Back OweMe

OweMe Privacy Policy

Last updated: 23 August 2026 Applies to: the OweMe Android app, owemeapp.com, and the OweMe service.

⚠️ Not legal advice. Every claim below was checked against the source and describes what the software does today. That makes it accurate, not lawful — have it reviewed for Albania, for the EU/UK, and for the United States, which are the three regimes §8 answers to.

The section most easily made false by a later change is §4, "What we do not collect". Re-read it whenever a dependency is added — and see non-negotiable #6 in the root README.md before changing anything about what leaves the device.


1. Who is responsible for your data

OweMe is run by Enkel Xhelollari, an individual sole trader established in Albania. There is no company and no data protection officer; neither is required at this size.

Contact for any privacy question or request: owemeapp@gmail.com. A person reads it.

Which law applies to you

OweMe is run from Albania and is used from everywhere, so more than one privacy law can reach the same account, and which one reaches yours depends on where you are rather than on where we are.

Rather than sort you into a regime and give you only what it demands, the rights in §8.1 are given to every user, wherever they live. §8.2 and §8.3 then add what a particular law obliges us to spell out — the GDPR and UK GDPR for readers in Europe, and the state privacy laws for readers in the United States. Nothing in §8.2 or §8.3 takes anything away from §8.1.


2. What OweMe is

OweMe records who owes whom within a group of people, and works out who could pay whom to settle up in the fewest transfers. It never moves, holds, or processes money. It has no connection to your bank, no payment rail, and no ability to transfer funds. A "settlement" in OweMe is a note that a payment happened somewhere else.

This matters for your privacy because it means OweMe never sees a bank account, a card number, or a transaction from your bank. There is nowhere for one to go.

In short

The rest of this document is long because it is specific. If you read nothing else, these are the three answers people actually want:

What we hold. Your email address, your display name, a password we store only as a hash and cannot read, and the ledger you record — expenses, amounts, currencies, dates, categories, notes, settlements, and the names of the people you split with. Plus a device record if you use offline mode, and a receipt of any Play purchase. That is the whole of it, and §3 breaks it down field by field. No location, no analytics, no advertising, no tracking, no special-category data — §4.

You can take it with you, whenever you like, without asking us. Profile → Privacy & terms → Download a copy of my data gives you everything we hold as a JSON file. Any group exports as CSV from Group settings → Export as CSV, including entries the free plan hides — a window that stopped you taking your own data would make this promise a lie. Both are immediate, free, and need no request. §8.1.

You can delete your account yourself, in the app or on the web, and it takes effect at once rather than becoming a request somebody has to action. What is erased and what survives — and why some of it must — is set out in full in §7, in plain terms, because "we delete everything" would not be true.


3. What we collect, and why

3.1 Your account

Data Why Legal basis (GDPR Art. 6)
Email address Signing in; account recovery; nothing else Contract — 6(1)(b)
Display name So other members of your groups can see who you are Contract — 6(1)(b)
Password Stored only as an argon2id hash. We cannot read it Contract — 6(1)(b)
Account timestamps (created, last seen) Security, and answering "was this account active?" Legitimate interests — 6(1)(f)
Whether your email is verified So a reset code cannot be sent to an address you never proved you own Contract — 6(1)(b)

We do not ask for your real name, address, phone number, or date of birth.

Verification and reset codes. Confirming your email and resetting a forgotten password both work by a short code sent to your address. The code is short-lived and stored hashed; the email itself goes through our mail provider (§5) and contains the code, your display name, and nothing else.

A forgotten password can only be reset from a confirmed address. If nobody has ever proved they can read the address on an account, we will not send a reset code to it — an unconfirmed address is not evidence of who owns the account, and a mistyped one belongs to a stranger. Confirming takes one code, from Profile in the app, and nothing else in OweMe depends on it. If you cannot sign in and cannot confirm, write to the address in §12 and a person will help you.

3.2 What you record in the app

The ledger itself: groups, the people in them, expense descriptions, amounts, currencies, dates, categories, notes, settlements, and any recurring schedules you set up.

Some of this is personal data about other people — the names of those you split with. If you add somebody by name who has no OweMe account, you are providing their name to us on your own initiative. Please only add names those people would be comfortable with; a first name or nickname is enough for the app to work.

Invites. An invite link or QR code contains a random token, nothing about you and nothing about the person you send it to. We store only a hash of it, so a copy of our database hands out no group access. Tokens expire, can be revoked, and only ever grant access to the one group they were made for.

Friends is not a stored list. It is worked out from the groups you share with somebody, so there is no social graph here to leak.

Legal basis: contract — 6(1)(b). This is the service.

3.3 Your devices

If you use offline mode, we store: platform (Android), an app install identifier, app and OS version, and a sync position. This is what lets one device know what another has already seen. Up to five devices at a time.

Legal basis: contract — 6(1)(b).

3.4 Purchases

If you buy a subscription or a premium group, we store a record of it: the Play product bought, its state, order identifiers, and a hash of the Play purchase token — never the token itself. We also store a one-way, salted identifier derived from your user id which we give Google so that a purchase can be matched to your account. It is meaningless to anyone but us and cannot be reversed into your email or name.

We never see your card, your Google account email, or your billing address. Google handles the payment entirely; we only ever ask them "was this purchase real, and is it still valid?"

If you redeem a coupon we store which coupon, and when.

Legal basis: contract — 6(1)(b); and legitimate interests — 6(1)(f) — for detecting fraudulent or replayed purchases.

3.5 The website

owemeapp.com sets no cookies, runs no analytics, and loads nothing from another company — no fonts, no scripts, no images from a CDN. If you give it your email address to be told about the launch, we store that address, the date, and the country Cloudflare already attached to the request. Nothing else: not your IP, not your browser. That list exists to send one email.

Legal basis: consent — 6(1)(a). Reply to that email and we delete the address.


4. What we do not collect

This section is unusually specific because it is the useful part.

The app requests exactly two Android permissions: internet, and camera — the second only at the moment you first tap "Scan receipt", and you can decline it and pick a photo instead.

No special-category data, and no profiling

GDPR Article 9 singles out categories that carry extra protection: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify you, data concerning health, and data about sex life or sexual orientation. Article 10 adds criminal convictions and offences.

We do not ask for any of them. There is no field for any of them anywhere in OweMe. We do not buy them, infer them, or derive them, and nothing in the app analyses what you record in order to work anything out about you.

There is one honest exception, and it is worth stating plainly rather than leaving you to discover it:

If you would rather we did not hold something, do not put it in a description — "lunch" works as well as any detail. That is the only mitigation that is genuinely in your hands, which is why we are telling you about it.

Why the risk here is low

Not a legal conclusion, just the shape of the thing. OweMe holds who owes whom and nothing that unlocks anything:

Receipt scanning is on your device

If you photograph a receipt, the image is read on your phone, using the text recognition built into Android. The photo is never uploaded, and neither is the text. Only the numbers you accept become an expense. Scanning works with no internet connection at all, which is the simplest proof that nothing leaves the device.


5. Who we share it with

We do not sell your data. We do not share it for advertising. There is no third-party analytics processor.

Who What they get Why
Google Play Billing (Google, US/IE) Your purchase, and the one-way account identifier from §3.4 To take payment and tell us whether a purchase is valid
Render (US) Hosts the API container. Sees data in transit and in memory Running the service
Neon (US/EU) Hosts the PostgreSQL database. Holds everything in §3.1–3.4 Storing the ledger
Cloudflare (US) DNS, TLS, and the website. Sees request metadata Serving owemeapp.com, and TLS for the API
Resend (US), or Brevo (EU/FR) Your email address and the code being sent Delivering verification and password-reset codes

That is the complete list. Nobody else receives your data.

Several of these are in the United States, so using OweMe involves a transfer outside the EEA. §8.2 names the mechanism each one relies on. It is written out once, there, rather than twice — two copies of a transfer clause are two things to keep in step, and the one that goes stale is the one nobody reads.

We will disclose data if legally compelled — a court order or equivalent — and will tell you unless we are prohibited from doing so.


6. How long we keep it


7. Deleting your account

Two of these you do yourself, and they take effect at once rather than becoming a request somebody has to action. The second exists because Google Play has required since 2023 that deletion be possible without the app installed.

Take your data first if you want a copy. Deletion is immediate and there is nothing left to export afterwards — see §8.1, which is one tap and needs no request.

Here is exactly what happens, because "we delete everything" would be untrue:

Erased immediately

Kept, and no longer linked to you

Expenses, settlements and balances in groups you shared with other people. Your seat in those groups is severed from your account and left as a ghost member labelled "Former member" — every name that seat carried is overwritten, including any nickname a member of that group had given you. The rows that remain say what was spent and what it settles; they do not say who you were.

Why: those rows are other people's financial records too. A balance reading "owes €40" with the name removed is unusable to the people still in that group, and they have a legitimate interest in the record of a debt they were part of. GDPR Art. 17(3) recognises this limit on erasure. Nothing that remains identifies you or can be traced back to your account.

Kept because the law requires it

If you ever bought a subscription or a premium group, the record of that purchase survives deletion: which product, when, and its state. Albanian accounting law requires the underlying records to be kept for 10 years and §6 says so, so it is repeated here rather than left for you to find. It is a receipt, not a profile — it carries no card, no bank detail and no billing address, because Google never gives us one (§3.4).

What none of it amounts to

After deletion there is no way to sign in, no address to write to you at, and nothing left that names you. What survives is somebody else's ledger and a receipt an auditor may ask for.


8. Your rights

Every right below is available to every user, wherever you live, and whichever of these laws does or does not technically bind us. Sorting people by postcode and giving each the statutory minimum would cost more to build than giving everybody the same thing.

How to use them. Most are self-service and instant, in the app: correcting anything, exporting everything, deleting the account. For the rest, email owemeapp@gmail.com. We answer within 30 days, and if a request is genuinely complicated we will say so and take at most 60. It is free; we will not charge you for asking, and asking will never get your account degraded, delayed or closed.

How we check it is you. Nearly always, by your own credentials — you are signed in, or you write from the address on the account. We deliberately do not ask for a document proving identity: collecting a passport scan to answer a privacy request would mean holding far more about you than the request is about. If we cannot satisfy ourselves that a request is yours, we will say so rather than guess, because the alternative is handing your ledger to somebody else. You may use an authorised agent; we will ask for your written permission and still verify you directly.

8.1 Everyone

8.2 The EU and EEA, the UK, and Switzerland

Under the GDPR, the UK GDPR and the Swiss revFADP, in addition to §8.1:

Two limits are worth stating rather than discovering:

8.3 The United States

California's CCPA/CPRA, and the comprehensive privacy laws now in force in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and a growing number of other states, give consumers a broadly similar set of rights.

We almost certainly fall below the thresholds that make those laws binding on us — the CCPA, for instance, applies to businesses over $25m in revenue, or handling 100,000 consumers, or making half their money selling personal information, and OweMe is one person's project that sells none. We are telling you the rights anyway, and honouring them, because a threshold is a reason a regulator cannot make us and not a reason you should get less.

Beyond §8.1, these laws ask for four things to be said explicitly.

1. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. Not now, and not in the preceding twelve months — including for consumers we know to be under 16, whom the CCPA protects specifically. There is no advertising business here to sell into: no ad SDK, no ad identifier, no analytics processor of any kind (§4). Because there is nothing to opt out of, there is deliberately no "Do Not Sell or Share My Personal Information" link; a link to an opt-out from something we do not do would imply we do it.

2. What we collect, in the categories the statute uses. Sources and purposes are in §3, retention in §6, and the recipients in §5 — this is the same information arranged the way the CCPA asks for it.

CCPA category Collected What, exactly
A. Identifiers Yes Email address, display name, an app install identifier, a salted hash of your IP in security logs
B. Customer records (Cal. Civ. §1798.80) Yes Which Play product you bought and whether it is live. No card, no bank detail, no billing address — Google never gives us one
C. Protected classifications No We never ask your age, sex, race, religion or anything like them
D. Commercial information Yes Your purchase and coupon history, and the ledger you record — expenses, amounts, categories, settlements
E. Biometric information No
F. Internet or network activity No No analytics, no browsing history, no record of which screens you open
G. Geolocation data No Never, in the app. The launch-list form keeps only the country Cloudflare already attached to the request (§3.5)
H. Audio, visual or similar No A receipt photo is read on your phone and never uploaded (§4)
I. Professional or employment information No
J. Education information No
K. Inferences No We build no profile of you and infer no characteristics
Sensitive personal information Yes Your account log-in credentials — an email address and a password we hold only as an argon2id hash

3. Sensitive personal information, and why there is no "limit" link. The CCPA counts account credentials as sensitive. We use yours to sign you in and for nothing else — never to infer a characteristic about you — which is the use §1798.121(d) exempts from the right to limit. So there is no "Limit the Use of My Sensitive Personal Information" control, because there is no other use to limit it to.

4. Appeals. If we refuse a request, we will tell you why, and you may appeal by replying to that refusal. A different reading by the same person is not much of an appeal at this size, and we will not pretend otherwise — so we will also tell you how to take it to your state Attorney General, which is the route Virginia, Colorado, Connecticut, Texas and the others provide. Colorado and Connecticut residents may also use the universal opt-out mechanisms those states recognise; there is nothing for them to switch off here, and a signal that arrives will be honoured all the same.

California "Shine the Light" (Cal. Civ. Code §1798.83): we disclose no personal information to third parties for their own direct-marketing purposes.

No financial incentive. We offer nothing in exchange for your data, so there is no incentive programme to disclose.

8.4 Everywhere else

Canada's PIPEDA, Brazil's LGPD, Australia's Privacy Act and the others all ask for some version of access, correction, deletion and an explanation. §8.1 is that, for everyone, and the contact in §12 is the way to use it. If your law gives you something §8.1 does not, ask — we would rather extend the list than argue about jurisdiction.


9. How we protect it

No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your rights we will notify the supervisory authority within 72 hours and tell you where required.


10. Children

OweMe is not directed at children, and the Terms require you to be at least 16 anywhere in the world. That is deliberately the stricter of the two thresholds we could have picked: the GDPR lets a member state set the digital- consent age as low as 13, and the US COPPA rule covers under-13s. One number that satisfies both is easier to honour than a map.

We do not knowingly collect data from anyone under 16, and we do not ask your age — asking would mean collecting a date of birth from everybody to catch the few, which is more data held, not less. If you believe a child has an account, write to owemeapp@gmail.com and we will delete it and everything on it. A parent or guardian may make that request; we will not require the child's password to act on it.


11. Changes

We will update the date at the top and, for anything that materially changes what we collect or who we share it with, tell you in the app before it takes effect.


12. Contact

Enkel Xhelollariowemeapp@gmail.com