English · Українська
Privacy
Navpil handles money between friends, so it handles names and amounts. This page says exactly what that means: what is collected, why, on what legal basis, how long it is kept, who else sees it, and how to get it back or have it removed — including if you never created an account.
Who is responsible
Navpil is operated by Yurii Mandzii, a sole proprietor (ФОП) registered in Ukraine. That is the data controller.
ФОП Мандзій Юрій БогдановичЛьвівська область, Львівський район, м. Львів, 79009, вул. Бальзака, 5, кв. 4, Україна
privacy@navpil.app
Our representative in the European Union. Because we offer Navpil to people in the EU and EEA, Article 27 GDPR requires us to appoint a representative there. We are appointing one. Until we can name them on this page, people in the EU and EEA should contact us directly at privacy@navpil.app, and we will answer within one month. We would rather tell you this is outstanding than leave you to discover it.
We are not required to appoint a Data Protection Officer and have not appointed one. Privacy questions go to privacy@navpil.app and are answered by the operator.
If you were invited to a split
You do not need an account and we will not ask you to make one. When you open a split link we process the display name you type, the items you claim, what you owe, and whether you have paid. We also store a token in your browser so you can come back to the same split.
We do this on the basis of legitimate interest (Art. 6(1)(f)) — our interest is running the split that you opened the link in order to join, and doing it needs to tell people apart. We do not ask for consent because consent you could withdraw halfway would mean removing you from a bill you genuinely owe, which breaks the arithmetic for everyone else at the table. A basis we could not honour would not be a stronger protection. We have written down the balancing test behind that decision, and we will send it to you if you ask.
A split expires on its own: 72 hours after it is created, or 24 hours after it is settled, whichever comes first. When it expires the split's contents are deleted outright. Nothing about you is carried between splits, and no profile is built.
One exception worth naming: if the person who created the split has an account, their own saved record of it — who was in it and who owed what — stays in their history until they delete it or delete their account.
You can remove yourself at any time, from inside the split, with no account and no email to us. Your name is replaced with “Guest” and the amounts stay as they are, so everyone else's ledger still adds up. That is also how you object to this processing under Art. 21.
If someone typed your name into a split, we received it from them rather than from you. The same removal control applies, and the person who entered it is responsible for what they entered.
If you have an account
We process your email address, display name, language, and the sign-in credential you chose — a passkey, a one-time email link, or a Google or Apple account. We also hold the splits, groups, balances and settlements you create, and a payout IBAN if you add one so people can pay you back.
The basis is the contract between us (Art. 6(1)(b)): this is the service you asked for. We keep it for as long as your account exists.
A payout IBAN you save to your account is encrypted at rest (AES-256-GCM). An IBAN typed into a single live split is held only for that split and is deleted when it expires. Sign-in links are single-use and expire within 15 minutes; a signed-in session lasts up to 90 days and you can end it by signing out.
You can download your account as JSON, and a group's expenses as CSV, from your profile, at any time, free. That is your Art. 20 right and it is never behind a payment.
Pausing versus deleting
Deactivate pauses notifications and hides you from shared ledgers. Your data stays exactly where it is, and signing in brings it back. Delete is permanent and immediate: we purge your account across our database, and replace your name in other people's shared splits with a placeholder so their records still add up. There is no grace period and no soft-hide. Pausing is not deleting — if you want your data gone, choose Delete.
Receipt photographs
When you scan a receipt, the image is sent to Google (Vertex AI), in Google's EU region, to read the text off it. We do not store the image — not on the free tier, not on a paid one, not at all. That is deliberate: a receipt can reveal things a receipt should not have to — a pharmacy line is health information — and the safest thing to hold is nothing.
What we can keep is the parsed result — the item names and prices we read off it. That only happens if you switch on Keep receipt details in Privacy & data. It is off by default. With it on we keep the parsed items for 24 months; you can delete them all in one tap, and switching the setting back off deletes them immediately. The photo is never stored.
The basis for keeping them is your consent (Art. 6(1)(a), and Art. 9(2)(a) where a receipt happens to reveal special-category data). You can withdraw it at any time, which is what the switch does; withdrawing does not make our earlier processing unlawful.
We also record one row per scan — which account, how many tokens it cost us, and whether it succeeded — so we can count usage against your allowance and know what scanning costs. That row holds no image, no items, no IBAN.
Preventing abuse
Cloud scanning costs us money per scan, so we count free scans per device and per IP address to stop a small number of people draining a free tier that exists for everyone. Both are stored as hashes rather than in the clear, are not linked to your account, and are deleted after about two days. The basis is legitimate interest — keeping a free tier viable for the people it is for.
Sign-in and split creation are protected by Cloudflare Turnstile, which receives your IP address in order to tell a person from a script.
Analytics, and the banner you are not seeing
Navpil sets no analytics or advertising cookies, uses no third-party analytics, and shows no cookie banner. The only things we store on your device are the ones the app needs to work: the token that lets you back into your own split, and — if you sign in — your session. European law lets us store those without asking, because they are the thing you asked for. There is genuinely nothing there to consent to.
What we do record, only if you switch on Analytics in Privacy & data, is first-party product use: a short list of first-time milestones against your account (the first split you host, the first scan, the first purchase), and which screens you open. They carry no advertising identifiers, and screen events are counters without your name on them. Milestones are deleted with your account. The switch is off by default, and with it off nothing is recorded at all. We do not use advertising trackers and we do not share data with ad networks.
Marketing
We will only send you product news if you switch on Marketing in Privacy & data. It is off by default, it is consent, and you can withdraw it in the same place. Transactional email — sign-in links, receipts, reminders you set up — is not marketing and is sent because you asked for the thing it is about.
Who else sees your data
| Who | What they get | Where |
|---|---|---|
| Cloudflare | Hosting, storage, database and logs — everything Navpil holds | EU + United States |
| Google (Vertex AI) | Your receipt photo, while it is being read. Not retained by us | EU region |
| Google, Apple (sign-in) | Your email address and name, if you sign in with them | United States |
| Apple, Google, browser push services | Notification text — names, group labels and amounts you already share. Never an IBAN, email or phone number | United States and your browser vendor |
| RevenueCat | Your Navpil user id, the product you bought and the store transaction id, so your licence works on every device you sign in on. Never card details | United States |
| Paddle | Your purchase on navpil.app. Paddle is the seller in its own right and has its own privacy notice | United Kingdom |
| Cloudflare Email | Delivery of sign-in links, invitations and reminders | EU + United States |
Card details never reach us. We record which product you bought, the amount, the currency and the payment reference, because tax law requires us to keep that. We do not sell your data, and we do not share it with anyone not named above unless the law requires it.
Settlement between you and your friends never passes through us. We show a bank QR code or a payment link and your own bank does the rest. We never hold, pool or move your money.
Where your data goes
We are in Ukraine. When you type a name into a split, upload a receipt or create an account, that information comes to us directly. Under EU data protection law that is not an “international transfer”, because there is nobody in the EU passing it on for you — you sent it to us yourself. Ukraine has no EU adequacy decision, and for this leg it does not need one.
When we pass data on to a company we use, that is a transfer, and each one is covered: Standard Contractual Clauses for Google Cloud and for RevenueCat, and the EU–US Data Privacy Framework with Standard Contractual Clauses as a fallback for Cloudflare. Ask us at privacy@navpil.app and we will send you a copy of any of them.
What is and is not held in the EU. Receipt reading runs in Google's EU region. A live split created on the European payment rail is held in Cloudflare's EU jurisdiction. Other account data — your profile, groups, balances and history — is stored on Cloudflare's global network and is not currently pinned to the EU. We would rather say that plainly than claim a residency we do not yet have end to end.
What we never log
Our logging deliberately strips IBANs, tokens, email addresses and QR payloads from both the names and the values it records. Your account identifier does appear in operational logs so that a request can be traced when something breaks.
Do you have to give us any of this?
Nothing here is required by law. A display name is needed to run a split — without one we cannot tell people apart. Everything else — an email address, an account, a payout IBAN, receipt scanning — is optional, and Navpil works without it.
We do not make automated decisions about you that produce legal effects or similarly significant effects. Reading a receipt extracts text; it does not decide anything about a person.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict how we use it, to object to processing based on legitimate interest, and to receive it in a portable form. Where we rely on consent — receipt archiving, analytics, marketing — you can withdraw it at any time, in Privacy & data, without affecting anything we did lawfully before you withdrew it.
Account holders can do most of this from the profile screen without asking us. Guests can remove themselves from inside the split.
Email privacy@navpil.app and we will reply within one month, which we may extend by two further months for a genuinely complex request — we will tell you if that happens.
You can complain to a supervisory authority. In Ukraine that is the Ukrainian Parliament Commissioner for Human Rights (the Ombudsman). If you are in the EU or EEA you may complain to the data protection authority of the country where you live, where you work, or where you think the problem happened — the list is published by the European Data Protection Board.
Children
Navpil is for people aged 16 and over. It is not directed at children, and we do not knowingly collect data from them. We do not verify age; if you believe a child has given us data, email us and we will remove it.
Changes
If we change how any of this works we will update this page and change the date at the top. If the change is significant, we will tell account holders directly rather than relying on you to re-read it.
← Navpil · Terms · Refunds · Support
Конфіденційність
English · Українська
Navpil має справу з грошима між друзями, а отже — з іменами та сумами. Ця сторінка пояснює, що саме ми збираємо, навіщо, на якій правовій підставі, скільки зберігаємо, хто ще це бачить і як отримати свої дані назад або видалити їх — навіть якщо ви ніколи не створювали акаунт.
Хто відповідальний
Navpil керує Мандзій Юрій Богданович, фізична особа-підприємець, зареєстрований в Україні. Це володілець персональних даних (контролер).
ФОП Мандзій Юрій БогдановичЛьвівська область, Львівський район, м. Львів, 79009, вул. Бальзака, 5, кв. 4, Україна
privacy@navpil.app
Наш представник у Європейському Союзі. Оскільки ми пропонуємо Navpil людям у ЄС та ЄЕЗ, стаття 27 GDPR вимагає призначити там представника. Ми його призначаємо. Доки ми не зможемо назвати його на цій сторінці, людям у ЄС та ЄЕЗ варто звертатися безпосередньо на privacy@navpil.app, і ми відповімо протягом одного місяця. Ми вважаємо за краще сказати вам, що це питання ще не закрите, ніж дати вам виявити це самостійно.
Ми не зобов'язані призначати відповідальну особу з питань захисту даних (DPO) і не призначали її. Питання щодо конфіденційності — privacy@navpil.app.
Якщо вас запросили до поділу рахунку
Вам не потрібен акаунт, і ми не проситимемо його створювати. Коли ви відкриваєте посилання на поділ, ми обробляємо ім'я, яке ви вводите, позиції, які ви обираєте, суму вашого боргу та статус оплати. Ми також зберігаємо токен у вашому браузері, щоб ви могли повернутися до того самого поділу.
Підстава — законний інтерес (ст. 6(1)(f)): провести поділ, заради якого ви й відкрили посилання, а для цього треба розрізняти людей. Ми не просимо згоди, бо згода, яку можна відкликати посеред процесу, означала б вилучення вас із рахунку, який ви справді маєте сплатити, і зламала б арифметику для всіх за столом. Підстава, якої ми не змогли б дотриматися, не була б сильнішим захистом. Ми письмово зафіксували оцінку балансу інтересів і надішлемо її на запит.
Поділ спливає самостійно: через 72 години після створення або через 24 години після розрахунку — залежно від того, що настане раніше. Після цього його вміст видаляється. Нічого про вас не переноситься між поділами, і жодного профілю не будується.
Один виняток варто назвати прямо: якщо той, хто створив поділ, має акаунт, його власний збережений запис — хто брав участь і хто скільки винен — залишається в його історії, доки він не видалить його або свій акаунт.
Ви можете вилучити себе будь-коли, просто в самому поділі, без акаунта й без листа до нас. Ваше ім'я замінюється на «Гість», а суми лишаються, щоб рахунок інших сходився. Це водночас і спосіб заперечити проти обробки за статтею 21.
Якщо ваше ім'я вписав хтось інший, ми отримали його від нього, а не від вас. Той самий інструмент вилучення діє, а відповідальність за введені дані несе той, хто їх вписав.
Якщо у вас є акаунт
Ми обробляємо вашу електронну адресу, ім'я, мову та обраний спосіб входу — passkey, одноразове посилання на пошту, обліковий запис Google або Apple. Ми також зберігаємо ваші поділи, групи, баланси й розрахунки, а також IBAN для виплат, якщо ви його додасте.
Підстава — договір між нами (ст. 6(1)(b)): це і є послуга, про яку ви попросили. Ми зберігаємо ці дані, доки існує ваш акаунт.
IBAN, збережений в акаунті, зашифрований у сховищі (AES-256-GCM). IBAN, введений в один живий поділ, зберігається лише для нього й видаляється разом із ним. Посилання для входу одноразові й спливають за 15 хвилин; сесія триває до 90 днів, і ви можете завершити її, вийшовши з акаунта.
Ви будь-коли й безкоштовно можете завантажити свій акаунт у форматі JSON, а витрати групи — у CSV. Це ваше право за статтею 20, і воно ніколи не за гроші.
Призупинення проти видалення
Призупинити — це вимкнути сповіщення й сховати вас у спільних рахунках. Дані лишаються на місці, і вхід повертає все назад. Видалити — назавжди й одразу: ми стираємо ваш акаунт у базі даних, а ваше ім'я в чужих спільних поділах замінюємо заглушкою, щоб їхні записи сходилися. Періоду очікування немає, прихованого стану немає. Призупинення — це не видалення: якщо ви хочете, щоб даних не було, обирайте «Видалити».
Фотографії чеків
Коли ви скануєте чек, зображення надсилається до Google (Vertex AI), у регіон ЄС, щоб зчитати текст. Ми не зберігаємо зображення — ні на безкоштовному тарифі, ні на платному, ніде. Це свідомо: чек може розповісти те, чого не мав би — рядок з аптеки є медичною інформацією, — а найбезпечніше зберігати ніщо.
Ми можемо зберегти результат розпізнавання — назви позицій і ціни. Це відбувається, лише якщо ви увімкнете Зберігати дані з чека в розділі «Конфіденційність і дані». За замовчуванням вимкнено. Увімкнене — ми зберігаємо позиції 24 місяці; ви можете видалити все одним дотиком, а вимкнення налаштування видаляє їх негайно. Фото не зберігається.
Підстава — ваша згода (ст. 6(1)(a), а також ст. 9(2)(a), якщо чек розкриває особливі категорії даних). Ви можете відкликати її будь-коли — саме це робить перемикач; відкликання не робить попередню обробку незаконною.
Ми також записуємо один рядок на кожне сканування — який акаунт, скільки це коштувало, чи вдалося. У ньому немає ні зображення, ні позицій, ні IBAN.
Запобігання зловживанням
Хмарне сканування коштує нам грошей за кожен скан, тож ми рахуємо безкоштовні сканування на пристрій та на IP-адресу, щоб кілька людей не вичерпали безкоштовний тариф, який існує для всіх. І те, і те зберігається у вигляді хешів, не пов'язується з вашим акаунтом і видаляється приблизно за дві доби. Підстава — законний інтерес.
Вхід і створення поділу захищає Cloudflare Turnstile, який отримує вашу IP-адресу, щоб відрізнити людину від скрипта.
Аналітика і банер, якого ви не бачите
Navpil не встановлює аналітичних чи рекламних cookie, не використовує сторонню аналітику й не показує банер про cookie. На вашому пристрої ми зберігаємо лише те, без чого застосунок не працює: токен, який пускає вас назад у ваш поділ, і — якщо ви увійшли — вашу сесію. Європейське право дозволяє зберігати це без запиту, бо це і є те, про що ви попросили. Погоджуватися справді нема на що.
Що ми записуємо, лише якщо ви увімкнете «Аналітику», — короткий перелік перших подій у вашому акаунті: перший поділ, перше сканування, перша покупка. Кожна фіксується один раз і видаляється разом з акаунтом. Перемикач вимкнено за замовчуванням, і поки він вимкнений, не записується нічого. Рекламних трекерів ми не використовуємо й даних рекламним мережам не передаємо.
Маркетинг
Новини про продукт ми надсилаємо, лише якщо ви увімкнете «Маркетинг». За замовчуванням вимкнено, це згода, і відкликати її можна там само. Службові листи — посилання для входу, підтвердження, нагадування, які ви налаштували, — це не маркетинг.
Хто ще бачить ваші дані
| Хто | Що отримує | Де |
|---|---|---|
| Cloudflare | Хостинг, сховище, база даних і журнали — усе, що тримає Navpil | ЄС + США |
| Google (Vertex AI) | Фото чека на час розпізнавання. Ми його не зберігаємо | Регіон ЄС |
| Google, Apple (вхід) | Ваша пошта та ім'я, якщо входите через них | США |
| Apple, Google, служби push | Текст сповіщення — імена, назви груп і суми, якими ви й так ділитеся. Ніколи IBAN, пошта чи телефон | США та виробник вашого браузера |
| RevenueCat | Ваш ідентифікатор у Navpil, куплений продукт і номер транзакції магазину, щоб ліцензія працювала на всіх ваших пристроях. Ніколи дані картки | США |
| Paddle | Ваша покупка на navpil.app. Paddle є продавцем самостійно й має власну політику | Велика Британія |
| Cloudflare Email | Доставка посилань для входу, запрошень і нагадувань | ЄС + США |
Дані картки до нас не потрапляють. Ми записуємо, який продукт куплено, суму, валюту й платіжне посилання, бо цього вимагає податкове законодавство. Ми не продаємо ваші дані й не передаємо їх нікому, крім названих вище, якщо цього не вимагає закон.
Розрахунок між вами та друзями ніколи не проходить через нас. Ми показуємо банківський QR-код або посилання, а далі працює ваш банк. Ми ніколи не тримаємо, не акумулюємо й не переказуємо ваші кошти.
Куди рухаються ваші дані
Ми в Україні. Коли ви вводите ім'я в поділ, завантажуєте чек або створюєте акаунт, ця інформація надходить до нас напряму. За правом ЄС це не «міжнародна передача», бо немає нікого в ЄС, хто передавав би її за вас — ви надіслали її нам самі. В України немає рішення ЄС про адекватність, і для цього етапу воно не потрібне.
Коли ми передаємо дані компанії, послугами якої користуємось, це вже передача, і кожну з них покрито: Стандартні договірні положення для Google Cloud і RevenueCat та Data Privacy Framework ЄС–США зі Стандартними договірними положеннями як запасним варіантом для Cloudflare. Напишіть на privacy@navpil.app — надішлемо копію.
Що зберігається в ЄС, а що ні. Розпізнавання чеків працює в регіоні ЄС Google. Живий поділ, створений на європейській платіжній рейці, тримається в юрисдикції ЄС Cloudflare. Інші дані акаунта — профіль, групи, баланси, історія — зберігаються в глобальній мережі Cloudflare і наразі не прив'язані до ЄС. Ми краще скажемо це прямо, ніж заявимо про резидентність, якої ще не маємо наскрізь.
Чого ми ніколи не записуємо в журнали
Наше журналювання свідомо вирізає IBAN, токени, електронні адреси та вміст QR — і з назв полів, і зі значень. Ідентифікатор вашого акаунта в технічних журналах присутній, щоб можна було простежити запит, коли щось ламається.
Чи зобов'язані ви щось із цього надавати?
Нічого з цього не вимагає закон. Ім'я потрібне, щоб провести поділ — без нього ми не розрізнимо людей. Усе інше — пошта, акаунт, IBAN, сканування чеків — необов'язкове, і Navpil працює без цього.
Ми не ухвалюємо автоматизованих рішень щодо вас, які мали б юридичні чи подібні істотні наслідки. Розпізнавання чека витягує текст, а не вирішує щось про людину.
Ваші права
Ви можете запитати копію своїх даних, виправити їх, видалити, обмежити обробку, заперечити проти обробки на підставі законного інтересу та отримати дані в машинозчитуваному форматі. Там, де підставою є згода — зберігання чеків, аналітика, маркетинг, — ви можете відкликати її будь-коли в розділі «Конфіденційність і дані», і це не вплине на законність того, що ми зробили раніше.
Власники акаунтів роблять більшість цього самостійно в профілі. Гості вилучають себе прямо в поділі.
Напишіть на privacy@navpil.app — ми відповімо протягом одного місяця, який можемо подовжити ще на два для справді складного запиту, попередивши вас.
Ви можете подати скаргу до наглядового органу. В Україні це Уповноважений Верховної Ради України з прав людини. Якщо ви в ЄС або ЄЕЗ — до органу захисту даних країни, де живете, працюєте або де, на вашу думку, сталося порушення.
Діти
Navpil призначений для людей від 16 років. Він не адресований дітям, і ми свідомо не збираємо їхніх даних. Вік ми не перевіряємо; якщо ви вважаєте, що дитина надала нам дані, напишіть — ми їх видалимо.
Зміни
Якщо щось із цього зміниться, ми оновимо сторінку й дату вгорі. Якщо зміна суттєва, ми повідомимо власників акаунтів напряму, а не покладатимемось на те, що ви перечитаєте сторінку.
← Navpil · Умови · Повернення · Підтримка