Even

Privacy policy

Even app

As of: August 2026

This privacy policy explains how the Even app processes personal data in connection with groups, shared expenses, and synchronization.

1. Controller

The controller is Sebastian Taatz Consulting UG (haftungsbeschraenkt). Contact and registry details are available in the legal notice.

2. Data processed

  • local app data such as group name, member name, expenses, shares, balances, and settings
  • technical sync data such as group ID, event ID, timestamps, sender ID, and event type
  • encrypted content data when a group is synchronized across devices or members
  • store and device information provided by the app stores for installation, updates, or optional purchases
  • support data when users actively contact us

3. Local storage and synchronization

Even is designed local-first. Many data points are stored and processed on the device first.

When group synchronization is used, events are sent to Supabase in encrypted form. The server does not store plain-text expenses but needs technical metadata for authorization, ordering, abuse prevention, and troubleshooting.

4. Purposes and legal bases

  • providing app functions for groups and expenses under the user contract
  • synchronizing data between authorized group members under the user contract
  • security, abuse prevention, and troubleshooting based on legitimate interests
  • support communication based on the user's request
  • optional consent where future push, analytics, or similar optional features are enabled

5. Recipients and service providers

Even may use Supabase for synchronization and technical infrastructure. App store providers process data independently for installation, updates, and optional purchases.

The Supabase Data Processing Addendum incorporates the EU Standard Contractual Clauses for transfers covered by them. Supabase may process data wherever Supabase or its subprocessors maintain facilities; where a region is selected, data is stored and primarily processed there unless an exception applies.

Data is not shared for ad profiling. Even does not sell personal data.

Supabase Data Processing Addendum

6. Retention and deletion

Local data remains on the device until users delete it in the app or remove app data.

Synchronized data is stored only as long as needed for group functionality, security, and traceability, or until a deletion function is used.

7. Data subject rights

Data subjects may request access, rectification, deletion, restriction, portability, and objection. Consent can be withdrawn at any time with future effect.

A complaint may also be lodged with a data protection supervisory authority.

8. Contact

Privacy questions can be sent using the contact details in the legal notice.