Legal
Privacy
Last updated . This page is written in plain English so you can actually read it. It describes what the app does with your information — it is not legal advice.
The Bachledger is a small tool for planning a party and splitting its costs. It has no ads, no trackers sold to anyone, and no business model that depends on your data: guests use it free, and the host who creates a party pays for a plan. The short version: what you type into a party is visible to the people in that party, your own budget and personal expenses are visible only to you, and receipt photos are read once by an AI service so you do not have to type the line items.
What we collect
- Your account. An email address, or a Google sign-in, plus the display name and avatar you choose. Sign-in is handled by Firebase Authentication; passwords are never stored by us.
- What you type into your parties. Party and event names, dates, places, notes, costs, RSVPs, deposits, expenses, budgets, settle-up records, and the trip details a host fills in.
- Receipt photos you upload. The image itself and the amounts read from it.
- Host plan billing. If you subscribe as a host, the payment page and the billing portal are Stripe’s: your card details go to Stripe and never reach us. We keep only what we need to know whether your plan is active — your Stripe customer id, the subscription and plan, its status, the renewal or trial-end date, and whether it is set to cancel.
- Basic technical data. Google Firebase records the usual server-side information needed to run a service of this kind — the device and browser type, IP address, and error logs.
There is no advertising SDK, no analytics profile sold onward, and no contact list, photo library, or location access beyond the single photo you pick when you scan a receipt.
How it is used
To run the app and do the arithmetic: show your parties, keep RSVPs and costs in sync between everyone, split each event, convert between currencies at the rate the host entered, and work out who owes whom. We also use it to fix things that break — an error report tells us a screen failed, not what your weekend cost.
Who can see what
- Members of a party see that party: its events, costs, shared expenses, RSVPs, the guest list, and settle-up balances.
- Hosts and co-hosts additionally manage events, costs, the guest list, and the trip details they wrote.
- Only you see your personal ledger: your budget and the expenses you mark personal. Other members never see those numbers, and neither does anyone else in a different party.
- Nobody outside the party can open it. Party data is not public and is not indexed by search engines. These rules are enforced on the server by Firebase Security Rules, not just in the app.
Receipt photos and AI
When you scan a receipt, the photo is stored in the party’s private Firebase Storage folder and sent once to OpenAI’s API, which reads the merchant, the line items, the tax and the tip and sends them back as text. Under OpenAI’s API terms, content sent through the API is not used to train their models. The photo stays visible to your party so someone can check the bill, and you can delete it at any time — deleting the photo keeps the amounts you already entered.
Please do not photograph anything you would not want the rest of the party to see.
Third parties
- Google Firebase (Authentication, Firestore, Storage, Hosting) stores the data and authenticates you.
- OpenAI reads receipt photos you choose to scan, as described above.
- Stripe processes host plan payments and stores the card; it receives your email address and account id so it can match the subscription to you.
That is the whole list. Your information is never sold, rented, or traded, to anyone, for any purpose.
No ads, no selling data
There are no advertisements in the app and no plans for any. Nothing about you or your party is packaged up for advertisers, data brokers, or anyone else. If that ever changes, it will be announced here first and it will not apply retroactively to trips already in the app.
Keeping and deleting your data
Your parties stay until someone removes them, because people come back to a ledger months later to settle up. You can delete a receipt photo from the expense it belongs to. A host can delete an entire party, which removes its events, expenses and balances for everyone. You can leave a party you were invited to. To have your account and everything attached to it deleted, ask through the feedback link inside the app and it will be done; some backup copies may persist for a short period before they expire.
Security
Traffic is encrypted in transit, data is stored in Google Cloud, and access is enforced by security rules that check party membership on every read and write. No system is perfect, so use a strong password (or Google sign-in), and do not put card numbers, passport details, or door codes you would not share with the group into a party.
Children
The app is intended for adults — 18 or older. It is not directed at children and we do not knowingly collect information from them.
Changes to this page
When something material changes, the date at the top changes with it and the new version is posted here. Continuing to use the app after that means the updated page applies.
Contact
Questions, corrections, or a deletion request: use the feedback link inside the app. It reaches the same small team that builds it. There is no support email address to publish yet, and inventing one would be worse than saying so.
See also the terms of use.