Privacy Policy
Shared Expenses · Last updated 20 September 2026
This policy explains what Shared Expenses stores, where it is kept, and how to have it removed. It covers the Shared Expenses mobile app for iOS and Android. The app is run by Mohsin Ali as an independent developer.
You do not need an account
You are never required to sign up. When you first open the app it quietly creates an anonymous identifier with Google Firebase Authentication — a random string, not linked to your name, your email, or any other app. Joining somebody else's group needs nothing but an invite code.
You may optionally add an email address and a password, so that your groups can be recovered if you reinstall the app or change phone. That is the only situation in which the app holds an email address. It is never shared, never used for marketing, and never shown to the other people in your groups. If you do not add one, your groups exist only on that single installation.
What the app stores
Only what you type in, plus the bookkeeping needed to keep a shared ledger honest:
- Names you enter. The display names you give yourself and the people you split with. These are free text — if you type a real name, a real name is what gets stored.
- Groups. Group names, their default currency, and who belongs to them.
- Expenses. The description you write, the amount, the currency, who paid, and how it was split.
- Settlements. Records of payments between people, including amount and currency.
- Personal balances. A counterparty name, a reason, an amount, a currency, and which direction the debt runs.
- Invite codes and when they were created, claimed, and by which anonymous identifier.
- An email address, only if you chose to back up your data. It is held by Google Firebase Authentication as your sign-in. The password is kept only as a cryptographic hash, which nobody — including us — can read or recover.
- An activity log. Every expense and settlement writes an entry recording what happened, when, and which anonymous identifier did it. Expenses are never edited or deleted in place — a correction reverses the original and writes a replacement, so the history stays auditable.
What the app does not collect
- No advertising, and no advertising identifiers.
- No analytics or crash-reporting service.
- No third-party trackers of any kind.
- No contacts, photos, location, camera, or microphone access.
- No bank details or payment information. The app records that a payment happened; it never moves money and is not connected to any bank or payment provider.
Nothing is ever sold, rented, or shared with advertisers or data brokers.
Where the data is kept
Data is stored in Google Cloud Firestore, in Google's
me-central2 region, which is located in Dammam, Saudi Arabia.
Google acts as the hosting provider. As part of operating that service, Google
processes technical information such as the IP address your device connects
from; this is covered by
Firebase's
own privacy documentation.
Who else can see your entries
Anything you add to a shared group or a shared personal balance is visible to the other people in it. That is the point of the app. Access is enforced by server-side security rules: you can only read a group you are a member of, and membership is only granted by claiming a valid, unexpired invite code.
An invite code is a bearer token — anyone holding it can join that group. Send codes only to the person you mean to invite.
On your device
The app keeps a local copy of your data so it works offline, using Firestore's offline cache and your device's local app storage. Deleting the app removes that local copy.
Keeping and deleting your data
Data is kept for as long as the group or balance exists. Because the ledger is append-only, reversed expenses remain visible in the activity history rather than disappearing — otherwise the balances could not be checked.
If you added an email, you can delete your account from inside the app, at Account → Delete account. That removes your sign-in and your profile record straight away, and you will not be able to get back in.
To have your data deleted, email support@mohsinapps.com from the device you use the app on and say which groups you want removed. Requests are handled within 30 days. Note that entries you added to a group shared with other people form part of their balances too; where that is the case, your personal details are removed but the amounts may be retained in an anonymised form so the other members' books still add up.
Deleting the app without asking for removal leaves the data on the server, and because there is no account you will not be able to reach it again.
Children
Shared Expenses is not aimed at children under 13, and the app does not knowingly collect information from them.
Changes
If this policy changes, the date at the top of this page changes with it. Significant changes will be noted in the app.
Contact
Questions about privacy, or a deletion request: support@mohsinapps.com