Privacy
Navpil handles money between friends, so it handles names and amounts. This page says exactly what that means: what is collected, why, how long it is kept, and how to get it back or have it removed — including if you never created an account.
Who is responsible
Navpil is operated by Yurii Mandzii, a sole proprietor (ФОП) registered in Ukraine. That is the data controller.
ФОП Мандзій Юрій БогдановичЛьвівська область, Львівський район, м. Львів, вул. Бальзака, 5, кв. 4, Україна
privacy@navpil.app
TODO: EU representative (GDPR Art. 27). If you are in the EU or EEA you may contact our representative instead of us, and we will name them here.
If you were invited to a split
You do not need an account and we will not ask you to make one. When you open a split link we process the display name you type, the items you claim, what you owe, and whether you have paid. We also store a token in your browser so you can come back to the same split.
We do this on the basis of legitimate interest — dividing a bill is what you opened the link to do, and doing it needs to tell people apart. We do not ask for consent because consent you could withdraw halfway would mean removing you from a bill you genuinely owe, which breaks the arithmetic for everyone else at the table. A basis we could not honour would not be a stronger protection.
A split expires on its own: 72 hours after it is created, or 24 hours after it is settled. Nothing about you is carried between splits, and no profile is built.
You can remove yourself at any time, from inside the split, with no account and no email to us. Your name is replaced with “Guest” and the amounts stay as they are, so everyone else's ledger still adds up. That is also how you object to this processing under Art. 21.
If you have an account
We process your email address, display name, language, and the sign-in credentials you chose — a passkey, a sign-in link, or a Google or Apple identity. We also hold the splits, groups, balances and settlements you create, and a payout IBAN if you add one so people can pay you back.
The basis is the contract between us: this is the service you asked for. We keep it for as long as your account exists.
You can download everything as JSON or CSV from your profile, at any time, free. That is your Art. 20 right and it is never behind a payment. Deleting your account removes your personal data and replaces your name in other people's shared splits with a placeholder, so their records survive without you in them.
Receipt photographs
When you scan a receipt, the image is sent to Google (Gemini) to read the text, then discarded. We do not keep it. That is the default and it is deliberate: a receipt can reveal things a receipt should not have to — a pharmacy receipt is health information — and the safest thing to hold is nothing.
If you ever turn on receipt archiving, we will ask you separately and explicitly, it will be off until you do, and you will be able to delete everything in one tap.
Scanning may process the image outside the EEA. TODO: confirm the Art. 28 processor terms and transfer safeguards before EU launch.
Payments
Card details never reach us. Payment is handled by LiqPay in Ukraine and by Paddle elsewhere; in-app purchases go through Apple or Google. We record which product you bought, the amount, the currency and the payment reference, because tax law requires us to keep that.
Paddle acts as the seller for purchases outside Ukraine, which means Paddle is a controller of that sale in its own right and has its own privacy notice.
Settlement between you and your friends never passes through us. We show a bank QR code or a payment link and your own bank does the rest. We never hold, pool or move your money.
Preventing abuse
Cloud scanning costs us money per scan, so we count scans per account and per device to stop a small number of people draining a free tier that exists for everyone. The device identifier is stored only as an irreversible hash, is never linked to your account, and is deleted after two days.
Analytics, and the banner you are not seeing
Navpil sets no analytics cookies and shows no cookie banner. That is not an oversight — it is the reason there is nothing to consent to. We count things like “how many people finished a split” without identifying who, and we do not use advertising trackers or share data with ad networks.
Who else sees your data
- Cloudflare — hosting, storage and the database.
- Google — reading receipt text, when you scan one.
- LiqPay, Paddle, Apple, Google — payments, when you buy something.
- An email provider — sending sign-in links and reminders you asked for.
We do not sell your data. We do not share it with anyone else unless the law requires it. TODO: confirm this list against what is deployed at launch.
Your rights
You can ask for a copy of your data, correct it, delete it, object to processing based on legitimate interest, or ask us to restrict it. Account holders can do most of this from the profile screen without asking. Guests can remove themselves from inside the split.
Email privacy@navpil.app and we will reply within 30 days. If you are unhappy with how we handled it, you can complain to your national data-protection authority — in Ukraine, the Ombudsman's office.
Children
Navpil is for people aged 16 and over.
Changes
If we change how any of this works we will update this page and change the date at the top. If the change is significant, we will tell account holders directly rather than relying on you to re-read it.