Quits — Privacy Policy
Quits splits bills with friends. It has no account, no ads, no analytics and no tracking of any kind. We hold the small amount of data the app needs to split your expenses and keep them in sync. This page lists all of it.
Quits is made by Luxxat Labs, IP, a sole proprietor registered in the Republic of Kazakhstan.
What we hold
| Data | Why | Where it is stored | How long |
|---|---|---|---|
| An anonymous account id | To give your phone an identity, sync your groups, and remember a Pro purchase | Google Firebase (Authentication and Firestore) | While the app's data exists. There is no in-app path that deletes it. |
| An Apple or Google sign-in, if you choose to add one (this brings a name, and an e-mail address) | Only so you can restore your groups on another phone | Firebase Authentication; Apple or Google act as the sign-in provider | While it stays linked. You can unlink it in Settings. |
| The member names you type, including friends who do not have the app | To show who owes whom | Firebase Firestore, on the group | With the group. A group can be archived, but is never hard-deleted. |
| Expenses: title, amount, currency, rate, who paid, the split, the date, your note | The app's main job | Firebase Firestore | The log is append-only, so an edit or a delete keeps the earlier entry. |
| Push tokens (at most 10) and your push on/off setting | To send a reminder about a debt, or to tell you a payment was marked paid | Firebase Firestore and Firebase Cloud Messaging | Removed when a token stops working; otherwise kept. |
| Your purchase receipt: store, transaction id, account id, time | To unlock Pro, and to stop the same receipt being used twice | Firebase Firestore, after Apple or Google confirm it | Kept indefinitely, on purpose — it is the record that blocks re-use. |
| Your IP address, hashed | To stop invite-code guessing and other abuse | Firebase Firestore, as a salted SHA-256 hash — the address itself is never written | A daily sweep deletes the record about 24 hours after its counting window ends. |
| The IP address of a web-page visitor | To rate-limit requests to the page | Cloudflare, in the running worker's memory | Never written to storage. It is gone when that worker instance is. |
| Suggestions board: your posts, your votes, your reports, and your hidden and blocked lists | To run the board and its moderation | Firebase Firestore | Kept. Posts and reports cannot be deleted by users. |
| A currency pair for a rate lookup, such as EUR to KZT | To fetch today's rate | Sent to the rate provider; not stored by us with your data | No personal data is sent with it. |
Scroll the table sideways on a phone.
What we never collect
Your location. Your contacts. Your photos. Health data. Browsing history. An advertising id. And not one analytics event — Quits carries no analytics SDK, no advertising SDK and no attribution SDK at all.
Nothing we hold is sold or shared for advertising. Nothing is used to track you across other apps or websites.
Who handles data on our behalf
- Google Firebase — Firestore (the database), Authentication (including the anonymous identity), Cloud Functions and Cloud Messaging (push). Your groups, expenses and account id live here. Our Cloud Functions run in Google's
europe-west1region. - Cloudflare — serves the read-only web page and counts requests per IP address to rate-limit it. That count stays in the worker's memory.
- Exchange Rate API, with Frankfurter (ECB) as a fallback — currency rates. They receive a currency pair and nothing else: no account id, no names, no amounts. Rates by Exchange Rate API.
- Apple and Google — the purchase itself. We send the receipt to their verification service to confirm that it is real.
Firebase and Cloudflare run networks in many countries, so data may be stored or processed outside the country you live in.
No account, and the optional sign-in
You never make an account with us. Firebase gives your phone an anonymous identity with no sign-up screen, and that is what the "no account" promise means. Signing in with Apple or Google only links that same identity to another device. It is optional, it is never needed for anything in the free core, and you can unlink it in Settings.
Notifications
Push is off until something in the app actually needs it — the first time you send a reminder or mark a payment. A reminder goes to the person who owes, at most once a day for that debt. A "marked paid" notice goes only to the person who is owed. A claimed payment that nobody touches gets one reminder after three days. We never send a marketing push.
The invite link and the web page
A group's invite link opens the app, or, for someone without it, a read-only web page showing that group's balances, who pays whom, and the expenses. Anyone holding the link can see that, so share it only with the people in the group. A visitor can pick which member they are (carried in the address, not in a cookie) and mark a debt paid, which the person who is owed then confirms in the app.
The page tells search engines not to index it, is sent with no-store so browsers and networks do not cache it, and sends no referrer, so the link is never handed to another site. Any member can reset the link in group settings, and the old one stops working at once.
Deleting things — the honest version
- Reset the invite link changes the code, link and QR. Nothing else is deleted.
- Leaving a group needs your balance to be zero. The group keeps every expense you added, you remain in it as a member without the app, and that phone loses access.
- Archiving a group moves it out of the main list for everyone. Nothing is deleted, and any member can bring it back.
- Deleting the app removes the copy on that phone. The group stays in the cloud for the other members, because a group is never hard-deleted.
- There is no button that erases your data from the cloud, and no request-a-deletion flow. We would rather write that plainly than promise one that does not exist yet.
What you always have instead: a free JSON export that carries every expense and every member of every group you are in. Your data is never locked inside Quits.
Security
Data travels encrypted, over HTTPS. The database rules let a member read only their own groups, and the web page reads a group only through that group's share token, which is never sent to another site.
Children
Quits is not directed at children under 13, and we do not knowingly collect their data.
Changes to this page
If what we collect changes, this page changes with it and the date at the top moves.
Contact
Luxxat Labs, IP — sole proprietor, Republic of Kazakhstan
Privacy and general questions: hello@luxxatlabs.dev
Content reports and moderation: moderation@luxxatlabs.com