Privacy policy
SwipeSplit is built by Tiny Mammoth. This page explains what SwipeSplit handles when you use it, in plain language. The short version: receipt photos are read once and never stored, tables delete themselves after 24 hours, and accounts are optional.
Tables
When someone starts a split, SwipeSplit creates a table: the restaurant name, the line items and amounts, the display names people type in, who claimed what, and any pay handles the host adds. Tables live in our database for 24 hours and are then deleted. Each table is reachable only through its unguessable link, and the tokens that prove who the host and each guest are stored hashed, so nobody at Tiny Mammoth can use them to act as you.
Receipt photos
When you tap Scan a receipt, your photo is sent once, over an encrypted connection, to our server, which passes it to Anthropic's API to read the text. We do not save the photo, and it is not kept after the read. Anthropic processes it under its commercial API terms and does not use it to train its models. If the AI reader is unavailable, SwipeSplit falls back to reading the receipt on your own phone, and in that case the photo never leaves your device.
Accounts (optional)
You never need an account to start or join a table. If you sign in with Apple or Google, we store the sign-in provider's user id, the email address it shares with us (Apple may give us a private relay address), the display name you choose, and the pay handles you save so they follow you between devices. A sign-in cookie keeps you signed in on that browser. You can delete your account at any time from Settings, and everything above is removed immediately.
Pay-back links
Pay handles open Venmo, Cash App, Zelle, or Apple Cash on your phone. No money moves through SwipeSplit, and we never see your payment details. Those apps' own privacy policies apply once you are in them.
What stays on your phone
SwipeSplit uses your browser's local storage to remember your display name, your pay handles, and whether you have seen the swipe hint. That data stays on your device and is not sent to us until you put it into a table.
What we don't do
We do not run advertising or analytics trackers, we do not sell or share personal information, and we do not build profiles. When a table is created we record where the visit came from (the referring website's domain, or a tag like ?ref=oji on a table-tent QR code) so we can tell which restaurants and posts are working. That record contains no personal information.
Service providers
SwipeSplit runs on Cloudflare, which serves the site, stores tables, and sees the connection details (such as your IP address) that any website host sees, for security and performance. Anthropic reads receipt photos as described above. Feedback you send from the Send feedback link, along with the page you sent it from, goes to Tiny Mammoth's internal tools.
Children
SwipeSplit is not directed at children under 13, and we do not knowingly collect information from them.
Security
Everything travels over HTTPS. Host and guest tokens are stored hashed. Tables expire after 24 hours. No system is perfectly secure, so please do not put anything in a table that you would not want the other people at that table to see.
Your choices
Delete your account from Settings at any time. For anything else, including a copy of what we hold about you, email support@tiny-mammoth.com. If you are a California resident: we do not sell personal information, and the rights above apply to you.
Changes
If this policy changes in a way that matters, we will note it on the What's new page. The date at the top tells you when it was last updated.
Contact
Tiny Mammoth · support@tiny-mammoth.com
See also the terms of service.