Legal
Privacy Policy
Last updated 8 September 2026
In short
Deline holds your trip plan and the record of what everyone spent. Everything you add to a trip is visible to everyone else on that trip - there is no private expense. Receipt photographs are sent to OpenAI in the United States to read the text off them. Notifications go out through Expo and Apple, also in the United States, and a notification says who added what. Usage analytics run on PostHog in the EU, carry no trip content, no names and no amounts, and never record your screen. This website counts visits on the same EU analytics, which stores nothing on your device; the only thing this site ever writes there is a note that you closed the box saying Tripline is now Deline. If you join the Android waitlist on this site, your first name and email address are held until that one email goes out and are then deleted. Account emails - a password reset link, an address confirmation - are delivered by Resend in the EU. Nothing is sold, nothing goes to advertisers or data brokers, and nothing tracks you across other companies' apps. You can delete your account inside the app; your name goes, the amounts stay so nobody else's balance breaks.
Version 1.5. Effective 8 September 2026.
Who is responsible for your data
The data controller is Adam Hessel, an individual, of Kocktorpsvägen 50, 132 43 Stockholm, Sweden. Deline is a product name, not a company - there is no registered entity behind it and no organisation number, and the person named here is the one legally responsible.
Email support@deline.dev about anything on this page, including any request about your own data. It is a real mailbox and a person reads it.
No data protection officer is appointed. One is not required at this scale - Deline is not a public body, its core activity is not large-scale monitoring, and it processes no special category data. That is stated rather than left out, because an omission reads like an oversight.
Everything in a trip is visible to that trip
This is first because people assume the opposite about money, and the assumption is expensive. Every expense, amount, balance, who owes whom, every note, place, date and photograph you add to a trip is visible to every member of that trip. There is no per-item privacy, no private expense, and no way to hide an amount from someone you are splitting it with.
Nobody outside the trip can see it. Access is enforced in the database, per row, so being signed in to Deline gives you nothing on a trip you are not a member of. Two exceptions, both deliberate and both worth knowing: profile pictures and trip banners are stored in public buckets, which means anyone holding the exact file address can fetch the image without signing in. The address contains a random identifier and is not published anywhere, so it is not guessable in practice, but it is not access controlled either and it would be dishonest to tell you it was.
What is collected
Your account
Your email address, and the display name you choose. If you sign in with Apple or Google, the identifier they give us and whatever name they supply. The email address identifies your account and is how you are contacted about it. Your display name is shown to everyone on a trip you join.
Two emails can be sent to that address, and only two: a link for setting a new password when you ask for one, and a link for confirming the address when you sign up. They are delivered byResend, in Ireland, which receives the address and the message. There is no newsletter and no marketing mail, so there is nothing to unsubscribe from.
Setting a new password happens on this website rather than in the app, at deline.dev/forgot-password. That page answers the same way for an address that has an account and one that does not, deliberately, so it cannot be used to find out whether somebody is a Deline user.
Your trip content
Everything you put in a trip: destinations, dates, bookings, transport, places to stay, plans and notes, and any place name, address or coordinate you type or import. Deline never asks for or reads your device location. There is no location permission in the app and no purpose string in the build.
Costs
What each expense was, what it cost, who paid, who owes whom, and any itemised receipt lines. Amounts are held as whole numbers of the smallest unit of the currency, and every calculation is done on integers, which is why the arithmetic reconciles exactly.
Photographs
Receipt photographs, trip photographs and your profile picture. Receipts and trip photographs are in private storage readable only by members of that trip. Profile pictures and trip banners are in public storage - see above.
Camera and photo library
Only when you choose to add a photograph, and only for that. iOS asks first and you can change your mind in Settings at any time.
Technical records kept for limits and abuse
Counts of receipt scans against your account and your trip, timestamps of failed invite-code attempts, and a record of each call to the text-extraction service with its token counts and cost. These hold no message content and no trip content. They exist to enforce the quotas described in the subscription terms and to make guessing an invite code expensive.
People who are not Deline users
Deline lets you add someone to a trip who has no account - a friend who has not installed it, or has no intention of doing so. They appear on the trip as a name, they hold a real balance, and the app calls this a ghost member.
That means personal data is held about people who never interacted with Deline. What is stored about them is: the name typed in by the person who added them, the initials and colour derived from it, optionally a picture, and every expense, share and settlement pointing at their place on the trip. No contact details of any kind are held - there is no field in the database for an email address or a phone number for a ghost member, so there is no way to reach them.
The legal basis is legitimate interest, GDPR Article 6(1)(f). The balancing, in one sentence: a group cannot split a bill without naming who is in it, what is held is a first name and a share of a restaurant bill rather than anything sensitive, it is visible only to the few people already on that trip, and the alternative - refusing to let anyone be named until they install an app - makes the product impossible for the exact situation it exists for.
Article 14 normally requires that a person be told when data about them is obtained from someone else. Because Deline holds a name and no way at all of contacting the person,direct notification is impossible, which is the position Article 14(5)(b) provides for. This page is the public notice that stands in its place, which is why it is readable without an account and without the app.
If you have been named on a trip and you are not a user
You have the same rights as anyone else and you do not need to create an account to use them. Email support@deline.dev with the name you were added under and, if you know it, the trip or the person who added you. You can ask what is held about you, ask for it to be corrected, ask for your name to be removed, or object to it being held at all.
What removal means in practice, stated plainly: your name is replaced with a non-identifying label. The amounts stay. They have to - other people on that trip are still settling up against them, and deleting a share silently breaks the arithmetic for four other people who did not ask for anything. If you want that outcome anyway, say so and it will be discussed rather than refused by policy.
The person who added you is responsible for having had a reason to. The Terms say so.
Receipt scanning and booking import
When you photograph a receipt, or import a booking screenshot, the image is sent toOpenAI in the United States, which reads the text and returns the items and amounts so the bill can be itemised for you.
What is sent is the image and a fixed instruction, and nothing else. Specifically:
- your name, email, account identifier and trip identifier are not sent
- no other member's name is sent
- the image used for reading is a separate, smaller copy which is discarded after the call
Inputs and outputs sent to OpenAI's API are not used to train OpenAI's models.This is the developer API, which behaves differently from the consumer ChatGPT product, and the distinction is the reason the sentence is worth making. OpenAI does apply its own limited retention for abuse monitoring; zero-retention processing is not enabled on this account, so the image is held briefly by OpenAI under that policy rather than not at all.
What Deline keeps is the separate stored copy of the receipt, in private storage with the expense, so the bill can be re-read when a split is questioned, plus the extracted lines and amounts. If you abandon a scan without saving the expense, nothing is stored. Delete the receipt from the expense and the image is deleted from storage.
The extraction is best effort and it can misread an amount or a date. It makes no decision about any person - it reads text off a picture, and you review and correct the result before anything is saved.
Notifications
If you allow notifications, a push token for your device is stored. It is an address for your phone, not a name, and no other user can read it - it is not exposed through the app's data interface at all.
Delivery goes through Expo's push service in the United States and then Apple's notification service. A notification carries content: the name of the member who added something, the trip name, and the title of the expense or plan, for example "Anna added a cost" under the title "Dinner at Vapiano". So a member's name, a trip name and an item title leave the EU each time one is sent. Legal basis is legitimate interest - keeping a group in step on a shared trip is what the notification is for - and you can turn them off at any time. Deline has its own per-category switches - plans, costs, payments and people joining - so you can keep one kind and drop another, and those choices are stored against your account. Turning notifications off for Deline in iOS Settings stops them regardless.
Product analytics
This section describes the app. The website is further down, and is a smaller thing.
Deline uses PostHog to understand how the app is used: which screens people reach, which flows they start and abandon, and what breaks. The instance is hosted in the European Union (eu.i.posthog.com), so this is not a transfer outside the EEA.
What is recorded:
- Named product events - a fixed list the app is allowed to send, such as "a cost was added" or "a stop was added". Each carries only a handful of allow-listed properties describing the shape of what happened: for a cost, whether it came from a receipt scan or was typed, how it was split, and whether it was in a foreign currency.Not the amount, not the description, not who paid.
- Screen views, by route pattern -
/trip/[tripId]/costs, never the resolved address, so no trip or expense identifier is carried in a screen name. - App lifecycle - installed, opened, backgrounded, became active.
- Device and app details the analytics library attaches automatically - device type, manufacturer and model, operating system and version, app version and build, and screen size. This is standard technical metadata and is how a crash on one iOS version is told apart from one on another.
Events are tied to your account by your Supabase user identifier and nothing else - an opaque code. Your email address, your display name and your picture are never sent, and no profile held by the analytics provider contains any of them.
What is deliberately not collected, and is prevented in code rather than by policy:
- No trip content. The app maintains a list of permitted property names, and anything matching a name, an email address, a title, a note, a description or an amount is dropped before it is sent. Trip names, member names, place names, expense descriptions and every sum of money are all refused by that rule.
- No session replay. It is switched off in the app. Nothing records your screen.
- No autocapture. Taps and gestures are not harvested; only the events above are sent.
- No location. Analytics providers normally infer a city and country from the network address a request arrives from. Deline switches that inference off at the source, so it is not derived and not stored. Your IP address is also anonymised on arrival.
Analytics events are kept for 12 months, then deleted.
The legal basis is legitimate interest - knowing which parts of the app work is how it gets fixed - and it is a defensible one here precisely because what is collected is limited to the above. You can object at any time by emailing support@deline.dev, and analytics for your account will be switched off.
This website
Since 20 August 2026 deline.dev counts visits, on the samePostHog instance in the European Union. It is deliberately a much smaller thing than the app's analytics, and it works differently: there is no account here, so there is nobody to attach anything to.
- Three events. A page view - which page, plus the link parameters in the address bar if you arrived from a link we shared - leaving the page, and a tap on a Download button. Nothing else, and no page performance measurement.
- The measurement stores nothing on your device. No cookie, no local storage. The visitor identifier lives in memory for the life of the page and is gone when you leave, so two visits by the same person are two anonymous visits and cannot be joined up.
- No session recording, no autocapture, no location. The same three switches the app sets, set the same way.
- Do Not Track is honoured. If your browser sends it, nothing is loaded and nothing is sent.
The legal basis is legitimate interest - knowing whether anybody reads this site is how it is decided what to write next. The cookie and tracking page covers this in full, including why there is no banner in front of it.
The Android waitlist
Deline is an iPhone app. Under every Download button on this site there is a second button,Join the waitlist for Android, which opens a box asking for a first name and an email address. Nothing on this site asks for either anywhere else, so this section is the whole of it.
- Two things are stored. The first name you type and the email address you type, plus the date you typed them. Nothing else - no IP address, no device, no record of which page you were on.
- It is used for one thing. Telling you, once, that the Android app is ready, and asking at the same time whether you would like to be one of the first testers. It is not a newsletter, it is not passed to anybody, and it is not joined up with anything in the app.
- The legal basis is consent - you typed it into a box that said what it was for. You can withdraw it at any time by emailing support@deline.dev, and we will delete your entry.
- The list is deleted once that email has gone out. It exists to send one message, and it is destroyed after it has sent it.
The list is held in the same Supabase database as everything else, in Ireland, in a part of it that cannot be read by the website or the app - only by us.
Tracking, advertising and crash reporting
Deline contains no advertising, attribution or crash-reporting software. No advertising identifier is read, nothing you do is tracked across other companies' apps or websites, nothing is shared with data brokers or advertisers, and nothing is sold. Deline does not show the iOS tracking permission prompt because it has nothing to track you with.
Apple provides aggregate App Store statistics - how many people installed Deline from a given link. Those are counts, not individuals, and you cannot be identified from them.
This website is separate, and quieter. deline.dev sets no cookies, and the only thing it ever writes to your device is a note that you closed the box telling you Tripline is now Deline - so it does not show you that box again. It holds no identifier and is read by nobody but your own browser. That is why you were not asked to accept anything on your way in. The site does count visits, anonymously and in the EU -described above. The cookies and tracking notice sets out exactly what is stored, why there is no banner, and the one external request the invite page can make.
Why we are allowed to hold it
- Performing our contract with you, Article 6(1)(b) - your account, your trips, your expenses, your photographs, and your subscription if you buy one. Reading a receipt or a booking screenshot is part of this too: photographing a bill so it can be itemised is asking Deline to do the thing you installed it for, so sending that image to be read is performance of our agreement rather than something separate you opt into. Deline cannot do what you installed it for without any of these.
- Legitimate interests, Article 6(1)(f) - ghost members as described above; notification delivery; product analytics as described above; the scan quotas and rate limits that stop one account running up a bill with no ceiling; and keeping the service secure. You can object to any of these.
- Your consent, Article 6(1)(a) - camera, photo library and notification access, which you grant per device and can withdraw in iOS Settings at any time; and the Android waitlist on this website, which you withdraw by emailing us.
- Legal obligation, Article 6(1)(c) - where a law requires records to be kept or handed over.
Who else processes it
A small number of processors, each only for what is listed: Supabase for the database, storage and sign-in; OpenAI for reading receipt images;Expo and Apple for notification delivery;Resend for the two account emails; PostHog for the analytics described above, in the app and on this website; and Cloudflare for serving deline.dev. The full list, with regions and dates, is on the sub-processors page.
Other people on your trips also see the content you add to those trips. That is not a transfer made on your behalf - it is you sharing with them, and it is the point of the app.
Where your data is held, and transfers out of the EU
The database and file storage are in the European Union, hosted by Supabase on Amazon Web Services in Ireland. That covers your account, your trips, your expenses and your photographs.
Account emails are not one of them: they go out through Resend's European region, in Ireland.
Two things leave the EU, and only two:
- Receipt and booking images sent to OpenAI in the United States, for text extraction.
- Notification content sent through Expo in the United States, and then Apple, for delivery.
Both transfers rely on the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914), incorporated into the data processing terms agreed with each provider. OpenAI's API processing is not EU-resident by default and is not configured to be, so the image is processed in the United States under those clauses.
How long it is kept
- Your account - until you delete it.
- Trip content, expenses and photographs - until you delete them in the app, or the trip is deleted. Deleting an expense deletes its receipt image.
- Push token - until you delete your account, or the token stops working.
- Scan counters and usage records - deleted with your account.
- Subscription record - deleted with your account. Apple keeps its own record of the purchase, which is not ours to delete.
- The Android waitlist - until the Android app is out and the one email has gone, and then the list is deleted. Sooner if you ask.
Trips are shared, and that has a consequence worth stating. Content you added to a trip stays with the trip after you leave or delete your account, because four other people are still using it. Your name is removed from it - see below - but the expenses, the amounts and the receipt photographs you took remain part of that group's record. If you want a specific photograph removed as well, ask and it will be dealt with individually.
If everyone on a trip deletes their account, the trip becomes unreadable by anyone, including us through the app. The rows are not currently erased. This is stated because it is true, not because it is good, and a cleanup routine is a known outstanding item.
Deleting your account
You can delete your account from inside the app - Profile, then Delete my account. No email, no form, no explanation required.
What that deletes:
- your login, email address and password
- your profile, your display name and your initials
- your profile picture, including any older ones you replaced
- your push token, so notifications stop
- your subscription record, your scan counters and your usage history
- your name on every trip you were on, replaced with a neutral label
What deliberately stays, and why:
- The amounts. What you paid and what you owed remain on each trip, now attached to a former member rather than to you. If they were removed, every remaining member's balance would be wrong, and they did not ask for that. This is the legitimate interest that justifies keeping it.
- Receipt photographs and trip photographs. A receipt is the evidence for a split other people are still settling, and a trip photograph is part of a shared record other people also contributed to.
- Notifications already delivered to other people's phones. Those are on their devices and cannot be recalled.
Details of exactly what is removed are on the account deletion page, which needs no login to read. If you would rather it was done for you, email support@deline.dev.
Your rights
You have the right to:
- get a copy of the personal data held about you - the app has this built in, under Profile
- have inaccurate data corrected
- have your data deleted, in the app or by asking
- restrict or object to how it is processed, including objecting to anything relying on legitimate interest
- receive your data in a portable, machine-readable form
- withdraw consent you have given, such as camera or notification access
Email support@deline.dev and you will get an answer within one month.
If you are not satisfied, you can complain to the Swedish authority,Integritetsskyddsmyndigheten (IMY), at imy.se. If you live elsewhere in the EU or EEA you can complain to your own national authority instead.
Automated decision-making
There is none. Nothing about you is decided automatically in a way that produces legal effects or similarly significantly affects you. The receipt reader extracts text from a picture you chose to take, and you review and correct what it produces before anything is saved. It makes no judgement about any person.
Security
Data is encrypted in transit and at rest, as provided by Supabase on Amazon Web Services. Access to a trip's content is enforced at the database level, per row, so being signed in gives you nothing on a trip you are not a member of. The keys that could bypass that are held only by server-side functions and never ship inside the app.
No system is perfectly secure and this page will not tell you otherwise. People with administrative access to the hosting project can technically reach stored data; that access is limited to what is needed to run and repair the service.
If something goes wrong
If a breach of personal data occurs that is likely to result in a risk to your rights and freedoms, it will be reported to IMY within 72 hours of becoming aware of it, as Article 33 requires. If it is likely to result in a high risk to you, you will be told directly, without undue delay, in plain language: what happened, what data was involved, and what to do about it.
Age
Deline is for people aged 16 and over and is not directed at children. If you believe someone under 16 has an account, email support@deline.dev and it will be deleted.
Changes to this policy
If what is collected or what is done with it changes, this page changes and the version number and date at the top move with it. If the change is significant, you will be told in the app rather than left to notice.
Contact
Adam Hessel
Kocktorpsvägen 50, 132 43 Stockholm, Sweden
support@deline.dev