Privacy policy

In effect from: October 3, 2026

tabhug is a shared notebook of expenses for a group of friends. This page says in plain words what we store, why, where it goes and how to delete it. There are no ads, no tracking and no analytics in tabhug; we do not sell your data or pass it on for advertising.

1. Who is responsible for the data

tabhug is run by its owner («we»), who is the controller of your data. For anything about your data, write to [email protected] — that is how to reach us.

This version is in effect from October 3, 2026.

2. What we store and why

  • Account: your e-mail address and when the account was created. It lets you sign in from any device and gives a room its host. There is no password: we send a one-time code and keep only its hash.
  • Sign-ins: for each sign-in to an account, or to a room without an account — the hash of a random key, when it was created and last used, and the name of the device and the browser («iPhone · Safari»). The key itself is not on the server; it lives only in your browser.
  • A room: its name, currency and settings, the members’ names (typed in by the room’s host), receipts (title, date, total, items, who paid and who had what), transfers between members (who, to whom, how much, when, a note), requests to check a receipt.
  • Payment details: whatever a member (or the host on their behalf) wrote in «where to send the money» — a card number, an IBAN, a phone number.
  • The room’s history: who changed what and when. It keeps earlier versions of receipts and names so that any mistake can be undone — until the room is deleted.
  • Photos of receipts and what the model read from them (see section 5).
  • Invitations: the hash of a link that works for 10 minutes.
  • Technical data: your IP address — in the server’s memory for up to an hour, to limit abuse (guessing codes, creating rooms in bulk), and in the web server’s access log (14 days).

We do not collect your location, your contacts or anything about your device beyond the above, and we build no profiles.

3. On what legal basis

  • To provide the service you use (GDPR art. 6(1)(b) — performance of a contract): the account, sign-ins, rooms, receipts, transfers, payment details, invitations, and reading a photo you sent yourself.
  • Our legitimate interest (GDPR art. 6(1)(f)): protection against abuse and technical logs; keeping photos of receipts with what was read from them, to measure and improve recognition; processing the names of people a host typed into a room (the host’s and the group’s interest in working out their shared costs).
  • You can object to processing based on legitimate interest — see section 12.

We do not rely on consent, because nothing optional (ads, analytics, newsletters) exists in the service.

4. If your name was added to a room

A member of a room is a name the host typed in. It can appear in the room and in receipts before you have come in yourself, or if you never do. The host is responsible for telling the people they add, and for what is written about them.

We see only the name as it was written («Andrew», «Kate from work») and do not connect it with any other information about you unless you come in yourself.

To be removed: ask the room’s host to change or delete the name, or write to us at [email protected] with the room and the name. The name disappears from receipts and history completely when the room is deleted; on request we can replace it with a neutral one («Member») throughout the room’s history by hand.

5. Photos of receipts and the AI model

You never have to photograph a receipt — it can always be typed in. If you do take a photo:

  • Before sending, your browser shrinks the photo and redraws it, so its metadata (where it was taken, the phone model, the time) is not sent. The server removes it as well, should any arrive.
  • The server sends the photo to an AI model to be read, through the intermediary OpenRouter (USA); the model is provided by Google. We require the request to go only to providers that do not keep what they are sent and do not train their models on it. Nothing about you or the room is sent along with the photo.
  • The photo and what the model read are kept on our server until the photo is deleted. A photo no receipt was saved from is deleted by itself after a day. Members of the room can see the photo. The pairs «what the model read / what was true» help us improve recognition: we measure how often a reading needs fixing and try other models on them (the photo is then sent to another model on the same terms).

If there is something on the receipt you would rather not share, cover it or type the receipt in.

A photo and its reading can be deleted by whoever took it or by the room’s host: open the photo in the receipt and press «Delete photo». All photos of a room go when the room is deleted.

6. Payment details

Payment details exist so that other members can pay you, so every member of the room can see them. They are plain text: we do not verify them and we make no payments.

Write only what a transfer needs (a card number or an IBAN) and never a card’s expiry date, CVV, passwords or bank codes. You can change or clear them at any time: the old ones are then gone, and the room’s history keeps only a note that they were changed.

7. Who else has access to the data

Inside a room: every member sees everything in it — receipts, photos, balances, payment details, the history. The host also sees how many devices each member came in from, whether they linked an account, and when they were last there. Members’ e-mail addresses are seen by no one but us.

Those who help us run the service (processors):

  • A hosting provider in the Netherlands (EU) — the server that holds the database and the photos.
  • Cloudflare — the network every request to the site passes through (protection against attacks); it sees your IP address and the technical details of a request.
  • OpenRouter, and Google as the model provider — receive the photo of a receipt to read it (section 5).
  • Google (Gmail) — sends the e-mail with the sign-in code: it receives your e-mail address and the code.
  • Google Fonts — your browser loads the typeface from Google’s servers; Google sees your IP address when it does.

We may disclose data where the law requires it. Data is not passed to any other third party.

8. Transfers outside the EU and Ukraine

Cloudflare, OpenRouter and Google are American companies, so your IP address, your e-mail address with the sign-in code, and photos of receipts may be processed in the USA and other countries. These transfers rely on the European Commission’s adequacy decision (the EU–US Data Privacy Framework) for the companies that take part in it, and on the standard contractual clauses in those providers’ terms.

The database and the photos are stored on a server in the Netherlands (European Union).

9. How long we keep it

  • An account — until you delete it.
  • A room with everything in it (receipts, history, payment details, photos) — until its host deletes it.
  • A message sent with «Report a problem»: your text, the e-mail for a reply, the page’s address, the browser, the IP address and the room’s figures (how many people, receipts and currencies, how it is set up — no names, titles or amounts) — for as long as it takes to look into it and answer.
  • Sign-in codes and invitations — valid for 10 minutes, deleted a day after they expire.
  • Sign-ins to an account or a room — for as long as you use them: a sign-in not used for 90 days stops working and is deleted.
  • Revoked sign-ins — 30 days, then deleted. A sign-in you ended yourself («Leave the room on this device») is deleted at once.
  • IP addresses in the abuse counters — up to an hour; web server logs — 14 days.

10. What is kept in your browser

In the browser’s storage (localStorage): the key of your account sign-in and your e-mail address, the keys of the rooms entered from this device with the rooms’ names, the list of your rooms as the account last saw it (their names and your balance), the language you chose, the last currency used in a room. This is what saves you signing in every time.

Two cookies: th_lang — the language you chose, so that the page opens in it straight away; th_in — a mark that «this browser has rooms» (nothing about you), so that a reloaded page shows your list at once. There are no other cookies, advertising and analytics ones included, which is why there is no cookie banner.

«Sign out» and «Leave the room on this device» erase the corresponding keys from the browser.

11. Security

  • Everything between you and the site travels over HTTPS.
  • Sign-in keys, codes and invitations are stored on the server only as hashes: a copy of the database does not let anyone in as someone else.
  • An invitation works for 10 minutes; a personal one works once. A host can end all of a member’s sign-ins, and a sign-in not used for 90 days ends by itself.
  • Photos are served only to members of the room.
  • Keys, codes, e-mail addresses, payment details and the contents of receipts are not written to the server’s logs.

Everything in a room is seen by all its members — write only what you are happy to show the whole group.

12. Your rights and how to use them

  • A copy of your data: in a room, the «⋯» menu → «Data and privacy» → «Download everything (JSON)» or «Receipts as a table (CSV)». This is also the right to data portability.
  • Correction: receipts, transfers and payment details are edited in the room; a member’s name is changed by the host.
  • Deleting a photo: in the receipt, «Delete photo».
  • Leaving a room: «Data and privacy» → «Leave the room on this device». Your name and receipts stay in the room — they are part of the shared account.
  • Deleting a room and everything in it (the host): «Data and privacy» → «Delete the room». It is final and immediate.
  • Deleting your account: the start page → «Account» → «Delete account». Rooms you host have to be deleted first.
  • To object to processing, restrict it, or ask for something the interface does not offer (for example, erasing your name from a room’s history) — write to [email protected]. We answer within a month.

If you believe we are infringing your rights, you may complain to a supervisory authority: in Poland — the President of the Personal Data Protection Office (UODO); in another EU country — its data protection authority; in Ukraine — the Ukrainian Parliament Commissioner for Human Rights.

13. Children

The service is not meant for children under 16. If you are younger, use it only with a parent’s permission. If we learn that a younger child created an account without it, we will delete the account.

14. Changes

If what we store or where we send it changes, we will update this text and the date above. We will announce significant changes on the start page in advance.

Terms of use