This is the previous policy dated 2026-09-07. Read the current Privacy Policy

Settly Privacy Policy

This Policy covers the Settly Android app and its privacy and terms website. Settly calculates how to split expenses; it does not transfer money, track completed transfers, or provide a financial account. Subscription conditions appear in the Terms of Use.

The U.S. disclosures below address the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and other applicable state privacy laws. A law and its rights apply when its jurisdictional, business, and processing requirements are met.

1. Scope and key privacy facts

Settly does not send settlement titles, participant names, item descriptions, or settlement amounts to operator, advertising, diagnostics, analytics, or subscription-verification servers. This content is stored locally, except for image sharing initiated by the user and Android system backup enabled by the user.

Usage analytics is optional. Firebase Analytics collection and delivery are permitted only after both [Optional] Analytics collection and use and [Optional] International data transfer have been saved as agreed. Declining either choice does not prevent settlements, image sharing, subscriptions, or restoration. Free-version limits and Pro benefits are independent of analytics consent.

Before the initial notice is acknowledged, Settly does not start UMP, AdMob, remote Firebase diagnostics, or RevenueCat. Afterwards, configured release builds automatically collect crash and performance diagnostics. RevenueCat also checks the current entitlement for free users, not only after someone taps a purchase button. Notice acknowledgement and Google's ad choices are not treated as optional analytics consent.

Settly has no app login. Installation identifiers and RevenueCat's randomly generated app user identifier can be associated with usage or purchases. They are not treated as fully anonymous merely because they do not contain a name.

2. Categories of personal information

The following describes current processing, including testing before public launch. Over the preceding 12 months, or since processing began if shorter, disclosures are limited to the functions and recipients described in this Policy. A provider may process information that the operator does not directly receive.

CategoryExamples and sourcesPurposeRetention period or criterion
IdentifiersFrom the device, Google SDKs and store: IP address, advertising/app set IDs, Firebase installation/session and Analytics app-instance IDs; RevenueCat app user ID and Play transaction identifiers. From a requester: email and necessary verification informationAds and privacy choices, diagnostics, consented analytics, subscription verification, website delivery, supportProvider-specific periods below. Not placed in the settlement database or custom diagnostic logs. Support messages are retained while needed to resolve a request and satisfy applicable recordkeeping duties
Commercial informationPlay/RevenueCat product, base plan, purchase token, transaction and entitlement state, renewal, expiry, refund, subscription price/currency and period; displayed subscription prices in consented analyticsPurchase validation, acknowledgement, restoration, entitlement updates, subscription operations and consented purchase-flow analysisStore and RevenueCat records and device caches. Subscription expiry or uninstall does not itself delete server records; see Section 8
Internet or other electronic network activityApp/ad interactions; crashes and technical state; performance timings and network URLs without queries or bodies; consented limit-reached, subscription-screen/price-view and purchase-attempt-result events; SDK automatic events such as first opens and sessionsAds, fraud prevention, troubleshooting and performance; with both consents, improving limits and subscription usabilityAd data follows provider policies and choices. Crashlytics starts deletion after 90 days; Performance after 30 days for IP-linked events and 60 days for installation-linked/deidentified performance data. Analytics detail retention is set to two months
Approximate geolocation and device informationIP-derived approximate location or country, model, app/OS/SDK version, language, network and technical device stateAd delivery, fraud prevention, diagnostics and consented usage analysisRelevant service retention. Hosting visitor IPs are retained for a few months. Settly does not request precise location permission
Support communicationsEmail address, message and necessary request or purchase verification information supplied by a userAnswer questions, exercise rights, resolve disputesUntil no longer needed for the request, compliance or dispute; applicable legal records may be retained separately

Manual analytics events contain entry points, limit type, free/Pro verification state, product, monthly/annual plan, offer, trial duration, displayed subscription price/currency, and a bounded purchase-result category. Subscription prices are not the expense amounts in settlement tables, and purchase-attempt results are not a definitive revenue ledger.

Manual events exclude settlement content, order numbers, purchase tokens, RevenueCat customer IDs, raw errors and app-defined user IDs. Settly does not link Firebase and RevenueCat user IDs. Analytics advertising-ID collection, automatic screen reporting, ad storage, ad-user-data use and ad personalization are disabled. These settings do not eliminate installation identifiers or all SDK automatic events. Depending on installed SDKs and integrations, automatic events extend beyond the four manual event types.

Settly does not set names, emails or phone numbers as RevenueCat customer attributes. Additional automatic device-identifier collection and RevenueCat SDK diagnostics are disabled; necessary purchase verification still occurs. Custom diagnostic records exclude settlement content and raw purchase tokens.

3. Your optional analytics choices

4. Local data, backup and sharing

The local Room database contains settlement names, currency and rounding unit, participant names/order, items, amounts, payers and split participants. DataStore contains preferences, notice version, the two analytics choices, consent version and save time. They remain until changed or deleted through the relevant app/Android controls.

Unsaved or failed input is held in memory and cleared on successful save, cancellation, related-data deletion or process end. A shared PNG is cached until the next image share, deletion of all settlement data or Android cache cleanup. The receiving app controls its copy.

Android system backup or device transfer may include the settlement database and ordinary settings when enabled. Purchase-entitlement and RevenueCat caches are excluded by Settly's backup allowlist. Backup retention and deletion follow Android and the user's account settings; local deletion need not immediately remove older backup copies.

The app uses Android's sandbox but does not add separate database encryption or an app lock. Protect the device with access controls and security updates. The operator cannot remotely access or recover local settlement content.

5. Providers and disclosures

RecipientInformation and functionWhen processing occurs
Google LLC — AdMob, UMP and applicable ad partnersIdentifiers, ad/app activity, approximate location and technical diagnostics for privacy choices, advertising, measurement and fraud preventionAfter initial notice acknowledgement; ad requests only when UMP permits them
Google LLC — Firebase Crashlytics and Performance MonitoringInstallation/session identifiers, crashes, device/app state and network/performance data for troubleshootingAutomatically after notice acknowledgement in configured release builds
Google LLC — Google Analytics for FirebaseThe consented manual and automatic analytics information in Section 2Collection is enabled only after both consents; events are sent over encrypted connections, possibly later because of connectivity
RevenueCat, Inc.Subscription identifiers, transactions, technical connection information and entitlement status for validation, acknowledgement, restoration and subscription operationsAfter notice acknowledgement, including free-user initialization and customer/product queries; purchases, restoration and Play server notifications
Google PlayPayment and subscription information for purchases, renewals, cancellation, refunds and verificationThrough Play services, payment screens, verification and server notifications
Google LLC — Firebase HostingVisitor IP for page delivery, abuse prevention and hosting usage analysisWhen the privacy or terms website is opened
Google Workspace (Gmail) — Google Asia Pacific Pte. Ltd. / Google LLCSupport email, replies and necessary verification informationWhen a user contacts support and the operator responds
User-selected backup or sharing recipientLocal settlement data/settings or the requested PNGThrough user-enabled Android backup or an intentional share

RevenueCat and providers performing diagnostics, analytics and hosting process information under their applicable service and data-processing terms. Store payments and advertising-party processing may also be governed by those parties' independent terms. Settly does not disclose settlement content to the advertising, analytics, diagnostics or purchase-verification providers.

6. Sale, sharing and advertising choices

Settly does not sell personal information for money. Conditional AdMob disclosures of identifiers, app/ad activity and approximate location for advertising across unaffiliated services may constitute sharing for cross-context behavioral advertising or targeted advertising under applicable state law. For this notice, Settly treats these advertising disclosures as sharing and provides opt-out methods.

Exercise the Right to Opt-Out through Google's Ad privacy choices entry in Settings when available, the Do Not Sell or Share My Personal Information page, or the privacy contact. Google messages govern personalization and applicable regional consent or opt-out signals. Non-personalized ads can still process data for delivery, measurement and fraud prevention.

A verified Pro entitlement stops banner requests but does not disable diagnostics or separately consented analytics. Changing the Android advertising ID or an ad choice is not an analytics withdrawal or a RevenueCat deletion request.

The policy website installs no advertising or analytics tracking scripts or cookies. It does not sell or share browser data regardless of a Global Privacy Control (GPC) signal. A signal on this website does not automatically change every Android-app setting; use the applicable in-app control or contact us.

7. Sensitive Personal Information, children and automated decisions

Settly does not request government identifiers, financial account credentials, precise location, biometric, genetic or neural data, health information, or other Sensitive Personal Information for profiling. Do not enter such information in free-text fields or support emails. The app does not request contacts, precise location, camera, microphone, health or biometric permissions.

Settly does not use Sensitive Personal Information for purposes requiring a Right to Limit Use control. If that practice changes, the required notice and controls will be provided. Local expense amounts are not financial-account credentials.

Settly is not designed or directed to children, including children under 13, and does not knowingly sell or share information of anyone under 16. If inappropriate child-data processing is identified, the operator will take applicable steps to stop it and delete information it controls. A parent or guardian can contact us.

Settly does not use Automated Decision-Making Technology to make legally or similarly significant decisions about employment, credit, insurance, housing or similar opportunities. Settlement results use arithmetic on user input, not significant profiling.

8. Retention, deletion and destruction

Analytics event- and user-level detail retention is set to two months, with extension on new user activity off. Expired detail is removed through Google's monthly deletion process; setting changes can take 24 hours to apply. The setting does not uniformly limit standard aggregated reports, separately retained copies, or subscription records. Analytics retention

RevenueCat data is retained under the operator's service agreement, applicable deletion requests and legal exceptions, not simply until a user's Pro subscription expires. Contract termination, return/deletion and backup exceptions follow the RevenueCat DPA. Google Play retains transaction information under its policies and legal duties.

Delete all settlement data removes the device's settlements, participants, items and cached share images. It preserves preferences, notice acknowledgement, analytics consent and purchase entitlement. It is not an analytics-withdrawal, subscription-cancellation or server-deletion command. Uninstalling the app does not cancel a Play subscription.

Support information is deleted when no longer needed for the request, applicable compliance or disputes. Where Korean e-commerce recordkeeping applies to the operator's records, contract/withdrawal and payment/service-supply records are kept for five years, complaint/dispute records for three years and advertising records for six months. This does not cause local settlement content to be uploaded.

Support email retention is separate from the two-month Analytics setting. Under the Google Cloud Data Processing Addendum, deletion that is no longer recoverable by the operator instructs Google to erase the data from its systems as soon as reasonably practicable, within 180 days, subject to legally required retention. Trash/recovery stages are not confirmation of completed system deletion.

Unneeded electronic records are deleted through the relevant storage/provider tools. Required records are retained separately for the permitted purpose. Server and backup deletion can follow a provider's schedule; neither local reset nor a submitted request means all remote copies have already been erased. Restoring or syncing an active purchase can recreate a RevenueCat record; deletion is distinct from cancelling renewal.

9. U.S. privacy rights

Depending on applicable law and exceptions, you may have the Right to Know or access information about collection and disclosures, Right to Delete, Right to Correct, Right to Opt-Out of sale/sharing, targeted advertising or qualifying profiling, Right to Limit Use of Sensitive Personal Information, and Data Portability. Non-Discrimination means no unlawful retaliation for exercising these rights. Where applicable, you may appeal a denied request.

Settly provides no discount or financial incentive in exchange for analytics consent or sale/sharing of data. Pro is an optional subscription for its stated benefits, not an analytics-consent incentive.

10. Requests, verification and appeals

Contact corp@solidsoft.team · 010-2615-3559 with Settly privacy request, your requested action and a reply address. Settly is online-only and does not require an app account to submit a request. Requests are free unless applicable law permits a fee.

For access, correction or deletion, we may ask for minimal information to identify the relevant record and verify authority. Authorized agent requests are accepted through the same contact, with authorization checks where permitted. An advertising opt-out does not require creation of an account or identity verification, though information to identify the affected device or record may be needed.

Email is not used as the app's Analytics or RevenueCat identifier. Email alone may therefore be insufficient to locate an installation's records. We explain the minimal information needed and use provider tools or support channels. If a record cannot be matched or a legal exception applies, we explain the limitation and available alternatives. Do not send passwords, full card numbers, raw purchase tokens or participant lists.

When CCPA deadlines apply, we acknowledge requests within 10 business days, respond within 45 days, and explain any permitted 45-day extension. Advertising opt-outs are addressed as soon as feasible and within 15 business days where required. Other applicable deadlines take precedence. To appeal, reply with Privacy request appeal; we respond under the relevant state procedure.

11. International processing

Solidsoft operates in the Republic of Korea. Google LLC processes data in the United States and may use distributed facilities and subprocessors elsewhere. Google LLC's address is 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States; contact its privacy inquiry channel.

For locations and provider scope, see Google data centers, Firebase processing locations, Firebase subprocessors and Google advertising/analytics subprocessors. These are provider-wide lists of possible facilities and recipients, not a claim that every listed recipient receives each user's data or that all information stays only in the U.S.

RevenueCat, Inc. is a U.S. provider at 1032 E Brandon Blvd #3003, Brandon, FL 33511. Contact compliance@revenuecat.com. Its DPA identifies U.S. infrastructure/operations subprocessors and support for Korean customers.

Support email: Google Workspace (Gmail) — Google Asia Pacific Pte. Ltd. / Google LLC. Processing may occur in Singapore, the United States and other countries in Google's published Workspace facilities/subprocessor lists below. Support messages are kept while needed for the request or applicable legal records, then removed through Google's recovery and system-deletion procedures.

Google's contracting-entity information identifies Google Asia Pacific Pte. Ltd. for Korean Workspace customers, at 70 Pasir Panjang Road, #03-71, Mapletree Business City II, Singapore 117371. See the Workspace subprocessor list for entities, activities and countries, and service-specific terms for the scope of data-location commitments. No single-country storage guarantee is made. The operator can escalate requests through Google's Workspace privacy support, which requires an administrator account.

Transfers occur through encrypted connections for the functions and at the times in Section 5. Optional usage analytics requires both consents and may be withdrawn in Section 3. Operational diagnostics and purchase verification are separate processes, not covered by analytics consent.

12. Security

Settly uses the Android sandbox, limited app permissions, encrypted SDK transport, delayed external-service startup and consent-based analytics controls. Custom logs exclude settlement content. Business and provider account access is limited to operational needs. No method guarantees complete security; protect the device and accounts.

13. Changes and contact

This revision adds consent-based Firebase Analytics, retention and withdrawal details, RevenueCat subscription processing and updated rights procedures. Practices are reviewed at least annually and when materially changed. Required notices and consents will precede changes that need them; app features apply in versions that include them.

You may also contact the California Privacy Protection Agency or the relevant state attorney general/privacy regulator.

Official references