Privacy notice
Version of 7 August 2026. It describes Ticipa as it runs today at https://ticipa.app — in a closed test run, where an account is only created with an invitation code. The German version above is the legally relevant one; this translation is here so that the same facts are readable in English.
In short
- No tracking. No analytics tools, no advertising, no tracking pixels, no fonts and no scripts from other servers. Everything a page needs comes from Ticipa's own server.
- No payment details. No money moves through Ticipa. There are no account numbers, no IBANs, no card details and no payment service. Ticipa works out who would have to transfer what to whom — the transfer happens elsewhere.
- Closing an account does not erase it completely, and this says so. Name, handle and address are overwritten, but the expenses and shares stay, because everybody else's balance depends on them. The whole of it is in section 9.
1. Controller
Georg Mayer
«POSTAL ADDRESS — the operator fills this in»
E-mail: stuff@georgmayer.eu
No data protection officer has been appointed. Your contact for anything to do with your data is the controller himself.
2. What Ticipa stores
Your account: e-mail address, handle (the unique name others find you by), display name, a voluntary one-line description, your password only ever as an Argon2 hash, optionally a second sign-in factor (its secret encrypted) with recovery codes, your language, your settings (day or night, which notifications you want), when you last signed in, and when the account was created and last changed.
Telegram, only if you link it yourself: the number of your chat with Ticipa's bot, when it was linked and, if Telegram stops accepting messages for you, when that happened. Nothing else — no name, no username, no phone number. One button on the “What Ticipa tells you” page deletes the row at once and completely; sending “stop” to the bot does the same.
Invitations: an invitation code is stored only as a hash, together with who issued it, a note, the expiry date and who redeemed it. A group invitation also holds the e-mail address of the invited person, even when they have no account — an invitation cannot be delivered otherwise.
Groups and membership: the group's name, description, currency, time zone and rules; per member the role, the place in the chore rotation, and when they joined or left.
Expenses: title, notes, category, amount and currency, the exchange rate with its date and the European Central Bank's reference rate beside it, who paid, the date of the expense, how it is split and each person's share. Every change to an expense is kept as a full snapshot with its time and its author, as is every settlement of a period and every correction behind one.
Chores: title, notes, recurrence, who is assigned, when something was due, who ticked it off and when.
Limits: the ceilings a group sets itself, and the alarms that fired.
Board and messages: what you write on a group's board, and private messages between members of the same group. Both are stored as plain text in the database. They are not end-to-end encrypted: whoever runs the server could technically read them. That is not done — but a promise is not encryption, which is why it is written here.
Pictures: your profile picture, a group's picture, a picture in a message or on the board, and a picture hanging on an expense — together with who uploaded it and when. The picture you uploaded is never the one handed out. Ticipa recomputes five versions of it in the sizes a page needs, and those are the only ones anybody else ever sees. The recomputing leaves the camera data behind — the location included, which some cameras write into a picture. The uploaded file itself stays on the server as it arrived.
Files that are not pictures: what sits in a group's drawer, or hangs on an expense as a PDF, a spreadsheet or the like — the file itself, its name, a voluntary description, the uploader's claim about its type, its size, who uploaded it and when. There is no recomputing here: the other members of the group download such a file exactly as you uploaded it. What is inside it is then inside their copy too — including whatever the program you made it with wrote into it.
Photographed bills: photograph a bill so that Ticipa can read the amount, the date and the merchant off it, and the photograph sits here for six hours at most. Turn it into an expense and it hangs on that expense from then on, and the copy that was there for the reading is deleted at once. Who reads it is in section 6.
Feedback: what you send through the feedback page — title, text and which page you were on.
Two logs: a group's timeline (who entered, changed, ticked off or settled what, and when) and a security log of acts such as closing an account. Both are append-only: the database itself refuses to delete a row.
Sessions: signing in creates a session. It holds when it started, when it was last used, your browser's identification string (the first 200 characters) and the IP address the request came from. Both are shown on "Your account" under your devices, so that you can recognise a session that is not yours and end it. Sessions live in Redis, not in the database, and vanish with their expiry.
Counters against abuse: failed sign-ins and password-reset requests are counted briefly, by IP address or e-mail address.
What Ticipa does not store: no payment details, no identity documents, no location that Ticipa itself collects, no profile of your behaviour.
3. Why, and on what legal basis
| Why | Which data | Legal basis |
|---|---|---|
| Running your account and providing groups, expenses, chores, settlements, the board and messages | account, groups, expenses, chores, posts, messages | Art. 6(1)(b) GDPR — performance of the usage agreement |
| Inviting somebody into a group | the invited person's e-mail address | Art. 6(1)(f) GDPR — legitimate interest: an invitation cannot be delivered without the address |
| Sending notifications | e-mail address, display name, language, the event itself | Art. 6(1)(b) GDPR |
| Keeping you signed in and making a session recognisable | session, browser string, IP address | Art. 6(1)(f) GDPR — legitimate interest: safe operation, and you should be able to spot a session that is not yours |
| Fending off abuse | counters by IP or e-mail address | Art. 6(1)(f) GDPR |
| Pushing short notices to Telegram | chat number, the event, the group's name | Art. 6(1)(a) GDPR — your consent, given by linking and withdrawn with one button |
| Keeping it possible to see how a number came about | the group's timeline, an expense's revision history | Art. 6(1)(b) and (f) GDPR — a common pot nobody can audit is not one |
| Evidencing security-relevant acts | security log | Art. 6(1)(c) and (f) GDPR |
Where Ticipa relies on legitimate interest, the interests have been weighed: the logs record what happened to the group's money, and they hold nothing about you that is not already visible inside the group. You can object to this processing — section 10.
4. What mail Ticipa sends
Every message is plain text, with no images and no tracking pixel. There is no newsletter and no advertising.
- Setting a new password — at your own request. The link is valid for half an hour and works exactly once.
- An invitation to a group — to the address the inviting member gave. The link is valid for 14 days and works exactly once.
- Notifications. By default these arrive by mail: somebody joins, leaves, is invited or is removed, a role or a group setting changes — and every spending alarm. Everything about money, chores, the board and messages is by default only a count inside the app. You can change that per kind and per channel. Only the spending alarm cannot be switched off, only narrowed to the people it concerns.
5. Cookies
Ticipa sets only the cookies it needs to work. There are no tracking cookies, no analytics cookies and no third-party cookies, which is why no consent banner stands in front of them (§ 165 (3) TKG 2021 in Austria, § 25 (2) TDDDG in Germany).
| Cookie | For | How long |
|---|---|---|
ticipa_session |
keeps you signed in. Holds a random id and nothing else — everything about the session lives on the server | 24 hours after your last activity, 30 days with "stay signed in". Signed out, 2 hours, so that the sign-in form itself is protected |
ticipa_lang |
your language | one year |
ticipa_theme |
day or night | one year |
ticipa_tz |
your time zone, so that a date is dated in your day and not the server's. Written by the browser | one year |
ticipa_chat_note |
that you pressed away the note above a group's chat, so it does not stand there again every time you open it. Holds the word "dismissed" and nothing else. Written by the browser | one year |
ticipa_design |
which of the two looks you chose. Holds "ticipa" or "studio" and nothing else | one year |
ticipa_chat_sort |
the order your chat list stands in. Holds "activity", "az" or "za" and nothing else | one year |
Besides those, one single thing in the browser's own store, which is not a
cookie: under ticipa_emoji_recent stand up to five emoji you reached for last,
so that the picker opens on them. It never leaves your browser and it stays
until you clear this site's data there. Ticipa puts nothing else in the browser
— no session store, no offline cache, no database in the browser.
6. Who else sees the data
The other members of your groups. They see your display name, your handle, your description, what you have entered, your share of every joint expense, your balance, your chores, your posts on the board and the messages you write to them — and your profile picture, and every picture and every file you put into the group. They do not see your e-mail address.
The mail server Ticipa delivers mail through: «MAIL SERVER, AND ITS PROVIDER IF IT IS NOT THE OPERATOR'S OWN — the operator fills this in».
The European Central Bank — but without you. Once every working day Ticipa's background process downloads the published reference rates from www.ecb.europa.eu. That is the server fetching a public file; your browser never talks to the bank, and not one piece of personal data goes with it.
The model that reads a photographed bill — it runs on a second machine of the same controller, in the same house, reachable over the local network only. The scaled-down photograph goes there, and the amount, the date and the merchant come back. No outside service and no outside company is involved; photograph no bill and nothing goes there at all.
Telegram — but only if you link it yourself, and only the least possible. Once you have linked your Telegram account, Ticipa pushes short notices there, and Telegram necessarily sees which chat number they reach and what the line says. That is why the line deliberately says almost nothing: what kind of thing happened and in which group, plus a link. Never an amount, never the text of a message, never who owes whom. Telegram is a service of Telegram Messenger Inc. with servers outside the EU. Link nothing and not one piece of your data goes there — and one button on the “What Ticipa tells you” page ends it at once, whenever you like.
Nobody else. No analytics service, no advertising network, no cloud provider, no processor for hosting: Ticipa runs on hardware the controller operates himself. Data is handed to an authority only where the law obliges it or a valid order exists.
7. How long
| What | How long |
|---|---|
| Account | as long as it exists — then section 9 |
| Expenses, shares, settlements, corrections | as long as the group exists: they are its memory |
| Chores, board, messages, feedback | as long as the group exists |
| Picture | as long as the thing you chose it for; a picture nothing uses is deleted after six hours |
| File that is not a picture | as long as the group exists, or until somebody deletes it — and then it is really gone |
| Photographed bill | six hours at most — turn one into an expense and the photograph hangs on it from then on, and the reading copy goes at once |
| Invitation | the row stays; the e-mail address is removed thirty days after it is redeemed or expires |
| The group's timeline and the security log | not deleted — the database refuses |
| Session | 24 hours or 30 days after your last activity, and immediately when you sign out |
| Counters against abuse | minutes to hours |
| Telegram link | until you end it — one button, or “stop” to the bot |
Three runs tidy up on their own, and all three are here. Every night the e-mail address is taken off invitations that have been redeemed or expired for thirty days — the rest of the row stays: who invited, into which group, with which role, and what became of the invitation; only the address goes, and the row records when it went. Every night, every picture older than six hours that nothing points at is deleted — uploaded, never chosen, the window closed. And every hour the photographed bills older than six hours go, row and file.
Sessions and the counters against abuse fall away by themselves, at the times given above. Nothing else in this table is tidied up by Ticipa on its own. If something of it should go, write to us — section 10.
8. Where the data is
Everything sits on a server the controller runs himself: the database, the session store, the application, the pictures. A photographed bill travels to a second machine of the same controller in the same house for the moment of the reading — section 6 — and otherwise sits here too.
There is no transfer to a country outside the EU or the EEA — with one exception, and you switch it on yourself: link your Telegram account and the short notices travel over Telegram's servers, which are outside the EU. What is transferred is in section 6. Link nothing and no data of yours leaves this server.
9. Closing an account: what actually happens
You close your account yourself, on the "Your account" page. Your password is asked for again, because the step cannot be undone. On request the operator does it for you.
This is overwritten or destroyed:
- the e-mail address — replaced by an address nothing can ever be delivered to,
- the handle and the display name — other members see "Former member" from then on,
- the description and the profile text,
- your profile picture — the file itself is deleted from the disk in the same step, not left for a later tidying-up run,
- the password hash, the second sign-in factor and the recovery codes,
- your settings and the time of your last sign-in,
- every right the account held,
- the Telegram link, if there was one — the row is deleted, not merely marked,
- every session on every device is ended.
This stays, pseudonymised: every expense, every share, every settlement, every correction, every chore and the membership row itself — all still tied to the account, which now has no name. Your posts on the board, your messages and the group's timeline also keep their text — and a picture you sent into a conversation stays too, for the same reason as the message it sits in: the conversation belongs to the other people as well.
Why. Your share of a joint expense is what makes everybody else's share of it add up; the database itself rejects a split that does not add up to the amount. Removing your share would silently change what every other member of the group is owed or owes. So Ticipa weighs your right to erasure against the rights of the other members (Art. 17(1) and (3) GDPR) and pseudonymises instead of deleting. The same statement is made before anybody creates an account.
If that is not enough for you, write to stuff@georgmayer.eu. Your case will be looked at and you will get an honest answer about what is possible and what is not.
10. Your rights
You have the right, at any time, to
- Access (Art. 15 GDPR) — what is stored,
- Rectification (Art. 16 GDPR) — name, handle and description you change yourself on "Your account",
- Erasure (Art. 17 GDPR) — with the limit described in section 9,
- Restriction of processing (Art. 18 GDPR),
- Data portability (Art. 20 GDPR) — the button is there: "Download my data" on "Your account". It hands you a JSON file straight away, holding your own rows — your account, your groups, what you paid and what you owed, your chores, your posts and the messages you wrote. What other people wrote is in their copy and not in yours; sign-in secrets — the password hash, the second factor, the recovery codes — are in nobody's,
- Objection (Art. 21 GDPR) to anything that rests on a legitimate interest.
One line to stuff@georgmayer.eu is enough. It is answered within one month at the latest.
Complaint. You can complain to a supervisory authority — the one of your residence, of your place of work, or of the place where the infringement is alleged to have happened (Art. 77 GDPR). In Austria that is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, +43 1 52 152-0. In Germany it is the authority of your federal state.
11. Security
- All traffic is encrypted (HTTPS).
- Passwords are hashed with Argon2id and never stored in the clear.
- The second sign-in factor's secret is stored encrypted.
- A session lives on the server; the cookie holds nothing but a random id that says nothing by itself.
- That id is replaced on every change to the account's strength — signing in, a new password, switching the second factor on or off.
- Every form carries a token against requests from other sites.
- Sign-in attempts and password requests are rate-limited.
- Who may see what is decided by the server alone, never by the browser.
12. No automated decisions
There is no profiling and no automated decision within the meaning of Art. 22 GDPR. The one thing Ticipa judges by itself is an exchange rate: if the rate entered is more than three per cent away from the European Central Bank's reference rate for that day, the row is marked. Nothing is decided about a person, and nothing follows from it.
13. Changes
If what Ticipa does with data changes, this notice changes with it and carries a new date. The version in force is always the one here.