We are the developers of TabMates, an app for splitting shared expenses with
friends, flatmates and travel groups. This policy explains what personal data the
app handles, why, and what choices you have. Sections 12 and 13 cover this
website (tabmates.de) and the web app (app.tabmates.de) specifically.
Unlike a purely offline app, TabMates uses a backend server so that the people in a group can share groups and expenses and stay in sync across their devices. That means some of the data you enter is sent to and stored on the TabMates server. This policy describes exactly what that involves.
1. Information We Collect
We only collect what is needed to run the app. We do not collect data for advertising, profiling, or sale.
Account data
- Email address — for registered accounts only. It is used to sign you in, verify your account, and recover your password.
- Username — the display name shown to other members of your groups.
- Password — stored on the server only in hashed and salted form. We never store or have access to your password in plain text.
- Account type and status — whether your account is a registered or guest account, your email-verification status, and an internal user ID.
If you choose to continue as a guest (an anonymous account), you provide only a username — no email address is collected.
Content you create
- Groups — group names, optional descriptions, group membership, and invite links/tokens you create or use to join.
- Expenses — the expenses, income and settlements you record: titles, descriptions, amounts, currencies, who paid, how each entry is split between members, and the related timestamps.
This content is, by design, shared with the other members of the groups you belong to, because that is the purpose of the app.
Device and technical data
- Push-notification token — a Firebase Cloud Messaging (FCM) token used to deliver notifications to your device.
- Device platform (e.g. Android, iOS, Desktop, Web), app language/locale, and app version — used to deliver localized notifications and to check whether an update is available.
- Server logs — standard request information (such as IP address and request metadata) that any web server records in order to operate the service securely.
2. How We Use Your Information
We use the data above only to:
- Provide the core service — create and sync your groups and expenses, calculate balances and who owes whom, and deliver real-time updates between members.
- Authenticate you and keep your account secure.
- Send you transactional emails — account verification and password reset. These are not marketing emails.
- Deliver push notifications about activity in your groups.
- Check whether a newer version of the app is available.
- Keep the service secure, prevent abuse, and diagnose problems.
We do not use your data for advertising, we do not build profiles about you, and we do not sell or rent your data to anyone.
3. Legal Bases for Processing (GDPR)
If you are in the European Economic Area, we process your data on these legal bases:
- Performance of a contract — operating your account and providing the expense-sharing service you asked for.
- Legitimate interests — keeping the service secure, preventing abuse, and maintaining and improving reliability.
- Consent — for push notifications, where your device (e.g. Android 13+ and iOS) asks for your permission. You can withdraw this at any time in your device settings.
4. Third-Party Services
The app itself does not include analytics, crash reporting, advertising, or third-party sign-in. To operate, the service relies on a small number of providers (“sub-processors”):
- Firebase Cloud Messaging (Google) — delivers push notifications. Google receives your device push token and the notification payload. Firebase Analytics is explicitly disabled in the app. In the web app, the Firebase code itself is also loaded from Google’s servers on every page load; see Section 13. See Google’s privacy policy.
- Infomaniak — email delivery provider that sends transactional emails (verification and password reset). The provider receives the recipient email address and message content needed to deliver the email. Infomaniak is based in Switzerland. See Infomaniak’s privacy policy.
- Cloudflare — the web app uses Turnstile, an invisible bot check, on the sign-up, sign-in and password-reset screens. Cloudflare receives your IP address, user agent and technical browser signals in order to tell real people from automated abuse. This applies to the web app only; see Section 13. See Cloudflare’s privacy policy.
- Hosting — the TabMates backend, where your account and your groups and expenses are stored, runs on first-party servers located in the European Union (Germany). The web app and this website are separate: they are static program and page files served by GitHub Pages, and no account data passes through them. See Sections 12 and 13.
- App stores / Google Play in-app updates — if you installed the app from Google Play or another store, that store collects data such as your account info and download history under its own privacy policy. On Android, the in-app update feature queries Google Play for the latest version. See Google Play.
- GitHub — if you interact with the project’s source code or issues on GitHub, GitHub’s own privacy practices apply to your activity there. GitHub also hosts this website and the web app; see Sections 12 and 13.
5. Data Storage and Security
- In transit: all communication with the server uses encrypted HTTPS/WSS connections.
- On your device: authentication tokens are kept in the operating system’s secure storage (Android Keystore / iOS Keychain). Your groups and expenses are also cached locally so the app works offline.
- In the browser: the web app has no operating-system keystore available to it, so it keeps your session in encrypted browser storage instead, and your offline copy of your groups and expenses in a local browser database. Section 13 describes exactly what is stored and how to clear it.
- On the server: your data is stored on servers in the EU; passwords are stored hashed and salted.
- We recommend enabling your device’s built-in lock screen (PIN, fingerprint or face unlock) to protect the data cached on your device.
6. Data Retention and Deletion
- Your account and the content you create are kept for as long as your account is active.
- Uninstalling the app removes the local cache from your device, but it does not delete your data from the server.
- You can delete your account yourself, at any time, under Profile → Delete
account — in the app or in the web app at
app.tabmates.de. The account and the personal data listed above are deleted immediately. Step-by-step instructions are on the account deletion page. - Encrypted backups are purged within 90 days.
- Note that expenses you added to a shared group are retained or anonymized, so that the remaining members keep a consistent record of their shared spending.
- Where we are legally required to keep certain records, we retain them for the legally mandated period and delete them afterwards.
7. Your Rights (GDPR)
Depending on your location, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data (you can edit much of it directly in the app).
- Erase your data (“right to be forgotten”).
- Port your data to another service.
- Restrict or object to certain processing.
- Lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, contact us via the channel in Section 11.
8. Children’s Privacy
TabMates is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided personal data, please contact us so we can delete it.
9. International Users
The TabMates backend is hosted in the European Union (Germany), and your account, groups and expenses are stored there. If you use the app from outside the EU, that data is still processed on these EU servers.
Some of the providers listed in Section 4 are based outside the EU. Transfers to Google (Firebase Cloud Messaging) and Cloudflare (Turnstile) in the United States, and to GitHub, Inc. as the host of the web app and this website, take place on the basis of the EU–US Data Privacy Framework and, where applicable, the European Commission’s Standard Contractual Clauses (Art. 45 and Art. 46 GDPR). Infomaniak is based in Switzerland, for which the European Commission has issued an adequacy decision.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected here with an updated “Last Updated” date. We recommend checking this policy periodically within the app or on the official project repository.
11. Contact
If you have any questions about this policy or want to exercise your privacy rights, you can reach out via the official GitHub repository: github.com/TabMates/app. Postal contact details are listed in the imprint.
12. This Website
This section applies to tabmates.de, the promotional website you are reading
now. It is a separate thing from the TabMates app and from the web app at
app.tabmates.de — the web app is covered in Section 13, and its privacy
profile is not the same as this site’s.
- No cookies. This site sets no cookies of any kind. The only thing stored in
your browser is your light/dark theme preference, held in
localStorageon your own device and never transmitted anywhere. - No analytics and no third-party requests. There are no analytics scripts, tag managers, advertising pixels or embedded third-party widgets. Fonts and all other assets are served from this domain, so loading a page contacts no server other than the one hosting it.
- Hosting and server logs. The site is a set of static files hosted by GitHub Pages (GitHub, Inc.). As the hosting provider, GitHub processes standard server-log data — including your IP address, the requested page, and your user agent — in order to deliver the site and protect it from abuse. This is necessary for operating the website (Art. 6(1)(f) GDPR, legitimate interest in a secure and functional site). See the GitHub Privacy Statement.
- Outbound links. Links to the web app, Google Play, and GitHub take you to services with their own privacy policies, as described in Section 4.
13. The Web App
This section applies to the browser version of TabMates at app.tabmates.de,
which you can also install as an app on your device. It is the same TabMates
service as the mobile app — Sections 1 to 11 apply to it in full — but running in
a browser involves a few things the mobile app does not.
Hosting. The web app is a set of static files — the program itself — hosted by GitHub Pages (GitHub, Inc.). As the hosting provider, GitHub processes standard server-log data, including your IP address, the requested file, and your user agent, in order to deliver those files and protect the service from abuse (Art. 6(1)(f) GDPR, legitimate interest in a secure and functional service). See the GitHub Privacy Statement.
Only the program is served this way. Your account, groups and expenses do not pass through GitHub. Once the web app has loaded, it talks directly to the TabMates backend in Germany over encrypted HTTPS and WSS connections, exactly as the mobile app does.
Third-party requests. Unlike the promotional site at tabmates.de, the web
app does contact a small number of third parties in order to work:
- Google (
www.gstatic.com) — the web app loads the Firebase JavaScript code from Google’s servers on every page load, so that push notifications are available. Google receives your IP address and user agent as part of that request. Firebase’s automatic data collection is explicitly switched off. - Firebase Cloud Messaging (Google) — if, and only if, you turn notifications
on, that code contacts
firebaseinstallations.googleapis.comandfcmregistrations.googleapis.comto create a browser installation identifier and a web push token. This is the browser equivalent of the push token described in Section 1. - Cloudflare Turnstile (
challenges.cloudflare.com) — an invisible bot check on the sign-up, sign-in and password-reset screens. Cloudflare receives your IP address, user agent and technical browser signals in order to tell real people from automated abuse of those screens (Art. 6(1)(f) GDPR, legitimate interest in protecting accounts). Turnstile is a bot check, not analytics or advertising, and is not used to track you across websites.
There are no analytics scripts, tag managers, advertising pixels or third-party sign-in providers in the web app.
What the web app stores in your browser. The web app sets no cookies. Everything below is stored on your own device, is needed for the app to work, and is not transmitted anywhere except as already described in this policy:
- Your session — your email address, username, user ID and login tokens, held
encrypted in
localStorageso that you stay signed in between visits. - Your settings — theme, language, notification preference, and markers
recording how far your device has synchronised, held in
localStorage. - An offline copy of your data — your groups, your expenses, the usernames of the other members, and the activity history, held in a local database in your browser’s Origin Private File System, so that the web app works offline just like the mobile app.
- The program files — cached by a service worker so the app still opens without a connection.
Clearing it. Signing out removes your session and your local copy of your data. Clearing this site’s data in your browser settings removes everything listed above. Both only affect the device you are using — to delete your account and the data held on the server, use Profile → Delete account as described in Section 6.