Back to Home

Privacy Policy

Last Updated: July 12, 2026

Introduction

Welcome to ShareBill. We are committed to protecting your privacy. This Privacy Policy explains what personal data we collect, how we process it, and what rights you have under the EU General Data Protection Regulation (GDPR) and Germany's Telecommunications Digital Services Data Protection Act (TDDDG – formerly TTDSG).

This application is designed to be privacy-friendly: no account registration is required to use the core features.

Disclaimer: Use At Your Own Risk

ShareBill is provided "as is" without any warranties. While we take reasonable measures to protect your data, there is a possibility that data could be lost or inadvertently deleted. Please use this application at your own risk and do not store critical information here.

Data Controller

The responsible entity (data controller) for data processing under Art. 4(7) GDPR is:

Email: schadeapps@gmail.com

We are currently a non-commercial project and have not designated a data protection officer, as this is not legally required under Art. 37 GDPR given the nature and scope of our processing activities.

What Data We Collect and Why

1. Group and Expense Data (Firebase Firestore)

When you create or join a group, we process the following information:

  • Group Name: The name you give your group.
  • Member Names: The names of participants you enter.
  • Expenses: Amount, description, category, payer, and how the cost is split.

Purpose: This data is used solely to provide the bill-splitting functionality you request.

Legal basis: Art. 6(1)(b) GDPR — processing is necessary for the performance of a contract (the use of our service) to which you are a party.

Where it's stored: Google Firebase Firestore. See "Third-Country Transfers" below. Each group is assigned a unique, non-guessable ID and access requires knowledge of this ID.

2. Browser Local Storage

To provide a seamless, login-free experience, we store the following data in your browser's local storage:

  • Group IDs: A list of groups you have created or visited (key: sharebill-groups).
  • Consent Flag: A flag remembering your preference regarding this notice (key: sharebill-privacy-consent).

Purpose: Group IDs are required to retrieve your groups on return visits. The consent flag prevents repeated display of this notice.

Legal basis: Group IDs are stored based on our legitimate interest under Art. 6(1)(f) GDPR in providing core app functionality. The consent flag is stored based on your consent under Art. 6(1)(a) GDPR.

This data never leaves your device unless you clear your browser data.

Under §25(2) TDDDG, storage of group IDs in local storage is exempt from consent because it is strictly necessary for providing the service you expressly request.

3. Cookies

Our application uses the following cookies, all of which are strictly necessary:

  • NEXT_LOCALE: Stores your language preference (1-year expiry). Set by the language switcher.
  • sidebar_state: Stores the sidebar open/closed state (7-day expiry).
  • __cfuvid: Set by Cloudflare for security features such as rate limiting and bot detection. This is a session cookie.

All cookies listed above are strictly necessary for the functionality or security of the service. They are exempt from consent under §25(2) TDDDG. No tracking, advertising, or analytics cookies are used.

4. Firebase Authentication (Optional)

If you choose to sign in with Google or Apple, Firebase Authentication processes:

  • Your email address (if provided by the provider).
  • A unique user ID from the authentication provider.

Purpose: To link your groups across devices and enable account recovery.

Legal basis: Art. 6(1)(b) GDPR — necessary for the performance of a contract (providing cross-device sync).

Sign-in is entirely optional. You can use all core features without authenticating.

Recipients of Your Data

We share your data only with essential service providers who process data on our behalf (data processors under Art. 28 GDPR):

  • Google Firebase (Firestore, Auth) — cloud database and authentication provider. Data processing agreement in place.
  • Cloudflare — CDN and security services. Processes IP addresses for security purposes.
  • Vercel — hosting platform. Standard server logs may include IP addresses.

We do not sell your data to third parties. We do not use analytics, advertising, or tracking services.

Third-Country Data Transfers

Data you enter is processed using Google Firebase, a service provided by Google LLC (USA). While your data may be stored in EU data centers, Google is a US-based company, so limited international data transfers may occur.

These transfers are safeguarded by Standard Contractual Clauses (SCCs) adopted by the European Commission under Art. 46(2)(c) GDPR, ensuring an adequate level of data protection.

Cloudflare, Inc. (USA) also processes data subject to SCCs.

How Long We Store Your Data

Group and expense data: Stored in Firebase until you delete the group or until we delete inactive groups after 12+ months of inactivity.

Browser data (local storage/cookies): Stored until you clear your browser data or the cookie expires.

Firebase Auth data: Stored until you unlink your account or request deletion.

Consent records: We retain a record of your consent preferences in your browser as long as you use the service.

Your Rights Under the GDPR

As a data subject under the GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR): Request a copy of your personal data.
  • Right to rectification (Art. 16 GDPR): Request correction of inaccurate data.
  • Right to erasure (Art. 17 GDPR): Request deletion of your data.
  • Right to restriction of processing (Art. 18 GDPR).
  • Right to data portability (Art. 20 GDPR): Receive your data in a structured, machine-readable format.
  • Right to object (Art. 21 GDPR): Object to processing based on legitimate interests.
  • Right to withdraw consent (Art. 7(3) GDPR): Withdraw your consent at any time without affecting the lawfulness of processing before withdrawal.
  • Right to lodge a complaint (Art. 77 GDPR): File a complaint with your local data protection supervisory authority. In Germany, this is the Landesbeauftragte für den Datenschutz of your federal state or the Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI).

To exercise your rights, contact us at schadeapps@gmail.com.

Provision of Data

Providing your group and expense data is necessary for using our service. Without this data, we cannot provide the bill-splitting functionality. There is no statutory or contractual obligation to provide this data; it is entirely voluntary.

Automated Decision-Making

We do not use automated decision-making or profiling as defined in Art. 22 GDPR.

Data Security

We implement appropriate technical and organizational measures (Art. 32 GDPR) to protect your data, including: encryption in transit (TLS) and at rest (Firebase encryption), Firebase Security Rules restricting access by group ID, and minimal data collection principles. We do not track, analyze, or monetize your data.

Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or legal obligations. If we make significant changes, we will notify you via the app interface. Please review this page periodically.

Contact

If you have any questions about this Privacy Policy or how we handle your data, please contact us at:

Email: schadeapps@gmail.com