SPLITO Logo SPLITO Back to App

Privacy Policy

The Dev Story · Version 2.2 · Last Updated: September 2026
Summary in Plain English

SPLITO is designed with an ephemeral, privacy-first architecture. We do not sell your personal data or display third-party advertisements. In Offline Mode, all calculations and expenses are stored locally on your device without leaving your browser. In Online Mode, chat messages and expense logs sync temporarily to Google Firebase and are automatically deleted after 30 days.

1. Data Controller & Scope

This Privacy Policy applies to the SPLITO web application (splito.thedevstory.com), operated by The Dev Story. We comply with applicable international data protection standards, including India's Digital Personal Data Protection Act (DPDPA 2023), the European Union's General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).

2. What Personal Data We Process

We practice strict data minimization. We only process data in the following contextual circumstances:

  • Email Address (Contextual & Optional): Collected only if you voluntarily provide an email in the Feedback & Support modal to receive a response from our team. We never request emails on landing or during group creation.
  • Group Chat Messages (Online Mode Only): Ephemeral live chat messages, timestamps, and chosen participant nicknames sent within group chat.
  • Expense & Group Details: Group names, member names, expense amounts, split shares, currencies, and recorded settlements created by you and your peers.

3. Notice: Open Shared Groups & Non-Encrypted Chat

⚠️ Do Not Disclose Private or Sensitive Information: Shared group links allow collective access to group members. Real-time chat messages and expense logs are synchronized via Google Firebase for collaboration and are not end-to-end encrypted (E2EE). Users must never disclose passwords, bank accounts, debit/credit cards, CVVs, OTPs, government IDs, or confidential personal data on SPLITO. Chat is intended strictly for general trip coordination, dining conversations, and expense-related discussions.

4. Cookies, Local Storage & Telemetry (ePrivacy / GDPR Disclosure)

SPLITO does not use invasive tracking cookies or commercial ad beacons. We utilize local browser storage mechanisms strictly for functionality and security:

  • Strictly Necessary Local Storage: Stores your active group data, expense ledgers, local UI theme preference, and PBKDF2 PIN hashes on your local device.
  • Security & Anti-Abuse Telemetry: In Online Mode, a pseudonymized visitor identifier (stored as SPLITO_fp_visitor_id via FingerprintJS CDN) is used to prevent malicious bot spamming, brute-force abuse of Firebase endpoints, and to enforce feedback rate limits. This hash is never used to profile individuals or track cross-site activity.

5. Third-Party Subprocessors & Infrastructure

To provide high availability and real-time synchronization, SPLITO relies on the following trusted infrastructure providers:

  • Cloudflare Pages & CDN: Web application hosting, edge caching, DDoS mitigation, and SSL/TLS transport encryption.
  • Google Firebase (Google Cloud Platform): Real-time cloud database synchronization for Online Mode with TLS 1.3 encryption.
  • Google Fonts: Web typography delivery via cached stylesheet requests.
  • FingerprintJS (openfpcdn.io): Client-side anti-bot security verification.

6. Storage Infrastructure & 30-Day Auto-Purge

  • Local Storage (Offline Mode): In Offline Mode, 100% of your data remains on your physical device in browser localStorage. No network transmission occurs.
  • Cloud Storage (Online Mode): Online groups synchronize via Google Firebase Realtime Database with end-to-end transport encryption.
  • Ephemeral 30-Day Lifecycle: Online groups, transactions, and chat records are scheduled to automatically delete 30 days after inactivity.
  • Instant Manual Deletion: Clicking "Delete Group" immediately cascades complete removal across local storage and Firebase cloud storage.

7. Age Restriction (Protection of Minors under DPDPA Section 9)

SPLITO is intended for users who are at least 18 years of age (or the age of majority in your jurisdiction). We do not knowingly solicit, process, or market to individuals under the age of 18 without verifiable parental authorization.

8. Your Legal Rights & Data Controls

You maintain full ownership of your data:

  • Right to Access & Export: Export your complete group ledger at any time in JSON, CSV, PDF, or WhatsApp text formats.
  • Right to Erasure (Right to be Forgotten): Purge any group or transaction on demand.
  • Right to Withdraw Consent: Submit feedback anonymously without an email, or use Offline Mode exclusively.

9. Designated Grievance Redressal (DPDPA 2023 Requirement)

In accordance with Section 8 and 12 of India's Digital Personal Data Protection Act, 2023, if you have any questions, concerns, or requests regarding the handling or deletion of your personal data, you may reach our designated contact channel:

  • Operator: The Dev Story
  • Grievance Email: thedevstory26@gmail.com
  • In-App Channel: Via the Feedback & Support modal
  • Resolution Timeline: We acknowledge and address legitimate data inquiries within 30 days.