Skip to content

Privacy Policy

Last updated: 29 September 2026

This notice explains what personal data MySharedXP processes, why, who receives it, how long we keep it and what rights you have. It applies to the iOS and Android apps, the web app and this website.

1. Who is responsible for your data

The controller for the personal data described in this notice is TNV NextGen, a sole proprietorship (eenmanszaak) at Hollywoodlaan 58, 1325 HS Almere, the Netherlands, registered with the Dutch Chamber of Commerce (KVK) under number 98216260, VAT number NL005316081B12 ("MySharedXP", "we", "us"). You can reach us at privacy@tnvnextgendigital.com.

The controller is established in the Netherlands, so no EU representative under Art. 27 GDPR is needed. For any question about your personal data, write to privacy@tnvnextgendigital.com.

2. What this notice covers

This notice applies to the MySharedXP apps for iOS and Android, the MySharedXP web app at app.mysharedxp.com and the website mysharedxp.com. It is written to meet Articles 13 and 14 of the General Data Protection Regulation (GDPR).

3. The data we process

Depending on how you use MySharedXP we process the following categories of personal data:

  • Account and identity data: email address (your login), first name, last name, display name, optional phone number (used only if you enable SMS two-factor authentication), profile picture, short bio, time zone, default currency, verification status and last login time. If you sign in with Apple or Google we receive an identity token and the name and email address the provider shares with us.
  • Financial and group data: the expenses you record (amount, currency, category, title, notes, date), how they are split, settlements and payments, budgets, recurring expenses, and the groups you belong to. Together this is a record of your spending and of who owes whom.
  • Receipts: images you attach to expenses. A receipt often contains more than the expense itself, for example a merchant address or the last digits of a payment card. Only attach receipts you are comfortable storing. Photos are re-encoded before upload, which removes camera metadata such as GPS coordinates.
  • Receipt scanning (Pro): on iPhone and iPad the printed text is read on your device with Apple's Vision framework and only the recognised lines are sent to our server, which picks out the merchant, total and date. If the on-device reader cannot make out the text the scan is refused; in some releases such a photo may instead be sent to Amazon Textract in Frankfurt to be read, and this notice says so when it is. On Android and the web the photo is sent to Amazon Textract until on-device reading is available there. Textract does not keep the image.
  • Subscription data: your subscription tier, expiry date, product identifier and the store transaction identifier, as reported by Apple, Google or Stripe. We never receive or store payment card details; the app stores handle payment.
  • Support and feedback: the subject and text of support tickets and feedback you send us, your rating if you leave one, and what you choose to attach: screenshots and, if you tick "Include device logs", a log with the app version, operating system, device model, language and the app's recent technical messages. The log does not contain your expenses, receipts or passwords.
  • Activity and notifications: an activity log and notifications attributed to you (for example "you added an expense").
  • Friends and referrals: the people you are friends with in the app, friend requests you send or receive, and, if you use a referral code, who invited whom and when. Other people can find you to send a friend request only as your profile visibility setting allows: "Everyone" by name or email address, "Friends Only" by exact email address only, "Private" not at all. Search results show your public profile, never your email address.
  • Invitations: when you invite someone who is not yet on MySharedXP by email, we store that email address with your invitation so that the person is linked to you if they sign up. The person invited is not contacted by us; you share the invitation yourself. If you invite someone, make sure they are happy to hear from you.
  • Push notification tokens: if you allow notifications, the device token issued by Apple or Google is stored with your account so we can deliver notifications to that device. When someone else signs in on the same device, the token moves to their account. It is deleted when you sign out or delete your account.
  • Consent records: the version of the Terms and this notice you accepted, your confirmation that you are 16 or older, and each time you switch usage statistics on or off, with a timestamp. We keep these to prove consent (Art. 7(1) GDPR).
  • Usage statistics (opt-in only): Settings has a "Share Usage Data" switch, off by default. In the current release the feature itself is disabled, so nothing is recorded even if the switch is on. When it is enabled and switched on, the app records anonymous events such as "expense created" with an enum value (for example the split type). These events carry a random install identifier, never your account, and contain no names, titles, notes or amounts. Recorded events are kept for at most 13 months and are deleted with your account.
  • Advertising (free accounts only): adverts come from Google AdMob (Google Ireland Limited for the EEA and UK): a banner on the Dashboard and Groups screens, an occasional inline banner and one full-screen advert after a settlement is recorded. To serve and measure ads the Google Mobile Ads SDK processes the vendor identifier of your device, your approximate location derived from your IP address, the adverts you see and tap, and technical diagnostics. We do not request the advertising identifier (IDFA / Android Advertising ID), so ads are not personalised across other companies' apps by us and we do not use tracking as defined by Apple's App Tracking Transparency framework. In the EEA and UK Google's consent form is shown before the first advert and your choices can be changed at any time in Settings > Ad privacy options. Coffee and Pro subscribers see no ads and the ad SDK is never started for them.
  • Siri and Shortcuts (Pro, iPhone and iPad): when you ask Siri or run a Shortcut, Apple turns your request into the action's details, for example an amount and a group, under Apple's own privacy terms. MySharedXP receives only those details, never your voice, and handles them like the same action in the app. For Pro members, the names of your groups and of the people in them are also added to your device's own search (Spotlight), which stays on the device and is cleared when you sign out.
  • On-device data: preferences such as notification settings and feature flags are stored on your device and are not sent to us. Face ID / Touch ID / fingerprint unlock uses the operating system; no biometric data reaches us.
  • Web app: the web app keeps your sign-in session, your display preferences (theme, text size, language), the split you used last and whether you accepted these documents in your browser's local storage. This is needed for the web app to work and is not used for tracking; signing out removes the session.
  • Website: the website sets no cookies and runs no analytics. Our hosting provider (AWS) records the IP address and requested URL of each visit in short-lived server logs to operate the service.

4. Why we process it and on what legal basis

  • Providing the service you signed up for (accounts, groups, expenses, splits, settlements, receipts, subscriptions, support): performance of a contract, Art. 6(1)(b) GDPR.
  • Keeping the service secure (login, verification codes, optional two-factor authentication, abuse prevention, server logs): our legitimate interest in a secure service, Art. 6(1)(f) GDPR.
  • Reading receipts with optical character recognition (Pro feature): performance of a contract, Art. 6(1)(b), triggered only when you tap "scan".
  • Anonymous usage statistics: your consent, Art. 6(1)(a) GDPR, given by enabling the toggle and withdrawable at any time by disabling it.
  • Advertising on free accounts: in the EEA and UK, your consent given through Google's consent form, Art. 6(1)(a) GDPR, withdrawable in Settings > Ad privacy options; elsewhere our legitimate interest in funding the free tier, Art. 6(1)(f) GDPR. Subscribing removes advertising entirely.
  • Complying with legal obligations, for example tax and accounting rules for subscription revenue: Art. 6(1)(c) GDPR.
  • Providing your data is not required by law. Without an email address and the data needed to record expenses we cannot provide the service.

5. Who receives your data

Other members of your groups see your display name, profile picture, the expenses you record in that group and your balance in it. That is the purpose of the app; please keep this in mind before adding someone to a group.

We use the service providers ("sub-processors") listed in the table below. We do not sell personal data. The only advertising network is Google AdMob, used for free accounts only as described in section 3; no third-party analytics or crash-reporting SDK is embedded in the apps and the website runs no analytics.

Each provider processes personal data under a data processing agreement or, where it acts on its own account (for example Apple and Google for sign-in and store payments), under its own data protection terms. The apps contain code for a second sign-in provider that is switched off and receives no data.

Sub-processors that receive personal data
ProviderPurposeData location
Amazon Web Services (Amplify, Cognito, AppSync, DynamoDB, S3, Amplify Hosting)Hosting, authentication, database and file storage for the apps and websiteFrankfurt, Germany (eu-central-1)
Amazon Textract (AWS)Reads text from receipt images when a Pro user taps "scan"Frankfurt, Germany (eu-central-1)
Google AdMob (Google Ireland Limited / Google LLC)Adverts and ad measurement for free accounts, with the User Messaging Platform consent form in the EEA and UKIreland / United States
Apple Inc.Sign in with Apple, App Store payments, push notifications on iOS (APNs)EU / United States
Google LLCGoogle Sign-In, Google Play payments, push notifications on Android (Firebase Cloud Messaging)EU / United States
Stripe Payments Europe, Ltd.Payments for subscriptions bought on the web (card details go to Stripe, never to us); we keep the Stripe customer and subscription identifiersIreland / United States
European Central Bank (data.ecb.europa.eu)Daily euro reference rates for expenses in other currencies (Pro). Our servers ask for currency codes and dates only; nothing about you is sentGermany (EU)

6. International transfers

All account, financial and receipt data is stored in AWS data centres in Frankfurt, Germany (eu-central-1). Some providers have parent companies in the United States and may access data from there for support or operations. For those transfers we rely on the EU-US Data Privacy Framework, under which these providers are certified, and on the European Commission’s Standard Contractual Clauses. The European Central Bank receives only currency codes and dates, never personal data.

7. How long we keep it

We keep personal data only as long as the purposes above need it:

  • Account and profile data: until you delete your account. Deletion takes effect at once: your sign-in is removed and your profile is replaced by an anonymous placeholder.
  • Invitations to people who are not on MySharedXP: 90 days, after which they are deleted automatically, or earlier when the person signs up or you delete your account.
  • Inactive accounts: if you have not signed in for more than 24 months we may delete your account as described above, after telling you by email at least 30 days beforehand.
  • Expenses, splits and settlements you share with others: when you delete your account they are anonymised (your name is removed and cannot be restored) so that other members’ records stay correct. Entries in a group’s activity written while you were a member (for example “Added Alex to the group”) stay visible to that group’s members.
  • Receipt images: deleted with the expense they belong to or with your account, whichever comes first.
  • Support tickets, their attachments and feedback: until you delete your account; they are deleted with it.
  • Notifications and your personal activity log: until you delete your account; they are deleted with it. Activity in a group stays with that group for its members.
  • Anonymous usage events: at most 13 months. They are not linked to your account.
  • Subscription records: our copy is deleted with your account. Apple, Google and Stripe keep their own payment records as tax law requires; for web purchases Stripe keeps the invoices we must retain for seven years under Dutch tax law.
  • Push notification tokens: until you sign out or delete your account.
  • Consent records: after account deletion, in anonymised form (linked only to an internal identifier, not to your name or email), for as long as we may need to show what was agreed, at most five years (the Dutch limitation period for claims).
  • Backups: at most 35 days, after which deleted data is gone from backups too.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15);
  • have inaccurate data corrected (Art. 16);
  • have your data erased (Art. 17);
  • restrict processing in certain cases (Art. 18);
  • receive your data in a portable, machine-readable format (Art. 20);
  • object to processing based on legitimate interests (Art. 21);
  • withdraw consent at any time, without affecting processing that happened before you withdrew it (Art. 7(3));
  • lodge a complaint with a supervisory authority, in particular in the EU country where you live or work. Our lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).

9. How to exercise your rights

  • Export your data: in the app, go to Settings > Account > Export Data to download a JSON file with your account and expense data.
  • Delete your account: in the app, go to Settings > Account > Delete Account. This removes your account and personal data as described in section 7.
  • Correct your data: edit your profile in Settings.
  • Withdraw consent to usage statistics: switch off "Share Usage Data" in Settings.
  • Everything else, or if you cannot access the app: email privacy@tnvnextgendigital.com. We answer within one month; we may ask you to confirm your identity first.

10. Automated decision-making

The settlement optimiser suggests the smallest set of payments that clears a group’s balances. It is a calculation you can ignore or override, has no legal or similarly significant effect on you, and we do not profile users. No decisions under Art. 22 GDPR are made.

11. Children

MySharedXP is not directed at children. You must be at least 16 years old to create an account. If you believe a child under 16 has created an account, contact privacy@tnvnextgendigital.com and we will delete it.

12. Cookies, local storage and tracking

The website sets no cookies, uses no local storage and loads no third-party scripts or fonts. There is therefore no cookie banner.

The web app stores only what it needs to work in your browser (see section 3, "Web app"). Storage that is strictly necessary for a service you asked for does not require consent under the Dutch Telecommunications Act (art. 11.7a); we use none for tracking or advertising.

13. Security

Data is encrypted in transit (TLS) and at rest on AWS. Access to production systems is restricted and logged. You can add two-factor authentication to your account and lock the app with Face ID, Touch ID or fingerprint.

14. Changes to this notice

When we change this notice we update the date at the top of this page. If a change materially affects how we use your data we will also tell you in the app or by email before it takes effect.

This notice is also available in other languages. Those versions are AI translations; if they differ from this English text, the English text prevails.

Questions about this notice? Contact privacy@tnvnextgendigital.com