← Home

Privacy Policy

Last updated: August 2026, applies to 8bitsplit.app

8bitSplit is a personal utility for splitting bills among friends. This page explains exactly what data the app touches, where it goes, and how long it stays. Plain language, no filler.

What we store on our servers

—

Event data: When you create an event, we store the event title, participant name labels you enter (e.g. “Alice”, “Bob” — whatever you type), venue names, item names, prices, and who paid. This is the minimum needed for the app to work.

—

Access tokens & join codes: Random access strings (e.g. Xk2…) identify the creator and any invited Buddy (co-op editor). A separate, shorter 16-character join code identifies Watcher (view-only) access, and can be shared as a code or a link — both grant the same read-only access, nothing more. None of these are linked to any account, email, or identity.

—

Retention: All event data is automatically deleted 7 days after the event was created. There is no archive. Once deleted, it cannot be recovered. You can also manually delete individual participants and venues at any time.

Optional: payment QR codes & proof screenshots

—

What it is: The event creator can optionally attach a QR code or payment handle (e.g. eSewa, Khalti, Venmo, UPI) so the group knows where to send money, and anyone marking a transfer as paid can optionally attach a screenshot as proof. Both are entirely optional — nothing about the app requires them.

—

Where it lives: Images are stored directly in our own database alongside the rest of your event data — the same one described above. They are never sent to a third-party image host or CDN.

—

Metadata stripping: Every uploaded image is re-processed before storage to strip EXIF metadata, including GPS location and device information that phone cameras often embed automatically.

—

Retention: The payment QR/handle is deleted automatically once every transfer in the event is marked as settled — it has no reason to stick around once nobody needs to see it anymore. Everything else (including proof screenshots) is deleted with the rest of the event after 7 days, same as everything above.

—

Visibility: Anyone with the event's link can view this information, the same as the rest of the event — access is controlled by who has the link, not by a login.

What stays only in your browser

—

LocalStorage (not cookies): When you create or join an event, your editor token and role are saved in your browser's localStorage under keys named fairsplit_token_* and fairsplit_role_*. This data never leaves your device except as a header on requests you make to the app. Clearing your browser data removes it.

—

"Continue where you left off" recall list: Every event you create, join, or view is added to a purely local list on your device (fairsplit_meta_*) — title, total, expiry date, and your role — so you can find your way back without re-typing a link. This list is never sent to our servers; we have no way to see it. Once an event expires and is deleted server-side, its entry stays as a read-only stub (title + total only) for your own records, until you remove it.

We do not use cookies. There is no cookie banner because there is nothing to consent to.

Installing as an app

If you install 8bitSplit to your home screen or app drawer, a minimal service worker runs in the background. It does not cache your data, does not enable offline use, and does not track anything — its only purpose is to satisfy the browser's technical requirement for a “real” install versus a plain bookmark. Every request still goes straight to the network, exactly as it does in a normal browser tab.

Receipt scanning (OCR)

—

What happens to your image: When you scan a receipt, the image is sent from your browser to our backend server, which downscales it and strips EXIF metadata (device model, GPS location, etc.) before forwarding it to Google's Gemini API for text extraction. The image is not stored by 8bitSplit at any point — it is processed in memory and discarded. Only the extracted text (item names, prices) is returned and optionally saved as part of your event.

—

Third party: Google's Gemini API receives and processes receipt images. We use its free tier, and Google's terms for the free tier allow inputs and outputs to be used to improve their models — this is different from a paid API tier, where they aren't. Their data handling is governed by the Gemini API Additional Terms of Service. Do not scan receipts containing sensitive personal or financial account information.

Analytics & performance

—

Vercel Analytics: We use Vercel Analytics to count page views. It collects anonymous visit counts, country-level location (not city or IP), and referrer URL. No personal data, no cross-site tracking, no advertising profiles.

—

Vercel Speed Insights: We use Vercel Speed Insights to monitor page load performance (Core Web Vitals). It collects technical timing data — no personal information.

Both are provided by Vercel, Inc. See the Vercel Privacy Policy for details.

Server logs & IP addresses

Our backend server (hosted on Render) generates standard access logs. IP addresses appear in logs only when a rate limit is exceeded — for example, if many requests come from the same address in a short window. This is used to identify and block abuse, not to track normal users. Log retention is governed by Render's Privacy Policy.

What we don't do

✓

We do not sell, rent, or share your data with advertisers.

✓

We do not build user profiles or track behaviour across sessions.

✓

We do not require registration, email, or any personal identification.

✓

We do not use third-party ad networks or tracking pixels.

Data hosted in

Our backend database is hosted on Neon (PostgreSQL), and the backend server runs on Render. Both are US-based cloud providers. The frontend is hosted on Vercel (global CDN).

Your choices

—

Delete your event data: As event creator, you can delete individual participants and venues from the dashboard at any time. All remaining data is automatically purged after 7 days.

—

Clear browser storage: To remove your editor tokens from your device, clear localStorage in your browser settings (Settings → Privacy → Clear browsing data, or equivalent).

Contact

Questions about this policy? Email bhattaraimanas@gmail.com.