This privacy policy explains how personal data is processed when you use the mobile application "kwitto" (Android) and the website kwitto.app, in accordance with Regulation (EU) 2016/679 (GDPR). The German version is authoritative.
stoneland-five
[company name incl. legal form]
[address]
Email: datenschutz@kwitto.app
kwitto is used to record and split shared expenses. We process the data you enter yourself (account, groups, expenses, receipts) and technical data required to operate, secure, and debug the app. kwitto shows no ads and does not sell data. kwitto does not send its own emails — the only exception are account emails from the sign-in platform (e.g. password reset, email verification).
In groups, users also record information about other people (such as names of travel companions or placeholder members without their own account). In doing so, users act in a private, household context (Art. 2(2)(c) GDPR); they are themselves responsible for the content of their entries. We provide the technical platform for this and do not review the entries.
When you register, we process your email address, display name (alias), and sign-in credentials. You can sign in with email/password or via a third-party provider (Google account); with third-party sign-in we receive the profile data you release there (email, name).
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
Groups, members, expenses, splits, settlements, comments, and activity entries you create are stored and shown to the members of the respective group. Amounts, titles, and participants of an expense are visible to all group members — that is the purpose of the app. To determine the basic scope after the trial period (Terms, section 4) we keep a counter in your account of the entries created per calendar month; it is deleted together with the account.
Legal basis: Art. 6(1)(b) GDPR.
Photographed or uploaded receipts (photos, PDFs) and image attachments to support messages are stored in our cloud storage and are accessible only to authorized group members or support staff.
If you use the receipt archive, the receipts stored there (photos, PDFs), the details you saved (such as merchant including address, receipt number, items with serial numbers) and — when AI recognition is used — an extracted text excerpt of the receipt are stored until you delete them. Receipts may contain personal data (e.g. names, addresses or payment details printed on the receipt). Archived receipts are accessible to you only.
Legal basis: Art. 6(1)(b) GDPR.
When you actively start the "Magic Scan" feature, the selected receipt image is transmitted to the AI interface of Google (Gemini) for automatic text and amount recognition. Transmission happens via our servers. The paid programming interface we use is covered by Google's data processing addendum: content is used neither to improve Google services nor to train models. Google stores requests and responses for a limited period solely to detect and prevent abusive use. The image is transmitted in full and may therefore contain everything visible on it (such as merchant, location, time and line items). No transmission takes place unless you actively start this feature.
The same applies when you start AI recognition in the receipt archive: in addition, document-identity details are recognized (such as the merchant's legal name and address, receipt number, payment method, model and serial numbers, and a text excerpt of the receipt) and shown to you as suggestions for adoption.
Legal basis: Art. 6(1)(b) GDPR; for third-country transfer see section 5.
You can import an export file from another app (e.g. Splitwise) into kwitto. Reading the file, calculating the balances and creating the group happen entirely on your device and in your account — the file itself is transmitted neither to us nor to any third party.
Only if kwitto cannot determine the file's structure on its own do we additionally offer AI-assisted format detection. It runs solely with your explicit consent, which you give for each individual file and which applies to that one operation only. What is then transmitted to the AI interface of Anthropic (Claude) is:
Names, amounts, dates and descriptions are therefore not transmitted — only the structure of the file is. The sole exception are short, repeating labels such as category names (e.g. "Groceries") or currency codes, which are transmitted as-is because they are needed to map the categories and contain no personal data. The mapping between placeholders and the real values never leaves your device.
The result is a suggestion of what each column means. It is shown to you before the import and you can change it; kwitto then performs the import itself locally again.
Legal basis: Art. 6(1)(a) GDPR (consent); no transmission takes place without your consent. For third-country transfer see section 5.
For notifications (e.g. new expense, payment request) we process device push tokens via Firebase Cloud Messaging. Push can be disabled in the system and app settings.
Legal basis: Art. 6(1)(b) GDPR.
When the app crashes, technical reports (device model, OS version, crash stack trace, pseudonymous installation ID) are collected via Firebase Crashlytics to fix errors. Firebase Analytics collects aggregated usage events (e.g. app start) to improve the app; there is no advertising tracking.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stable, secure operation).
Firebase App Check verifies that requests originate from an unmodified, authentic app installation (Play Integrity attestation).
Legal basis: Art. 6(1)(f) GDPR (security of the service).
One-time trial period. So that the trial period (Terms, section 4.1) cannot be claimed repeatedly by registering again, we store at registration a cryptographic digest (SHA-256 hash) of your normalised email address (lower case; for Gmail addresses without dots and without a "+" suffix), together with the time and the internal identifier of the account with which the trial period was started. The address cannot be recovered from the digest; it is only compared with the digest of a newly registered address. The digest is retained after you delete your account (section 6) — otherwise the trial period could be repeated at will by deleting and re-creating the account.
Legal basis: Art. 6(1)(f) GDPR (abuse prevention).
For offline use, the app stores data locally on your device (encrypted app storage). This data only leaves the device when it is synchronized with your account.
We use the following service providers as processors:
We do not share data with other third parties unless legally required to do so.
Where data is transferred to the USA (Google LLC, Anthropic PBC), the transfer is based on the adequacy decision for the EU-U.S. Data Privacy Framework or on EU standard contractual clauses (Art. 45, 46 GDPR).
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on legitimate interests (Art. 21 GDPR). To exercise these rights, contact datenschutz@kwitto.app.
You can also request a copy of your data directly in the app (Profile → "Data export (GDPR)"); it is provided as a report in your inbox.
You also have the right to lodge a complaint with a data protection supervisory authority, e.g. at your habitual residence. Authority responsible for us: [supervisory authority].
Providing account data is required to use kwitto; without it, no account can be maintained. All other information is voluntary.
We update this privacy policy when features or the legal situation change. The version published in the app and on kwitto.app applies; version and date are stated at the top of this document.