Trust center
Security at Nauro
How we handle account access, shared links, and receipt information—and the choices that help you keep your information safe.
On this page
1. Our approach
We use account authentication, access permissions, revocable share links, and limits on sensitive requests to help protect Nauro Split. Security also depends on how information is shared and how your device and sign-in account are protected.
Our Privacy Policy explains what information we collect, which providers help process it, and how retention and deletion work.
2. Protecting accounts and sessions
- Sign in with Apple, Google, or an email magic link. Supabase provides the app's authentication service.
- Account requests require a valid sign-in session. Permissions determine which bills and account information a user can access.
- Nauro Split stores sign-in credentials in secure native storage on iOS and Android. If that storage is unavailable, the app may ask you to sign in again.
Drafts, synchronized bill caches, preferences, receipt images, and exports can use other app storage. They do not all have the same storage protections or deletion behavior as sign-in credentials.
3. Protecting shared bill links
- A link can show one participant's breakdown or a group view of the bill. Check the audience before sharing.
- Public links use randomly generated access tokens. Creators can revoke supported links, and links may expire.
- Receipt viewing has its own access permissions where available. A short-lived image URL limits access through that URL; it does not determine how long the image is stored.
Treat a bill link as private. A forwarded link may expose names, items, and amounts to another person. Selecting a name in a group view does not verify that person's identity. Revoking a link cannot recall screenshots, downloads, or information already seen.
4. Protecting receipt data
When you choose receipt recognition, your selected image is uploaded to Nauro and sent to an AI provider to extract the items and totals. This can happen before you finish or save the bill. Manual entry is available if you prefer not to upload a receipt.
Nauro can store receipt images and thumbnails, recognition results, and your corrections. Images can also be saved in app storage. Check the entire receipt for information you do not want to submit or share, and review the recognized details before relying on them.
AI providers and hosting services also process information under their applicable terms and settings. See receipts and AI processing in the Privacy Policy for more detail.
5. Service diagnostics
We use technical information to investigate failures, protect the service, and resolve support requests. This can include connection information, request timing and status, app versions, and support codes.
The production app can automatically report errors and stack traces. Error details may include information involved in the failed operation. Our hosting and service providers also maintain operational records; see the service-provider information in the Privacy Policy.
6. Account deletion
You can start account deletion from Profile → Data and privacy → Delete account in the app. The process begins with a 30-day recovery period during which your account is deactivated. After that period, account finalization removes or changes selected account data. Some account references, usernames, and shared history may remain identifiable; this process does not make every record anonymous.
Some shared bill records, transaction records, backups, and information needed for legal or security purposes may remain. Deleting your account does not cancel an App Store or Google Play subscription or remove copies other people saved. Read retention and deletion for the details, or contact us for help with a request.
7. Your security choices
- Protect your device and the Apple, Google, or email account you use to sign in.
- Send bill links only to the intended recipients, and revoke a link if it is exposed.
- Use device settings to manage camera, photo, notification, and lock-screen preview permissions.
- Check the recipient and amount in an external payment app before completing a payment.
8. Report a vulnerability
Email privacy@nauro.app or use the contact form and choose the privacy and security topic. Include the affected feature, what happened, potential impact, and steps we can reproduce using your own test data. An app version or support reference can help.
Keep the initial report free of private bill links, receipt images, passwords, sign-in tokens, payment details, and other people's information. Avoid accessing anyone else's data or disrupting the service. We can coordinate any sensitive details after the initial report.