← e-split

Privacy notice

Effective September 17, 2026

e-split is an independent beta recordkeeping service operated as e-split. Questions and privacy requests can be sent to privacy@e-split.com.

What e-split keeps

We keep the information needed to run the service: your ChatGPT authentication identifier, email and account name; the profile name, bio, color, and visibility you choose; household addresses; split names and dates; member and invitation details; bills, expense shares, disputes, repayment reports, returns, deadlines, and audit history; private Personal and Business tracker entries, categories, notes, business-purpose and review fields, import references, and tracker history; payment usernames you choose to share; bill-inbox routing rules and extracted suggestions; notification preferences and encrypted push subscriptions; and limited operational error references.

Receipts in My expenses are visible only to their account owner. Attachments in a split are private to the people authorized for that split. Original files are stored separately from their database metadata in private object storage and are never published as public links. Bill email bodies are processed to create a review item but are not stored as message content. Sender, subject, extracted fields, confidence, warnings, and attachment metadata are stored only while the item awaits review. Adding or ignoring it scrubs that review data and attachments; closing the split removes any remaining inbox items.

How information is used

We use this information to authenticate you, show the shared records for your splits and your private Ledger, send invitations you request, prepare bills and expense drafts, calculate balances and Ledger summaries, create exports you request, deliver reminders you opt into, protect the service, and respond to support or privacy requests. e-split does not sell personal information or use financial data for advertising.

Who can see shared records

Active members of a split can see its shared ledger and the names attached to it. Depending on the feature, owners or the people involved may see invitation addresses, payment usernames, inbox review items, receipts, or dispute details. A member’s profile bio and color are shared only when that member turns on group visibility. Avoid entering secrets or unrelated sensitive information in descriptions and notes.

Service providers and optional integrations

You may read a Ledger receipt with AI before saving a record. Its original photo is stored in e-split only when you save the record and attachment. Private scan results, file fingerprints, and credit or attempt history are retained even if you discard the draft, so retries and usage limits remain accurate. Your account export includes scan results and credit history; deleting your account removes the scan data.

Retention and deletion

Active split records remain while the split is in use. Closing a used split removes private receipt bytes, invitations, inbox setup and messages, payment handles, and other private coordination data. Its pseudonymized shared ledger remains read-only with a review date seven years after closure so members can retain the record they relied on. Unused splits can be deleted instead.

Deleting an account immediately removes the profile, private Ledger records, contact link, payment handles, notification subscriptions, and access. Uploaded private files are made inaccessible immediately and deletion from object storage is retried until complete. Shared records already relied on by other members remain under “Former member.” Starting a fresh account is blocked until pending private-file cleanup finishes. Export tools provide portable copies without receipt bytes; a broader access or deletion request can be made by email.

Exports

A tracker CSV is created only when you request it. It can be imported into Google Sheets or another spreadsheet service, but that copy then sits outside e-split’s access controls and cannot be recalled or deleted by e-split. Receipt references lead back to an authenticated e-split page; receipt files are not made public or embedded in the export.

Optional beta counts

A Profile setting can share weekly aggregate counts for payment handoffs and completed repayment steps. It is off by default and stays on your device. These counts contain no account, device, split, expense, amount, currency, URL, or free text, are retained for up to 90 days, and are disabled when the browser sends Global Privacy Control or Do Not Track.

Your choices

You can enter tracker records manually, store a receipt without scanning it, keep all receipt or PDF reading off, remove tracker receipts and records, edit profile visibility, remove payment usernames, disable a push device, choose or pause 7-day, 3-day, and 24-hour reminders, leave beta counts off, export records, close or delete eligible splits, and delete your account. You can also request access, correction, or deletion by emailing us. We will verify the account before releasing private information.

Security and changes

e-split uses access checks, private cache controls, encrypted push endpoints, signed webhooks, short-lived attachment downloads, rate limits, and data-minimizing notifications. No service can guarantee absolute security. Material changes to this notice will be posted here with a new effective date. During beta, features and retention practices may change as safeguards improve.

Contact: privacy@e-split.com · Terms of use