Effective 9 August 2026
Privacy
This notice explains what Schism handles, why it is used, and the controls available to you.
What stays on your device
By default, receipt images, receipt OCR text, voice audio and supported transaction SMS are processed on your device and are not sent anywhere. SMS understanding is disabled unless you explicitly opt in and grant Android permission. Raw SMS, OCR text and voice audio are never sent to the Schism service under any setting. You review parsed details before choosing whether to create or share an expense.
Cloud receipt reading, if you turn it on
Settings offers an optional cloud reader that is off unless you choose it. It exists because a large vision model reads a crumpled or dimly lit bill more accurately than a model small enough to run on a phone. Turning it on means the receipt photo leaves your device. You are told this and must accept it before the first cloud scan, and you can switch back to on-device reading at any time.
There are two ways to use it, and they send your photo to different places:
- Your own API key. You paste a Google (Gemini) or Groq key into Settings, and the photo goes from your phone straight to that company under your own account. It does not pass through Schism, and we never see it or your key. Their terms and privacy policy govern what they do with it.
- Schism's cloud reader. The photo is sent to the Schism service, which forwards it to Google or Groq for reading and returns the result. Schism does not store the image: it is held in memory for the length of the request and discarded. It is not written to disk, not written to the database, and not recorded in logs. The provider still receives the image, under their terms.
Either way, only the parsed result — merchant, items, amounts — becomes an expense, and only if you choose to save it. Choosing on-device reading, the default, means no receipt image ever leaves your phone.
What uses the Schism service
To provide accounts and shared groups, Schism processes your account name, email address, optional phone number, authentication and session data, group membership, expenses, splits, balances, invitations, item claims, and related activity. Other members of a shared group can see the group information needed to collaborate.
When the app downloads an optional OCR model, the request can include ordinary network metadata such as IP address, time, requested model version, and user agent. Receipt content is not part of that request.
Other services your device may contact
Schism asks our service which OCR model to use, and that request is then redirected to Hugging Face, where the published model files are hosted. Your device downloads the model from Hugging Face directly, so Hugging Face receives ordinary network metadata such as your IP address and the file requested. No receipt image, receipt text, or message content is involved.
Builds installed outside Google Play check the public GitHub Releases page for a newer version, which means GitHub receives ordinary network metadata for that request. Builds installed from Google Play do not make this request; Google Play handles their updates.
When you choose to settle up using a UPI app, Schism hands the payment amount and note to whichever UPI app you pick. Schism does not process the payment and never receives your payment-card or bank credentials.
Purchases, ads, and consent
For a Google Play subscription, Schism may receive and verify a Google Play Billing purchase token, product identifier, and subscription status to provide entitlement and prevent fraud. Schism does not receive your payment-card details.
The Play-distributed app includes Google Mobile Ads and the Google User Messaging Platform. Depending on your choices, region, and Google’s processing, these SDKs may collect or share IP-derived general location, app interactions, diagnostics, and device or account identifiers for advertising, analytics, consent management, security, and fraud prevention. Where required, the app asks for consent and provides Privacy choices in Settings.
Why, how long, and with whom
We use this data to operate accounts, sync shared expenses, calculate balances, verify purchases, prevent abuse, provide support, and meet legal obligations. Service data is encrypted in transit. It is handled by infrastructure and service providers needed for those purposes and is not sold. We do not sell your personal data.
Account and shared data is kept while your account is active. When you delete your account, that data is deleted or de-identified straight away, and backup copies containing it are purged within 30 days. Records we are required by law to keep are retained only for as long as that obligation lasts. Schism is operated from India and your data is processed there.
Your controls
You can leave SMS import off, revoke Android permissions, use manual or receipt entry instead, change applicable ad Privacy choices in the app, and delete your account. Contact dev.keshwani345@gmail.com with privacy questions.