Ticipa

Draft — this document still has gaps that the operator has to fill in, and it has not been reviewed by a lawyer.

Privacy notice

Version of 1 August 2026. It describes Ticipa as it runs today at https://ticipa.app — in a closed test run, where an account is only created with an invitation code. The German version above is the legally relevant one; this translation is here so that the same facts are readable in English.

In short

  • No tracking. No analytics tools, no advertising, no tracking pixels, no fonts and no scripts from other servers. Everything a page needs comes from Ticipa's own server.
  • No payment details. No money moves through Ticipa. There are no account numbers, no IBANs, no card details and no payment service. Ticipa works out who would have to transfer what to whom — the transfer happens elsewhere.
  • Closing an account does not erase it completely, and this says so. Name, handle and address are overwritten, but the expenses and shares stay, because everybody else's balance depends on them. The whole of it is in section 9.

1. Controller

Georg Mayer

«POSTAL ADDRESS — the operator fills this in»

E-mail: stuff@georgmayer.eu

No data protection officer has been appointed. Your contact for anything to do with your data is the controller himself.

2. What Ticipa stores

Your account: e-mail address, handle (the unique name others find you by), display name, a voluntary one-line description, your password only ever as an Argon2 hash, optionally a second sign-in factor (its secret encrypted) with recovery codes, your language, your settings (day or night, which notifications you want), when you last signed in, and when the account was created and last changed.

Invitations: an invitation code is stored only as a hash, together with who issued it, a note, the expiry date and who redeemed it. A group invitation also holds the e-mail address of the invited person, even when they have no account — an invitation cannot be delivered otherwise.

Groups and membership: the group's name, description, currency, time zone and rules; per member the role, the place in the chore rotation, and when they joined or left.

Expenses: title, notes, category, amount and currency, the exchange rate with its date and the European Central Bank's reference rate beside it, who paid, the date of the expense, how it is split and each person's share. Every change to an expense is kept as a full snapshot with its time and its author, as is every settlement of a period and every correction behind one.

Chores: title, notes, recurrence, who is assigned, when something was due, who ticked it off and when.

Limits: the ceilings a group sets itself, and the alarms that fired.

Board and messages: what you write on a group's board, and private messages between members of the same group. Both are stored as plain text in the database. They are not end-to-end encrypted: whoever runs the server could technically read them. That is not done — but a promise is not encryption, which is why it is written here.

Feedback: what you send through the feedback page — title, text and which page you were on.

Two logs: a group's timeline (who entered, changed, ticked off or settled what, and when) and a security log of acts such as closing an account. Both are append-only: the database itself refuses to delete a row.

Sessions: signing in creates a session. It holds when it started, when it was last used, your browser's identification string (the first 200 characters) and the IP address the request came from. Both are shown on "Your account" under your devices, so that you can recognise a session that is not yours and end it. Sessions live in Redis, not in the database, and vanish with their expiry.

Counters against abuse: failed sign-ins and password-reset requests are counted briefly, by IP address or e-mail address.

What Ticipa does not store: no payment details, no identity documents, no photos, no location, no profile of your behaviour.

3. Why, and on what legal basis

Why Which data Legal basis
Running your account and providing groups, expenses, chores, settlements, the board and messages account, groups, expenses, chores, posts, messages Art. 6(1)(b) GDPR — performance of the usage agreement
Inviting somebody into a group the invited person's e-mail address Art. 6(1)(f) GDPR — legitimate interest: an invitation cannot be delivered without the address
Sending notifications e-mail address, display name, language, the event itself Art. 6(1)(b) GDPR
Keeping you signed in and making a session recognisable session, browser string, IP address Art. 6(1)(f) GDPR — legitimate interest: safe operation, and you should be able to spot a session that is not yours
Fending off abuse counters by IP or e-mail address Art. 6(1)(f) GDPR
Keeping it possible to see how a number came about the group's timeline, an expense's revision history Art. 6(1)(b) and (f) GDPR — a common pot nobody can audit is not one
Evidencing security-relevant acts security log Art. 6(1)(c) and (f) GDPR

Where Ticipa relies on legitimate interest, the interests have been weighed: the logs record what happened to the group's money, and they hold nothing about you that is not already visible inside the group. You can object to this processing — section 10.

4. What mail Ticipa sends

Every message is plain text, with no images and no tracking pixel. There is no newsletter and no advertising.

  • Setting a new password — at your own request. The link is valid for half an hour and works exactly once.
  • An invitation to a group — to the address the inviting member gave. The link is valid for 14 days and works exactly once.
  • Notifications. By default these arrive by mail: somebody joins, leaves, is invited or is removed, a role or a group setting changes — and every spending alarm. Everything about money, chores, the board and messages is by default only a count inside the app. You can change that per kind and per channel. Only the spending alarm cannot be switched off, only narrowed to the people it concerns.

5. Cookies

Ticipa sets only the cookies it needs to work. There are no tracking cookies, no analytics cookies and no third-party cookies, which is why no consent banner stands in front of them (§ 165 (3) TKG 2021 in Austria, § 25 (2) TDDDG in Germany).

Cookie For How long
ticipa_session keeps you signed in. Holds a random id and nothing else — everything about the session lives on the server 24 hours after your last activity, 30 days with "stay signed in". Signed out, 2 hours, so that the sign-in form itself is protected
ticipa_lang your language one year
ticipa_theme day or night one year
ticipa_tz your time zone, so that a date is dated in your day and not the server's. Written by the browser one year

6. Who else sees the data

The other members of your groups. They see your display name, your handle, your description, what you have entered, your share of every joint expense, your balance, your chores, your posts on the board and the messages you write to them. They do not see your e-mail address.

The mail server Ticipa delivers mail through: «MAIL SERVER, AND ITS PROVIDER IF IT IS NOT THE OPERATOR'S OWN — the operator fills this in».

The European Central Bank — but without you. Once every working day Ticipa's background process downloads the published reference rates from www.ecb.europa.eu. That is the server fetching a public file; your browser never talks to the bank, and not one piece of personal data goes with it.

Nobody else. No analytics service, no advertising network, no cloud provider, no processor for hosting: Ticipa runs on hardware the controller operates himself. Data is handed to an authority only where the law obliges it or a valid order exists.

7. How long

What How long
Account as long as it exists — then section 9
Expenses, shares, settlements, corrections as long as the group exists: they are its memory
Chores, board, messages, feedback as long as the group exists
Invitation the row stays after it expires or is redeemed, including the address it was sent to
The group's timeline and the security log not deleted — the database refuses
Session 24 hours or 30 days after your last activity, and immediately when you sign out
Counters against abuse minutes to hours

Ticipa tidies nothing up on its own today. There is no automatic deletion run. If something should go, write to us — section 10.

8. Where the data is

Everything sits on a server the controller runs himself: the database, the session store, the application. There is no transfer to a country outside the EU or the EEA.

9. Closing an account: what actually happens

You close your account yourself, on the "Your account" page. Your password is asked for again, because the step cannot be undone. On request the operator does it for you.

This is overwritten or destroyed:

  • the e-mail address — replaced by an address nothing can ever be delivered to,
  • the handle and the display name — other members see "Former member" from then on,
  • the description,
  • the password hash, the second sign-in factor and the recovery codes,
  • your settings and the time of your last sign-in,
  • every right the account held,
  • every session on every device is ended.

This stays, pseudonymised: every expense, every share, every settlement, every correction, every chore and the membership row itself — all still tied to the account, which now has no name. Your posts on the board, your messages and the group's timeline also keep their text.

Why. Your share of a joint expense is what makes everybody else's share of it add up; the database itself rejects a split that does not add up to the amount. Removing your share would silently change what every other member of the group is owed or owes. So Ticipa weighs your right to erasure against the rights of the other members (Art. 17(1) and (3) GDPR) and pseudonymises instead of deleting. The same statement is made before anybody creates an account.

If that is not enough for you, write to stuff@georgmayer.eu. Your case will be looked at and you will get an honest answer about what is possible and what is not.

10. Your rights

You have the right, at any time, to

  1. Access (Art. 15 GDPR) — what is stored,
  2. Rectification (Art. 16 GDPR) — name, handle and description you change yourself on "Your account",
  3. Erasure (Art. 17 GDPR) — with the limit described in section 9,
  4. Restriction of processing (Art. 18 GDPR),
  5. Data portability (Art. 20 GDPR) — there is no button for this yet; write to us and you will get your data in a common format,
  6. Objection (Art. 21 GDPR) to anything that rests on a legitimate interest.

One line to stuff@georgmayer.eu is enough. It is answered within one month at the latest.

Complaint. You can complain to a supervisory authority — the one of your residence, of your place of work, or of the place where the infringement is alleged to have happened (Art. 77 GDPR). In Austria that is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, +43 1 52 152-0. In Germany it is the authority of your federal state.

11. Security

  • All traffic is encrypted (HTTPS).
  • Passwords are hashed with Argon2id and never stored in the clear.
  • The second sign-in factor's secret is stored encrypted.
  • A session lives on the server; the cookie holds nothing but a random id that says nothing by itself.
  • That id is replaced on every change to the account's strength — signing in, a new password, switching the second factor on or off.
  • Every form carries a token against requests from other sites.
  • Sign-in attempts and password requests are rate-limited.
  • Who may see what is decided by the server alone, never by the browser.

12. No automated decisions

There is no profiling and no automated decision within the meaning of Art. 22 GDPR. The one thing Ticipa judges by itself is an exchange rate: if the rate entered is more than three per cent away from the European Central Bank's reference rate for that day, the row is marked. Nothing is decided about a person, and nothing follows from it.

13. Changes

If what Ticipa does with data changes, this notice changes with it and carries a new date. The version in force is always the one here.