FairOwe

Privacy Policy

Last updated: 29 August 2026 · Effective: 29 August 2026

FairOwe is an expense tracker and group bill-splitter. This policy explains exactly what the app reads, what stays on your phone, what is stored on our servers, and who else can see any of it. It is written to be specific rather than reassuring — where something does leave your device, we say so plainly.

The short version

FairOwe never reads your SMS inbox and never asks for the READ_SMS permission. It reads incoming notifications from a fixed list of bank and payment apps, parses them entirely on your device, and syncs only the finished expense — amount, merchant, category, date, account tail — to your account. The original alert text stays on your phone and is never uploaded. If you add someone to a group, their name and phone number are stored with that group so other members can see who owes what.

1. Who we are

FairOwe is operated by Ganesh J, India. For any question about this policy or your data, contact fairowe.app@gmail.com.

For users in India, this contact also serves as our grievance channel under the Digital Personal Data Protection Act, 2023. We aim to respond within 30 days.

2. What we collect

Account information

Your phone number, which is how you sign in. We verify it with a one-time password. Optionally, a display name and a backup email address if you choose to add one.

Expenses you record

Amount, merchant or description, category, date, payment account label and its last digits, and any note you add. This includes expenses created automatically from a bank alert and those you type in yourself.

Notification-derived data

If you switch on auto-capture, FairOwe reads notifications posted by a fixed allow-list of banking and payment apps — currently HDFC, ICICI, SBI, Axis, Kotak, PNB, Bank of Baroda, Google Pay, PhonePe and Paytm, plus the Google and Samsung Messages apps, since many bank SMS alerts only reach the phone through them. Notifications from every other app are discarded inside the listener before they reach the app's code or disk.

The raw alert text stays on your device. It is kept locally so you can check the source of an expense later, and it is never transmitted to us or anyone else.

Contacts

If you grant contacts access, FairOwe reads your address book on the device only, to let you pick people to add to a group. Your address book is never uploaded.

To tell you which contacts already use FairOwe, the app computes a one-way SHA-256 hash of each selected phone number and sends only those hashes to our server, which compares them against hashes of existing accounts. We never receive a raw phone number that we did not already hold.

Where contact data does leave your phone: when you actually add someone to a group, the name and phone number you selected for them are stored on our servers as part of that group's membership, and are visible to the other members of that group. This is what makes shared balances work. It applies only to people you deliberately add — never to the rest of your address book.

Group and settlement data

Groups you create or join, their members, shared expenses, how each expense is split, and settlements recorded between members. Everyone in a group can see that group's expenses, splits, balances and member list.

Device and technical data

A push notification token and platform name, so we can alert you to group activity. Basic device and app version information attached to crash reports. On the free plan, the device's advertising ID and IP address are also seen by our ads provider (section 5a); FairOwe Pro removes ads, and this collection with them.

Diagnostics and analytics

Crash reports and error diagnostics, and anonymous product-usage events (for example, that an expense was created — never its contents). Crash reporting includes a session replay feature that may capture screen interactions around the time of an error, which can include the screen contents visible at that moment.

3. What never leaves your phone

FairOwe performs no server-side parsing. Every alert is turned into an expense by code running on your phone.

The one exception, and it is off until you switch it on. If the on-device reader cannot make out a photographed bill, FairOwe Pro can offer to send that single photo to be read by an AI text-recognition service (Anthropic), which returns the text and does not use it to train models. This is off by default, is switched on by you in Privacy & data, applies only to bills you photograph and choose to retry, is limited to a fixed number of reads a month, and never applies to notification text. The photo is not stored by us.

4. Why we use it

We do not sell your data. Your expenses, balances, contacts and notification-derived data are never shared with advertisers and are never used to build advertising profiles — the ad SDK has no access to them. What advertising does involve is described in section 5a.

5. Who else processes your data

We use the following service providers, each only for the purpose listed:

Provider Purpose Data involved
Supabase Database, authentication, sync Account, expenses, groups, settlements
MSG91 One-time password delivery Phone number
Expo & Google Firebase Cloud Messaging Push notification delivery Push token, notification text
Sentry Crash reporting and diagnostics Error data, device info, session replay
Google AdMob Showing ads on the free plan Advertising ID, IP address, device and app information
Google Play Billing Processing and verifying subscriptions Purchase token, subscription status
Anthropic Optional cloud reading of a photographed bill, only on FairOwe Pro and only after you switch it on The single bill photo you chose to retry. Not used for model training
PostHog Product analytics Anonymous usage events

We may also disclose data where we are legally required to, or to protect the rights and safety of our users.

5a. Advertising, and how to change your choices

On the free plan FairOwe shows a single Google AdMob ad when you open the app — at most once every four hours, never during onboarding, and never while an expense you captured is still waiting to be reviewed. FairOwe Pro removes ads entirely, and the change takes effect immediately on purchase.

To serve those ads, Google receives your device's advertising ID, IP address and basic device and app information. Google acts as an independent controller of that data under its own privacy terms, and the ad partners involved are listed inside the consent form itself. None of your expenses, balances, contacts or notification text is ever sent to Google for advertising, or to anyone else for advertising.

Where the law requires consent — the EU and UK under GDPR, and India under the DPDP Act — you are asked before the first ad request, through Google's certified consent form. If you decline personalised ads, ads are requested on a non-personalised basis instead, which uses far less data. You can revisit the decision at any time in the app: You → Privacy & data → Ad privacy choices. That row appears wherever Google tells us a privacy-options entry point is required for you.

You can also reset or delete the advertising identifier itself in Android Settings, under Privacy → Ads. That control is outside FairOwe and applies to every app on the device.

6. Where data is stored, and for how long

Your synced data is stored on Supabase infrastructure in the Asia Pacific (Singapore) region. Some providers listed above process data outside India.

We keep your data for as long as your account exists. Deleting your account removes your personal data from our servers, except where we are required to retain something by law. Shared group expenses you contributed to may remain visible to the other members of that group, since the record belongs to the group as a whole.

Data held only on your phone is removed when you uninstall the app.

7. Your choices and rights

8. Android permissions, and why

Permission Why FairOwe needs it
BIND_NOTIFICATION_LISTENER_SERVICE Reads bank and payment notifications so expenses record themselves. Filtered to an allow-list; parsed on device; raw text never uploaded.
READ_CONTACTS Shows your address book when adding people to a group. Read on device; only people you pick are stored.
POST_NOTIFICATIONS Group activity alerts, the capture self-test, and the optional daily report and settle-up reminders your phone schedules for itself.
CAMERA Photographing a bill so it can be read into an expense. The photo is read on your phone and is not stored or uploaded, unless you switch the cloud reader on yourself. FairOwe never reads your photo gallery.
REQUEST_IGNORE_BATTERY_OPTIMIZATIONS Asks Android not to suspend the app in the background. Without it, alerts arriving while FairOwe is closed are silently missed.

FairOwe deliberately does not request READ_SMS or RECEIVE_SMS. These permissions are explicitly blocked in the app's manifest.

9. Children

FairOwe is not directed at children under 18, and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will remove it.

10. Security

Data in transit is encrypted with TLS. Your session credentials are held in the device's secure keystore. Server-side access is restricted per account by row-level security, so one account cannot read another's data. No system is perfectly secure, and we cannot guarantee absolute security.

11. Changes to this policy

We will update this page when our practices change and revise the date at the top. For material changes we will notify you in the app.

12. Contact

FairOwe
fairowe.app@gmail.com