Privacy policy
How Open Splitwise handles your Splitwise account data on this instance.
OAuth access token
When you connect Splitwise, this app stores your OAuth access token in an encrypted server-side session cookie (iron-session). The cookie is httpOnly, so it is not exposed to browser JavaScript. The token is used only on the server to call the Splitwise API on your behalf.
Cached Splitwise data
If a database is configured, the app syncs and caches Splitwise data in PostgreSQL—for example expenses, groups, friends, and related metadata needed for explore and insights. This is a local copy to power search and analytics; it is not sent to third parties beyond your Splitwise API requests.
Optional AI features (BYOK)
If you enable AI in Settings, you can store an API key encrypted in the local database. Supported providers include OpenAI, OpenRouter, Google Gemini, and Anthropic Claude (or a custom OpenAI-compatible endpoint). The key is used only on this server when you use smart filters, category review, or narrative insights. Smart filters send filter catalogs (group, friend, and category names) and your query. Category review sends expense descriptions and notes for loaded rows when you turn it on. Narrative insights send spending aggregates — not individual expense rows or your Splitwise OAuth token.
Retention
Your session token is kept until you disconnect. Synced Postgres data is kept until you explicitly delete it — disconnecting does not remove cached expenses or metadata.
Disconnect vs delete synced data
Disconnect in Settings only ends your session (the OAuth token is removed from the cookie). Your synced database rows remain so you can reconnect and continue where you left off.
Delete synced data (Privacy & data section, while connected) removes all cached rows for your Splitwise account from PostgreSQL. Your session stays active unless you also disconnect.
Open Splitwise is not affiliated with Splitwise. Settle up and manage groups in the official app.