This is the previous policy dated 2026-09-10. Read the current Privacy Policy

Settly Privacy Policy

This Policy covers the Settly Android app, shared-table viewer, and privacy and terms website. Settly calculates how to split expenses; it does not transfer money, track completed transfers, or provide a financial account. Subscription conditions appear in the Terms of Use.

The U.S. disclosures below address the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and other applicable state privacy laws. A law and its rights apply when its jurisdictional, business, and processing requirements are met.

1. Scope and key privacy facts

In versions supporting cloud collaboration, after a separate cloud notice is acknowledged, all settlements, participants, items, notes and attached photos sync to the operator's Firebase servers, whether or not a link has been shared. If you have created a table, your full category list and its order also sync, including unused categories. Offline changes are stored locally and uploaded after reconnection. Settlement content is not included in advertising, diagnostics, usage analytics or subscription-verification data.

Each table has a hard-to-guess sharing code. Anyone with its link can view it on the web or edit together in the app. Only its original creator can delete the whole server table. Reinstalling or resetting app data can lose owner access; reopening a link does not restore that ownership. See Sections 4 and 8.

Usage analytics is optional. Firebase Analytics collection and delivery are permitted only after both [Optional] Analytics collection and use and [Optional] International data transfer have been saved as agreed. Declining either choice does not prevent settlements, image sharing, subscriptions, or restoration. Free-version limits and Pro benefits are independent of analytics consent.

Before the initial notice is acknowledged, Settly does not start UMP, AdMob, remote Firebase diagnostics, or RevenueCat. Afterwards, configured release builds automatically collect crash and performance diagnostics. RevenueCat also checks the current entitlement for free users, not only after someone taps a purchase button. Notice acknowledgement and Google's ad choices are not treated as optional analytics consent.

Settly has no user-facing signup or login. Cloud sync uses a Firebase anonymous authentication ID linked to RevenueCat to check the creator's subscription limits. Installation, authentication and purchase identifiers can be associated with usage or purchases; they are not fully anonymous merely because they lack a name. Analytics IDs are not linked to those purchase IDs.

2. Categories of personal information

The following describes current processing, including testing before public launch. Over the preceding 12 months, or since processing began if shorter, disclosures are limited to the functions and recipients described in this Policy. A provider may process information that the operator does not directly receive.

CategoryExamples and sourcesPurposeRetention period or criterion
User-provided content, including photosFrom you or a collaborator: settlement title, currency/rounding, participant names/order, item names, amounts, payers, split participants, assigned category name, notes and selected photosCalculation, offline editing, synchronization, collaborative editing and shared web viewingLocal database/files and the operator's Firestore/Cloud Storage in Seoul, Republic of Korea. Section 8 explains table, attachment and deletion retention
Creator category catalogAll category IDs, names, order, deletion markers and catalog revision managed by the creator, including unused categoriesA consistent selection list across every table the creator makes and its app collaboratorsLocal Room database and the operator's Firestore. Deleting the creator's last server table removes the server catalog; local settings remain
Sync and access metadataTable/item/photo IDs, hashed sharing codes, creator authentication ID and table count, revisions, operation IDs/digests/editor IDs, actual view/edit times, attestation materials and tokens, hashed IP/ID rate counters, request types/error codesLink access, owner deletion, creator limits, conflict handling, retry deduplication and service securityFirebase/Google Cloud and local sync queues. Polling is not recorded as a new visit. Rate counters expire after 24 hours and are then removed through the provider's automatic deletion process; other criteria are in Section 8
IdentifiersFrom the device, Google SDKs and store: IP address, user agent, advertising/app set IDs, Firebase authentication/installation/session and Analytics app-instance IDs; RevenueCat app user ID and Play transaction identifiers. From a requester: email and necessary verification informationAuthentication, ads and privacy choices, diagnostics, consented analytics, subscription verification, website delivery, supportProvider-specific periods below. Only necessary authentication identifiers are linked to cloud table metadata; ads/Analytics IDs and purchase tokens are not stored as settlement content. Support messages remain while needed for the request or applicable duties
Commercial informationPlay/RevenueCat product, base plan, purchase token, transaction and entitlement state, renewal, expiry, refund, subscription price/currency and period; displayed subscription prices in consented analyticsPurchase validation, acknowledgement, restoration, entitlement updates, subscription operations and consented purchase-flow analysisStore and RevenueCat records and device caches. Subscription expiry or uninstall does not itself delete server records; see Section 8
Internet or other electronic network activityApp/ad interactions; crashes and technical state; performance timings and network URLs without queries or bodies; consented limit-reached, subscription-screen/price-view and purchase-attempt-result events; SDK automatic events such as first opens and sessionsAds, fraud prevention, troubleshooting and performance; with both consents, improving limits and subscription usabilityAd data follows provider policies and choices. Crashlytics starts deletion after 90 days; Performance after 30 days for IP-linked events and 60 days for installation-linked/deidentified performance data. Analytics detail retention is set to two months
Approximate geolocation and device informationIP-derived approximate location or country, model, app/OS/SDK version, language, network and technical device stateAd delivery, fraud prevention, diagnostics and consented usage analysisRelevant service retention. Hosting visitor IPs are retained for a few months. Settly does not request precise location permission
Support communicationsEmail address, message and necessary request or purchase verification information supplied by a userAnswer questions, exercise rights, resolve disputesUntil no longer needed for the request, compliance or dispute; applicable legal records may be retained separately

Manual analytics events contain entry points, limit type, free/Pro verification state, product, monthly/annual plan, offer, trial duration, displayed subscription price/currency, and a bounded purchase-result category. Subscription prices are not the expense amounts in settlement tables, and purchase-attempt results are not a definitive revenue ledger.

Manual events exclude settlement content, order numbers, purchase tokens, RevenueCat customer IDs, raw errors and app-defined user IDs. Settly does not link Firebase Analytics and RevenueCat user IDs; linking the separate Firebase authentication ID for creator-limit verification is different. Analytics advertising-ID collection, automatic screen reporting, ad storage, ad-user-data use and ad personalization are disabled. These settings do not eliminate installation identifiers or all SDK automatic events. Depending on installed SDKs and integrations, automatic events extend beyond the four manual event types.

Settly does not set names, emails or phone numbers as RevenueCat customer attributes. Additional automatic device-identifier collection and RevenueCat SDK diagnostics are disabled; necessary purchase verification still occurs. Custom diagnostic records exclude settlement content and raw purchase tokens.

3. Your optional analytics choices

4. Local data, cloud sync, backup and sharing

The local Room database and photo files contain the settlement content listed in Section 2. DataStore contains preferences, notice version, the two analytics choices, consent version and save time. Cloud sync uploads existing and new tables after the separate cloud notice. A creator's full category list and its order also sync, including unused categories, and apply across all tables they create. Other general settings are not synced.

App users with a sharing link receive the creator's full category list for item selection. It is not automatically merged into their personal settings. Only the creator can manage that list in Settings; the web displays only category names assigned to that table's items. Deleting a category leaves its linked items uncategorized without deleting their other contents. A deletion marker prevents old input from restoring that classification. Do not include information you do not want to share in category names. Deleting the creator's last server table also removes the server category list; local category settings remain.

Every table has a code, including a table whose link you have not sent. There is no public directory of tables. Anyone who obtains or receives the link can view names, notes, photos and calculated results. In the app they can also add, edit or delete items and participants. There is currently no per-invitee approval, permission tier or link rotation. Share links only with trusted recipients and ensure you may include other people's information.

Actual table opens and edits update service timestamps. Background sync, polling and retries of the same operation do not count as new activity. There is currently no inactivity-based automatic table deletion. Any future retention change will be separately communicated. These service records are separate from optional usage analytics.

Unsaved or failed input is held in memory and cleared on successful save, cancellation, related-data deletion or process end. A shared PNG is cached until the next image share, deletion of all settlement data or Android cache cleanup. The receiving app controls its copy.

Android system backup or device transfer may include the settlement database, sharing links and ordinary settings when enabled. Purchase-entitlement/RevenueCat caches and anonymous authentication credentials are excluded by Settly's backup allowlist. A backup or link does not guarantee restoration of original owner access. Backup retention and deletion follow Android and the user's account settings; local deletion need not immediately remove older backup copies.

A shared link displays current server content. A PNG is sent to the selected receiving app, not separately uploaded as a shared-result image to the operator. Later edits or deletion cannot recall recipients' image copies. The app uses Android's sandbox but does not add separate database encryption or an app lock. Protect the device with access controls and security updates. The operator cannot access content that has not left your device, but authorized operational access to synced server content is possible.

5. Providers and disclosures

RecipientInformation and functionWhen processing occurs
Google Cloud/Firebase — Firestore, Cloud Storage, Cloud Functions and deletion retry jobsSettlement content, sync metadata and access-protection information for storage, collaboration, viewing, deletion and securityAfter the cloud notice, during creation, editing, sync, link opening and deletion; settlement storage and functions are configured in Seoul
Google LLC — Firebase Authentication/App Check and Google Play IntegrityAnonymous authentication IDs, connection information, attestation materials and tokens for authentication and app-integrity checksAfter the cloud notice, during authentication, token issuance/validation and server requests
Google LLC — AdMob, UMP and applicable ad partnersIdentifiers, ad/app activity, approximate location and technical diagnostics for privacy choices, advertising, measurement and fraud preventionAfter initial notice acknowledgement; ad requests only when UMP permits them
Google LLC — Firebase Crashlytics and Performance MonitoringInstallation/session identifiers, crashes, device/app state and network/performance data for troubleshootingAutomatically after notice acknowledgement in configured release builds
Google LLC — Google Analytics for FirebaseThe consented manual and automatic analytics information in Section 2Collection is enabled only after both consents; events are sent over encrypted connections, possibly later because of connectivity
RevenueCat, Inc.Subscription identifiers, transactions, technical connection information, entitlement status and the linked Firebase anonymous authentication ID for purchase and creator-limit verificationAfter initial notice acknowledgement for free-user initialization, customer/product queries, purchases, restoration and Play notifications; after the cloud notice for identity linking and server-side creator-limit checks
Google PlayPayment and subscription information for purchases, renewals, cancellation, refunds and verificationThrough Play services, payment screens, verification and server notifications
Google LLC — Firebase HostingVisitor IP for page delivery, abuse prevention and hosting usage analysisWhen shared-table, privacy or terms pages are opened
Google Workspace (Gmail) — Google Asia Pacific Pte. Ltd. / Google LLCSupport email, replies and necessary verification informationWhen a user contacts support and the operator responds
Link holders and user-selected backup/sharing recipientsShared table content, including notes/photos; local data/settings or requested PNGWhen a link holder opens the table, through enabled Android backup or an intentional image share

RevenueCat and providers performing diagnostics, analytics and hosting process information under their applicable service and data-processing terms. Store payments and advertising-party processing may also be governed by those parties' independent terms. Settly does not disclose settlement content to the advertising, analytics, diagnostics or purchase-verification providers.

6. Sale, sharing and advertising choices

Settly does not sell personal information for money. Conditional AdMob disclosures of identifiers, app/ad activity and approximate location for advertising across unaffiliated services may constitute sharing for cross-context behavioral advertising or targeted advertising under applicable state law. For this notice, Settly treats these advertising disclosures as sharing and provides opt-out methods.

Exercise the Right to Opt-Out through Google's Ad privacy choices entry in Settings when available, the Do Not Sell or Share My Personal Information page, or the privacy contact. Google messages govern personalization and applicable regional consent or opt-out signals. Non-personalized ads can still process data for delivery, measurement and fraud prevention.

A verified Pro entitlement stops banner requests but does not disable diagnostics or separately consented analytics. Changing the Android advertising ID or an ad choice is not an analytics withdrawal or a RevenueCat deletion request.

Shared-table, policy and terms pages install no advertising or analytics tracking scripts or cookies. They do not sell or share browser data for advertising regardless of a Global Privacy Control (GPC) signal. Shared-table opens update the service's last-viewed timestamp separately. A signal on this website does not automatically change every Android-app setting; use the applicable in-app control or contact us.

7. Sensitive Personal Information, children and automated decisions

Settly does not request government identifiers, financial account credentials, precise location, biometric, genetic or neural data, health information, or other Sensitive Personal Information for profiling. Do not include such information in free-text fields, attached photos or support emails. Only user-selected photos are imported as app-specific JPEG copies; Settly does not perform OCR or face identification. The app does not request contacts, precise location, camera, microphone, health or biometric permissions.

Settly does not use Sensitive Personal Information for purposes requiring a Right to Limit Use control. If that practice changes, the required notice and controls will be provided. Local expense amounts are not financial-account credentials.

Settly is not designed or directed to children, including children under 13, and does not knowingly sell or share information of anyone under 16. If inappropriate child-data processing is identified, the operator will take applicable steps to stop it and delete information it controls. A parent or guardian can contact us.

Settly does not use Automated Decision-Making Technology to make legally or similarly significant decisions about employment, credit, insurance, housing or similar opportunities. Settlement results use arithmetic on user input, not significant profiling.

8. Retention, deletion and destruction

Analytics event- and user-level detail retention is set to two months, with extension on new user activity off. Expired detail is removed through Google's monthly deletion process; setting changes can take 24 hours to apply. The setting does not uniformly limit standard aggregated reports, separately retained copies, or subscription records. Analytics retention

RevenueCat data is retained under the operator's service agreement, applicable deletion requests and legal exceptions, not simply until a user's Pro subscription expires. Contract termination, return/deletion and backup exceptions follow the RevenueCat DPA. Google Play retains transaction information under its policies and legal duties.

Deleting a table you created blocks link access and further edits once the server receives the request, then deletes its content, photos and child operation records. Failed cleanup is retried. Whole-table deletion cannot be undone in the app. Offline deletion waits on the device until reconnection; others can still see the server copy until then. Uninstalling or clearing app data before transmission can lose the queued deletion.

Removing an invited table removes only that device's table and pending changes, not the server copy. Delete all settlement data also acts only on this device: it clears tables, participants, items, photos, links, sync queues and share-image caches. To delete server content, first delete tables you created from the list and let those requests finish online. Preferences, notice acknowledgement, analytics consent and purchase entitlement remain. These actions do not cancel a subscription, withdraw analytics consent or delete unrelated server records.

While a table exists, its synced content, item/participant undo state and retry-deduplication records are retained. Photos removed from an item can remain on the server until whole-table deletion. Afterwards, only a minimal deletion marker containing the table ID and sharing-code hash remains, without settlement content, names or authentication IDs, for as long as the sync service needs to prevent old offline requests from recreating that table.

Cloud Storage photos currently have a seven-day provider soft-delete period. They are inaccessible through the app/link during this period and then follow the provider's final deletion process. This is not a user-facing table restoration or undo service. Cloud Storage deletion

Reinstallation or data reset can lose the original anonymous identity; joining again through a link does not restore owner access. There is currently no account linking, ownership recovery or inactivity-based automatic table deletion. Losing ownership does not immediately delete server content. Use Section 10 to request deletion or restriction of remaining information.

Authentication identifiers and creator counts remain while needed for authentication, permissions and limits. Firebase retains other authentication information until the associated user is deleted and then applies its system-deletion process; authentication IP logs are kept for a few weeks. App Check materials/tokens follow the applicable provider and feature rules and are not placed in settlement content or custom logs. Firebase privacy information

Support information is deleted when no longer needed for the request, applicable compliance or disputes. Where Korean e-commerce recordkeeping applies to the operator's records, contract/withdrawal and payment/service-supply records are kept for five years, complaint/dispute records for three years and advertising records for six months. These duties are not a basis for retaining entire settlement tables as statutory transaction records.

Support email retention is separate from the two-month Analytics setting. Under the Google Cloud Data Processing Addendum, deletion that is no longer recoverable by the operator instructs Google to erase the data from its systems as soon as reasonably practicable, within 180 days, subject to legally required retention. Trash/recovery stages are not confirmation of completed system deletion.

Unneeded electronic records are deleted through the relevant storage/provider tools. Required records are retained separately for the permitted purpose. Server and backup deletion can follow a provider's schedule; neither local reset nor a submitted request means all remote copies have already been erased. Restoring or syncing an active purchase can recreate a RevenueCat record; deletion is distinct from cancelling renewal.

9. U.S. privacy rights

Depending on applicable law and exceptions, you may have the Right to Know or access information about collection and disclosures, Right to Delete, Right to Correct, Right to Opt-Out of sale/sharing, targeted advertising or qualifying profiling, Right to Limit Use of Sensitive Personal Information, and Data Portability. Non-Discrimination means no unlawful retaliation for exercising these rights. Where applicable, you may appeal a denied request.

Settly provides no discount or financial incentive in exchange for analytics consent or sale/sharing of data. Pro is an optional subscription for its stated benefits, not an analytics-consent incentive.

10. Requests, verification and appeals

Contact corp@solidsoft.team · 010-2615-3559 with Settly privacy request, your requested action and a reply address. Settly is online-only and does not require an app account to submit a request. Requests are free unless applicable law permits a fee.

For access, correction or deletion, we may ask for minimal information to identify the relevant record and verify authority. Authorized agent requests are accepted through the same contact, with authorization checks where permitted. An advertising opt-out does not require creation of an account or identity verification, though information to identify the affected device or record may be needed.

Email is not used as the app's authentication, Analytics or RevenueCat identifier. Email alone may therefore be insufficient to locate a table or an installation's records, or establish ownership. We explain the minimal information needed and use provider tools or support channels. If a record cannot be matched or a legal exception applies, we explain the limitation and available alternatives. Do not send passwords, full card numbers, raw purchase tokens or participant lists.

When CCPA deadlines apply, we acknowledge requests within 10 business days, respond within 45 days, and explain any permitted 45-day extension. Advertising opt-outs are addressed as soon as feasible and within 15 business days where required. Other applicable deadlines take precedence. To appeal, reply with Privacy request appeal; we respond under the relevant state procedure.

11. International processing

Solidsoft operates in the Republic of Korea. Google LLC processes data in the United States and may use distributed facilities and subprocessors elsewhere. Google LLC's address is 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States; contact its privacy inquiry channel.

Settlement storage and server functions are configured in Seoul, Republic of Korea. Firebase Authentication operates in the United States; other Google services and support may use distributed facilities under their applicable terms. For Google Cloud agreements with Korean customers, Google's entity guide identifies Google Cloud Korea LLC unless otherwise agreed, at Gangnam Finance Center 20fl., 152 Teheran-ro, Gangnam-gu, Seoul, and describes the role of Google Asia Pacific Pte. Ltd. and affiliates. See the contracting-entity guide.

For locations and provider scope, see Google data centers, Firebase processing locations, Firebase subprocessors and Google advertising/analytics subprocessors. These are provider-wide lists of possible facilities and recipients, not a claim that every listed recipient receives each user's data or that all information stays only in the U.S.

RevenueCat, Inc. is a U.S. provider at 1032 E Brandon Blvd #3003, Brandon, FL 33511. Contact compliance@revenuecat.com. Its DPA identifies U.S. infrastructure/operations subprocessors and support for Korean customers.

Support email: Google Workspace (Gmail) — Google Asia Pacific Pte. Ltd. / Google LLC. Processing may occur in Singapore, the United States and other countries in Google's published Workspace facilities/subprocessor lists below. Support messages are kept while needed for the request or applicable legal records, then removed through Google's recovery and system-deletion procedures.

Google's contracting-entity information identifies Google Asia Pacific Pte. Ltd. for Korean Workspace customers, at 70 Pasir Panjang Road, #03-71, Mapletree Business City II, Singapore 117371. See the Workspace subprocessor list for entities, activities and countries, and service-specific terms for the scope of data-location commitments. No single-country storage guarantee is made. The operator can escalate requests through Google's Workspace privacy support, which requires an administrator account.

Transfers occur through encrypted connections for the functions and at the times in Section 5. Optional usage analytics requires both consents and may be withdrawn in Section 3. Operational diagnostics and purchase verification are separate processes, not covered by analytics consent.

12. Security

Settly uses the Android sandbox, limited app permissions, encrypted SDK transport, delayed external-service startup and consent-based analytics controls. Custom logs exclude settlement content. Business and provider account access is limited to operational needs. No method guarantees complete security; protect the device and accounts.

The sync service uses authentication, app verification, hard-to-guess codes, private storage, blocked direct database/file access and request limits. It is not an end-to-end encrypted service. Possessing a link is enough to access its table; it does not establish a recipient's identity. Do not publicly post links, and contact us about leaks or inappropriate sharing.

13. Changes and contact

This revision adds all-table cloud sync, link-based app collaboration and web viewing, anonymous authentication and creator-limit verification, actual activity timestamps, owner deletion and post-reinstall ownership limits. Practices are reviewed at least annually and when materially changed. Required notices and consents will precede changes that need them; cloud sync applies in supporting app versions after the separate cloud notice.

You may also contact the California Privacy Protection Agency or the relevant state attorney general/privacy regulator.

Official references