Privacy

What Split knows about you

Split has no accounts, so most of what a privacy policy usually covers does not exist here. This page says what is left.

Effective 1 September 2026

Who runs this

The official service at peanutsplit.com is operated by Squirrel Labs Ltd, a company registered in England and Wales (company number 14558823), registered office Office One, 1 Coldbath Square, Farringdon, London EC1R 5HL. Squirrel Labs is the controller of the personal data described here, under UK data protection law.

This notice covers peanutsplit.com only. Peanut’s wallet and card are a different product with a different policy, and nothing on this page describes them. If you settle a balance through a Peanut payment link, you leave Split and Peanut’s privacy policy applies from that point.

There is no account

Split asks for no email address, no password, no phone number and no identity document. A room is a link, and holding the link is what grants access. Nobody has to prove who they are to use it, and there is no profile to look you up in afterwards.

The room link is therefore a credential. Anyone you send it to can read and change the room, and we cannot tell them apart from you.

What the service stores

A room and its contents are held on our servers, because everyone in the group has to see the same numbers. That is:

  • the room’s name, currency and drawing;
  • the display names people type for themselves, which do not have to be real names;
  • each expense: its description, amount, date, who paid, and how it was split;
  • settlements recorded in the room, and the reactions people leave on an expense;
  • a push subscription for each device that turns notifications on in a room — the browser’s push address, its keys, and the browser’s user-agent string;
  • a record of edits to the room, kept so the group can see what changed rather than for us to read.

Whatever the group writes into a room is stored as written. An expense described “dinner with Ana” names Ana, and there is nothing we can do about that from here — so put into a room only what the group is happy for the group to read.

What stays on your device

Your list of recent rooms, the token that says which member of a room you are, and your app settings live in your browser’s local storage. They are not sent to us. Clearing site data loses them, and a room you have no link to is a room you cannot get back.

Split itself sets four cookies. Each one is needed for the product to work. None of them measures you or advertises to you.

  • ps-locale— the language you chose. One year.
  • device-id— a random value with no meaning outside this site, used to keep an installed home-screen app recognised as the same anonymous device rather than a new one. It is not tied to a name, an email or a room. Ten years.
  • __Host-ps-install-handoff— written only when you start adding Split to an iPhone home screen. iOS copies cookies into the new app but not local storage, so this random secret is the one thing that tells the new app which room you were already in. The page cannot read it; only our server can. 24 hours.
  • __Host-ps-install-handoff-ready— written at the same moment, and says only that a handoff is waiting. The page reads this one to know whether to ask for it. 24 hours.

Both handoff cookies are cleared as soon as the new app has the room.

Measurement

We use PostHog to count how the product is used, on European infrastructure. It is deliberately blind: automatic capture is off, session recording is off, page text is masked, and no room link, member name, expense description or amount is ever attached to an event. What we get is that a room was created, an expense was added, a share sheet opened — not whose, and not for how much.

When something breaks, Sentry receives the error. Errors only: no performance tracing and no session replay, and room links are stripped out of the report before it is sent.

Advertising

Since 24 August 2026, peanutsplit.com carries a Google Ads tag (AW-17182428820). It runs on this site only, and it has one job: to tell Google that an ad click ended in a room being created, so we can tell which adverts are worth paying for.

When you arrive from a Google advert, the link carries a click identifier. The tag reads it and stores it in a Google cookie on this site (_gcl_aw) so that a room created later in the same browser can be matched back to that click. If you did not arrive from an advert, there is no click identifier to store.

The tag reports no page views. When a room is created it reports one event, with no value attached and nothing about the room — not its link, its name, its currency or its amounts. The address it reports is rebuilt before it is sent: room links are removed, and so is anything else in the URL except the Google click identifiers and the campaign labels that were already public in the advert.

Google is an independent controller of what it receives. Google’s advertising policy covers that half. You can block the cookie in your browser; the product works exactly the same without it.

Photographs of receipts

If you photograph a receipt to fill in an expense, the image is sent once to a language-model provider to be read, and the answer comes back as text. Split does not keep the photograph: there is no column, bucket or temporary file for it, and neither the image nor anything read off it is written to a log. The provider is required to be one that retains nothing and trains on nothing. The feature is off entirely unless the operator has configured it.

Who else is involved

We do not sell personal data, and nothing here is used to build an advertising profile of you. The service depends on:

  • Google Ads — conversion measurement, as described above;
  • PostHog — product analytics;
  • Sentry — error reports;
  • a language-model provider — receipt photographs, held for the length of one request;
  • your browser vendor’s push service — it delivers a notification you asked for, and it necessarily sees that a message was sent to your device;
  • our hosting provider — ordinary web-server request logs, including IP addresses.

Some of these operate outside the UK. We may also disclose data where the law requires it.

How long it is kept

A room is kept for as long as the service runs. The app has no way to delete a room, and nothing expires one on a timer, so a room nobody has opened in a year is still there for whoever still holds the link.

Deleting an expense or a settlement hides it rather than removing it. The row stays, with its description, its amount and how it was split, because the six-second Undo needs it back and the room history is a record of what changed. Nothing removes those rows later. Removing a member works the same way: the person is marked former, and their name and their part of past expenses stay.

A feedback report you choose to send is deleted after 90 days. The handoff record written when you add Split to an iPhone home screen holds a room id and a hashed member token. It is deleted as soon as the new app confirms it has the room. If that never happens, it lasts 24 hours and is then swept.

Your rights, and the awkward part

Under UK data protection law you can ask for a copy of your personal data, ask us to correct it, ask us to delete it, object to how we use it, or complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first.

Being accountless cuts both ways. We have no way to find “your” data, because there is no identifier that connects you to a room from our side. To make a request about a room, send us its link — that is the only thing that identifies it. Anyone else holding the same link can make the same request, which is one more reason to treat it as a credential.

Erasure is a request to us, not a button. Nothing in the app removes anything: deleting an expense or a settlement hides the row and keeps it, and there is no delete for a room at all. Write to the address at the end of this page, send the room link, and say what you want removed. We then remove it from the database by hand.

Everyone in a room can already see everything in it. Removing your name or your expenses changes what the rest of the group sees, so tell them rather than surprising them.

Children

Split is not intended for anyone under 18, and we do not knowingly collect data about children. Contact us if you believe we have.

Contact

  • Email: support@peanut.me
  • Post: Squirrel Labs Ltd, Office One, 1 Coldbath Square, Farringdon, London EC1R 5HL

If this page changes we will change the date at the top. This notice is written in English; a translation, if one is ever published, does not override it.