch the image, and anyone holding a statement link that includes the expense (see Links you share); every request goes through our server, which checks one of the two before returning it. Deleting the expense moves it to Recently Deleted and the photo goes with it — still stored, so restoring the expense restores the receipt too. The image is erased when the expense is permanently removed: automatically once its 30 days are up, or straight away if you delete it permanently yourself. Deleting your account erases the photos in any group that is removed with it. - The people you keep in People. Your People list is a private address book: for each person you add, we store the name, one email address and one phone number, plus a photo if you give them one (stored in Cloudflare R2 at
contact-avatar/<id>.jpg). This list is yours alone — it is never shown to anyone else, and no other account can read it. When you add one of these people to a group, the name you gave them becomes part of that group’s member list, and a copy of their photo is stored for that group so everyone can tell them apart. The email address and phone number stay private to you: they are never shown to the group, and the only contact details a member list ever carries are the ones an account holder chose to publish to that group themselves. - Matching the people you add to their own accounts. The address and number you saved are compared against accounts, so that somebody you added by hand can take the place you made for them instead of starting over as a second entry. Nothing is ever linked automatically, and nobody is put in a group without agreeing to it. An email address is compared only against an address its owner has proved to us, through Sign in with Apple, a sign-in link we emailed, or a code we emailed to confirm it; on a match, that account is offered the place and is told the group’s name, the name you added them under, and the name you go by in that group. Accepting or declining is theirs alone, you are not told which they chose, and until they accept, nothing about their account reaches the group. If they join the group with its invite code instead, the App asks them whether that place is theirs; it is never taken for them. A phone number is never treated as proof, because nobody verifies the number on an account: instead we ask you, the person who wrote it down, whether the account that turned up is really them, and that account hears nothing unless you say yes and it then accepts. We keep no record of any of these offers — each one is worked out afresh from your list every time it is shown — so correcting the address, unlinking the person from that group, or deleting them from People withdraws an offer nobody has answered yet. Deleting a person from People deletes their entry and photo and leaves every group untouched.
- Links you share. Two things in a group can be shared as a link that opens in a web browser, with no account needed. A statement is one member’s bills, with their receipt photos, what they paid, and what they owe, with the names of the people they need to settle with; you can share your own, and a group’s owner or an admin can share anyone’s. A board is who should pay whom in the whole group, and how much — names and amounts only; only the group’s owner or an admin can turn it on, and every member can see that it is on. Neither shows email addresses, phone numbers, profile photos, or private notes. Anyone holding the link can open it, so share it only with people you mean to; turning a link off, or making a new one, stops the old link working straight away, and a statement link nobody opens for 90 days stops working on its own.
- Purchase records. If you subscribe to Zplity Pro, we receive the subscription status from RevenueCat (linked to your Zplity account identifier). Apple processes the payment; we never see your card details.
- Support correspondence. If you email us, we keep the message and any attachments long enough to resolve the issue.
1.2 Information collected automatically
- Push tokens. If you grant notification permission, iOS issues an APNs device token that we store so we can notify other group members when you log an expense or settle up, and so we can tell you when somebody adds you to a group of theirs.
- Basic request metadata. Standard web-server logs (IP address, user-agent, timestamps) are written by Cloudflare and retained for a short window for security and abuse detection. We do not link these logs to your account.
1.3 What we do not collect
- No advertising identifiers (no IDFA), no third-party SDKs for analytics or ads.
- No location data.
- No copy of your address book. When you add people from your iPhone’s Contacts, the App asks for permission to read them, so you can search for the people you want. They are read on your iPhone and are not sent to us: only the people you tick are, and from each of those only the name, one email address, one phone number, and the photo if it has one. If you allow access to only some contacts, the App works with just those, and you can change or withdraw the permission at any time in iOS Settings. We store no address-book identifier, so nothing we keep points back at an entry on your phone.
- No camera use beyond what you start. The camera runs only while you are scanning a receipt or a group’s QR code. A QR code is read on your iPhone and only the invite code in it is used; nothing the camera sees is sent to us except a receipt photo you scan or keep.
- No photo-library access. Choosing a profile photo or a receipt runs through Apple’s out-of-process picker, which hands us only the single image you select.
- No biometric data — we do not run face recognition on profile photos.
- No tracking across other apps or websites.
2. How we use information
- To provide the App’s core function: storing groups, computing balances, sending push notifications.
- To keep your People list, so adding the same person to a new group doesn’t mean typing them in again.
- To match the people you add to their own accounts, so they can be offered the place you made for them rather than added to it.
- To authenticate you (verifying Apple identity tokens, emailing sign-in links and codes, issuing our own session JWTs).
- To confirm an email address you put on your account, by emailing it a code.
- To enforce fair-use limits on the free tier.
- To respond to support requests.
- To comply with legal obligations.
We do not use your data to train machine-learning models, sell it, or share it for advertising.
3. Service providers we share data with
We use a small set of vendors that act as data processors on our behalf:
- Apple Inc. — Sign in with Apple, App Store payments, APNs push delivery. Governed by Apple’s privacy policy.
- Cloudflare, Inc. — hosts the Worker, D1 database, KV store, R2 object storage (profile photos and the receipt photos you attach to expenses), and the marketing site. Data is stored in Cloudflare’s global edge infrastructure.
- Google LLC (Gemini API) — receives the receipt images you submit for parsing and extracts line items and totals from them. This is the model Zplity uses by default.
- OpenAI, L.L.C. — receives the same receipt images when a scan falls back to an OpenAI model, either because Gemini is unavailable or because we have moved scanning there. Nothing else is sent to it.
- Resend — sends the only emails we send: sign-in links and codes, and codes that confirm an email address you put on your account. It receives the address and the email’s contents.
- RevenueCat, Inc. — manages subscription entitlements (linked to your user id, with subscription status only — no personal data beyond that).
Section 4 sets out what the AI providers on this list may and may not do with an image. We do not sell personal information, and we do not share it with third parties for their own marketing.
4. AI processing
We use third-party AI services to analyze receipt images and extract information such as merchant name, date, total amount, and category. Receipt images submitted for AI processing are transmitted to our AI processing providers, such as Google Gemini or OpenAI. When using their paid API services, these providers do not use submitted content to train or improve their AI models under their applicable terms.
Only an image you submit for scanning is sent this way, and only at the moment you start the scan. A receipt photo you then keep on an expense lives in our own storage (see Section 1.1) and is not sent for AI processing again. Nothing else you keep in Zplity — group names, expenses, balances, People entries, profile photos — is sent to an AI provider at all.
5. Data retention and account deletion
Group and expense data is kept while your account is active so other group members can continue to see shared history. Section 5.1 sets out how long everything else is kept once it stops being current. When you tap Settings → Delete account in the App, the following happens server-side. The personal-identifier deletion below runs as a single atomic database transaction; the surrounding steps (Apple token revocation, the session-revocation marker, and photo cleanup) are coordinated alongside it on a best-effort basis.
- Apple token revocation. If you signed in with Apple, we ask Apple to revoke the Sign-in-with-Apple refresh token tied to your account. If Apple is temporarily unreachable, the App surfaces a one-step instruction for you to finish the revoke from iPhone Settings → your name → Sign in with Apple → Zplity → Stop Using Apple ID.
- Permanent deletion of personal identifiers. Your
usersrecord, push tokens, rate-limit counters, any code still waiting to confirm a new email, and all personal identifiers (email, phone number, profile name, Apple subject) are deleted from our database immediately — not soft-deleted, not queued for later, no recovery window. Your profile photo goes with them: unlike a receipt photo, it belongs to your account rather than to a group’s shared history, so it is deleted from R2 and members of your former groups see initials in its place. - Deletion of your People list. Every person in your People list, their photos in R2, and the private links tying them to group member rows are deleted outright. Unlike your membership rows below, none of this is anonymized and kept: nobody else can see your People list, so there is no shared history to preserve. The groups those people are in are untouched, and any offer of a place that rested on an address in your list stops being made, since the list it was worked out from is gone.
- Places you turned down. We keep a record of each invitation you declined, so that place is never offered to you again; that record is deleted with your account.
- Group ownership transfer. For each group where you were the owner and at least one other linked member remains, ownership transfers to the longest-joined remaining member.
- Anonymization in shared groups. For each group where other members remain, your membership row is anonymized: the link to your account, your email, and your phone number are cleared. The display name you typed when joining each group is preserved so historical expenses you paid for or participated in remain attributable for the surviving members — Bob still needs to know that the dinner ledger says "Alice paid $90." From their view you appear as a former member with no contact info. Receipt photos you attached to expenses in those groups are kept for the benefit of the remaining members and stay in R2 until the expense is permanently removed — they are not erased by your account deletion, because the expense itself is not. Any private note you wrote on one of those expenses is erased with your account: your account was the only one that could ever read it, so keeping it would leave your words in a bill nobody can open.
- Cascade deletion of solo groups. If a group has no other linked members after your deletion, the entire group is deleted, along with its expenses, items, settlements, and any receipt photos in R2 storage.
- Session revocation. Any session token issued to your account is added to a revocation list for the remainder of its natural 30-day lifetime, so a token that may have leaked from your device cannot be replayed after deletion.
- Audit row. A single row is written to an internal
deletion_audittable holding a salted, irreversible hash of your Apple identifier (or, for an account that only ever signed in by email, of its email address) and the deletion timestamp — used only to demonstrate, if asked by a regulator, that your request was honored. The row contains no reversible personal data.
After deletion you may sign in again with the same Apple ID or email address to create a fresh account, but historical balances on past shared expenses stay attributed to the anonymized membership — they are not re-linked to your new account. This is intentional: re-linking would partially undo the deletion you asked us to perform.
Backup snapshots may persist for up to 35 days before being overwritten in the normal course of database backup rotation.
5.1 How long we keep things
Deleting something in Zplity does not erase it on the spot. It moves to Recently Deleted, where any member of the group can put it back, and is erased for good when the window below expires. A nightly job does the erasing; there is no step where a person decides. You can also erase something immediately from Group info → Recently Deleted → Delete now, which skips the window and cannot be undone.
| What | Kept for |
|---|---|
| Deleted expenses and payments, with their receipt photos | 30 days, then erased |
| Statement links you revoked, or that nobody opened | 90 days after they stop working, then erased |
| Receipt-scan usage records (no image, no receipt contents — a count, a size, a timestamp, and whether it succeeded) | 400 days, then erased |
| Sign-in links and codes sent to your email, codes that confirm a new email, and rate-limit counters | Reaped daily once spent or expired |
| A record that you declined a place in a group | Kept while that group exists — a place you turned down is never offered to you again, which needs the record of your answer |
| Your account and personal identifiers | Erased immediately on request — no window, no recovery period |
| The deletion audit row (a salted hash, no reversible data) | Kept indefinitely, as the record that we honored your request |
A member who leaves or is removed from a group keeps a name-only tombstone in that group for as long as the group exists. This is not a retention choice we can shorten: expenses record who paid and who shared, so removing the name would leave the remaining members holding a ledger that no longer says whose money moved. It carries no email and no phone number. If the person had an account, the row keeps a pointer to it that nobody in the group can see, so that if somebody adds them back they land in their own row, with their own history, rather than beside it as a stranger. Deleting your account clears that pointer outright, here as everywhere else.
Separately, a nightly job reconciles our photo storage against the records that reference it, so an image whose expense, member or contact no longer exists is erased rather than lingering. It ignores anything uploaded in the previous 24 hours, so a photo you are in the middle of adding is never mistaken for one nobody wants.
5.2 Who can delete shared records
Expenses and payments belong to a group rather than to one person, so not everyone can remove them. An expense can be deleted by whoever entered it, or by the group’s owner or an admin. A recorded payment can also be deleted by either of the two people it is between, since they are the ones who would notice it is wrong. Anything deleted appears in Recently Deleted for the whole group, so a removal is visible to the people it affects rather than silent.
Editing is deliberately open to every member — the commonest correction in a group is somebody fixing a number that was typed wrong — so an expense changed by anyone other than the person who entered it shows who last changed it, and when.
6. International transfers
Cloudflare and our AI processing providers may process data in the United States and other countries. Where required, we rely on standard contractual clauses and equivalent safeguards to lawfully transfer personal data outside your country of residence.
7. Your rights
Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, and similar regimes), you may have the right to access, correct, port, restrict, or delete the personal data we hold about you, and to object to certain processing. To exercise any of these rights, email contact@nthcube.com. Two of them you can exercise directly in the App without contacting us: edit your profile name, photo, email address, and phone number at any time under Settings → Profile, and delete your account in one tap from Settings → Delete account.
California residents: in the prior 12 months we collected the categories of personal information listed in Section 1 for the purposes listed in Section 2. We do not sell or “share” personal information as those terms are defined under the CCPA/CPRA.
8. Security
Traffic to our servers is encrypted with TLS. Session tokens are signed HS256 JWTs with a 30-day lifetime, rotated on request. Sign-in links, sign-in codes, and codes that confirm an email are stored only as one-way hashes, expire after 15 minutes, and work once. Receipt images you submit for parsing are kept in memory during the parsing round-trip and not written to disk. Your profile photo and any receipt photos you attach to an expense are stored privately in R2 and served only after we verify, on each request, that you share a group with the person or expense concerned — or, for a receipt photo, that the request carries a statement link that includes that expense. No system is perfectly secure; if we ever learn of a breach affecting you, we will notify you in line with applicable law.
9. Children
Zplity is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.
10. Changes
We may update this policy from time to time. If the changes are material, we will notify you in-app or by email before they take effect. The “Effective” date above always reflects the current version, and the list under it says what that version changed.
11. Contact
NthCube LLC
contact@nthcube.com