Even

Privacy Policy

Last updated August 2026

Arkley Interactive LLC (“we,” “our,” or “us”) builds and operates the Even mobile application (the “App”), and we’re the ones you should contact about how it handles your data. This Privacy Policy explains what we collect, why, and what say you have over it when you use Even to share and split expenses. It covers the Even app specifically; for how our company website handles information, see our company Privacy Policy. Reach us at hello@arkleyinteractive.com with questions or to exercise any of the rights below.

1. Information We Collect

  • Account Information: When you create an account, we collect authentication data via Sign in with Apple and Sign in with Google (including your name and email address).
  • Transaction & Expense Data: We collect expense amounts, descriptions, group names, and images of receipts uploaded for AI parsing.
  • Technical Data: We securely process transaction data through our backend infrastructure powered by Supabase and Supabase Edge Functions.
  • Receipt Images (AI Parsing): When you scan a receipt, the image is sent through our Supabase Edge Functions to Google’s Gemini API, which reads the image and returns the itemized data. Google processes this image content as described in the Gemini API Additional Terms of Service.
  • Diagnostic & Crash Data: We use Sentry to collect crash reports and error diagnostics (such as device type, OS version, and app state at the time of an error) so we can identify and fix bugs.
  • Sign-In Codes: When you sign in by email, we use Resend to deliver the one-time passcode to your inbox; Resend processes your email address and the code solely to send that message.
  • Bot Protection: We use Cloudflare Turnstile to protect sign-in from automated abuse. Turnstile may collect technical and interaction data as described in the Cloudflare Turnstile Privacy Policy.

2. How We Use Your Information

We use the collected data to facilitate group expense splitting, execute AI-driven receipt parsing, maintain account synchronization, diagnose and fix errors, and provide user support. We do not sell your personal data.

Account, transaction, and expense data are processed on the basis of performance of a contract — we need this data to provide Even’s core functionality. Diagnostic, crash, and bot-protection data are processed under our legitimate interest in preventing abuse and fixing problems with the App.

3. Recipients & Third-Party Processors

A handful of outside companies help us run the App, each limited to a specific job:

  • Supabase — backend database, authentication, and Edge Functions used for expense and receipt processing.
  • Google (Gemini API) — reads scanned receipt images to extract line items.
  • Sentry — crash and error diagnostics.
  • Resend — delivery of one-time sign-in codes by email.
  • Cloudflare — bot protection (Turnstile) during sign-in.
  • Apple and Google — Sign in with Apple and Sign in with Google authentication.

These companies operate infrastructure in multiple countries, including the United States, so your data may be stored or processed there rather than in your home country. Our contracts with them obligate them to protect your data to a standard consistent with this policy, using mechanisms such as Standard Contractual Clauses where applicable.

4. Data Retention & Deletion

We retain your data for as long as your account is active. Users have the right to request the deletion of their accounts and all associated transaction history at any time. Account deletion requests can be initiated directly within the App settings or by visiting our Data Deletion Request section below.

Shared & Collaborative Data: Even is a collaborative platform for group expense sharing. When you participate in an expense group created by another user, the transaction logs, group data, and receipts are associated with that group. Requesting the deletion of your account will permanently wipe your personal profile and credentials. However, to preserve the financial integrity of shared groups for other active users, any expenses or groups you participated in will remain intact, and your identity within those groups will be permanently anonymized to a non-identifiable placeholder name (e.g., “Guest”).

5. Your Rights

Depending on where you live, you can ask us to:

  • send you a copy of the personal data we hold about you;
  • fix inaccurate account or profile information;
  • delete your data (see Section 4 for how deletion interacts with shared groups);
  • pause or limit specific processing, or object to it; and
  • undo any prior consent you gave us, going forward.

Email hello@arkleyinteractive.com to make any of these requests — we may need to confirm it’s really you before acting on it. If you’re unhappy with how we’ve handled a request, you’re entitled to raise it with the data protection regulator in your country.

6. Security

We lean on the encryption, access controls, and monitoring built into our infrastructure providers rather than rolling our own, since that reduces the surface area for mistakes. Even so, nothing sent over the internet or stored on a server is risk-free, so treat your account credentials the way you would any other financial login.

7. Children’s Privacy

Even isn’t built for children, and we don’t knowingly let anyone under 16 create an account. If you find out a child has done so anyway, email hello@arkleyinteractive.com and we’ll remove their data.

8. Changes to This Policy

This page reflects our current practices, and we’ll edit it as the App changes — the date at the top always tells you when that last happened. If a change meaningfully affects how we handle your data, we’ll also flag it inside the App rather than leaving it to this page alone.

Data Deletion Request

Email hello@arkleyinteractive.com from the address associated with your account with the subject line “Account Deletion Request.” We’ll delete your account and associated data as described above within 30 days.

This permanently deletes your personal profile, credentials, and login access. Expenses and groups you shared with other active users are kept so their records stay intact, but your identity within those groups is anonymized to a non-identifiable placeholder name (e.g., “Guest”).

A self-service deletion form will replace this process in the future.