Legal

Delete your data

Effective

Splitmate is an Android app for splitting bills with friends, made by Quizuncle, and currently given out through a Google Play closed test. There is a groups-only web client beside it. This page sets out every way to delete the data either of them holds, and it is written so that you can follow it whether or not you have Splitmate in front of you.

There are five routes, and they remove different amounts. If you want the short answer: deleting your account — in the Android app, or in the groups-only web client — reaches our server yourself, immediately, with nobody to wait on. Those two are not the same deletion, and route 2 says exactly where they part company. Emailing us is still the only way to reach what neither of them can: your name and picture in a group you shared, and a whole group’s own records. There is a table at the end showing which route removes what.

No route on this page removes everything. Whichever one you use, the expenses and settlements you added inside a group you share with other people stay in that group, because they are part of what everybody else in it is owed. That is stated in every section below rather than once at the top, because it is the fact most likely to be assumed away.

If you use Splitmate in a browser — the groups-only web client at web.splitmate.quizuncle.com, which needs a Google sign-in and has no offline queue — then four of these five routes are yours too. Only route 1 is not: there is no app storage to clear, because a browser tab keeps no copy of anybody’s expenses in the first place and reads them from the server every time.

Route 2 is there under the Me tab, and it removes less than the Android one does — that section is written in two halves for exactly that reason, and the difference is visible to the people you share groups with. Route 3 and route 4 are both there, with tighter rules about when a removal is allowed at all. Route 5 is the same email for everybody. Signing out is not a deletion in either place: it ends the session on that device and removes nothing from the server.

Two things to know first

1. Delete your account in the app, or email us, before you clear the app’s data — not after. The Android app has no login: no email address, no password, no phone number and no user directory. The only thing that identifies your copy of it is an anonymous identity generated when you first installed it, and that identity is what route 2 uses to find your data on the server, and what an email request has to be matched against. Once you clear that data or uninstall the app, the identity is gone from your phone: route 2 can no longer reach the account it belonged to, and we may have no way left to work out which entries in the database were yours either. This warning is about the phone. The web client signs you in with Google instead, so nothing you do to a phone can strand it.

2. Expenses you logged as Just me cannot be recovered — unless you turned on backup. By default they are never uploaded anywhere, so clearing the app’s data or uninstalling it destroys them permanently and there is no copy for anyone to restore. If you turned on Back up your personal expenses in Settings, a copy exists on the server under your own identity, and it comes back the same way a group does — see personal ledger backup, and route 2 for what deleting your account does to that copy.

Route 1 — Remove everything on your phone

You do not need the app open, and you do not need us.

  • To wipe the data and keep the app: open Android SettingsAppsSplitmateStorage & cacheClear storage. On some phones the last two steps are called Storage and Clear data.
  • To remove the app as well: press and hold the Splitmate icon, choose App info, then Uninstall. Uninstalling clears the data on the way out.

This removes, from that phone:

  • every expense you logged as Just me, permanently and with no copy anywhere — unless you had turned on backup, in which case the server still has one;
  • the local copy of every group you are in, with its members, expenses, settlements and chat history;
  • your display name, your profile picture and every app setting;
  • any invite code the app had stored for a group you shared;
  • the anonymous identity this installation was using, and with it the phone’s way back into any group it had joined.

This removes nothing from the server. Specifically, it leaves behind:

  • your display name, avatar colour and profile picture in every group you were in — the other members still see them;
  • every expense and settlement you added to a group, and every message you sent;
  • the entry recording that your identity was a member of each of those groups;
  • your personal-ledger backup, if you had turned it on.

If you signed in with Google before doing this, reinstalling the app and signing in again brings your groups and chats back, because the identity comes back with the sign-in. A backed-up personal ledger comes back the same way. Just-me expenses you never backed up do not come back, because they were never sent anywhere to come back from.

If what you actually want is for the server copy to be gone too, do that first — route 2 or route 5 — because once this route runs, route 2 has no signed-in identity left to delete, and an email request may have nothing left to match it against either.

Route 2 — Delete your account yourself

This is the one route on this page that needs nobody’s help but yours, and both clients have it. Each shows you what it is about to do, then makes you type DELETE before anything happens. There is no faster way to reach our server, and no reply from us to wait on.

The two are not the same deletion, which is why they are set out separately here. They remove different things, and one of the differences is visible to the people you share groups with. If you have used both, use the phone’s: it reaches everything the other one does, and more.

On the phone

Open Settings, scroll down to Account, and tap Delete account.

What it removes, the moment you confirm:

  • your push notification registrations, on every device the account was using;
  • your personal-ledger backup, if Back up your personal expenses was turned on — see personal ledger backup;
  • your own membership of every group you were syncing, all at once. Where you had marked which member of a group is you, that row is marked as having left, exactly as removing a member marks one: you come out of the balances and out of new splits, and the row itself, with your name and picture on it, stays;
  • your Splitmate identity itself, including the Google email address, display name and profile picture attached to it, if you had signed in with Google;
  • everything this phone was holding, the same as route 1.

In the browser

You sign in with Google there, so the account being deleted is the one that Google address is attached to. Open the Me tab, and under Account tap Delete account. Same disclosure, same typed DELETE. Leave the tab open until it finishes: half of this is network round trips, and a tab closed part-way through can leave the job unfinished with nobody left who can complete it.

What it removes:

  • your Splitmate sign-in. Nobody, you included, can ever sign in as you again;
  • your notification registrations on every device signed into that account, not only the one you are sitting at;
  • your personal-ledger backup, and the list of people you had blocked;
  • your list of groups, your list of chats, and your own way into every group you are in. No account of yours can open them again;
  • what this client had saved in that browser, which is a short list on purpose: it keeps no copy of anybody’s expenses to delete, and reads them from the server every time.

One thing the browser leaves standing that the phone does not: the member row your name is on. The phone marks yours as having left, so you come out of the balances. The browser deliberately does not touch it, so the people still in those groups go on seeing you in the member list and in the balances as though you were still there. That is a decision, not an oversight: every screen in that client hides a member marked as gone, so marking yours while your share of the expenses stayed would leave everybody else’s balances not adding up, with no row left to explain the gap and no way to put it back from there. If that row matters to you, delete your account from the phone, or ask us — see route 5.

Neither version removes your expenses, settlements, member rows, or chat messages inside groups you shared with others. Those stay exactly where they are, visible to everyone still in those groups, and both clients say so before you ever reach the point of no return. Route 3 explains why: that data belongs to the group’s own history, and nothing gates it on who added it. Once your account is gone, nobody — not you, not us, not the people still in the group — can go back and remove it.

Two of those are firmer than a policy. A chat message cannot be removed outright by anybody at all, its sender included; while you are signed in you can clear the text of your own (route 4), and once your account is gone not even that is left. And an abuse report you filed is kept as evidence, and neither client can edit or remove one — evidence a party could quietly revise would be worth nothing.

One more thing the phone’s version ends: a recovery code written on paper. A recovery code works by naming that identity, so deleting the identity is what stops the code from working — permanently, the instant you confirm, whether or not the paper it is written on still exists. If you were keeping a code as a way back into this account, this is the step that closes that door for good. That is the intended outcome of deleting an account, but only if you know it is coming before you type DELETE. There is nothing equivalent to lose in the browser: it has no recovery codes, only your Google sign-in.

This cannot be undone, by you or by asking us afterwards. If a step could not be completed — a server write failing partway through — you are told which one, in words rather than in error codes. The phone tells you after the fact, on its way back to onboarding. The browser tells you before it deletes the account itself, while trying again still means something, and trying again is safe: a step that already worked does nothing the second time.

Route 3 — Remove entries inside a group

Three things inside a group can be removed from inside Splitmate itself, and all three travel to everybody else’s copy. The Android app has all three; so does the browser client, where the rules about when a removal is allowed at all are tighter.

Removing a member

Open the group, open its member list, and use Remove beside the person. The app asks you to confirm first.

There is one thing this screen will not let you do. Once you have marked which member of a group is you, your own row carries no Remove button: taking yourself out is a different action, with a different name, and it lives on the group’s own menu rather than in this list — see leaving a group below.

Removing somebody takes them out of the balances and stops them being included in new splits. That is the whole of it, and the rest is worth spelling out because it is easy to assume otherwise:

  • It does not reach their phone. The device they joined the group on keeps the copy it already has, and goes on receiving the group’s updates and its chat.
  • Their display name, avatar colour and profile picture stay in the group’s records on the server, marked as removed rather than erased.
  • Their share of past expenses stays exactly where it is, along with every expense and settlement they added. It has to: the group’s history would stop adding up without it.
  • The browser client refuses the removal outright while that person is not settled up. The Android app allows it. That is the same difference the route 2 callout describes, in the one direction where it costs you an action rather than leaving one undone.

Deleting an expense

Deleting an expense takes it out of the balances and hides it from every member. The record underneath — its description, its amount and its note — stays on the server behind a marker that says it was deleted. That marker is what carries the deletion to everyone else’s phone, which is why it cannot simply vanish. The browser client does the same thing to the same row.

Leaving a group

This is how you end your own membership of one group while keeping your account and your other groups. Open the group, open its overflow menu, and choose Leave group; the browser client puts it on the same menu. The item is there only where there is a membership to end — not on a group that was never synced, and not on one you have already left.

You cannot leave a group you owe money in. The Android app blocks it and names the figure. The browser client is stricter and blocks it in both directions, whether you owe or are owed, because it has no way to repair the balances afterwards. Settle up first and the action comes back.

What leaving does:

  • your own row in the group is marked as having left — the same mark removing a member leaves. You come out of the balances and out of new splits, and the row, with your name and your picture on it, stays for everyone else;
  • your way in ends now. Coming back needs a fresh invite from somebody still in it;
  • if you were the last one out, the group’s invite code is retired in the same step, so a link nobody is left to use stops working;
  • on the phone only, and only if you owed nothing and were owed nothing, this device’s copy of the group and its chat are deleted along with the membership. If a balance was outstanding, that copy is kept, because there is still an obligation worth remembering.

What it does not do is take anything out of the group. Your share of past expenses, the expenses and settlements you added, and the messages you sent are all still there, for the same reason they survive route 2: they are part of what everybody else is owed.

There is still no way to delete a whole group from inside either client. Leaving one ends your own membership and nothing else; the group, its expenses, its chat and its records carry on for whoever is left. If you want a group’s own records gone, that is an email request — see route 5, which can do it where you are its only member, or where every member asks together.

Route 4 — Delete your chat messages

Press and hold your own message in a chat and choose Delete for everyone. The option only appears on a message you sent, and only while it has not already been deleted. The browser client puts the same action behind the actions button on your own message, and it does exactly the same thing to the same row.

This is the one action in the app that erases content from the server. The text is removed — not hidden, not flagged — for every participant, and their copies update as soon as their phones connect. Deleting your account does not do this: nothing, not even us, can remove a message row entirely once it exists — only its own sender can ever clear its text, and only while signed in as them.

What stays behind is an empty marker: the message’s id, who sent it, and when. It has to stay, so that the deletion reaches a phone that was offline at the time and so that the conversation does not renumber itself for everybody else. The marker carries none of what you wrote.

Two things it cannot reach. A notification already delivered to somebody’s phone carries the text of the message, and deleting the message afterwards does not recall it. And anything anyone copied or captured on their own screen is theirs, not ours.

Messages other people sent are theirs to delete, because only a sender can delete their own message. Ask them, or ask us at route 5.

Route 5 — Ask us to erase what the app cannot reach itself

Deleting your account now handles most of what used to need an email — your notification token, your personal-ledger backup, your membership of every group, and your Google sign-in record all go the moment you confirm it, with nobody to wait on. Leaving a group handles the narrower case, one group at a time, without touching your account. What is left is what neither of those can reach: your name and picture in a group you shared, a whole group’s own records, the member row a browser-side account deletion leaves standing, and anything you want gone without ending a membership to get it. For those, email splitmate@quizuncle.com with the subject Delete my Splitmate data. A person reads it; there is no form and no account to sign into.

What to put in the email

Because the Android app has no login, the hard part is matching your request to the right rows. Help us do that:

  • Your Splitmate ID, if your version of the app has one. Open Settings and look for a Copy my Splitmate ID row; if it is there, tap it and paste the value into the email. This is the most reliable thing you can send, and on its own it is enough.
  • If you use the browser client, the Google address you sign in with is enough on its own: it is the identity everything there is keyed to, and there is no Splitmate ID row to copy.
  • If your version has no such row, tell us instead: the name of each group you want your data removed from, the display name you used in it, and roughly when you joined. If you still have a group’s invite code, include that as well — it identifies the group exactly.
  • What you want removed — your own details only, or everything in a group that can be traced to you.
  • If you signed in with Google, say so and give the address, so we can find the sign-in record too.

Please send this before you clear the app’s data or delete your account. Once either has happened, your Splitmate ID is gone with it, and a description of a group may be all either of us has left to go on.

What we remove

  • your member entry in each group you name, with the display name, the avatar colour and the profile picture in it;
  • the entries that record your device’s membership of those groups, and your own private index of which groups you are in;
  • your notification token, so that phone stops being addressable;
  • the text of chat messages you sent, and your entry in each conversation;
  • your Firebase sign-in record, including the Google email address, the name and the link to the profile picture held against it, if you used the optional Google sign-in;
  • the whole group, its chat and its invite code, where you are its only member — or where every member of it asks us together.

What we will not or cannot remove

  • Expenses and settlements in a shared group, at one member’s request. A bill you paid is what tells the other members what they owe; deleting it would silently change their balances and their history. Those rows are as much their record as yours, so we will not delete them on one person’s say-so. If the group agrees, we will remove the group entirely.
  • Messages other people wrote. Those are theirs, on the same reasoning.
  • Anything already on somebody else’s phone. Every member’s device keeps its own copy of the group it belongs to. We can delete the server’s copy; we cannot reach into another person’s phone, and neither can the app.
  • A notification that has already been delivered, or anything anybody saved, copied or captured on their own screen.

How long we take

We reply within 7 days to confirm what we have been able to match, and complete the deletion within 30 days of that confirmation. We will tell you what was removed and what was not, and why. The only reason we will come back with a question is that we could not identify your data from what you sent.

Which route removes what

Every kind of data Splitmate holds, and what removes it. “On your phone” means the copy in the Android app’s private storage on your own device; “on the server” means the copy in the Google database that members of a group share. The privacy policy lists exactly what is in each.

Two things the table leaves implicit, to stay readable. Route 2 from the phone wipes that phone’s copy of everything as well, the same as route 1, on top of whatever it removes from the server — the phone column names only route 1, for brevity. And a browser has no equivalent column at all: it holds no copy of any of this, so every server answer below is the whole answer for somebody who only ever used the browser client. Where the two versions of route 2 differ, the cell says which one it means.

DataOn your phoneOn the server
Expenses you logged as Just meRoute 1Never sent there, unless you turned on backup — see the row below
Your personal-ledger backup, only if you turned it onRoute 1 removes your copyRoute 2, or turn the backup switch off in Settings and choose to delete the stored copy
App settings: theme, currency, your nameRoute 1Never sent there
Your display name in a groupRoute 1Route 5
Your profile picture and avatar colourRoute 1Route 5
Whether you appear in a group’s balances and new splitsRoute 3Route 3 — being removed, or leaving. Also route 2 from the phone, for every group at once; the browser’s route 2 leaves this exactly as it is
Expenses and settlements you added to a groupRoute 1 removes your copyRoute 5, and only with the group’s agreement
Chat messages you sentRoute 1 removes your copyRoute 4, or Route 5
Chat messages other people sentRoute 1 removes your copyTheir own Route 4, or Route 5 with the group’s agreement
Your Splitmate identity, and its membership of a groupRoute 1Route 2, or Route 5
The list of people you had blockedNot kept there — both clients read it from the serverThe browser’s Route 2, or Route 5. Route 2 from the phone does not reach it
Your notification tokenRoute 1Route 2, Route 5, or automatically once Google reports the phone unreachable
Your Google email and profile details, if you signed inRoute 1 ends the sessionRoute 2, or Route 5
A group’s invite codeRoute 1 removes your copyRetired automatically where you are the last member out, by route 3’s leave or by route 2. Otherwise Route 5
A whole group, with its expenses and its chatRoute 1 removes your copyRoute 5, if you are its only member or the group asks together
Your email address, if you used the notify form on this websiteThe app never has itEmail us — see the notify list. Deleted after the launch either way.

This website

This site keeps one cookie, qu_theme, holding the word dark or light so the page matches the theme you picked. It is not an identifier and nothing tracks you here. Clearing your cookies removes it — see the privacy policy.

The notify list

There is one form on this site: the box on the home page for being told when Splitmate has a public release. If you used it, we hold the email address you typed, the moment it arrived, and a short label recording which form it came from. Nothing else — no IP address, no browser details, no cookie — and it is not connected to any Splitmate install or to any group.

To come off it, email splitmate@quizuncle.com and say so. Send it from the address you gave us, or tell us what that address was; there is no identity to match here, so this is the quickest request on the page and we remove the whole record.

It also goes without you asking. The list exists for one announcement, after which everyone who does not say they want to stay on it is deleted — the privacy policy states that in full.

Contact

Deletion requests, and any question about this page, go to splitmate@quizuncle.com.


Effective . See also the privacy policy and the terms of use.