The short version
ManaSplit is local-first. Message and call history are primarily kept on your devices. Cloud services move queued messages, signal calls, synchronize account and group records, deliver notifications, store media you choose to upload, and maintain shared expense data.
Information we handle
| Category | Examples | Why |
|---|---|---|
| Account and profile | Name, email address, phone number when provided, profile photo, account identifiers, sign-in provider | Create and secure your account, identify you to your groups, and support account recovery. |
| Contacts and social graph | People you add, group membership, invitations, linked devices | Connect you with the people and devices you choose. ManaSplit does not upload your full address book. |
| Financial activity | Expenses, amounts, currencies, categories, receipts, shares, settlements, recurring bills | Calculate and synchronize the shared ledger. ManaSplit does not connect to or store bank-account or payment-card credentials. |
| User content | Messages, reactions, photos, video, audio, files, and content shared with a group | Deliver the content you choose to the people you choose. Text message history is not stored permanently in Firestore. |
| Calls | Participants, call type, signaling state, device push token, and local call history | Connect audio and video calls and present native incoming-call notifications. Audio and video are not recorded by ManaSplit. |
| Location | A location you actively attach to a message | Share that location with the selected chat. ManaSplit does not continuously track your location. |
| Device and diagnostics | Device identifier for linked-device security, platform, app version, notification token, error and delivery status | Operate notifications, pairing, synchronization, reliability, abuse prevention, and support. |
| Optional security monitoring | Email, username, phone, or domain you explicitly enroll, encrypted before storage; security findings | Check supported breach and threat-intelligence sources with your consent. |
| Optional AI inputs | Your question and the relevant facts you select or permit | Answer questions about your expenses. The app labels whether an answer used on-device processing, Apple Private Cloud Compute, or deterministic logic. |
How we use information
- Provide accounts, shared ledgers, chat, calls, media, notifications, backups, and linked-device synchronization.
- Authenticate requests, prevent unauthorized access, investigate abuse, and maintain service reliability.
- Perform calculations, search, receipt parsing, and optional AI assistance requested by you.
- Respond to support, legal, privacy, and security requests.
- Comply with law and enforce our Terms and Community Standards.
We rely on performance of our agreement with you to provide the service, consent for optional permissions and features, legitimate interests in security and reliability, and legal obligations where applicable.
Where information lives and how long we keep it
On your device
Your message history, call history, downloaded media, wallpapers, AI indexes, and some settings are stored locally. Removing the app can remove device-local content unless you use an enabled backup.
In transit
Realtime Database holds message queues, delivery state, typing state, and call signaling. Queued messages and call state are designed to expire after delivery or hangup, with server cleanup for stale records.
Persistent cloud records
Firestore holds profiles, group and chat metadata, expenses, settings needed for synchronization, device registrations, and security-monitoring records you enable. Firebase Storage holds profile and group images, receipts, expense attachments, and chat media you upload. Downloaded media may remain available to intended participants until deleted through the product or account-deletion process.
We keep account and shared-ledger records while your account is active and as needed for the group. Account deletion removes your account and associated data except information we must retain for legal, fraud-prevention, dispute, backup-cycle, or security reasons. Temporary logs and backups age out on operational schedules.
Service providers and disclosures
We share information only as needed to operate the feature you use:
- Google Firebase and Google Cloud: authentication, databases, storage, functions, notifications, encryption-key management, and optional threat checks.
- Apple: Sign in with Apple, Apple Push Notification service, CallKit, iCloud backup when enabled, on-device Foundation Models, and optional Private Cloud Compute.
- LiveKit: real-time audio and video transport.
- Expo: application tooling and notification delivery services where used.
- Have I Been Pwned, Google Web Risk, and configured threat-intelligence providers: optional Security Center checks. Queries are minimized and scoped to the feature you request.
We may disclose information when required by law, to protect people and the service, or as part of a business transaction with appropriate safeguards. We do not sell or rent personal information.
Your choices and rights
- Control camera, microphone, photos, location, local-network, Face ID, and notification permissions in iOS Settings.
- Choose whether to use optional AI, cloud analysis, backup, nearby transport, and security-monitoring features.
- Edit your profile and notification preferences in the app.
- Initiate full account deletion in ManaSplit under Settings, or follow our account-deletion guide.
- Request access, correction, deletion, restriction, objection, portability, or appeal where local law provides those rights.
To make a privacy request, email privacy@manasplit.app. We may verify your identity before acting on a request.
Children
ManaSplit is not directed to children under 13, or the higher minimum age required where they live. We do not knowingly collect personal information from children who cannot lawfully consent. Contact us if you believe a child has provided information without appropriate permission.
International processing
Our providers may process information in the United States and other countries. Where required, we use contractual and technical safeguards for international transfers.
Security
We use access controls, encryption in transit, end-to-end encryption for supported messages, device-bound security, secret management, bounded cloud functions, and data-minimizing architecture. No service is perfectly secure. Please report a concern through our security page.
Changes to this policy
We may update this policy as the product or law changes. We will change the effective date and provide additional notice when a change materially affects your rights or how we use information.
Contact
ManaSplit
Email:
privacy@manasplit.app
General support:
hello@manasplit.app