Even — Privacy Policy

Last updated: July 25, 2026 Effective date: July 11, 2026 Version: 1.0.1

1

Who we are and the scope of this policy

Even is a bill-splitting and expense-tracking application for iOS, Android, and the web. Even helps you and the people you share costs with keep an accurate, shared record of group expenses and of who owes whom.

Even is a record-keeping tool only. Even never holds, moves, transmits, or settles money, and Even is not a bank, payment processor, money transmitter, or e-money issuer. When you "Settle Up" in Even, the app only records that a payment happened somewhere else (for example, in cash or through your own bank or e-wallet app) so that your balances update. Even does not collect, store, or process payment-card numbers, bank-account numbers, or any payment credentials, and it does not facilitate the payment itself.

This Privacy Policy explains what personal data Even collects, why, how it is stored (on your device and in the cloud), who it is shared with, and the rights you have over it.

Data controller / Personal Information Controller (PIC). The operator of Even is:

Even
Quezon City, Philippines
evenappofficial@gmail.com

For the purposes of the Philippine Data Privacy Act of 2012 (Republic Act No. 10173, "DPA") we are the Personal Information Controller; for the purposes of the EU General Data Protection Regulation ("GDPR") we are the data controller.

Data Protection Officer (DPO). You can reach our Data Protection Officer at:

Even
evenappofficial@gmail.com

EU Representative. Even is operated from the Philippines and does not specifically target or market its services to individuals in the European Union, nor does it monitor the behavior of individuals in the EU. Accordingly, we have not appointed an Article 27 EU Representative. If you are in the EU and choose to use Even, the protections described in this policy still apply to you.

2

A note on what Even does not do

Because privacy is a core design choice for Even, we want to be explicit about practices we do not engage in:

The only external services Even relies on are the infrastructure processors named in Section 7 (mainly our own backend at Supabase, our sync engine PowerSync, Google Sign-In for optional login, and Firebase Cloud Messaging / Apple APNs for optional push notifications).

These practices are also reflected in our app-store privacy disclosures. Our Apple App Store "privacy nutrition label" and our Google Play "Data safety" form are intended to be consistent with this policy; in particular, they reflect that Even does not use data for tracking or advertising. If you notice any discrepancy, this policy and the actual behavior of the app govern, and we will correct the store disclosures.

3

What personal data we collect

3.1 Account and identity data

3.2 Profile data

3.3 Expense, balance, and group records ("transactional records")

These are records of shared costs and debts among users. They are not payment instruments and contain no card or bank details:

3.4 Data about other people that you provide

When you add someone to a group who is not yet on Even (a "placeholder" or "roster" member), or when you invite someone by email, you provide us with limited personal data about that person — typically a name (and a derived initial and display color) and, for invites, an email address. You are responsible for ensuring you have the right to share this information (see Section 5 on legal bases). Placeholder members have no account and no profile until they sign up and claim their membership.

Your device-local "People"/roster of contacts you have shared with is stored only on your device and is never synced to our servers or visible to anyone else.

3.5 Finding and connecting with other users (email lookup)

When you send a friend request, Even looks the recipient up by email address in our user directory to find their account. This means that if you have registered with a given email address, another Even user who knows that email can send you a friend request and connect with you. We use your email address for this lookup only to operate the friends feature; we do not use it to build a public directory, and email addresses are not exposed to other users through this lookup beyond confirming a request can be sent.

3.6 Device and push-notification data

3.7 Network and infrastructure data (IP address)

Whenever the app communicates with our backend, our infrastructure providers (in particular Supabase) necessarily receive and process your device's IP address and basic connection metadata as part of routing that network traffic. This is inherent to how any internet-connected app works. IP addresses are used to deliver the service, maintain security, and prevent abuse; Even does not use them for tracking, profiling, or advertising, and we do not build location profiles from them.

3.8 Reference data (not about you)

Even syncs a table of currency exchange rates to every device. These are global reference figures, refreshed daily; they are not personal data. See Section 7.4.

3.9 Sensitive data

Even does not intentionally collect any sensitive or special-category personal information (such as data about health, religion, ethnicity, political views, or precise location). Please do not enter sensitive personal information into free-text fields such as expense titles, payment method labels, or comments.

4

How we collect data and how it is stored

4.1 How we collect it

4.2 On-device storage (PowerSync SQLite)

Even is offline-first. Your group data is cached in a local SQLite database on your device using PowerSync, so the app works without a connection. Changes you make offline are queued locally and uploaded when you reconnect. This on-device database is not separately encrypted by the app; it is protected by your operating system's app sandbox and by your device's own security. We recommend keeping a passcode or biometric lock enabled on your device to protect the data cached there.

Two local tables — your roster ("People" you've shared with) and your app settings/preferences — are stored only on your device and are never uploaded or shared.

4.3 Cloud storage (Supabase)

Your synced data is stored in our cloud backend hosted on Supabase (a PostgreSQL database, authentication service, and file storage). Access is enforced server-side by Row-Level Security (RLS) policies so that you can only read and write data for groups you belong to. Avatar photos are stored in Supabase Storage and referenced by URL.

Certain records are stored only on the server and are never synced to any device: your push device tokens, an internal push-delivery log, and a deleted-accounts audit record (see Sections 7.3 and 9).

5

Why we process your data, and our legal bases

We process your personal data only for the purposes below. For users protected by the GDPR, we identify the Article 6 lawful basis for each purpose; for users protected by the Philippine DPA, the corresponding criteria under Sections 12–13 (consent, contract, legal obligation, and legitimate interests) apply.

PurposeWhat it involvesGDPR legal basis (DPA equivalent)
Account creation & authenticationCreating your account, signing you in (email/password or Google), maintaining your sessionPerformance of a contract (contract)
Providing the core serviceCreating/joining groups, recording expenses and payments, calculating splits and balances, comments and activity feedPerformance of a contract (contract)
Offline syncSyncing your group data between your device and our backend via PowerSyncPerformance of a contract (contract)
Currency conversionApplying and displaying FX ratesPerformance of a contract (contract)
Finding & connecting with friendsLooking users up by email address to send and accept friend requestsPerformance of a contract, or our legitimate interests in operating the friends feature (contract / legitimate interests)
Push & local notificationsSending you notifications about new expenses, payments, and members added to your groupsYour consent (given when you enable notifications and OS permission); you can withdraw it at any time (consent)
Processing data about non-users you addStoring names/emails of placeholder members and invitees so groups and invites workOur legitimate interests in operating a shared ledger, relying on your representation that you may share that data (legitimate interests)
Security, integrity & abuse preventionEnforcing access controls (RLS), protecting accounts, processing IP/connection metadata, preventing misuseOur legitimate interests in keeping Even secure (legitimate interests)
Legal complianceResponding to lawful requests, meeting legal obligationsCompliance with a legal obligation (legal obligation)

We will not use your personal data for any new, incompatible purpose without first informing you and, where required, obtaining your consent. Because Even has no analytics or advertising, we do not process your data for profiling, ad targeting, or behavioral tracking.

Withdrawing consent. Where we rely on consent (for example, push notifications), you can withdraw it at any time — by turning off notifications inside Even (globally or per group) or in your device's system settings — without affecting your ability to use the rest of the app. Where we rely on legitimate interests, you may object as described in Section 10.

6

Automated decision-making and profiling

Even does not carry out any automated decision-making or profiling that produces legal or similarly significant effects about you. Balances and splits are deterministic arithmetic based on the data you and your group members enter; they are not profiling.

7

Who your data is shared with

7.1 Other members of your groups (and your friends)

Even is a shared ledger by design. When you are in a group, the other members of that group can see:

Members can also see the membership roster, including members who have left or whose accounts were deleted. To keep everyone's view of the group consistent, the fact that a member has left or that their account has been deleted is itself synced to other members' devices (as status flags), so that such members are shown as departed or "(deleted)".

If you and another person are friends on Even, they can see your profile (display name, avatar, avatar color, phone, and timezone). Being friends does not by itself let them see your groups or expenses — that only happens in groups you actually share.

Other group members cannot see your global push preference, when you last opened the Activity feed, your device push tokens, your device-local roster/app settings, or your email/password.

7.2 Our infrastructure processors (sub-processors)

We share personal data with a small number of service providers who process it on our behalf and under our instructions to run Even. We do not authorize them to use your data for their own purposes. Processing locations are set out in Section 8.

ProcessorRoleData it handlesProcessing location
SupabaseBackend hosting: authentication, PostgreSQL database, file storage, and Edge Functions (our own backend)Your email and encrypted password hash (Supabase Auth), user ID, profile data, all synced group/expense/payment/balance data, avatar photos, push device tokens, and IP/connection metadataSouth Korea (`ap-northeast-2`, Seoul)
PowerSyncOffline-first sync engine that synchronizes your local SQLite database with our Supabase backendThe group data that syncs to and from your deviceSouth Korea (`ap-northeast-2`, Seoul)
Google (Google Sign-In / Google Identity)Optional OAuth login providerAuthenticates you and returns your Google email, account ID, name, and profile-picture URL (used only for sign-in and to seed your avatar)Global (primarily United States)
Google Firebase Cloud Messaging (FCM)Delivers push notifications to Android and iOS devicesYour device push token, user ID, and platform, plus the notification content for whitelisted eventsGlobal (primarily United States)
Apple Push Notification service (APNs)Delivers push notifications to iOS devices (reached via FCM, not directly by Even)Your iOS device push token and the notification payload, as relayed through FCMGlobal (primarily United States)

Push notifications are dispatched by a Supabase Edge Function ("push-fanout") that is triggered when a relevant record is created, reads only what is needed to deliver a notification, and honors your notification preferences (see Section 12). On iOS, notifications are delivered to Apple's APNs through FCM; Even does not send notification payloads directly to APNs.

Google APIs are also used to look up standard IANA timezone information; this timezone lookup runs locally on your device and does not transmit personal data.

Some features rely purely on your device and transmit nothing to any third party: choosing an avatar from your camera or gallery (image files are processed locally and only sent to Supabase if you upload them), generating unique identifiers, showing local notifications, and using your device's native share sheet ("Share").

7.3 Server-only records

Your push device tokens and an internal push-delivery log are stored only in our backend and are never synced to any device. A deleted-accounts audit record (see Section 9) is likewise server-only.

7.4 Exchange-rate provider

Our server (not your device) fetches daily currency exchange rates from open.er-api.com, a free public exchange-rate API, on a scheduled basis. This is an outbound request from our backend for reference data only; no personal data about you is sent to that provider.

7.5 Legal, safety, and corporate transfers

We may disclose personal data if required to do so by law or valid legal process, to protect the rights, safety, or security of our users or the public, or in connection with a merger, acquisition, financing, or sale of assets — in which case we will require the recipient to honor this policy or notify you as required by law.

7.6 We do not sell or "share" your data

We do not sell your personal information and we do not disclose it for cross-context behavioral advertising, as those terms are used under California law. Because we do not sell or share personal information, no "Do Not Sell or Share My Personal Information" opt-out is required; there is nothing to opt out of. We also have no advertising or tracking data to reflect in app-store "data shared for advertising" disclosures.

8

International data transfers

Even is operated from the Philippines, but our processors operate globally and may store and process your data outside the Philippines — including in South Korea — where our Supabase database and PowerSync sync service are hosted, in the `ap-northeast-2` (Seoul) region — and in the United States and other regions, in the case of Google, Firebase, and Apple.

9

Retention and account deletion

9.1 How long we keep data

We keep your personal data for as long as your account is active and as needed to provide Even to you and the groups you belong to. When data is no longer needed for these purposes, we delete or anonymize it, subject to the specific rules below and any legal obligation to retain it.

When you delete your account, or delete a specific group, expense, payment, or comment, the item is removed from all synced devices immediately. On our servers, such deletions are recorded as soft-deletes (the record is marked deleted and excluded from the app) and we currently retain these soft-deleted copies rather than hard-deleting them on a fixed schedule. Aside from the rules above, we do not enforce fixed maximum retention periods; we keep data only as long as necessary for the purposes described in this policy or as required by law.

9.2 Deleting your account (in-app)

You can delete your account at any time from within the Even app. When you do, our server-side `delete_own_account` process runs in a single transaction and:

  1. Deletes your authentication record (your `auth.users` row), including the authentication metadata described in Section 3.1. This immediately frees your email address for reuse and cascades the deletion of your profile and your friendships (in both directions).
  2. In groups where you have financial history (you paid expenses, received splits, or were part of a payment), your membership is retained as a tombstone: your display name and balances are preserved and your row is marked as a deleted account, so that the group's math remains correct. You will appear to other members as a departed / "(deleted)" member.
  3. In groups where you have no financial history, your membership is removed entirely.
  4. Writes a minimal server-only audit record to a `deleted_accounts` table (your user ID, email, display name, and the deletion timestamp). This record is never synced to any device and exists only as an internal audit trace, retained indefinitely.

Your uploaded avatar image file is not automatically deleted by this process. Because no automated storage-cleanup job is currently configured, it may remain in our storage until it is manually removed (see Section 9.4).

9.3 Why a deleted user's name stays on shared expenses

This is important and intentional: a deleted user's display name and their contributions remain attached to the shared expenses, splits, and payments they were part of, because those records belong to the whole group. Removing them would break every affected group's balance calculations and change what other members are shown to owe or be owed. Your account, profile, avatar reference, and friendships are gone, but the historical financial records that other people rely on are preserved so that group balances continue to resolve correctly. This preservation of another person's ledger is our legitimate interest and the group members' basis for continuing to see that data.

9.4 Residual copies

If you want data deleted beyond the in-app flow, contact us using the details in Section 1 and we will act on your request as described in Section 10.

10

Your rights and how to exercise them

Depending on where you live, you have rights over your personal data. We honor the following.

Under the Philippine Data Privacy Act, you have the right to: be informed; access your data; object to processing; have inaccurate data rectified; have your data erased or blocked; data portability; be indemnified for damage caused by unlawful processing; and file a complaint with the National Privacy Commission (NPC).

Under the GDPR, you have the right to: access; rectification; erasure ("right to be forgotten"); restriction of processing; data portability; object to processing based on legitimate interests; withdraw consent at any time; not be subject to solely automated decisions with legal/significant effects (we make none); and lodge a complaint with your local supervisory authority.

Under the California CCPA/CPRA, you have the right to: know/access the personal information we hold about you; delete it; correct it; opt out of the "sale" or "sharing" of personal information (we do neither — see Section 7.6); limit the use of sensitive personal information (we do not collect any); use an authorized agent; and receive equal service and no discrimination or retaliation for exercising your rights.

How to exercise your rights. Many actions are available directly in the app: you can view and edit your profile, change your password, adjust notification preferences, and delete your account from within Even (see Section 9.2). For any other request — including access or a portable copy of your data — contact us at evenappofficial@gmail.com or our DPO at evenappofficial@gmail.com.

We will verify your identity (for example, by confirming control of your account email) before acting on a request. We aim to respond within the timeframes required by law — generally within one month under the GDPR and within 45 days under the CCPA/CPRA (extendable where permitted), and within a reasonable period under the Philippine DPA. We do not charge a fee for reasonable requests. If we cannot fulfill a request, we will explain why, and you may appeal or complain to the relevant authority.

Please note the limits described in Section 9.3: to keep shared group balances accurate, we retain the display name and ledger contributions of deleted users on the shared expenses they were part of.

11

Security

We use organizational, physical, and technical safeguards designed to protect your personal data, consistent with Section 20 of the Philippine DPA and Article 32 of the GDPR, including:

No system is completely secure, but we work to protect your data against unauthorized access, loss, or misuse.

Data-breach notification. If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the National Privacy Commission and affected users as required by NPC rules (generally within 72 hours of knowledge), and — for users protected by the GDPR — the relevant supervisory authority and affected individuals in line with Articles 33–34.

12

Notifications and device permissions

Push notifications (optional). Even can send push notifications, but only for money- and membership-related events: when an expense is added, a payment is added, or a member is added to a group you belong to. Edits, deletions, and comments appear in your in-app Activity feed but do not trigger a push. You control notifications in two ways, both of which we honor:

On Android 13+ your operating system will ask for notification permission (the `POST_NOTIFICATIONS` permission), and on iOS you will be asked to allow notifications; you can grant or revoke this in system settings at any time. The app also uses standard network/internet access to sync your data and, on iOS, a background notification capability to receive pushes. Your push device token is removed when you sign out; if you uninstall the app or your device becomes unreachable, the token is pruned from our backend by a server-side process over time rather than deleted instantly.

Camera and photo-library access. If you choose to set an avatar, Even requests access to your camera or photo library through the standard system picker so you can select a photo. The image is handled on your device and is only uploaded to our Supabase Storage if you choose to save it; it is never sent to any advertising or analytics service. You can decline this permission and still use Even.

Contacts. Even does not currently access your device contacts.

Local notifications are shown directly on your device (title, body, and in-app routing information) and are not transmitted to third parties.

13

Children and minimum age

Even is not directed to children. You must be at least 16 years of age — and, if you are under 18, have the consent of a parent or legal guardian as set out in our Terms and Conditions — to create an account and use Even. We do not knowingly collect personal data from children below the applicable age. If we become aware that we have collected personal data from a child below the applicable age without appropriate consent, we will take reasonable steps to delete it. If you believe a child has provided us personal data, please contact us at evenappofficial@gmail.com.

14

Cookies and similar technologies

Even's mobile apps do not use cookies and do not use advertising or tracking identifiers.

On the device, Even uses local storage that is strictly necessary to run the service — for example, the on-device PowerSync SQLite database and local app-settings/preferences described in Section 4.2. This is not used for tracking.

For the web version of Even, we use only strictly-necessary browser storage (for example, to keep you signed in and to maintain your session). We do not use analytics cookies, advertising cookies, or any third-party tracking cookies. Because we set no non-essential cookies, Even does not display a tracking-consent banner.

15

Changes to this policy

We may update this Privacy Policy from time to time — for example, to reflect changes in the app, our processors, or the law. When we make material changes, we will update the "Last updated" date above, increment the version, and notify you by a reasonable means (for example, an in-app notice) before the change takes effect where required. Where a change requires your consent, we will ask for it. Your continued use of Even after an update takes effect means you acknowledge the revised policy.

16

How to contact us

For any privacy question or to exercise your rights:

Operator (Controller / PIC): Even
Address: Quezon City, Philippines
General contact email: evenappofficial@gmail.com
Data Protection Officer: Even — evenappofficial@gmail.com

You also have the right to complain to a data protection authority:

We ask that you contact us first so we can try to resolve your concern directly.