Privacy policy
Even app
As of: August 2026
This privacy policy explains how the Even app processes personal data in connection with groups, shared expenses, and synchronization.
1. Controller
The controller is Sebastian Taatz Consulting UG (haftungsbeschraenkt). Contact and registry details are available in the legal notice.
2. Data processed
- local app data such as group name, member name, expenses, shares, balances, and settings
- technical sync data such as group ID, event ID, timestamps, sender ID, and event type
- encrypted content data when a group is synchronized across devices or members
- store and device information provided by the app stores for installation, updates, or optional purchases
- support data when users actively contact us
3. Local storage and synchronization
Even is designed local-first. Many data points are stored and processed on the device first.
When group synchronization is used, events are sent to Supabase in encrypted form. The server does not store plain-text expenses but needs technical metadata for authorization, ordering, abuse prevention, and troubleshooting.
4. Purposes and legal bases
- providing app functions for groups and expenses under the user contract
- synchronizing data between authorized group members under the user contract
- security, abuse prevention, and troubleshooting based on legitimate interests
- support communication based on the user's request
- optional consent where future push, analytics, or similar optional features are enabled
5. Recipients and service providers
Even may use Supabase for synchronization and technical infrastructure. App store providers process data independently for installation, updates, and optional purchases.
The Supabase Data Processing Addendum incorporates the EU Standard Contractual Clauses for transfers covered by them. Supabase may process data wherever Supabase or its subprocessors maintain facilities; where a region is selected, data is stored and primarily processed there unless an exception applies.
Data is not shared for ad profiling. Even does not sell personal data.
6. Retention and deletion
Local data remains on the device until users delete it in the app or remove app data.
Synchronized data is stored only as long as needed for group functionality, security, and traceability, or until a deletion function is used.
7. Data subject rights
Data subjects may request access, rectification, deletion, restriction, portability, and objection. Consent can be withdrawn at any time with future effect.
A complaint may also be lodged with a data protection supervisory authority.
8. Contact
Privacy questions can be sent using the contact details in the legal notice.