Purpose
Split Pea is an iPhone app for one household. It helps people see who paid which bills, what income and debts the house carries, and where extra payments go. It is not a bank, not credit reporting, and not a public scoreboard.
Privacy
This is a product disclosure of what Split Pea actually stores and shares. It is written in household language and aligned with PIPEDA-style ideas (purpose, limited collection, household sharing, safeguards, access). It is not a lawyer-stamped privacy policy. Last updated 21 September 2026.
Split Pea is an iPhone app for one household. It helps people see who paid which bills, what income and debts the house carries, and where extra payments go. It is not a bank, not credit reporting, and not a public scoreboard.
You type it. The app does not log into a bank. Typical records: first name, optional email if you sign in, optional profile photo, Sign in with Apple identity when you use it; household name, invite, and how you split; bills, income, debts, extra payments, savings goals, a settlement log when a bill is marked paid, optional notes; quiet pulses and an activity log of what changed in the house. Optional scan: a statement photo or PDF. The phone reads it first. You confirm before anything is saved. If a dense PDF has no amount the phone can use, extracted text may be sent to a server function so we can suggest a title, amount, and due date. That text is not kept as a statement archive. Reminders, if you allow them, are scheduled on this phone.
No bank login, no Plaid, no ongoing statement scraping. No advertising identifier, no ads, no tracking SDK in this app. We do not sell household numbers.
Members of that household. You add people, or they join with the household invite. Anyone in the house can see the same bills, debts, income, goals, and notes. Leaving the household removes that person’s membership so they no longer read that house.
On device with SwiftData. A small widget snapshot (this week’s extra and a couple of upcoming dues) can sit in an App Group — not the full ledger, and no network from the widget. If you sign in, the house syncs to Supabase (Postgres). Auth is Sign in with Apple or email and password. Row-level security is written so only members of a household can read that household’s money tables. Optional avatars sit in a private storage bucket, readable by household members, not a public URL. Transport is TLS.
Cloud rows are scoped by household membership. Avatars are in a private bucket. There is no analytics or ads SDK. Signing out forgets the household on that phone. Optional Face ID, Touch ID, or device passcode lock stays on the phone. We never receive a face or a passcode.
Read everything in the app. Sign out on this phone. Leave the household. Delete account in Settings: removes your login and this phone’s copy. A partner keeps the house. If you used Sign in with Apple, you can also stop sharing in iPhone Settings. You can clear bills, income, debts, extras, and savings goals from Settings.
Questions about this disclosure: contact@splitpea.ca. If collection ever changes, we update this page — we do not invent extra collection here.