Privacy policy
This policy describes which data Arroz handles, where it lives, who can see it and what you can do about it. It covers the iPhone app and this site.
Last updated
In short
Arroz does two things that stay apart, and they are handled differently. The Split tab needs an account, because the bills are shared with other people: its data lives on a server. The Month tab is your personal budget, and its contents never leave your iPhone.
- If you never create an account, there is not a single row about you on our server.
- The app records usage anonymously, to know what to improve — never the content of what you write — and that can be switched off under Profile.
- There is no advertising, no advertising tracker, and no selling of anyone's data.
- You delete your account from inside the app, without asking anyone.
Who is responsible
The processing described in this policy is carried out by Santos Nascimento Ltda.
To raise anything about personal data — exercising your rights, asking a question or making a complaint — write to support@arroz.app.
What goes to the server
Data from the Split tab lives in a Postgres database managed by Supabase. It only exists for people who create an account and use that tab.
| Data | Where it comes from |
|---|---|
| Account identifier and email | From Sign in with Apple. If you choose to hide your email, Apple hands over one of its own relay addresses, and that is what we store — the real address never reaches our server. |
| Display name | Typed in by you, or taken from Sign in with Apple the first time. |
| Groups | Name, type (household or trip) and the six-letter code. |
| Group members | Each participant's name, including people added without having the app. |
| Expenses | Description, amount, date, who paid and how it was split. |
| Settlements | Who paid whom, how much and when. |
| Group history | Who logged, edited or deleted what, and when. |
| Notification token | Only if you turn alerts on. It identifies the device, not the person. |
Usage analytics
To know what to improve, what is confusing and where something breaks, the app records how it is used. That recording goes to PostHog. The app does not use their library, or anyone else's: it sends each event itself, and there is not a single line of third-party code running inside it.
This site counts visits too
Every page opened here is counted in the same PostHog: the path, the language and where the click came from. No cookie and no third-party library — the site sends it itself, with an identifier that lasts as long as the browser tab. Close the tab and it is gone: on a second visit you are someone else to the count. If your browser asks not to be tracked, nothing is sent.
What is recorded in the app
- Actions the app fires deliberately, one by one: that the app was opened, that an entry was created — with its type, income or expense, and whether it had a category —, that a recurring rule was created, that a group was created, that an expense was split and among how many people, and that an account was created or deleted.
- The app version, the build number and the iOS version — that is what separates a bug that only happens on one specific version. The device model is not sent.
- The IP address of the connection, which is stored alongside the event and from which the service infers an approximate location — country, city, region and time zone. No precise location is collected, and the app never asks your iPhone for location permission.
What is never recorded
- No amounts and no descriptions. The record says an expense was created; never how much, for what, or with whom.
- No names — neither yours nor those of the people in your groups.
- Nothing from the contents of the Month tab. The recording covers both tabs, but only counts usage: that an entry was created, never what is written in it.
- No screen recording and no automatic capture of taps. Every recorded event is written in the app's code, one by one.
The record is not tied to you
The identifier used is generated on the device itself and bears no relation to your account, your email or your name. It cannot be used to work out whose usage it is.
What never leaves your iPhone
All the contents of the Month tab — entries, categories, accounts and recurring rules. They sync through the private iCloud of your own Apple account, encrypted by Apple, between your devices. Not even we can reach them.
The usage analytics described above cover this tab, but only count that it was used — never what is written in it.
Your chosen language, the theme, the Face ID lock preference, the choice to share usage data or not, and your sign-in session — kept in the iOS Keychain — also stay on the device.
What the app does not do
- It has no advertising tracker, no ad SDK and no third-party library at all. The only thing sent out is the usage analytics described above, and it can be switched off.
- It shows no ads and sells nobody's data.
- It does not ask for contacts, location, camera, photos, microphone or calendar.
- It does not ask for anyone's email to invite them: invitations are a code, typed in by the person themselves.
- It does not move money and stores no card or bank account details.
Who can see what
The database enforces row-level access control, and it was verified with separate test accounts.
- You only see groups you belong to. Before joining, you cannot even read the group's code.
- Inside a group, every member sees the same expenses, balances and history — that is the point of the product.
- Nobody, not even the person who created the group, can edit or delete the history.
- Each person only sees the notification token of their own device.
Why we handle each piece of data
- Account identifier and email — to authenticate you and connect you to your groups. Without it there is no account.
- Name, groups, expenses and settlements — this is what the product is for: without them there is nothing to split.
- Group history — so members can check what changed in an account that belongs to all of them.
- Notification token — it only exists if you turn alerts on, and it goes away when you turn them off.
- Usage record — to know what to improve and what to fix. It is anonymous, and you can switch it off under Profile.
How long we keep it
Your account data stays for as long as the account exists. A group's expenses and history stay for as long as the group exists, because they are other people's balances.
The notification token is deleted when you turn alerts off or delete your account.
Usage events are kept in PostHog for 12 meses. Because they are not tied to your account, deleting the account does not reach them — there is no way to find them starting from you.
How to delete your account
You can delete your account from inside the app, under Profile. You do not have to ask anyone, and it cannot be undone. What happens:
- The account, the profile and the device tokens are deleted.
- Your name stops appearing, and your spot in the group becomes a vacant spot.
- The expenses you logged stay, because they are part of the other members' balances.
What is in the Month tab is not deleted here — it lives in your iCloud, and goes away with the app if you uninstall it.
Where the data is hosted
The database is hosted by Supabase, in the sa-east-1, em São Paulo region.
Usage analytics events are held on PostHog Cloud, in the United States. That is an international data transfer: they leave Brazil and become subject to the law there.
Your rights
Brazil's General Data Protection Law (LGPD) grants you, among others:
- confirmation that we process your data, and access to it;
- correction of incomplete, inaccurate or outdated data;
- portability of your data to another provider;
- erasure of data processed with your consent;
- information about who we share your data with;
- withdrawal of consent at any time.
Correction and erasure are self-service: you change your name and delete your account inside the app, at any time. Sending usage data is also switched off under Profile, without having to ask anyone. For anything else, write to support@arroz.app.
Minimum age
Arroz is intended for people aged 4 anos and over, matching the age rating registered on the App Store.
Changes to this policy
When the text changes, the date at the top of this page changes with it. Any change that materially alters what we handle, or why, is announced inside the app before it takes effect.
Contact
For anything about this policy or about your data: support@arroz.app. For questions about using the app: support@arroz.app.