Request Data Deletion
Effective June 1, 2026 · last updated August 3, 2026
- In the app. Open Settings → Manage my dataand choose “Delete my account.” You do not need to contact us first.
- By email. Write to privacy@splitgrub.com from the address tied to your SplitGrub account with the subject “Delete my account.” We confirm receipt within 3 business days.
You can undo it during those 30 days by signing in again and choosing to restore your account. After the 30 days have passed, restoring is no longer possible and the deletion is permanent.
What gets deleted
A deletion request removes the following data tied to your SplitGrub account:
- Your account record (email, display name, sign-in identity, payment-rail handles).
- Bills and trips you hosted on your own: the receipt image, parsed line items, claims, participants, payment-intent records, tip / tax / service-charge entries, and your share-math snapshots. Trips you shared with a co-host are handled differently — see “What we keep, and why” below.
- Trip-host invitations you minted, and any co-host memberships you accepted.
- Authentication state: refresh tokens, device-attestation records (App Attest / Play Integrity tokens), saved payment-handle data.
- Your locally-curated lists (saved parties, recent contacts) live only on your device and are removed when you uninstall the app. We do not hold a server-side copy of them.
Process
In the app.Choose “Delete my account” in Settings → Manage my data and confirm. You are signed out everywhere immediately, and the account stops working from that moment. Deletion of the data begins 30 days later. Sign in again within those 30 days if you want to restore it.
By email.
- Email privacy@splitgrub.com from the address tied to your account. Subject: “Delete my account.”
- We confirm receipt within 3 business days and may ask one or two clarifying questions to verify you're the account owner (this matters more if the account has co-hosts who share trips with you).
- Once verified, we queue the deletion on the same two-step schedule: the account stops working immediately, and deletion of the data begins 30 days later.
- You receive a confirmation email when deletion completes.
If you signed in with Apple. Deleting your account also asks Apple to revoke the Sign in with Apple connection. That request is best-effort: for accounts created before we began recording the connection, or if Apple declines the request, we may be unable to revoke it on your behalf. You can always remove it yourself in iPhone Settings → your name → Sign in with Apple → SplitGrub → Stop using Apple ID.
What we keep, and why
Some data outlives your account — either because we are required to keep it, or because it was never yours alone to delete:
- Audit-log entries — records of security-relevant events (sign-in attempts, payment confirmations, deletion requests), kept for fraud prevention and account security for up to 12 months.
Once deletion of the data begins — the second step, 30 days on — entries identify your account only by a one-way hash. Everything recorded before that, including the request that started the deletion, is kept as it was written: some entries carry your account identifier, and entries carry the IP address and browser or app version the request came from. We keep that security metadata under the fraud-prevention exception rather than erasing it, because an audit trail we can rewrite is not an audit trail. - Sign-up records — when an account is deleted, a record that a sign-up occurred remains. It is not linked to you: it carries no name, email or phone number, and the link to your account is removed. It does keep a one-way hash of the device you signed up on, so that new-account limits cannot be evaded by deleting and re-registering. The IP address on these records is erased on a rolling schedule. Retained under the same fraud-prevention exception.
- Trips and bills you shared with someone else — a shared trip does not die with your account, because it is not only yours. If you were the trip's host, it passes to one of your co-hosts and the bills on it go with it. If you scanned a bill onto someone else's trip, that bill stays with them. Either way the receipt image, the line items and the claims survive under the other host.
What is destroyed is everything of yours on those bills: your sign-in credentials for them, your saved payment handle and your phone hash are erased, and your name on them is replaced with a placeholder. If you want one of those bills removed outright, the host who now holds it has to be the one to delete it — ask them. - Backups — encrypted operational backups may contain your data until the backup rotates out of retention (currently 30 days). We don't actively read or restore from backups for deleted accounts; the data ages out.
- Aggregated metrics — non-identifying counts (e.g., “X receipts processed last month”) may include events from your past usage. These cannot be tied back to you.
The full retention table is in our Privacy Policy.
What about data others entered about me?
If you were a guest on someone else's bill (you tapped a magic link, picked items, paid), the host scanned and owns that receipt — not you. Deleting your own SplitGrub account doesn't remove their copy of the bill, because the bill is theirs. We hash your phone number on the host's side already, so what remains is a one-way hash plus the items you claimed, not personal data we can use to identify you.
If you want a host's copy of a bill removed, the host has to be the one to delete it — ask them. We can't override that on your behalf without their consent.
Partial deletion
You can also ask us to delete specific data without nuking the whole account — for example, a single bill or your saved payment handles. Same email, just say what you'd like removed. We'll confirm scope before acting.
Questions
For anything not covered above, the canonical reference is our Privacy Policy. For questions specific to your request, reply to the confirmation email or write to privacy@splitgrub.com.