Privacy Policy
Last updated 7 September 2026. Effective from first public release.
Zeroly is a shared record of who paid for what. This policy explains what we collect, why we need it, who else touches it, and how to get rid of it.
The short version
We collect your name, email, and the expenses you enter. We need them because a shared ledger does not work if nobody knows who spent what. We do not sell your data, we do not show ads, we do not track you across other apps or websites, and we never see or move your money. You can delete your account from inside the app at any time.
1. Who we are
Zeroly is made by Clanelite LLC, a limited liability company registered in Pennsylvania, United States. In this policy "we" and "us" mean Clanelite LLC, and "Zeroly" means the Zeroly iOS app and the pages on zeroly.app.
For privacy questions, write to support@zeroly.app.
2. What we collect
Information you give us when you sign in
Zeroly only offers Sign in with Apple and Sign in with Google. We never create or store a password. From your chosen provider we receive your name, your email address, and an identifier that lets us recognise you next time.
If you use Hide My Email with Sign in with Apple, we receive a relay address rather than your real one, and that is all we ever have. Zeroly works exactly the same either way.
A profile photo is optional. If you add one, we store it.
What you create in the app
| Data | Examples |
|---|---|
| Expenses and payments | Amount, currency, date, description, who paid, how it was split |
| Groups | Group name, who is a member, invitations you send |
| Notes | Free text you attach to an entry |
| Receipts | Photos you attach to an expense |
This is the substance of the product. It is stored so that you and the people you share a group with can see the same numbers.
Technical information
- Device token for notifications — if you turn on push notifications, one record per device so a second phone also rings. Deleted when you sign out or turn notifications off.
- App installation identifier — assigned by Firebase, used to deliver notifications and to separate one install from another.
- Crash and performance data — stack traces, device model, OS version, when the app crashes or is slow.
- Product interaction — which screens are opened and which features are used, so we know what to fix. Not linked to advertising and never used to build a profile of you.
3. What we deliberately do not collect
Stating this positively, because for a money app the absences matter as much as the presences:
- No card numbers, bank accounts, or payment credentials. Zeroly records who owes whom. It never moves money, and there is nothing to charge.
- No location. The app never asks.
- No advertising identifiers, no ad networks, no cross-app or cross-site tracking. Zeroly's privacy manifest declares tracking as false, and we intend to keep it that way.
- No selling or renting of personal information, to anyone, for any purpose.
- No reading of your contacts unless you explicitly use a feature that adds someone from Contacts, and then only at that moment and only the entry you pick.
- No uploading of receipt images for text recognition. If Zeroly reads a receipt to suggest an amount, that happens on your device.
4. How we use it
- To show you and your group members the same balances.
- To send notifications you have asked for — someone added an expense, someone paid you back.
- To let people invite each other to a group.
- To keep the service running: diagnosing crashes, finding slow screens, preventing abuse.
- To answer you when you write to support.
- To operate subscriptions. Purchases are handled by Apple; we receive whether your subscription is active, not your payment details.
Where the law requires a legal basis, ours is performance of our contract with you for everything needed to run the app, and our legitimate interest in a working, non-abusive service for crash and usage diagnostics. Where consent is required — notifications, camera, contacts — we ask at the moment the feature is used, and refusing leaves the rest of the app working.
5. Who else sees it
People you share a group with
This is the point of the product, and the most important line in this policy. When you add an expense to a group, every member of that group can see it — the amount, the description, the date, who paid, how it was split, any note, and any receipt you attach. They can also see your display name and profile photo. Do not put anything in a group that you would not want everyone in it to read.
Service providers
Zeroly runs on Google Firebase and Google Cloud, which process data on our behalf under Google's terms as a data processor. Specifically: Firebase Authentication (sign-in), Cloud Firestore (expenses, groups, balances), Cloud Storage (avatars and receipts), Cloud Functions (server logic), Firebase Cloud Messaging (notifications), Crashlytics (crash reports), and Google Analytics for Firebase, configured with ad personalisation switched off.
Data is stored in the United States. Apple processes subscription purchases and tells us only whether a subscription is active.
Legal
We will disclose information if we are legally required to, and we will tell you unless we are prohibited from doing so. If the business is ever sold or merged, your information may transfer with it, and this policy travels with it until you are given notice of a replacement.
6. How long we keep it, and deletion
You can delete your account from inside the app: Account → Delete account. It takes two taps and is not hidden behind an email request. There is a page explaining exactly what happens.
When you delete your account:
- Your profile, photo, email, notification tokens and receipts are deleted within 30 days. Encrypted backups age out on their own schedule shortly after.
- Entries you added to shared groups remain, attributed to "Deleted user." We cannot remove them without silently changing what other people are owed. Removing a $200 hotel bill from a trip would rewrite four other people's balances without their knowledge. Those records stay, detached from your identity.
- Groups where you were the only member are deleted entirely.
We never block deletion because you owe money or are owed it. We warn you, then proceed.
While your account is open, your data is kept for as long as you keep using Zeroly. Crash and usage diagnostics are retained on Google's default schedules, which are considerably shorter.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to object to certain processing, and to complain to a regulator.
In practice, most of these you can exercise yourself without asking us: your data is visible in the app, editable in the app, exportable as CSV or JSON, and deletable in the app. For anything you cannot do yourself, write to support@zeroly.app and we will respond within 30 days.
We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing for you to opt out of.
8. Security
Traffic between the app and our servers is encrypted in transit, with no exceptions configured. Who may read or write a record is enforced on the server, not in the app, so a modified client cannot reach another person's data. Sign-in tokens and identifiers are held in the iOS Keychain and are not synced to iCloud. Receipts and avatars are private by default and readable only by members of the relevant group.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects you, we will tell you.
9. Children
Zeroly is not intended for children under 13, and we do not knowingly collect information from them. If you believe a child has given us information, write to us and we will delete it.
10. Changes
If we change this policy we will update the date at the top. For a change that materially affects how we handle your information, we will tell you in the app before it takes effect.
11. Contact
support@zeroly.app
Clanelite LLC, Pennsylvania, United States