Krumbs Privacy Policy
Last updated: 6 August 2026
Krumbs is for splitting expenses between people. To do that it has to store who paid what and who owes whom. This page explains exactly what is stored, where it goes and how to delete it.
Who is responsible
The data controller is Lancelot-Project, owner of the Krumbs app and of krumbs.lancelot-project.com.
For anything related to your data, or to exercise your rights, write to privacidad@lancelot-project.com. For usage questions or problems, soporte@lancelot-project.com or the support page.
No data protection officer has been appointed: the processing does not meet any of the conditions that would require one (art. 37 GDPR).
The anonymous account
The first time you open Krumbs, the app automatically creates an anonymous account so you can start using it without signing up. That account already has an identifier and a profile with the name and colour you choose, even if you never give an email address. It is what keeps your expenses there when you close and reopen the app.
If you later save the account with your email, with Apple or with Google, that same account becomes linked to those credentials; no second account is created.
What is stored
| Data | Why | When |
|---|---|---|
| Account identifier | To tell your account apart from others and attach your expenses to it. | Created the first time you open the app. |
| Your name and avatar colour | So the people you split with know who you are. | When you type it. |
| Your email address | To recover your account if you change phone. It is not visible to other users: the database does not expose it to anyone but you. | Only if you save your account with email, Apple or Google. |
| Main currency | To show totals in your own currency. | Detected from your device; you can change it. |
| Expenses, groups and balances | The core of the app: amounts, dates, descriptions, who paid and how it is split. | When you create groups or add expenses. |
| Names of people you add | So you can split with someone who doesn’t use the app yet. | When you type their name. Krumbs does not access your address book. |
| Scanned receipt contents | So you can reopen and correct the split later. Includes the merchant name, the list of items with their prices and the text read from the receipt. | When you scan a receipt and save the expense. |
| Device time zone | To generate recurring expenses on the right day wherever you are. | Only if you create a recurring expense. |
| Invite codes | So other people can join your group or add you as a friend. | When you create a group or generate your friend link. |
| Push notification token and device type | To send notifications to this device. | Only if you accept notifications. |
| Log of notifications sent | To avoid sending the same alert twice and to rate-limit debt reminders. | When an alert is sent. |
| Scanner telemetry | To share out the receipt-reading service's quota, measure what it costs and detect abuse. Stores technical measurements (model, request size, duration, cost), never the contents of the receipt. | On every scan. |
| Technical connection data | To serve the app and the website and protect them from attacks. Processed by the infrastructure providers (IP address, device type, access logs). | Every time the app or the site connects. |
Krumbs uses no analytics, advertising, attribution or crash-reporting tools. There are no advertising identifiers, no third-party cookies and no cross-app tracking.
Photos of your receipts
When you scan a receipt, the image is sent to Google Cloud (Vertex AI), which reads it and returns the items and amounts. About that image:
- It is not stored on Krumbs servers. It is transmitted, processed and discarded.
- Google does not use it to train its models. It acts as a processor and only to return the reading, under the Google Cloud terms.
- The original photo stays on your device if you choose to attach it to the expense.
- What is stored is the result of the reading: merchant, items, prices and the text that was read, so you can reopen the receipt and fix the split.
A receipt can contain data you weren’t expecting: the venue name, the time, a table number or the last digits of a card. Only scan what you need to split.
Automatic reading of the receipt
Items and amounts are extracted by an automated model. It never decides anything for you: the result is shown to you to review and correct before the expense is saved, and it produces no legal effect and does not significantly affect you. There is no profiling and no automated decision-making within the meaning of article 22 GDPR.
Scanning is limited to a maximum number of scans per account per day — higher once you sign in with your email, Google or Apple than as a guest — to cap the cost of the receipt-reading service and to prevent abuse.
Invite links
When you share an invite link, whoever opens it sees a public page, with no account and no app installed:
- Group invite (
/join/…): shows the group’s name, emoji and colour. It does not show its members, its expenses or any amount. The link expires after 30 days and you can rotate or revoke it from the app. - Friend invite (
/friend/…): shows your name and avatar colour. You can regenerate or revoke it whenever you want.
These pages are served with instructions telling search engines not to index them, but a shared link is public in practice: anyone who receives it can open it. Only share it with people you want to let in.
Anyone who joins a group sees, from that moment, that group’s expenses, their amounts and who paid for what. That is the point of the app.
Who it is shared with
- The people in your groups. That is the point of the app.
- The providers that keep the service running, as processors and only to provide it (table below). That includes Google Cloud, which reads your receipt photos and uses them for nothing else (see “Photos of your receipts”).
- Apple or Google, only if you choose to save your account with them.
- Authorities, where a legal obligation requires it.
Krumbs does not sell your data, does not share it for advertising and does not profile you.
The app fetches exchange rates from a public currency service to convert between currencies. That request contains none of your data.
Where it is processed
| Provider | What for | Where |
|---|---|---|
| Supabase | Database and sign-in. | Database hosted in Ireland (European Union). The provider is a US company and may access it from outside the EEA for support. |
| Google Cloud (Vertex AI) | Reading receipt photos. Not used for any other purpose. | May be processed outside the EEA, covered by the standard contractual clauses. |
| Cloudflare | Serving this website and the invite pages; protection against attacks. | Global network, with servers in the EU and outside the EEA. |
| Expo | Delivering push notifications to your device. Only if you accept notifications. | United States. |
| Resend | Sending account confirmation and password recovery emails. | United States. |
Where processing involves an international transfer outside the European Economic Area, it relies on the standard contractual clauses approved by the European Commission or on an adequacy decision, depending on the provider. You can ask for information about the safeguards in place by writing to privacidad@lancelot-project.com.
How long it is kept
For as long as you have an account. Deleting it immediately removes your profile, your email, your private contacts, your friendships and your push notification tokens. Three caveats are worth understanding:
- Expenses you shared with other people remain in their groups, because they belong to them too and removing them would break their balances.
- So that those expenses still make sense, your name and avatar colour are kept inside those groups as an account-less contact, owned by another member of the group. In other words: the people you shared expenses with will still see your name in their history. Your email and the rest of your account data are not kept.
- Scanner cost telemetry and the technical log of notifications sent are kept without your account: once it is deleted, the identifier they contain can no longer be linked to you.
Technical logs held by infrastructure providers are kept for their own retention periods, usually short.
Your rights
You can access, correct, delete, port, object to and restrict the processing of your data, and withdraw at any time any consent you have given. The fastest routes:
- Correct: Profile → tap your name.
- Delete: Profile → Delete profile. Immediate and permanent. You can also use the account deletion page.
- Withdraw consent for push notifications: from your phone’s notification settings. Same for camera and photo permissions.
- Portability and anything else: write to privacidad@lancelot-project.com. The app does not have an export button yet, so this route is handled manually.
Requests are answered within one month, extendable by two more if the request is complex. To avoid handing your data to someone else, you may be asked for a reasonable check that the request comes from the account concerned, normally by writing from the email address linked to it.
If you believe your data has been handled improperly, you can complain to the Spanish Data Protection Agency (aepd.es) or to your local supervisory authority.
Legal basis
- Performance of the contract (art. 6(1)(b) GDPR): your account, groups, expenses, balances, receipt scanning and the confirmation and recovery emails. Without this data the app cannot work.
- Your consent (art. 6(1)(a)): push notifications and access to the camera or photos. You can withdraw it from your device settings, without affecting prior processing.
- Legitimate interest (art. 6(1)(f)): scanner cost telemetry, usage limits, service security, and preserving the expense history of the other members of a group when someone deletes their account.
- Legal obligation (art. 6(1)(c)): responding to requests from competent authorities.
Children
Krumbs is not directed at children under 14 and does not knowingly collect data from them. If we find an account belonging to a child under 14, it will be deleted.
Security
Your session is stored encrypted in the operating system’s secure store (Keychain on iOS, Keystore on Android). Access to data is restricted in the database by rules that prevent you from seeing anything outside your groups. If you find a security flaw, write to soporte@lancelot-project.com.
Changes
If this policy changes materially, you will be told inside the app before the changes take effect. The date above marks the latest version.