Owee Privacy Policy
Last updated: September 18, 2026
Owee is operated by Blank Canvas Labs LLC ("Owee", "we", "us"). This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you use the Owee mobile app, website, support channels, and related services (the "Service"). For questions or privacy requests, use the support page, Account → Support in the app, or email [email protected].
The short version: Owee syncs your account and splitting records so they work across your devices and with the people you choose. We do not sell personal information, share it for cross-context behavioral advertising, or use your content to train AI models.
Information we collect
Account and profile information
Our authentication provider, Clerk, processes your sign-in identifier and authentication information. We receive your name, email address, authentication identifier, and, when provided by Apple or Google, profile information such as an optional photo. Owee also asks for a profile phone number so people can recognize and find you.
Splits and other user content
We store pools, member names, expenses, settlements, balances, notes, categories, auto-split rules, invitations, and payment handles you enter. Pool members can see the shared records for pools they belong to. We also store a profile photo if you choose one. A local cache may remain on your device for speed and offline use and re-sync when you reconnect.
Contacts and invitations
Contact features are optional. If you choose one person with the iOS contact picker, Owee reads that person's display name, first phone number and email, and normalized forms of a bounded number of that person's phone numbers and emails. Selected contact information may be stored with an invitation placeholder until that record or your account is deleted. If you separately use "Find contacts on Owee," the app reads an accessible page of up to 300 contact cards after you grant permission. You choose whether to continue to another page. Current clients send normalized email addresses and full country-qualified phone numbers with temporary row tokens. Contact names stay on your phone during bulk matching; addresses, notes, photos, and device contact identifiers are not sent. These identifiers are personal data and are not hashed. Owee uses them only for exact account matching and does not persist the bulk request payload in its application database. Older supported clients may send contact names and legacy phone representations in their existing requests, but names are not match keys. Owee does not invite a match automatically or add someone to a pool until they accept.
Other Owee users may provide your name or contact details when they add you to a pool, select you from their contacts, create an invitation, or maintain a shared ledger.
Profiles, handles, discovery, blocking, and reports
Owee assigns each account a unique Owee handle. Signed-in users can use an exact handle to find an account. Name and partial-handle search is a separate profile choice that you can turn off during setup or later. Search results contain only the display name, Owee handle, and optional profile photo—not contact details, financial data, balances, or pool lists. Owee does not provide an anonymous web directory or allow search engines to index profiles.
Blocking prevents new discovery and personal invitations in both directions; it does not rewrite existing pool memberships, expenses, allocations, or balances. Profile reports include the selected category, optional details, and the minimum account and profile context needed for authorized review. We aim to review submitted reports within 72 hours. Reports and their review audits are retained for up to 90 days unless account deletion or law requires earlier or longer handling. Reporting is not an emergency service.
Optional bank and card information
Bank linking through Plaid is available only to users age 18 and older. If you are eligible and choose bank sync through an Owee Basic introductory offer, a previously started legacy trial, Owee Basic, or Owee Plus, Plaid provides Owee with supported account metadata and transactions for the Split inbox. Owee does not receive your bank login credentials, full card numbers, or account and routing numbers. Owee does not persist or display account balances, even if a balance field is included in account metadata.
Owee retains raw imported bank transactions on a rolling 270-day basis. Unlinking disconnects Plaid and stops new imports, but raw transactions already received remain until they age out under this retention period or are removed through account deletion. Expenses, splits, settlements, and pool history you created from an imported transaction are separate Owee records and remain until deleted under this policy. If Plaid removal is temporarily unavailable, Owee retains the encrypted removal credential only as needed to retry disconnection.
Receipt photos and extracted results
When you choose to scan a receipt, the receipt image and limited scan context, such as an optional merchant hint, are sent through Owee's backend to OpenAI to extract a draft merchant, total, and line items. Owee does not persist the receipt image bytes on its servers. Temporary extraction and recovery records may remain in Owee's backend for up to 24 hours so the result can be delivered or recovered. OpenAI states that API data is not used to train its models; under its standard API controls, request content may be retained for up to 30 days for abuse monitoring. If you do not scan a receipt, no receipt image is sent to OpenAI.
The app may keep a managed receipt-photo copy in its private on-device storage for an active draft or expense. When a managed photo becomes orphaned or is removed, Owee moves it to a private recovery area for up to seven days and then deletes it automatically. Account deletion removes active and recovery copies immediately; removing the app also removes its private storage.
Purchases and entitlements
Apple processes App Store payments. Owee receives and stores product, transaction, subscription, entitlement, and scan-credit information needed to verify purchases, unlock features, restore subscriptions, prevent duplicate grants, and handle refunds or revocations. Owee does not receive your payment card details.
Diagnostics, security, and support
When the app displays an unexpected-error screen, Owee sends a limited crash report to Convex with the error message, JavaScript and component stacks, platform and OS version, app, build, runtime, update and release-channel identifiers, and your account identifier when available. Reports are scrubbed for common secret, API-key, email-address, and phone-number patterns. Diagnostic entries may also appear in Convex operational logs under its configured retention. We also process security and rate-limit records and information you send when requesting support or reporting a profile.
Product analytics and identifiers
If you opt in, Owee sends a limited set of first-party feature and funnel events to PostHog to understand whether product flows work. Events use a random installation identifier stored on your device and include app, platform, build, runtime, update, and release-channel metadata, event names, and limited feature attributes such as plan, selected mode, status, count, or currency code. Owee does not send your Clerk or internal account identifier to PostHog or merge the installation identifier into your Owee account. Events do not include your name, email address, phone number, advertising identifier, merchant, transaction amount, bank transaction, receipt image or contents, expense note, or payment handle.
Owee disables PostHog session recording and screen replay, does not use an advertising identifier, and sends $geoip_disable with analytics events to disable IP-based location enrichment. PostHog and other service providers may still process an IP address as necessary to receive a network request, provide the Service, prevent abuse, and maintain security. Owee does not request or collect GPS or precise device location.
Product analytics is off unless you expressly turn on Share product analytics in Account → Data & Privacy. You can turn it off at any time without losing core functionality. Turning it off stops future collection, clears pending events, and removes the local installation identifier so any later opt-in starts with a new identifier. Signing out or deleting an account also rotates that identifier.
Website information
When you visit owee.ai, our hosting and network provider may process ordinary request information such as IP address, browser or device type, requested page, and request time to deliver and secure the website. Owee does not use that information for advertising or cross-site tracking.
Sources of information
Owee receives information directly from you; from Apple or Google through Clerk when you sign in; from Plaid when you choose to connect an institution; from Apple's App Store for purchases, subscription status, and refunds; automatically from the app and device for consent-based analytics and diagnostics; from website and network requests; and from other Owee users when they add a person to a pool, create an invitation, or maintain a shared ledger.
How we use information
- Create and authenticate accounts; sync pools and personal records; calculate balances; and share pool records with the members you choose.
- Match contact information you submit to an existing account, prepare an invitation, and prevent unauthorized joining.
- Provide profile and handle discovery, enforce blocking choices, review reports, and investigate abuse.
- Import supported transactions after you link an account and apply rules you configure.
- Extract receipt line items only when you initiate a scan.
- Verify purchases and provide Basic, Plus, trial, and scan-credit features.
- Maintain security, prevent fraud and abuse, enforce limits, diagnose errors, respond to support requests, and comply with law.
- Measure feature reliability and improve Owee using limited product analytics.
We do not use spending, receipt, contact, or split content for advertising, data brokerage, cross-company tracking, or AI-model training.
Device permissions
- Contacts (optional): used only when you select a contact or start contact discovery as described above.
- Photo Library (optional): used when you choose a profile or receipt image.
- Camera (optional): used when you choose to photograph a receipt.
- Face ID or device biometrics (optional): authentication occurs through iOS on your device. Owee receives only the result, not your biometric data.
You can decline or later revoke a permission in iOS Settings. The related feature may become unavailable, but manual splitting remains available.
Service providers
Providers process information for Owee to provide their services:
- Clerk — authentication and account management (clerk.com/privacy).
- Convex — application backend, database, storage, and synchronization (convex.dev/legal/privacy).
- Plaid — optional financial-account connection and transaction data (plaid.com/legal).
- OpenAI — user-initiated receipt extraction (developers.openai.com).
- PostHog — limited first-party product analytics (posthog.com/privacy).
- Apple and Google — sign-in services when selected; Apple also provides App Store distribution, payments, subscriptions, and purchase restoration (Apple Privacy Policy, Google Privacy Policy).
- Expo / EAS — app build and update delivery (expo.dev/privacy).
- Cloudflare — website hosting, network delivery, and security (cloudflare.com/privacypolicy).
Providers may process information in the United States and other countries. Where required, we rely on contractual and other safeguards for international transfers.
We may also disclose information when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or complete a merger, financing, reorganization, or sale. We do not sell or rent personal information, share it with advertisers, or use it for targeted advertising.
Retention
- Account information and Owee content generally remain while your account is active, unless you delete particular content or your account.
- Raw imported bank transactions follow a rolling 270-day retention period.
- Temporary receipt extraction and recovery records are deleted after up to 24 hours. OpenAI's standard abuse-monitoring retention may be up to 30 days.
- Removed or orphaned receipt-photo copies in private on-device recovery storage are deleted after up to seven days.
- Crash reports are retained for up to 90 days. Rate-limit and certain security records are retained for up to 30 days.
- Profile reports and their review audits are retained for up to 90 days.
- PostHog product-analytics events are generally retained for up to 12 months.
- Limited disassociated Apple purchase records may remain after account deletion to restore an active subscription, prevent duplicate grants and abuse, handle refunds, and meet legal or accounting obligations.
Backups and deletion queues may require a limited additional period before data is fully overwritten. We may retain information longer when required by law, needed to resolve a dispute, or necessary to protect the Service, and will restrict it to that purpose.
Your choices and rights
- Export: Account → Export my data creates a JSON export of the Owee data currently cached on that device, including profile, user, pool, expense, and settlement records. It is not a complete backend or service-provider access request. Email support to request access to other personal data Owee holds.
- Correct: edit available profile and app records, or contact support.
- Unlink a bank: disconnect the institution from Account to stop new imports.
- Permissions: revoke Contacts, Photos, Camera, or Face ID access in iOS.
- Product analytics: turn Share product analytics on or off in Account → Data & Privacy. It is off by default.
- Discovery and safety: manage name and partial-handle visibility, blocked accounts, and available profile report controls in the app. Exact-handle lookup remains available to signed-in users, subject to blocking.
- Delete your account: Account → Delete account severs your sign-in, removes or anonymizes personal profile information, schedules account-specific data for deletion, and signs you out. Shared pool history remains under "Former member" where necessary to preserve other members' ledgers. Certain encrypted bank-connection records may remain temporarily while deletion is retried, and limited disassociated Apple purchase records may remain for the purposes above. Deleting the app alone does not delete your account or cancel an App Store subscription.
- Privacy request: email [email protected] to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or deletion of associated analytics, as applicable in your jurisdiction. We may need to verify your identity. You may also appeal our response or complain to your local data-protection authority where those rights apply.
We do not discriminate against you for exercising a privacy right. Some rights are subject to legal exceptions.
Legal bases
Where applicable law requires a legal basis, we process information as needed to perform our contract with you, based on your consent for optional features, for our legitimate interests in securing and improving the Service where those interests do not override your rights, and to comply with legal obligations. You can withdraw consent for an optional feature, but prior lawful processing is not affected.
Children
Owee is a general-audience service. A person must be at least 13, or the higher minimum age required where they live, to create their own Owee account. If the person is below the age of legal majority, a parent or legal guardian must agree to the Terms on their behalf. Bank linking through Plaid is limited to users age 18 and older.
A parent or guardian may add a younger child by name as a non-account member in an adult-managed pool. Owee is not directed to children under 13 and does not knowingly allow them to create accounts or independently provide personal information. If you believe a child under 13 created an account or provided personal information directly, contact [email protected] so we can investigate and delete it as required.
Security
We use administrative, technical, and organizational safeguards designed to protect information. Data in transit is encrypted using HTTPS. Plaid access tokens are encrypted at rest, and production bank linking rejects unencrypted token storage. No storage or transmission method is completely secure.
Changes to this policy
We will post updates and revise the date above. When required by law, or when a change materially affects your rights or our data practices, we will provide additional notice and obtain consent where required.
Use the support page, Account → Support, or [email protected] for privacy questions or requests. See also the Terms of Use.
