HesabNa
HesabNa
Legal

Privacy Policy

Last updated September 16, 2026

We do not sell your data. We do not use your receipts for advertising. Your payment handles are only shown to people you explicitly share a bill with.

1. Information We Collect

This policy covers both HesabNa in your web browser at hesabna.app and the HesabNa app for iOS. The two store data differently in a few places; wherever that matters, the difference is stated explicitly below.

When you use HesabNa, we collect:

•

Email address (only if you create a full account, used for login and notifications)

•

Name and payment handles you choose to add to your profile

•

Receipt images you scan (processed automatically, deleted after 30 days; see Section 5)

•

Session data: who was in the group, item assignments, payment amounts

•

A random anonymous identifier if you open a bill link or use HesabNa without creating an account ("guest" mode); see Section 2 for what this is and is not

•

Basic usage events (which screens and features you use, to improve the product and understand how people use HesabNa)

2. Guest Mode and Anonymous Recognition

You can use HesabNa, including opening a bill someone shared with you, without creating an account. When you do, we assign you a random anonymous identifier (not your name, email, or any personal detail) so that if you open another bill later, in the same browser, we can recognize you and show a lightweight "Welcome back" message instead of treating you as a stranger every time.

This identifier:

•

Is generated and stored via your browser's own sign-in session, not a fingerprint. We never use canvas fingerprinting, device fingerprinting SDKs, or your IP address to identify or track you across visits.

•

Only persists in the same browser on the same device. A different browser, a different device, or clearing your browser data starts you over as a new, unrecognized guest.

•

Can be upgraded into a full account at any time (Profile → create account), which carries your history, payment preferences, and past bills over; see Section 5 of the Terms of Service.

•

Can be deleted at any time; see Section 7 below. Deleting it removes the identifier and everything tied to it; it does not remove other people's bills or records just because you were a guest on one.

We also record which of your devices have used HesabNa under this identifier (a randomly generated device marker, again not a fingerprint) so we can tell "the same guest returned" from "the same guest is now on a second phone," used only for the product itself, never sold or shared.

On the iOS app: the guest session is stored by the app rather than a browser, so it is not affected by clearing browser data. The iOS app additionally generates one random identifier (a UUID, not your Apple ID, advertising identifier, phone number, or any hardware serial) and stores it in the iOS keychain. Because the keychain is designed to survive app deletion, this identifier can persist if you delete and reinstall HesabNa, and the app reads the same value back on reinstall. Its only purpose is to stop the same device resetting the free-scan trial over and over by reinstalling or creating new accounts. It is never used for advertising, never used to track you across other apps or websites, and never sold or shared. It is removed if you erase all content and settings on the device, or restore from a backup that never contained it.

3. How We Use Your Information

We use your information to:

•

Process and display your receipt data

•

Generate per-person payment links for your group

•

Show your payment handles to bill recipients

•

Recognize you as a returning guest and personalize what you see accordingly (Section 2)

•

Send transactional emails (account confirmation, password reset); full accounts only

•

Measure product usage and calculate aggregate metrics (e.g. how many people return, how often bills get settled); never used to build an advertising profile of you

4. What We Do Not Do

We do not sell your personal data to third parties. We do not use your receipt data for advertising. We do not share your payment handles with anyone except the people you explicitly share a bill link with. We do not use fingerprinting, IP-based tracking, or any identification method beyond the anonymous browser-session identifier described in Section 2.

5. Data Sharing

Your data is shared only in these circumstances:

•

With participants of a specific bill: people you share a payment link with see the session data and your payment handles

•

With our infrastructure and service providers, all under data processing agreements: Supabase (database, authentication and file storage), Vercel (hosting), Google (receipt parsing, see below), PostHog (product analytics: usage events, never your receipt contents or payment handles), Resend (transactional email)

•

On the iOS app only: Sentry (crash and error reporting). If the app crashes or hits an error, Sentry receives a diagnostic report containing the device model, OS version, a stack trace and app state around the error. It is not used for analytics or marketing.

•

If required by law

How receipt parsing works: when you scan a receipt, the image itself is uploaded to our file storage and sent to Google's Gemini API, which reads it and returns the items, prices and taxes. We send the image for that one purpose; we do not send your name, your payment handles, or the list of people in your group to Google. Google's handling of data submitted to its API is governed by the Google APIs Terms of Service. The stored image is deleted 30 days after upload (Section 6).

6. Data Retention

Receipt images are automatically deleted 30 days after upload (a scheduled daily job, not a manual or best-effort process). Session and bill data is retained until you delete it from the app or delete your account. Profile data is deleted immediately when you delete your account. Anonymous guest activity events are kept in detail for 90 days to power features like "Welcome back," then automatically reduced to anonymous daily counts (e.g. "142 bills opened on this date") with the underlying detail permanently removed. The aggregate counts contain no identifier and cannot be traced back to any guest.

7. Security

All data is encrypted in transit (HTTPS) and at rest. Payment links use unique, non-guessable session identifiers. We do not store payment credentials, only the handle aliases you choose to display.

8. Your Rights

You have the right to:

•

Access the personal data we hold about you

•

Correct inaccurate data

•

Export a complete copy of your data as a downloadable file: on the web, Profile → Export my data. The iOS app does not currently include this export; iOS users can export a single bill as a CSV from that bill's screen, and can email hello@hesabna.app for a complete copy of their data, which we provide within 30 days.

•

Delete your account and associated data at any time: Profile → Delete my account and data on the web, Profile → Delete Account on iOS. This is immediate and irreversible; bills you organised are kept so other participants' records aren't affected, but they're no longer linked to your identity once deletion completes.

Guest (anonymous) users have the same rights, on both platforms, whether or not you've created a full account.

For anything these in-app tools don't cover, contact us at hello@hesabna.app.

9. Storage on Your Device, and Your Analytics Choice

On the web: we use your browser's local storage to keep you signed in and to remember a couple of lightweight preferences (like your display name, so you don't retype it). This is required for the app to work and isn't something you can opt out of while still using HesabNa, the same way you can't use any app without a session.

Analytics (PostHog) and cross-visit guest recognition (Section 2) are different on the web: the first time you visit, we ask whether to turn these on. Declining doesn't block anything (you can still scan receipts, split bills, and pay), it just means we won't log usage events or recognize you as a returning guest. You can find this choice again by clearing your browser's local storage, which brings the prompt back.

On the iOS app: the equivalent data is stored by the app itself rather than in a browser — your sign-in session, your display name, language, currency and other preferences, plus the trial-control identifier described in Section 2. Deleting the app removes the app's own storage; the keychain identifier in Section 2 may remain until you erase the device.

The iOS app does not show a first-run consent prompt. Product analytics runs unconditionally there and isn't something you can turn off from within the app. Crash reporting (Sentry, Section 5) is always on for iOS and is used only to find and fix crashes.

We do not use tracking as defined by Apple's App Tracking Transparency framework — HesabNa does not share your data with data brokers and does not track you across apps or websites owned by other companies — so the iOS app does not show the App Tracking Transparency prompt.

10. Changes to This Policy

We may update this Privacy Policy. We will notify you of material changes by email or in-app notice. The date at the top of this page reflects the most recent update.

11. Contact

Privacy questions? Email hello@hesabna.app. We respond within 2 business days.