Privacy policy
Last updated 8 September 2026
TabSplitter is run by MRX Software LLC. It splits a restaurant check by line item. This page describes everything it stores about you, why, who else can see it, and how to make it go away.
The short version: we keep what the app needs to work and nothing else. There is no advertising, no analytics, no tracking pixels, and nothing is sold or shared for marketing.
What we collect
If you have an account
- Your email address. It is how you sign in — either a one-time code sent to that address, or a linked Google account (see below); there are no passwords.
- A display name, guessed from the part of your email before the
@when the account is created, and editable afterward from your account page. - A @handle — a short unique name generated from your display name and editable on your account page. It is shown next to your name to the people on your tabs and trips, so two people with the same name can be told apart, and lets them add you by typing it.
- Optionally, a profile picture, a Venmo username, a Cash App cashtag and a phone number, if you add them on your account page. This is separate from the Venmo or Cash App handle you can also save on an individual tab or trip, and is visible only to you — apart from the administrator review of uploaded photos described under "Unlawful images" below.
- Sign-in codes, stored only as a hash and deleted once they expire, which is ten minutes after they are sent.
- If you sign in with Google: the name, email address and profile picture Google shares with us, and an access and refresh token for that sign-in — used only to verify who you are, never to read anything else in your Google account.
- Session records — a session token, its expiry, and the IP address and browser user-agent of the device that signed in. These let us keep you signed in and let you see where your account is being used. On a build where Premium is offered, that IP address is also looked up against an offline database for a country, to check a new subscription can be offered where you are — the country is used for that one check and is not stored. Premium is not currently offered, so this does not happen today.
- Your plan, and if you ever subscribe, a Stripe customer and subscription reference plus the subscription's status and billing period.
Tabs you create
- The name you give the tab, its currency, and the tax and tip you enter.
- Each line item's name, any note, its price, how many of it the line is for, and — if it was priced in a different currency from the tab — that currency.
- The names of everyone on the tab, who claimed which items, and how — an equal split, a number of shares, or a fixed amount or percentage claimed for that person specifically.
- Who paid, and who's paid whom back. Who fronted the bill, which transfers have been marked paid, and — if someone adds one — the Venmo username or Cash App cashtag that lets others pay them with one tap.
- The activity log — a plain-language line for each thing that happened on the tab (an item added or edited, someone joining, tax or tip changed, the tab settled or reopened, a transfer marked paid) and when.
- If you invite someone by email, their email address — shown to the tab's owner and co-owners, never to guests. If you add a co-owner, their existing TabSplitter account gets full edit rights on the tab, same as you.
- The receipt photo, if you take one, and which account took it. It is stored with the tab, and only you can see it — not guests holding the share link, and not co-owners, who are told a photo exists but can't open it. The items read off it are on the tab for everyone. You can remove the photo on its own from the tab; a site administrator can review it under the "Unlawful images" policy below.
Reading the receipt
When you scan a receipt, the photo is read to suggest the items, tax and tip, which you review before any of it goes on the tab. Depending on how the deployment you're using is configured, that reading happens on our own server, or the photo is sent to Anthropic's Claude API to be transcribed, under Anthropic's API terms; either way the photo itself is stored only with us. Nothing else about you or the tab is sent along with it.
Trips you create or join
- The name you give the trip.
- The names of everyone on the trip's roster, and — if someone adds one — the Venmo username or Cash App cashtag saved against them. If someone is invited by email, their email address; if someone joins while signed in, which account is theirs.
- Which of the trip's combined transfers have been marked paid, and the amount and currency for each.
Everyone on a trip's roster is copied onto each of its tabs as ordinary participants, and anyone added to one of those tabs is added to the roster — see "Tabs you create" above for what's stored on the tab itself from that point on. A trip has a share link like a tab's: anyone holding it can see the roster, the tabs in the trip, and the combined settle-up, and can join by name without an account. Email addresses on the roster are shown only to the trip's owner — not to other members, and never on the guest view. If a tab you started is put into a trip, its name, total and who paid are listed on that trip's page for everyone on the trip, who can open it through its share link like any other guest.
If someone shares a tab with you
You do not need an account to claim items. When you open a share link and pick or add a name, that name and your claims are stored on that tab and are visible to everyone else holding the link. We do not create an account for you and do not ask for your email. Your browser remembers which person you picked so you don't have to choose again; that stays on your device.
If that tab is part of a trip, a name you add yourself under also goes on the trip's roster and onto the trip's other tabs that haven't been settled, so your share on each counts in the trip's combined settle-up — and everyone holding the trip's link can see it there. If you were signed in when you joined, your account is recorded on that roster entry and the trip appears in your own list.
Push notifications
Turning on "Notify me on this device" — available to the owner and to any guest, with no account needed — saves that browser's push subscription (an endpoint URL and two encryption keys your browser generates, which identify the device and let us send it a notification through your browser's push service, not the content of anything). It's tied to the tab and to whichever person you're claiming as, used only to tell that device the tab has settled or that a reminder was sent, and deleted the moment you turn notifications back off. This feature is off entirely unless the app you're using has push notifications configured.
What we never collect
Card numbers and payment details never reach our servers. Payment is handled entirely by Stripe on their own pages. We also do not collect precise location — only the country-level check described above, and only when you start a Premium subscription — nor contacts, photos other than a receipt you deliberately take, or any advertising identifier.
Cookies
All of them are strictly necessary, and none are used for tracking: one holds your sign-in session, one briefly remembers which email address a code was just sent to so the next screen knows who is verifying, and — only for the few seconds of signing in with Google — one protects that handoff against being forged. There are no analytics or advertising cookies. Strictly-necessary cookies like these are exempt from cookie-consent requirements under GDPR and the ePrivacy Directive, precisely because the site can't function without them — so there is nothing to consent to, and no banner asking you to.
Unlawful images
Two features accept a photo you take yourself: a receipt, and a profile picture. Don't upload anything unlawful — most seriously, any image that sexually exploits a minor.
If we become aware that an uploaded photo appears to be that, we remove it and act on the account behind it, up to closing it. Where US federal law requires it, we also report the material to the National Center for Missing & Exploited Children (NCMEC), which can mean sharing the image itself and related account details (your email, account id, and when it was uploaded) with NCMEC and law enforcement, and keeping what we're legally required to preserve rather than deleting it the way the rest of this page describes. We may also turn either upload feature off entirely, for everyone, at any time — see our terms of service for the full acceptable-use policy.
Who else sees your data
- Stripe processes subscription payments and holds your billing details.
- Google, only if you choose to sign in with it — it authenticates you and shares your name, email and profile picture with us for that purpose.
- Our email provider delivers sign-in codes, tab and trip invitations, and payment reminders, which means it handles the recipient's email address and the message.
- Your browser's push service (run by Google, Mozilla, Apple or Microsoft, depending on your browser), only if you turn on notifications — it relays the notification to your device without seeing what a tab contains.
- Anthropic, only on a deployment configured to use Claude for reading receipts, and only the receipt photo — see "Reading the receipt" above.
- Anyone you give a share link to, including a co-owner you add. A share link is the key to that tab: whoever holds it can see its items, the names on it, the amounts, and the activity log — but not the receipt photo, which stays yours. Pass it on carefully. Everyone on a trip that one of your tabs is part of can open it the same way.
- Site administrators can view and remove any uploaded receipt photo or profile picture, to enforce the "Unlawful images" policy above. That is the only account content they see that you haven't shared with them.
- NCMEC and law enforcement, only for an uploaded photo that appears to be unlawful in the way described under "Unlawful images" above.
We do not sell personal data, and we do not share it for anybody's marketing. We will hand over data if the law genuinely requires it.
How long we keep it
- Sign-in codes: ten minutes, then deleted.
- Sessions: up to a year from when you last used the account, then they expire on their own.
- Tabs, items, claims, the activity log and receipt photos: until you delete the tab or your account — except a tab with a co-owner, or one inside a trip other people are on, which is handed to them when you delete your account rather than deleted (your receipt photo on it goes, since only you could see it).
- Trips, their roster and their payment marks: until the trip is deleted. A trip you created is handed to another member when you delete your account, if there is one; otherwise it goes with your account. Your own roster entry on someone else's trip loses its link to your account when you delete it.
- Your profile picture, Venmo, Cash App and phone: until you remove them or delete your account.
- Push subscriptions: until notifications are turned off on that device, the tab is deleted, or the push service tells us the device is gone.
- Billing records: Stripe keeps its own transaction records for as long as tax and accounting law requires, independently of us.
The one exception to all of the above: a photo we remove for being unlawful, and the account details around it, may be preserved rather than deleted — see "Unlawful images" above.
Deleting your data
You can delete any individual tab from its page, which takes its items, claims and receipt photo with it — or remove just the receipt photo and keep the tab.
If you created a trip, you can delete it from its page, which removes its roster and payment marks for everyone on it. The tabs started inside it are not deleted along with it — they just stop being grouped together. Its owner can also remove you from a trip's roster.
You can clear your profile picture, Venmo, Cash App or phone number at any time from your account page — there's a "Remove photo" button, and clearing a field's box and saving removes it.
You can delete your whole account from your account page. That removes your account and every tab you started, cancels any subscription so you are not charged again, and cannot be undone. Share links you handed out stop working. Two exceptions, so other people's records survive: a tab you gave a co-owner passes to them, and a tab inside a trip that has other members passes to the trip's owner — in both cases without your receipt photo.
If you claimed items as a guest and want your name off a tab, ask whoever started it — they can remove you — or write to us at the address below.
Your rights
Depending on where you live, you may have the right to see a copy of your data, correct it, delete it, or object to how it is used. The delete controls above cover most of that directly. For anything else, write to us and we will action it.
Children
TabSplitter is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has an account, contact us and we will remove it.
Changes
If this policy changes in substance we will update the date at the top. Continuing to use TabSplitter after a change means the updated policy applies.
Contact
Questions, requests, or complaints: privacy@tabsplitter.app. The rules for using TabSplitter are in our terms of service.