Skip to main content
Nauro
PrivacyTermsSecuritySupport

Privacy

Nauro Privacy Policy

Publication status

Published version

Version
privacy-2026-09-13.1
Effective
September 14, 2026

What we collect, why we need it, who can see it, and the choices you have across Nauro’s website and Nauro Split.

On this page
  1. Who we are and scope
  2. Information we collect
  3. Why we use information
  4. Account agreements
  5. Receipts, photos, and AI
  6. People and shared bills
  7. Service providers
  8. Subscriptions and payments
  9. Website storage and cookies
  10. Email, support, and notifications
  11. Retention and deletion
  12. Your choices and privacy rights
  13. Security and international processing
  14. Children
  15. Changes to this policy
  16. Contact Nauro

1. Who we are and what this policy covers

Nauro LLC operates Nauro from Massachusetts. In this policy, “Nauro,” “we,” “our,” and “us” refer to that operator.

This policy covers nauro.app, the Nauro Split iOS and Android app, shared-bill pages, our beta program, and related service interfaces, support, and communications that link to this policy. It also explains how we handle information about guests and other people added to bills, even if they do not have a Nauro account.

Future Nauro products may have additional notices. A product that uses information differently will explain those practices before the new processing starts. Third-party services you visit, including app stores and payment apps, have their own privacy policies.

2. Information we collect

We receive information from you, people who include you in a bill or group, your device and browser, and providers that help us run the service. Not every feature collects every category below.

On a small screen, scroll the table horizontally to read all columns.

CategoryExamplesWhere it comes from
Account and profileAccount ID, sign-in email, name, username, profile color, preferences, and optional contact or payment-handle information you provide.You and your Apple, Google, or email sign-in provider.
People and shared expensesFriends, requests, groups, guest names and optional guest email or phone, bill names and dates, items, quantities, amounts, allocations, payer information, comments or activity, and reported payment status.You and other people using Nauro.
Receipts and recognition resultsSelected receipt images and thumbnails; merchant and purchase details, including addresses; item descriptions, prices, tax, tip, totals, currency; recognition results, original model responses, and corrections.Photos you select or take, AI recognition, and your edits.
Device and service activityInstallation and capture identifiers, platform, app version, sign-in and feature-use timestamps, scan and usage counters, notification preferences, and push tokens.The app, device, and service providers.
SubscriptionsStore, product, purchase and renewal information, entitlement status, transaction references, and purchase-restoration information.Apple, Google, and RevenueCat.
Technical and diagnostic informationIP address, browser or device information, request timing and status, error messages, stack traces, support codes, and app/build identifiers. Error details may contain information involved in the failed operation.Your connection, app, browser, and hosting services.
Support and privacy requestsEmail address, selected topic, subject, message, optional support reference, and request-processing or verification correspondence.You and our correspondence with you.
In-app crash feedbackAn optional note and screenshot you choose, submission and crash identifiers, crash time and when feedback is received, error messages and stack traces, support code, platform, and app/update information.You and the app when you choose to send feedback after an error.
Beta signupEmail, optional preferred platform, signup source, consent record, policy version, and signup and confirmation timestamps.You and the confirmation process.

We do not request access to your device’s address book, microphone, or precise GPS location for Nauro Split. A merchant address printed on a receipt is different from accessing your device location. We do not collect your full payment-card number to process a Nauro Pro purchase.

Please provide only information needed for a split or request. Avoid uploading identity documents, medical records, account passwords, full card or bank-account details, or unrelated sensitive information. A receipt can contain personal information, so check the entire image before uploading or sharing it.

3. Why we use information

  • Create and secure accounts, authenticate sign-ins, and provide account settings.
  • Create, synchronize, calculate, organize, and share bills; manage participants; and show changes and user-reported payment status.
  • Recognize receipts, preserve images where the feature supports it, apply corrections, and troubleshoot recognition or calculation errors.
  • Provide purchases, restore access, maintain entitlements, and apply plan limits and abuse protections.
  • Deliver requested reminders, notifications, beta invitations, service messages, and support.
  • Diagnose crashes, operate infrastructure, prevent fraud and unauthorized access, and investigate misuse.
  • Respond to privacy requests, comply with applicable law, maintain necessary business records, and protect or defend legal rights.

We do not sell personal information or share it for cross-context behavioral advertising. We do not use receipt content to build advertising profiles or train a Nauro general-purpose AI model. Optional third-party advertising, session replay, and general website analytics tools are not currently enabled. Operational diagnostics and service-provider processing still occur.

Where a law requires a legal basis, the relevant basis may be providing a service you request, our legitimate interests in operating and protecting the service, compliance with law, or consent for a particular optional activity. We request consent when required; using Nauro is not blanket consent to unrelated uses of your information.

3a. Account agreements

When you explicitly accept published Terms, we record your account reference, the Terms and Privacy Notice versions presented, the applicable eligibility requirements and your confirmations, and the server receipt time. If eligibility depends on residence, we record the country you select. We do not ask for your full date of birth or identity documents as part of this confirmation. A Privacy Notice acknowledgement is not permission for unrelated processing.

Limited agreement evidence may remain after account deletion where needed to establish the applicable agreement, handle a dispute, or meet a legal obligation. These records are not a verification of your identity or an independent verification of age or residence.

4. Receipts, camera access, and AI processing

You can enter a bill manually. If you choose receipt recognition, the selected image and processing identifiers are uploaded to Nauro and sent to an AI provider to extract receipt details. A draft bill can remain unsaved while its receipt image has already been uploaded for scanning.

Nauro uses OpenAI’s API for receipt recognition in the current release configuration. Some environments support Microsoft Azure OpenAI. These services process the submitted image and instructions and return recognized data. Their business terms and configured safety and retention controls apply to that processing. We do not promise zero provider retention: completing a scan or deleting a Nauro bill does not mean every provider copy immediately disappears. Provider availability can also limit AI scanning while you travel.

If you submit a text or image request through a supported Nauro AI interface, the submitted text, conversation context, and image are also sent to the configured AI provider to generate the requested response. This does not give that interface access to unrelated conversations or other content on your device.

Nauro can store an optimized receipt image and thumbnail in Supabase object storage and a local copy in app storage. We also store recognized details, original recognition results, and later corrections. Correcting the displayed bill does not necessarily overwrite the original recognition record. Stored images support receipt review and bill features; retention is explained below.

App versions that include the AI scanning permission control ask before sending a receipt for AI scanning. In those versions, the app stores the decision, account reference, disclosure version, and time on that device; that local permission record is not included in the server export. You can turn off that control in Data & privacy to prevent future scans through it. This does not erase images already submitted.

Older app versions may not show this AI permission prompt or setting. If your version does not include it and you do not want a receipt sent for AI processing, use manual bill entry instead of scanning. Camera and photo permissions are separate from the AI scanning control.

Camera and photo-library permissions are controlled by your operating system. You can decline or revoke them in device settings and use manual entry. Revoking a permission prevents future access through that permission; it does not remove images you already submitted. To request removal of existing receipt information, use the available bill controls or contact us.

Recognition can be inaccurate. Review the image, items, participants, and totals before relying on or sharing a result. Do not submit a receipt you do not have a right to use.

5. People, guests, and shared-bill links

When people split together, Nauro makes relevant bill and profile information available to other participants. This can include display names, items, assignments, totals, reported payment status, and bill activity. A person may add a guest name and optional contact information without creating an account for that guest.

Anyone who obtains an active share link may be able to open the information that link exposes. Depending on the link and feature, this can be one person’s breakdown or the whole bill, including other participants’ display names and amounts. Selecting a name in a group view is not independent proof of that person’s identity. Review the sharing scope before sending a link.

Where receipt viewing is available, authorized viewers may also access the original receipt. A short-lived image URL limits that URL’s access time; it does not set the image’s storage duration. Link creators can revoke supported links. Revocation cannot recall screenshots, downloads, forwarded copies, or information someone has already seen.

Please tell other people when you enter their information, provide only what is needed, and obtain any permission required by law. If someone has entered information about you and you want to question, correct, or remove it, you can contact us without creating an account. We may ask for enough information to locate the record and verify your connection to it.

6. Service providers and other disclosures

We use providers to perform functions for Nauro. The information involved depends on the function:

  • Supabase: authentication, account and application databases, synchronization, and receipt object storage.
  • Google Cloud: application and website hosting, networking, scheduled tasks, and operational logs.
  • OpenAI, or Microsoft Azure OpenAI where configured: receipt recognition, responses to AI requests you submit, and associated safety processing.
  • RevenueCat, Apple, and Google: app-store purchases, subscription status, entitlements, and restoration.
  • Expo, Apple, and Google: mobile build/update services and notification delivery. Push delivery involves device tokens and notification content.
  • Resend and Spacemail, our business email provider: beta confirmation and contact records, support requests, and correspondence.
  • Upstash: temporary confirmation records and security/rate-limit records, which may involve network or pseudonymous identifiers.
  • Cloudflare: website hosting and delivery, network security, and related connection and request information.
  • Cloudflare Turnstile, when enabled on website forms: browser and network signals used to distinguish visitors from bots and protect form submissions. Cloudflare also uses these signals to improve its bot detection under its Turnstile Privacy Addendum.

Authorized personnel may access information when needed to operate the service, troubleshoot a problem, answer a request, or investigate security or misuse. We also may disclose information to professional advisers, in response to valid legal process, to protect people or legal rights, or in connection with a merger, acquisition, financing, or transfer of the business, subject to applicable law and confidentiality protections.

Providers process information under the arrangements applicable to each function; they do not all have the same role. For example, Cloudflare processes Turnstile security signals on our behalf to protect forms, and also processes those signals for its own bot-detection improvements under the Turnstile Privacy Addendum. Apple and Google separately handle their store accounts and billing under their own policies. We do not give providers permission through this policy to use your information for unrelated advertising.

7. Nauro Pro and payments between people

Apple or Google handles payment for an app-store subscription. Nauro and RevenueCat receive purchase and entitlement information, but not your full payment-card details. The store maintains its own transaction and billing records.

Nauro does not hold or transfer money between bill participants. If you choose a supported payment handoff, an external app such as Venmo may receive the recipient handle, amount, and note needed for that action. You decide whether to complete the payment under that provider’s terms. Nauro stores user-reported payment status and organizer confirmation; these are not independent verification by Nauro that funds moved.

8. Website cookies and device storage

Website versions with interactive bill or intake features use essential storage for security and those requested features. The public informational site is static and does not set those application cookies or save interactive preferences. We do not currently load advertising pixels or session-replay tools on either version.

  • Security cookie: where shared-bill, signup, or support forms are available, a random, HttpOnly session credential helps protect those API requests from abuse. It is not an advertising identifier.
  • Guest selection cookie: where group bill views are available, they use a separate HttpOnly credential scoped to the selected bill for up to 30 minutes.
  • Tab session storage: interactive bill views may keep a bill version, support reference, and previous participant total to explain changes between views. Closing the tab session normally clears this storage, subject to browser session-restoration behavior.
  • Privacy preference storage: where a Privacy Choices page provides browser preference controls, it can save an off/off preference for optional analytics and marketing in that browser. This does not submit an account-wide privacy request. The public informational site’s Privacy Choices page provides contact instructions instead.
  • App storage: sign-in credentials use secure native storage. Bill drafts, synchronized data caches, preferences, receipt files, and exports can use other app storage. Not every local record has the same protection or deletion behavior as a sign-in credential.

Forms with Turnstile verification load a Cloudflare security script and frame. Cloudflare can process the IP address, browser and connection characteristics, and website origin. Nauro sends the verification token to Cloudflare for validation; that verification request does not include the email address or message entered in the form. Blocking the verification script can prevent form submission.

Where an interactive sample is available, it uses fictional data and keeps sample assignments in page memory. It does not upload your sample edits or create a real bill. The public informational site’s bill illustration is static and also uses fictional data. Loading either website version still involves ordinary network and hosting information.

Browser privacy signals and collection across websites

Do Not Track: Nauro does not change its essential storage, operational diagnostics, or security processing in response to a browser Do Not Track signal. Optional advertising and general website analytics remain off whether or not that signal is present. A Global Privacy Control signal likewise does not disable essential or security processing. We do not currently sell personal information or share it for cross-context behavioral advertising; if we introduce processing subject to a legally required opt-out signal, we will honor that signal.

Other parties: Cloudflare may receive connection and security information about your visits to Nauro and other websites using Cloudflare over time, including IP addresses and browser or request signals. Cloudflare uses information across its services to operate and improve network security and bot detection. Its Privacy Policy and Turnstile Privacy Addendum explain that processing. This is separate from Nauro using advertising pixels or building advertising profiles, which we do not currently do.

You can manage cookies and storage through your browser or device. Blocking essential storage or verification scripts may affect features. Our Privacy Choices page explains available choices and how to contact us. Where browser preference controls are offered, saving them does not disable providers’ necessary security processing or submit an account-wide request.

9. Email, support, and notifications

Beta signup requires confirmation through a one-time email link before the address is added to the beta contact list. We use the address for the beta communications you requested. You can ask to be removed through our contact form or use the unsubscribe method provided in a marketing message. Necessary account, security, purchase, or request-related messages are separate from marketing.

Website support and account-deletion forms send the information you enter to Nauro through our email provider. These website forms do not accept attachments and reject raw bill links in support messages. Send a short support reference instead of a private link, password, receipt, or payment details. A successful deletion-form submission is a request for follow-up; it does not itself delete the account or verify your identity.

In supported app versions, the error screen lets you send feedback with an optional short note and an optional screenshot selected through the system photo picker. You can preview or remove the image before sending. This feature does not automatically capture or attach your screen. Review the entire image for personal information before choosing to send it. The selected image is resized and compressed, and embedded photo metadata is removed before storage.

Sending in-app crash feedback also includes the error message, available stack traces, support code, crash and submission identifiers, timestamps, and platform/app/update information so we can investigate. This feedback goes directly to Nauro’s private database; it is not sent through your email app or published as a bill or image link. Authorized personnel may access it to investigate errors or handle requests. You can send it without a working account session; its contents may still identify you or other people.

If you enable push notifications, providers receive the device token and message content needed to deliver them. A notification can contain a bill name, amount, or other activity information and may appear on a lock screen. You can manage Nauro notifications and lock-screen previews in the app and device settings.

10. How long information is kept and how deletion works

Retention depends on the information, the feature, whether it remains part of a shared record, and applicable business or legal requirements. We remove information when it is no longer needed for its documented purpose, subject to a legal hold or another applicable retention obligation. Some cleanup is automatic; other records require review or a verified request. We do not apply one automatic expiry period to every category.

  • Accounts and finished bills: finished bills can synchronize to Nauro for both free and paid accounts. Account and saved bill information generally remains while the account or relevant record is maintained, subject to deletion requests and the exceptions below.
  • Receipt images and recognition: linked receipt images, recognition results, and corrections may remain with the account or associated records until removed. Unclaimed pending uploads become eligible for background cleanup after 24 hours. This does not apply to every saved image or raw recognition record.
  • Unconfirmed beta requests: the pending confirmation record expires after 24 hours or is consumed on confirmation. Confirmation emails and delivery records may remain with the email provider; confirmed contacts do not inherit that 24-hour expiry.
  • Support, agreements, security, and purchase records: we review these records according to the purpose and event that justify keeping them, such as closing a request, resolving a dispute, ending an investigation, or meeting a legal recordkeeping obligation. Limited agreement evidence, suppression records that prevent unwanted email, and purchase or usage records may need to remain after other information is deleted. These categories do not all have an automatic expiry and are not all removed when an account is deactivated.
  • In-app crash feedback: the stored note, diagnostic details, and optional screenshot become eligible for background deletion 30 days after receipt. Cleanup runs in batches, so deletion may occur later; this is not a guarantee that separate operational logs or backups expire at the same time. Feedback is stored separately from account records and is not automatically removed by deleting an account. To request access to or deletion of feedback, contact us with the error code and approximate date and time. We may need additional information to locate the report and verify your connection to it.
  • Local copies: drafts, caches, receipt files, and exported files may remain on a device until removed through the relevant app, device, or file controls. Uninstalling or losing a device can also cause local data loss. Copies that you save or send elsewhere are outside Nauro’s deletion controls.

Account deletion

You can request deletion in the app’s privacy settings or through our website. An authenticated app request begins a 30-day deactivation and recovery period. After that period, finalization and related cleanup run as background processes. Restoration during the recovery period stops that deletion request.

Deactivation is not immediate erasure of every account, provider, or shared record. Finalization removes profile and contact details, clears the account’s sign-in credentials in Nauro’s database, replaces the visible profile with a deleted-account label, removes account-specific records such as push tokens and standalone AI scan records, and schedules owned receipt images for deletion. It also requests deletion of the Supabase sign-in identity and RevenueCat customer record. Storage and provider cleanup run separately and retry if a step fails, so they may finish after the account’s main records have been changed.

Shared bill and activity history, internal account references, and limited agreement, security, usage, purchase, support, or provider records may remain. These records are not necessarily anonymous. Information entered by another person may still appear in that person’s records. If you need additional information removed, tell us which information and we will assess the request under applicable law, including whether it is needed for another participant’s records.

Backups, operational logs, and service-provider copies follow their separate retention and deletion processes. We assess applicable deletion requests for the records we control and request provider deletion where supported and required; an app-store transaction record or provider security record may remain under that provider’s obligations. A legal hold, dispute, or security investigation may require limited retention. We do not promise that changing a profile, revoking a link, or deleting a bill erases every prior copy.

Deleting Nauro or your account does not cancel an Apple or Google subscription. Cancel it through the store’s subscription settings to stop future renewals.

11. Your choices and privacy rights

You can review available profile and bill settings, correct information you control, manage permissions, revoke supported share links, request deletion, and request a copy of your information. The in-app export includes supported server records; it is not a complete export of every local draft, image file, diagnostic record, or provider record. Contact us for information not included in that export.

Depending on where you live and which laws apply, you may have rights to access, correct, delete, or obtain a portable copy of personal information; withdraw consent; object to or restrict certain processing; opt out of sale, targeted advertising, or certain profiling; and appeal a denied request. We do not currently sell information, engage in cross-context behavioral advertising, or use profiling to make decisions with legal or similarly significant effects about you.

Submit a request through Contact Nauro using the privacy contact options, or use the contact details below. You do not need an account to ask about guest information. Where permitted, an authorized agent can act for you; we may request proof of authority. We may verify identity and the relevant account or record, but please do not send identity documents or sensitive credentials unless we have explained a necessary, secure verification process.

We respond within applicable legal time limits and explain any permitted extension or denial. Some requests may be limited to protect another person’s information or meet legal obligations. You can ask us to review a denial through the same contact channel and may complain to your state attorney general or other relevant privacy regulator. We do not discriminate against you for exercising applicable privacy rights, although a feature may require the information necessary to provide it.

12. Security and international processing

We use safeguards such as authenticated access, access controls, encrypted network connections, restricted administrative access, and security monitoring appropriate to the service. No app, website, device, or transmission is completely secure. Protect your device, sign-in account, and share links, and report suspected unauthorized access promptly.

Nauro is operated from the United States. Our providers may process information in the United States and other countries where they operate. Privacy laws may differ from those where you live. Where required, we use applicable contractual or other lawful safeguards for transfers. This policy does not claim that Nauro is certified under the Data Privacy Framework or that information always stays in one country.

13. Children

Nauro accounts and app services are intended for adults aged 18 or older. We do not direct the service to children under 13 or knowingly solicit their personal information. If you believe a child has provided information, contact us so we can investigate and take appropriate steps, including deletion where required. An eligibility requirement is not a claim that Nauro has independently verified every user’s age.

14. Changes to this policy

We may update this policy as the service or legal requirements change. We will publish the updated version and effective date here and keep a copy of prior published versions. For material changes, we will post a website notice and notify account holders by email or an in-app notice before the changes take effect. If an urgent legal or security requirement requires a sooner change, we will give notice as soon as reasonably possible. You can request a prior version through the contact details below.

When an account flow presents an updated Privacy Notice, its acknowledgement records that the notice was presented; it is separate from accepting Terms or consenting to optional processing. If a new use requires consent, we will obtain that consent before that use. A policy update does not retroactively authorize an incompatible use of information already collected.

Last prepared: September 13, 2026. The publication status and effective date appear at the top of this page.

15. Contact Nauro

Nauro LLC
Business mailing address
1 Washington Mall #1108, Boston, MA 02108, United States

For privacy, legal, or account-deletion requests, email privacy@nauro.app or use the contact form. You can also use the account-deletion page.

For support or accessibility help, email support@nauro.app. For general inquiries, email hello@nauro.app.

Nauro

Simple tools for organizing life together.

Company

AboutSecurityContact

Support

Help centerDelete accountAccessibility

Legal

Privacy policyTerms of servicePrivacy choices

© 2026 Nauro.

See each document for its version and effective date.