Privacy policy
Last updated September 20, 2026
This says what Tabrillo collects, what it does not, who else sees it, and how to get it back or get rid of it.
What we collect
The name you choose, and an email address or phone number if you give one. A guest account has neither until you add one.
The expenses you record: what was bought, what it cost, the date, the currency, who paid and who it was split between. Which groups you are in and who else is in them.
Device identifiers and usage data — which screens are opened and which steps are completed — so we can tell where people get stuck. With each use of the app: whether it is the iPhone app, the Android app or the website, the language it showed you, the app version, whether it was in dark mode, and how long it took to open. That record holds no amounts and no descriptions, is kept for 90 days, and is counted into daily totals that name nobody.
The country your device is set to, as two letters, which the app already uses to offer the payment methods people use where you are. We count accounts per country so we know when a country’s registration rules start to apply to us. Not your location: nothing reads where you are, and it is never used to decide anything about you.
What we do not collect
No bank details. No card numbers. No payment credentials of any kind.
Tabrillo does not move money, so there is nothing for us to hold. When you settle up you pay the other person directly, through whatever you already use, and record here that you did. We never see it.
We do not sell anything to advertisers, and there is no advertising network in the app.
Receipt photographs and files
A photograph of a receipt is resized on your device before it is sent. A PDF is sent as it is — shrinking it would lose the text layer that is the reason a PDF reads more accurately than a photograph of one.
Either way it is read and discarded. It is never written down: not on our side, where there is nowhere to put it, and not by the service that reads it beyond the moment it takes to answer.
What comes back is a draft you confirm. Nothing from a photograph reaches your ledger without you agreeing to it.
Voice
When you describe an expense out loud, your device turns the sound into text. The recording is not sent anywhere and is not kept.
You see the text before it goes anywhere, and can correct it. What leaves the device is exactly what you can read.
Who else processes it
Some things are done for us by other companies, under contract. They may use what they handle only to provide the service they are listed for, and for nothing else — not to train anything, not to build a profile, and not to sell on.
They are described by what they do rather than by name. What matters to you is what happens to your data, and that is the column on the right. The one exception is the company that reads your receipts, named below, because we make a specific claim about what it does with them and a claim about an unnamed company cannot be checked.
Adding a service to this list is a condition of adding it to the product: the list you are reading and the list of things we actually use are generated from one source, so a new dependency that is not disclosed here is a broken build rather than an omission somebody notices later.
One thing happens without us in the middle: if you import from Tricount, your device fetches that data from Tricount directly, so they see the request the way they would if you opened their app. We never receive it until it is already on your device.
Some of these are marked pending. That means we intend to use them and have not yet: nothing has been sent to them, because they are not connected to anything. They are listed now so this page does not change quietly on the day they are.
Data is processed in the United States and the European Union depending on the service. If you are in the EU or UK, transfers outside your region rely on the European Commission's standard contractual clauses.
| What we use it for | Status | What they handle |
|---|---|---|
| Cloud hosting and database | In use | Account details, your expenses, and the email address a sign-in link is sent to |
| AI receipt and text processing (Google) | In use | Receipt images and expense text, transiently. Not stored, and not used to train anything |
| Serving the site, its domain, and the sign-in check | In use | Request metadata: an IP address, a device type, which files were fetched; mail sent to our support address; and — when the sign-in check is on — the browser's answer to that check |
| Subscription management | In use | A purchase identifier and which plan is active |
| Payment processing | Pending | Billing details, which never reach us |
| Email delivery | In use | Your email address, and the operational alerts we send ourselves |
Your rights
You can see everything Tabrillo holds about you from inside the app: your account, your groups, every expense and every change anybody made to it.
You can take a copy of your data and you can delete your account, both from the account screen and without asking us. The copy comes two ways: one file holding everything in a format another program can read — your account, the groups you are in and who else is in them, every expense with who paid and how it was split, and every change anybody made to any of it — and a spreadsheet of your expenses with your share worked out, for reading rather than moving.
Two things are not in that file and it says so inside itself. Other people’s email addresses and phone numbers, which are not yours to take and which the app never shows you. And the usage record — which screens were opened, which steps were finished — because the app cannot read that back, including for you. Ask us for it at [email protected] and we will send it.
For a correction, or an objection to how we use something, write to [email protected].
Why we may hold this at all: you asked us to keep a shared ledger, and the ledger is the data. That is a contract we are performing, not a consent you gave, which matters because a consent can be withdrawn while the people you split with still depend on the entries. What does rest on your consent, each time: sending a photograph or a sentence to the AI features. We do no marketing, so there is nothing there to consent to.
If you are in the EU or UK you have these rights under the GDPR, and you can complain to your national data protection authority. If you are in California you have them under the CCPA, and we do not sell or share personal information as those laws define it.
If you are in India, the Digital Personal Data Protection Act, 2023 applies. We process what you give us for the purpose you gave it (its section 7), and you have the rights to access, correct, complete and erase your personal data, to withdraw a consent as easily as you gave it, to nominate somebody to exercise these rights for you, and to have a grievance answered. The account screen is the way to do the first four without asking us; for the rest, or if an answer does not satisfy you, write to [email protected] and then to the Data Protection Board of India.
Complaints about content in Tabrillo from India go to our Grievance Officer, Swan Business Group LLC, TX, USA, at [email protected] (Monday to Friday, 09:00–17:00 IST), or through Report on any expense or person in the app. A complaint is acknowledged within 24 hours and answered within 15 days, and sooner where the law requires it.
If you are in Brazil, the Lei Geral de Proteção de Dados applies. Our basis is the performance of the contract with you (article 7, V), and you have the rights in article 18: confirmation, access, correction, anonymisation, portability, deletion, information about who we share with, and to revoke a consent. The account screen does most of it; for the rest write to [email protected], and you may complain to the Autoridade Nacional de Proteção de Dados.
If you are in Australia, the Privacy Act 1988 and the Australian Privacy Principles apply. We collect only what the service reasonably needs, you may ask what we hold and have it corrected, and you may complain to us first and then to the Office of the Australian Information Commissioner. Data is held outside Australia, in the United States, under the contracts described above.
If you are in South Korea, the Personal Information Protection Act applies. We collect and use your information because it is necessary to provide the service you asked for (article 15(1)4), and you may ask to access it, to correct or delete it, to suspend its processing, and to withdraw a consent. Your information is processed by the companies listed above, outside Korea, to provide the service; the account screen does most of the above, and [email protected] does the rest. You may complain to the Personal Information Protection Commission.
What the AI does, and what it does not
Five things in Tabrillo are made with a language model: reading a receipt into a draft, turning a spoken sentence into a draft, the captions on a Wrapped deck, the Fairness Arbiter’s reading of a balance, and a reminder message written for you to send. Each is marked where you start it, and what comes back is marked as written by AI where it is shown.
None of it writes to your ledger. A draft is filled into a form you read and save; a reading is shown beside the arithmetic it is about; a reminder is shown to you and sent by you, or not. The model has no way to add, change or delete an expense, and it is told nothing about you beyond the lines it is asked about.
What you send to these features is used to answer you and then discarded. It is not kept by the company that runs the model and it is not used to train anything. Each feature can be switched off by us at any time, and when it is off it disappears rather than failing.
How long we keep it
Your expenses stay for as long as the groups they are in exist, because they are what those groups are for.
When you delete your account your name and contact details are removed and your entries are left in place, unnamed. This is deliberate: deleting them would change what everybody else in your groups is owed, silently, without their agreeing to it. A group can delete its own history.
A guest account that is never claimed and shows no activity is removed automatically after a period of inactivity.
If you are in California
California’s privacy law — the CCPA, as amended by the CPRA — uses its own vocabulary for things the rest of this policy describes in plain words. This section is the same facts in that vocabulary. Where the wording differs, the substance does not.
Where it comes from. Two places, and the second is worth saying plainly: from you, and from other people in your groups. Somebody who records an expense and names you as one of the people splitting it has entered information about you. That is what a shared ledger is, and it is why everyone in a group can see who entered what.
Why we collect it — the business and commercial purposes. To run the ledger: recording expenses, working out who owes whom, and showing the expenses behind a balance. To keep your account working across your devices. To keep the service working and safe, which covers abuse limits, error reports, and knowing which steps people get stuck on. And to meet legal obligations. Nothing is collected for advertising of any kind.
What we collect, in the categories the law uses:
| Category under the CCPA | What that is here | How long we keep it |
|---|---|---|
| Identifiers | The name you choose; an email address or phone number if you give one; identifiers for the device you use. | Until you delete your account. An unclaimed guest account with no activity is removed after 30 days. |
| Commercial information | The expenses you record: what was bought, what it cost, the date, the currency, who paid, and who it was split between. | For as long as the groups they are in exist. Deleting your account removes your name from them and leaves the entries, unnamed — see “How long we keep it” above for why. |
| Internet or other electronic network activity | Which screens are opened and which steps are completed — no amounts and no descriptions. Separately, a record that an AI feature was used: who used it, which feature, and when. Never what was in it. | 90 days for the usage record. One day for the record of an AI request. |
| Visual information | A photograph of a receipt, when you take one — resized on your device first — or a receipt you already have as a PDF, which is sent as it is. | We do not store either. What is kept is the draft it produced, once you have confirmed it, as an ordinary expense. |
| Audio information | Speech, when you choose to describe an expense out loud. Your own device turns it into text; the recording is not sent anywhere. | We never receive it, so there is nothing for us to keep. What leaves your device is the text you can read and correct first. |
Selling, sharing, and sensitive information
We do not sell personal information, and never have.
We do not share it for cross-context behavioural advertising. That is the term the CCPA uses for taking what is learned about you on one service and using it to aim advertising at you on another. There is no advertising network in Tabrillo, and no third party receives your information for any advertising purpose.
Because we do neither, there is nothing to opt out of, and you will not find a “Do Not Sell or Share My Personal Information” link here. The law asks for that link from businesses that do these things. This paragraph is what it asks for from the rest of us.
We do not collect sensitive personal information as the CCPA defines it. That category covers government identifiers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, the contents of your mail or messages, genetic and biometric data, health, and sex life or sexual orientation. It also covers a username and password together — and there is no password to collect, because signing in is a link sent to your email. Nothing in the app reads your location: the currency it suggests comes from your device’s region setting, which is a preference rather than a position.
So the right to limit how sensitive personal information is used does not arise. We are not claiming an exemption from it; there is simply none of it here.
Your California rights, and how to use them
To know. What we collect, where it came from, why, and who else receives it — the three sections above. You can also read your own account, groups, expenses and their history inside the app at any time.
To delete. From the account screen, without asking us. What deletion does and does not remove is described in “How long we keep it”.
To correct. Your name and contact details are yours to change in the app. For anything else, write to us.
To opt out of sale or sharing. There is nothing to opt out of — see the section above.
To limit the use of sensitive personal information. There is none to limit — see the section above.
Not to be treated differently for asking. We will not deny you the app, charge you a different price, give you a worse service, or show you something different because you exercised any of these rights.
How to ask: [email protected]. Tabrillo is an online service and you deal with us directly, so this is the address the law asks us to give.
How we check it is you: a request has to come from, or be confirmed from, the email address or phone number on the account. A guest account has neither — which is also why it holds nothing of yours to return, and why everything in it is already in front of you in the app. We will not ask you for anything extra to prove who you are.
Somebody acting for you: an authorised agent may make a request on your behalf. Send us written permission signed by you, and we will confirm it with you before acting on it.
Children
Tabrillo is not directed at children and is intended for people aged 13 and over. We do not knowingly collect anything from a child under 13. If you believe we have, write to [email protected] and we will remove it.
Changes, and getting in touch
If this changes in a way that matters, you will be asked to read it again before you carry on using Tabrillo.
Questions, requests, or anything you think is wrong here: [email protected]. A person reads that address.
Terms of use · [email protected] · © 2026 Swan Business Group LLC