Privacy policy
Quits, by Pixel Forge Labs · Last updated 26 July 2026
This policy explains what data Quits processes, why, and what your rights are. The short version: your expense data exists to keep your group in sync, receipt photos and voice notes are processed by AI only to extract the expense you asked for, and we don't sell data or show ads.
Data we process
- Account data. If you sign in with Google, we receive your name, email address, profile picture and Google account identifier. Signing in is required for AI features but not for basic expense tracking.
- Expense data. Groups, expenses, item lines, balances, notes and participant names you enter. This syncs through our servers so everyone in a group sees the same ledger.
- Payment handles. If you add ways to get paid back (for example a Venmo or Revolut username, a PayPal.me link, or an IBAN), these are stored with your group profile and shown to the members of your groups so they can pay you in one tap. Only add handles you are comfortable sharing with your groups.
- Receipt photos and voice notes. When you use AI capture, the photo and/or recording you submit is sent to our servers and processed by Google's Gemini API to extract items, prices and who-had-what. Receipt photos you attach are also stored so your group can view them on the expense.
- Device identifier. A one-way hash of your device ID, used to provide free trial scans before sign-in, to prevent abuse, and as the anonymous key for the usage analytics described below. It cannot be reversed into your device ID.
- Usage analytics. Our servers record a small set of product events — for example that onboarding was completed, a paywall was viewed, or a receipt scan succeeded — keyed to the hashed device ID or your account ID. We use PostHog, Inc. (US) to store and chart these events. The events never contain your expense contents, photos or recordings. There are no advertising or analytics SDKs inside the app itself.
- Purchases. If you buy a Trip Pass or Quits Pro, the payment is handled by the store you bought it through (for example Google Play). We never see or store your card details — only which plan is active on your account or group.
Who can see your group data
Quits is a shared ledger by design. Expenses, item assignments, balances, participant names, payment handles and attached receipt photos are visible to every member of the group. Group invite links and live-split view links act as keys: anyone you share such a link with can join or view that group's data, so treat links like you'd treat the ledger itself.
How AI processing works
Receipt images and voice recordings are transmitted to Google's Gemini API (Google Ireland Ltd. / Google LLC) under Google's paid API terms to perform the extraction you requested. Under those terms Google does not use your submissions to train its models.
We may retain submitted receipts, recordings and their extraction results to improve Quits' own extraction quality. This data is used only internally for that purpose and is never used to train third-party models or shared beyond the processors named in this policy. You can opt out of this retention, or have already-retained data deleted, by contacting us (see below) — extraction keeps working either way.
What we don't do
- No advertising and no ad trackers, in the app or on this site.
- No selling of personal data, and no sharing beyond the processors named in this policy.
- No access to your contacts, location, or anything beyond the camera/microphone content you explicitly submit.
Processors and where data is processed
We use a small number of service providers ("processors") to run Quits:
- Railway Corp. (US) — hosts our sync server, database and stored receipts.
- Google (Google Ireland Ltd. / Google LLC, US) — Google sign-in and the Gemini API for AI extraction.
- PostHog, Inc. (US) — product usage analytics, as described above.
Some of these providers process data in the United States. Where personal data leaves the EEA, the transfer is safeguarded by the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, as implemented in each provider's data-processing terms.
Retention and deletion
Expense data is retained while your account or group is active so the shared ledger keeps working. Analytics events and hashed device identifiers are kept only as long as needed for the purposes above.
You can delete your account directly in the app: Settings → Account → Delete my account. This permanently removes your server-side account — sign-in, remaining credits and any subscription status. Group ledgers are shared with other people, so group data you contributed remains part of those groups; leave or delete groups in the app to remove it.
You can also request deletion by email — including deletion of retained receipts and recordings, or deletion without access to the app — at support@quitsapp.co from your account address. We complete deletion requests within 30 days. See how to delete your account and data for a step-by-step guide.
Your rights
Pixel Forge Labs is based in Slovenia and complies with the GDPR. You have the right to access, correct, export and erase your personal data, and to lodge a complaint with your supervisory authority (in Slovenia: Informacijski pooblaščenec). For data portability, every group can be exported from within the app as a CSV spreadsheet or PDF report at any time.
Children
Quits is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
Contact
Data controller: Pixel Forge Labs, Slovenia. Questions and requests: support@quitsapp.co. See also our business details.
We will update this policy as the app evolves and note the date of the latest change above.