Privacy Policy
Effective August 20, 2026 · Last updated August 20, 2026
Overview
Halver ("Halver," "we," "our") is operated by CloudPath, LLC. We built Halver with privacy as a core principle. Your receipt is read on your phone, not on our servers — no cloud text-recognition service ever sees it. Money never flows through us. There are no advertising or tracking companies in Halver, and we do not sell your data.
Halver is sold and marketed in the United States, and our servers are in the United States. Anyone with a link can join a session from anywhere, and if you do, your information is handled under this policy and under United States law. If you live in California, your rights are set out under "Your California Privacy Rights" below — and we honour those same rights for everyone, wherever they live.
Roles
Halver has three kinds of user, with different data flows:
- Host. Uses the iPhone app to scan a receipt, share it with guests, track claims and confirm payments. Signs in with Apple or Google. Receives email when a session closes.
- App guest. Someone with the Halver app who joins a host's session and signs in. They see the receipt photo, claim their items, and receive their own settlement email. A host can also hand a receipt of their own to the session, in which case they are a contributor and other people owe them directly.
- Web guest. Joins from any browser using a link or a QR code — no account, no install. Types a display name, claims items, and follows a link into their own payment app. Web guests never see the receipt photo, because seeing it requires signing in and the web page has no way to sign in.
Receipt Photos and OCR
When the host photographs a receipt, the photo is read entirely on the phone using the system's own text recognition. Specifically:
- No recognition service ever sees your receipt. Not ours, not a third party's. If the on-device reading comes back poor, there is no cloud fallback — you are asked to retry or fix the items by hand. This has not changed and will not change without notice.
- The photo is uploaded in one case only: once another Halver app user actually joins your session, so they can see the same receipt and tap their own items. If you are splitting alone, or everyone joined from a browser, the photo is never uploaded at all.
- When it is uploaded, it goes straight from your phone into our storage — it never passes through our servers and never appears in any log. To download it you must be signed in and be on that session's participant list. Web guests cannot fetch it. The storage itself refuses to hand the image to anything except the three small pieces of our software that need it; there is no console or command-line route for us to look at it.
- It is deleted when the session closes. At close it is read once, to attach it to the settlement emails described below, and then deleted. An automatic sweep removes anything missed, normally within a day.
- Copies stay on the phones that saw it. Your own copy stays in Halver's private storage on your phone as part of your history. App guests who viewed the receipt keep a copy on their phone too. Those copies are yours; closing the session does not remove them.
Authentication
You sign in with Apple or with Google. We check the identity token against that provider's public keys, then map their ID for you to an internal user ID we generate. We store:
- Which provider you used and that provider's ID for you — so we recognise you next time.
- An internal user ID we generate, used to link your sessions.
- The email address the provider gave us the first time you signed in, plus a lower-cased copy of it used only to notice when the same person signs in twice with different providers.
- The display name you choose.
- Your saved payment-app handles.
- The separate "send my receipts here" address described in the next section.
We do not store passwords, photographs, or phone numbers.
Email — Address, Use, and Opt-Out
This section covers everything we do with email addresses.
How we get your address. The first time you sign in, Apple or Google gives us the email tied to that identity — with Apple this is usually a private relay address, not your real one. We store it as the starting default. You can change where Halver actually sends at any time in the app's Settings; the change applies immediately.
Web guests do not give us an email. There is no email field in the browser guest page. If you join from a browser, we have no way to email you.
What we send. Transactional email only — never marketing, never newsletters. There are three kinds:
- Settlement email at session close. When a session closes, everyone with an address on file gets an email covering the meal: restaurant, date, line items, what each person owes, and whether they have paid. Where a photo was taken, the receipt image is attached.
- A bill to someone who does not use Halver. A host can add a guest by typing their email address. That person gets one email with their share of the bill, and the receipt image where one exists. Every such email carries a link to stop receiving them.
- A confirmation link when you add a forwarding address in Settings. That email contains only the address being confirmed and the link.
Each person only gets their own receipts. If a meal has several receipts from several people, your email carries the items — and the photo — for the receipts you were actually on, and nothing from the others.
Who delivers it. Resend, an email delivery company. Resend receives the address, the contents of the email, and the attached receipt image, in order to deliver it. No other email vendor, no marketing platform, no enrichment service.
Addresses we do not keep. When a host types in the address of a guest who does not use Halver, we send the bill and then forget the address — it is not stored anywhere, and it never becomes an account. If that person uses the link to stop the mail, we keep a scrambled, one-way fingerprint of their address and nothing else, kept permanently so that we keep honouring it.
Opting out. Clear the receipt-email field in the app's Settings and we stop emailing you. People who were sent a bill without having an account use the link in the email. There is no separate unsubscribe link on the others, because these are transactional and the in-app control is the real switch.
Retention. We do not keep the contents of an email after sending it — your mailbox holds the lasting copy. Delivery and bounce events are recorded in our operational logs for 30 days so we can tell whether mail is getting through.
Forwarding Receipts by Email
You can forward receipt emails to an address Halver gives you, instead of photographing a paper receipt. This is optional, and it only works from email addresses you have added and confirmed in Settings — so nobody else can push things into your Halver inbox.
When a forwarded email arrives, our system pulls out the attachments and the message body as raw files and stores them. It does not read them, parse them, or try to work out what the receipt says — your phone does that when you next open the app. Alongside the files we keep a short record so your phone knows something is waiting; that record includes who sent it and the subject line.
The files are deleted automatically after 24 hours, and sooner than that once you attach the receipt to a session. The short record expires after 7 days, so your phone can still tell you that you missed something after the files themselves are gone.
We do not put the sender, the subject, the file names, or any receipt content into our logs. One exception we would rather state than hide: when you add a forwarding address in Settings, that address is written into our operational logs, which are kept for 30 days.
Session Data
For each meal we store:
- The line items, totals, tax, tip and fees taken from the receipt.
- Display names, item claims and per-person totals for everyone in the session.
- Payment status for each person, as marked by whoever is owed.
- Where a session has several receipts from several people, the name and payment handles of each contributor as they stood when that receipt was added.
- The restaurant's name, address and coordinates.
When a session closes, guests who never signed in are added together into a single anonymous line rather than kept as individual records.
Closed sessions are kept indefinitely so that you can look back at past meals. A session you start and never close is deleted automatically four hours after the last activity.
Web Guest Data
The browser guest page runs on Cloudflare's network. We collect only what is needed to take part in the session you joined:
- The display name you type.
- The items you claim.
There is no email field, no account, and nothing to install. Your browser keeps one small marker — a random ID it makes up itself — so that returning to the same session on the same device recognises you as the same guest. Nothing else is stored in your browser: no cookies, no tracking, and no scripts from any other company.
Cloudflare and Amazon see your IP address and browser details in the course of delivering your requests, as any website's infrastructure does. We do not record your IP address in our own logs.
Notifications
If you allow notifications, we store the token your iPhone gives us so we can reach it, and these go through Apple's push service. We delete a token 90 days after the app last ran.
The notifications themselves are deliberately empty of detail. They carry a fixed line of text, the session's ID, and what kind of event happened. No names, no amounts, no restaurant, no items. Apple and Google can see that we sent you a notification and when, but not what it was about.
Location
If you allow it, the iPhone app uses your location once, at the moment you scan, to work out which restaurant you are in. It asks Apple's Maps to do that lookup on the device.
Two pieces of location do reach us, and we would rather say so than imply otherwise:
- We send our server a short code standing for a roughly 150-metre square around you, paired with the restaurant name, so that the next person who scans in the same place does not need a fresh lookup. That entry is not attached to your account or to anyone's, and it is deleted after 90 days.
- The coordinates of the restaurant you picked are saved with the meal.
You can use Halver without giving it location at all; you then type the restaurant name yourself.
Payments
Halver does not process payments. When a guest is ready to pay, Halver opens a deep link to their preferred payment app (Venmo, Cash App, PayPal, etc.) with the amount pre-filled, or copies the host's handle for Zelle® payments, which have no such link. Payment happens entirely in that third-party app, between guest and host. Halver never sees or stores your card number, bank account, or payment-app credentials. Confirmation that payment was received is recorded by the host manually inside Halver.
Crash and Usage Data
The iPhone app sends one automatic message to TelemetryDeck, an analytics company, when the app starts and again when you come back to it after a long gap. That message contains a one-way scrambled version of the identifier Apple gives Halver for your device, along with your device model, iOS version, Halver's version, your language and region, and whether this is a test build.
That is the whole of it. Halver sends no other measurements. Nothing about receipts, restaurants, amounts, items or people is ever sent. TelemetryDeck does not receive an advertising identifier, and Halver does not track you across other apps or websites. We do not use Facebook Pixel, Google Analytics, AppsFlyer, Adjust, or any attribution SDK.
The browser guest page sends no usage data at all.
Third-Party Services
Halver relies on these outside services:
- Apple — Sign in with Apple; Apple Maps for the restaurant lookup, which happens on your device; Apple's push service for notifications; and the on-device text recognition that reads your receipt.
- Google — Sign in with Google, if you choose it. Google confirms who you are and gives us the email tied to that account. It does not receive bill contents, names, amounts, restaurant names, or session data.
- Amazon Web Services — our infrastructure. Our servers, databases and file storage all run in CloudPath's own AWS account.
- Cloudflare — serves the browser guest page, and passes forwarded receipt emails through to us as raw bytes without opening them.
- Resend — delivers our email. Resend receives the recipient's address, the contents of the email, and the attached receipt image.
- TelemetryDeck — the one automatic launch message described above, from the iPhone app only.
We do not sell your information, and we do not share it for advertising.
How Long We Keep Things
| What | How long |
|---|---|
| Your account | Until you delete it. There is no automatic expiry. |
| A meal in progress | Deleted four hours after the last activity if it is never closed. |
| A closed meal | Kept indefinitely. |
| Receipt photo on our servers | Deleted when the session closes; swept automatically, normally within a day, regardless. |
| Receipt photo on your own phone | Until you delete the meal from your history. |
| Forwarded receipt files | 24 hours, or sooner once you attach the receipt. |
| Forwarded receipt records | 7 days. |
| Forwarding addresses you confirmed | Until you remove them. Unconfirmed ones expire after 7 days. |
| Notification tokens | 90 days after the app last ran. |
| Restaurant lookup cache | 90 days. |
| "Do not email me" fingerprints | Kept permanently, so that we keep honouring them. |
| Server logs | 30 days. |
Deleting Your Account
Open Settings in the iPhone app and choose Delete my account. You do not have to email anyone, and it happens immediately.
What goes: your account and sign-in record, every meal you created along with its receipts, claims, participants and photos, your notification tokens, anything waiting in your forwarding inbox, and your forwarding addresses.
What stays: if you took part in someone else's meal, the name and payment handle you were showing at the time, and the items you claimed, stay in that person's record of the meal. We cannot remove those without destroying another person's copy of a bill you were both part of. Your sign-in is gone, so nobody can get back into the account, but that historical entry remains. Your contributions to other people's meals have your name and ID stripped out and become an anonymous line.
Children's Privacy
Halver is not directed at children and is rated 4+. We do not knowingly collect information from children under 13.
Your California Privacy Rights
Halver is sold and marketed in the United States. The California Consumer Privacy Act gives California residents the rights below, and we honour them for everyone, wherever they live.
- The right to know what we hold about you. Write to us and we will tell you, and send you a copy.
- The right to delete. Use Delete my account in the app, or write to us. We finish within 45 days.
- The right to correct anything wrong. Your name and email are editable in Settings; for anything else, write to us.
- The right not to be treated differently for exercising any of these. Halver works exactly the same either way.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. There is no "Do Not Sell or Share My Personal Information" link on this site because there is nothing to opt out of.
If you use an authorised agent, we will ask for proof that you gave them permission.
We answer within 45 days and will tell you if we need another 45.
Data Security
Everything between Halver and our servers travels over an encrypted connection, and the storage refuses unencrypted connections outright. Data is encrypted at rest in our databases and file storage. Access to production systems is restricted, and routine troubleshooting is done from summarised logs rather than by reading user records.
Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of Halver after changes constitutes acceptance of the updated policy.
Contact
If you have questions about this privacy policy, contact us at:
support@gethalver.com
CloudPath, LLC
Chicago, Illinois