Privacy Policy
Last updated: 2026-10-04
At a glance
This section is a summary. The sections after it are the policy, and they govern.
- Who is responsible: Wilfredo Oswaldo Hernández Argueta, publishing as Azurblade, in Santander, Spain — atencion@azurblade.com. Section 18 has the details.
- No signup needed. You join an event through a link and pick a name. We never ask for your real name or your phone number, and we ask for your email address only if you choose to create an account, which you also need in order to buy something.
- What we hold is what you type into an event, plus an anonymous identifier so your device can come back to it.
- The link is the credential. Anyone holding an event’s link can open that event and see the names and expenses in it. Share it only with the people you want there.
- Our processors: Supabase (Ireland) for the database, Sentry (Germany) for error reports, and Resend for the sign-in emails if you create an account. Cloudflare serves the pages and counts visits, Google Workspace holds our email, and Google Cloud delivers Google Play’s purchase notices if you buy in the Android app. That is the entire list.
- If you buy an Event Pass or CabuTally Pro, the seller handles that payment as its own controller — Google in the Android app, Stripe on the web; see section 1. We never see or store your card or bank details.
- No advertising, no tracking, no profiling. We count visits to the app in aggregate, with nothing stored on your device and nothing that identifies you (section 3.4). Nothing is sold, rented or shared, and nothing is used to train anything.
- The plugin for AI assistants keeps nothing. If you use CabuTally from ChatGPT or Claude, we receive only what the assistant sends to answer you, and store none of it (section 3.6).
- No cookie banner, because everything we store on your device is strictly necessary for a service you asked for. There is nothing to consent to.
- You can have your data deleted. With an account, you delete it yourself in the app (section 10). Without one, write to us with the event link and the name you used, so we can find it.
1. What this policy covers
This policy covers the CabuTally web and Android application at app.cabutally.com, its plugin for
AI assistants at mcp.cabutally.com, and this website at cabutally.com.
It does not cover anything you reach by leaving them. If you install CabuTally from Google Play, Google processes your installation and device data as its own controller, under its own privacy policy, and we neither see nor control that. The same goes for the AI assistant you use the plugin from: its provider processes your conversation as its own controller (section 3.6).
If you buy an Event Pass or CabuTally Pro, who sells it to you depends on where you buy it — and in both cases the payment is not ours to see:
- In the Android app, you buy from Google. Google Play processes your payment as its own controller for that transaction, under its own privacy policy, using whatever payment method your Play account holds.
- On the web, you buy through Stripe’s Link service, which processes your payment details — your card or bank information, your billing email, your name if you give one — as its own controller for that transaction, under its own privacy policy.
What reaches us from either one is limited to the fact that you bought something, when, its price, and a reference we use to grant the unlock — never your card number, its type, or its issuing bank.
What we send the seller. To start a web purchase we send Stripe your account’s email address, our internal reference for your account and, for an Event Pass, our internal reference for the event, so that the purchase reaches the right account and event. In the Android app we send Google nothing about you (section 7).
2. Some words used below
- Event — a shared space with a name, a currency, a list of members and a ledger.
- Member or guest — a person, or a placeholder for a person, in an event’s list.
- Host — the person who created an event. Every member of an event has a role (viewer, member, co-host or admin) and the person who created it is an admin. A role decides what someone may do — invite, edit, remove someone, close the event — and never what they may see: no role reveals another person’s private lines.
- Placeholder (or ghost) — a member added by someone else before that person has joined.
- Link — the invitation. Holding it is what grants access to an event.
3. What we collect
3.1 What you type
- The display name you choose for yourself in an event. It is chosen per event, it is not a real name unless you make it one, and there is no global profile: the same person in two events is not linked by anything visible.
- Event names, the currency, an optional target amount, and event settings.
- An event’s logistics, if whoever set them up filled them in — a start date and time, a place, a link to a map, and free-text notes.
- To-do items — a title, an optional free-text note, who has claimed them, an optional estimated price, and whether they are done.
- Expenses — a description, an optional note, an amount, who paid, who it is shared between, and whether it is marked private.
- Recorded payments and cash movements — an amount, who paid whom, and an optional note.
- Activity log entries — a record of who did what in an event, generated by your actions rather than typed by you. Some entries are visible only to specific people.
3.2 What is created automatically
- An anonymous account identifier. The first time you use the app, an anonymous account is created so your seat survives closing the browser. It contains no name or contact detail, but it is still personal data, because it identifies your device’s place in your events. It is a real, permanent record until it is deleted.
- Member identifiers and session records, which tie a device to a seat in an event.
- Invitation, seat-claim and recovery tokens, so links work. Seat-claim links are single-use and expire; invitations can be rotated or revoked by the host.
- Timestamps on essentially everything, which is what makes the ledger auditable.
- A purchase record, if you buy an Event Pass or CabuTally Pro — which product, when, whether it is still active, and a reference id from whoever sold it to you, Google or Stripe. Never your card details; see section 1.
3.3 If you choose to create an account
An account is optional. It exists so that clearing your browser does not lose your seats, and you need one to buy something. It is attached to the anonymous identity you already have — it does not create a second one.
- Email address, if you attach one. Sign-in is by a 6-digit code sent to that address; we do not store a password.
- Google account data, if you choose to sign in with Google: the email address and the basic profile Google returns. Google acts as its own controller for the sign-in itself.
- An optional preferred name, used only to prefill the join form. It is stored in a field the browser can write, so we treat it as unverified and it grants nothing.
3.4 Technical data
- Error and performance reports — when something breaks, a report is sent to Sentry, and so are timing measurements of every page load and screen change, and technical log lines from the app. They can include your IP address, browser and operating system version, and the sequence of screens that led there. Event links are stripped from these reports before they are sent, because an event link is a working credential.
- Server and delivery data — Cloudflare and Supabase process the IP address and request information needed to deliver pages and answer database queries.
- Visit statistics — when you open the app at one of its start pages (never an event or invitation link), a small script from Cloudflare reports that page, the site you came from, your browser, operating system, device type and country, and how fast the page loaded and responded. If you then open an event, a later speed measurement can carry that event’s internal reference, never its invitation link. The script stores nothing on your device and uses no identifier for you or your device. Cloudflare turns the reports into totals, and totals are all we see.
3.5 What we never collect
No phone number, no contacts, no address book, no location or GPS data, no advertising identifier, no device fingerprint, no biometrics, no payment card or bank details, and no special categories of data (health, beliefs, politics, ethnicity, sexuality, trade union membership). CabuTally never handles money between its members: it records what people say they spent and paid to each other. Money you pay for a paid feature goes to Google or to Stripe directly, never through us — see section 1.
What you have to give us is a display name, to join an event. Everything else is optional: an email address only if you create an account, and an account only if you want your seats to survive a lost browser or want to buy something. We never ask for your real name at all.
3.6 If you use CabuTally from an AI assistant
CabuTally has a plugin for AI assistants such as ChatGPT and Claude, at mcp.cabutally.com. It does
two things: it turns a plan into a link that opens the app with the event filled in, and it works out
who owes whom for a one-off list of payments. You need no account for either, and the plugin
writes nothing: an event exists only once you open the link and tap Create in the app, and from
then on the rest of this policy applies to it like any other.
- What we receive. Only what the assistant sends us to answer your request: an event name, the names of the people involved, a budget, a currency and, for a split, the amounts, who paid, who shares each payment and what it was for. Your assistant decides what to send from your conversation. We never see the conversation itself, and never ask for it.
- What we do with it. We work out the answer and send it back. We do not store the request, and we do not link it to you, to an account or to an event. We count how often each of the plugin’s two tools is used, and that count holds nothing from the request.
- Who else is involved. The plugin runs on Cloudflare (section 7), which handles the request as delivery data (section 3.4). The assistant’s provider, such as OpenAI or Anthropic, is its own controller for your conversation, under its own privacy policy, and we neither see nor control that.
4. Where the data comes from, when it is not from you
Other people can enter data about you, and you should know that before it happens. Someone creating an event can add you to it as a placeholder using a name they choose for you, and can record that you paid for something or owe a share of it. In that case we receive your data from them rather than from you, and the categories are the same ones listed in section 3.1.
The person who did it is the person who knows why. If you would rather not be in an event, ask them to remove you, or write to us at atencion@azurblade.com — see section 9.
5. Why we process it, and what allows us to
| What for | Legal basis |
|---|---|
| Running the event you joined: the ledger, the list, the split | Contract — Art. 6(1)(b) GDPR |
| Keeping your seat across sessions and devices | Contract — Art. 6(1)(b) |
| The activity log, so a group can see who changed what | Legitimate interest — 6(1)(f) |
| Error and performance monitoring | Legitimate interest — 6(1)(f) |
| Counting visits and measuring how fast the app loads, in aggregate | Legitimate interest — 6(1)(f) |
| Preventing abuse, spam and attacks on the service | Legitimate interest — 6(1)(f) |
| Optional account sign-in | Contract — Art. 6(1)(b) |
| Answering a request from an AI assistant through our plugin | Contract — Art. 6(1)(b) |
| Providing an Event Pass or CabuTally Pro you bought | Contract — Art. 6(1)(b) |
| Keeping a record of what you bought, for refunds, disputes and claims | Legitimate interest — 6(1)(f) |
| Answering a privacy request, and keeping a record that we did | Legal obligation — 6(1)(c) |
On the five legitimate interests. We considered whether they override your rights, and concluded they do not, for these reasons: the activity log exists because a shared ledger without attribution causes exactly the disputes the app is meant to prevent, and it is visible only inside the event it belongs to; error reports are the only way a service this small finds out it is broken, and event links are stripped from them; abuse prevention protects other users as much as us; a purchase record is how we answer a refund, a payment dispute or a claim about something you paid for; and visit totals tell a service this small whether people reach it and whether it is fast enough for them, and totals with no identifier for you are the least intrusive way to find out. None of the five is used to build a profile, to target you, or for any purpose outside running the service. If you object, write to us — section 9.
6. Who can see your data
6.1 Other people in your event
Anyone holding an event’s link can open that event. They will see the event name, the member names, the to-do list, the expense descriptions and the amounts. That is how joining works — the link is the invitation — and it is the most important sentence in this policy.
The host can rotate or revoke that link, which stops the old one working. If a link has reached someone it should not have, that is the fix.
6.2 What stays private even inside an event
- By default, who owes whom is private to the two people involved. You see only the debts you are part of, and neither the host nor anyone else gets a group-wide view of who owes what. A co-host or admin can switch the event to group-wide balances: everyone in it then sees every remaining debt, not only their own. The switch applies to everyone equally, the activity log shows who made it, and it can be switched back.
- Buying an Event Pass is visible to the whole event. The activity log shows who unlocked it, and shows it again if it ends through a refund or a payment dispute.
- An expense marked private is visible only to the people it involves.
- Activity log entries that would disclose what someone else spent or owes are shown only to the people they concern: the entries about a private expense, and the entry recording that a debt was settled.
- One money entry is visible to the whole event on purpose: cash handed over between two members. It names both of them and the amount, because either of them can record it — including against a placeholder, which cannot answer back — and the group seeing it is what keeps that claim honest.
6.3 Nobody else
We do not sell, rent, share or trade personal data. There is no advertising network, no third-party analytics, no data broker and no third party receiving data for its own purposes. The visit totals in section 3.4 are produced for us alone, by Cloudflare as our processor. The only recipients are the processors in section 7, and whoever sells you a paid feature — Google in the Android app, Stripe on the web — each receiving your payment data as its own controller; see section 1.
We would disclose data if a valid legal order required it. That has never happened; if it does, we will tell you unless the order forbids it.
If CabuTally ever changes hands — sold, merged, or transferred with the activity — your data goes with the service, and whoever takes it on is bound by this policy. We would say so in the app before it happened, and you can always ask us to delete your data first.
7. Processors
These companies process data on our instructions only, under written data processing agreements that meet Art. 28(3) GDPR.
| Processor | What it does | Where |
|---|---|---|
| Supabase | The database and sign-in | Ireland (eu-west-1) |
| Resend | Sending the sign-in code emails, if you create an account | Sent from Ireland; its records are in the United States, see below |
| Sentry | Error and performance reports | Germany (EU region) |
| Cloudflare | Serving and delivering the app and this site, running the plugin for AI assistants, and counting visits to the app | Global edge network — see below |
| Google Cloud | Delivering Google Play’s purchase notices to us, for a purchase made in the Android app | Google’s network — see below |
| Google Workspace | Our email, including every message sent to atencion@azurblade.com, privacy requests among them | Google’s network — see below |
That is the complete list.
Google appears as a seller and as a processor, and they are different things. When you buy in the Android app, Google is the seller and handles your payment as its own controller (section 1), which is why that role is not in this table. Separately, Google Play has to tell us that a purchase happened, that a subscription renewed, or that one was cancelled or refunded, so that what the app shows you stays correct. Those notices reach us through Google Cloud Pub/Sub, on a project we run and on our instructions, which makes Google our processor for that delivery. The notice carries a reference number for the purchase and nothing else — not your name, your email, your payment details, or anything from your events. We send Google no information about you at any point: we only ask it about a purchase reference it gave us.
Stripe is not in this table, for the reason section 1 gives: on the web it is the seller, and it processes your payment as its own controller, not on our instructions.
8. International transfers
Supabase and Sentry hold your data in the EU. Supabase is in Ireland; Sentry is on its EU region in Germany, which is a deliberate choice — the default would have been the United States. Both are US companies, and their staff may reach that data from outside the EU for support and maintenance; that access is covered by the European Commission’s Standard Contractual Clauses in their data processing agreements.
Cloudflare is the honest exception, and we would rather explain it than claim otherwise. Cloudflare delivers the app and this website, and runs the plugin for AI assistants, from a global network, so a request can be served by a machine outside the EU, and Cloudflare’s parent company is in the United States. What Cloudflare processes in that role is delivery data — IP address, requested address, browser type — plus the visit reports in section 3.4 and the plugin requests in section 3.6, which are answered and not kept, and not the contents of your events, which stay in the Supabase database in Ireland. The transfer is covered by Cloudflare’s data processing agreement, which incorporates the European Commission’s Standard Contractual Clauses, and Cloudflare’s certification under the EU–US Data Privacy Framework.
Resend is the second exception. Resend sends the sign-in emails, which carry your email address and the code, and only if you create an account. We send them from Resend’s EU region in Ireland, but that setting only decides where a message is routed from. Resend keeps its own records of it (the recipient address, the delivery status and its logs) in the United States, whatever region is chosen. The transfer is covered by Resend’s data processing agreement, which incorporates the European Commission’s Standard Contractual Clauses, and by Resend’s certification under the EU–US Data Privacy Framework.
Google Cloud is the third exception, and the smallest one. The purchase notices described in section 7 are delivered on Google’s own global network, and Google’s parent company is in the United States. What travels is a reference number for a purchase Google already made and already knows about — no name, no email, no payment details, nothing from your events — so there is nothing in it that identifies you to anyone who does not already hold the purchase. The transfer is covered by Google Cloud’s data processing addendum, which incorporates the European Commission’s Standard Contractual Clauses, and by Google’s certification under the EU–US Data Privacy Framework.
Google Workspace is the fourth. It holds our mailbox, so an email you send us, a privacy request included, is stored on Google’s global network. The transfer is covered by Google’s Cloud Data Processing Addendum, with the same Standard Contractual Clauses and EU–US Data Privacy Framework certification as above.
You can ask us for a copy of these safeguards at atencion@azurblade.com.
The seller’s own transfer safeguards govern the payment data it processes as its own controller — they are in Google’s and Stripe’s privacy policies, not this one, for the same reason Google’s govern an installation from Google Play (section 1).
9. Your rights
Under the GDPR you have the right to:
- Access — get a copy of the data we hold about you.
- Rectification — have inaccurate data corrected. Most of it you can correct yourself in the app.
- Erasure — have your data deleted. Section 10 explains what that means for a shared ledger.
- Restriction — have us stop using data while a dispute about it is resolved.
- Portability — receive the data you gave us in a machine-readable form.
- Object — object to processing based on legitimate interest, on grounds relating to your situation. Section 5 lists which processing that is.
- Withdraw consent — where we ever rely on consent. Today we do not rely on it for anything.
- Not be subject to automated decisions — see section 12.
How to exercise them. Write to atencion@azurblade.com. There is no form and no account needed. If you have an account, you can also delete it yourself in the app (section 10). We answer within one month, as Art. 12(3) requires. If a request is unusually complex we may extend that by two further months and will tell you why within the first month. Exercising a right is free; we may charge a reasonable fee only for a manifestly unfounded or excessive repeat request.
How we identify you, and why we have to ask. Unless you created an account, we hold no email address for you, so we cannot recognise you from a message alone. Send your request from a device that can open the event and include the event link and the display name you used in that event. A host can request deletion of an entire event. We ask for nothing beyond what is needed to locate the data, and we do not create an identity record in order to answer you.
Complaints. If you think we have handled your data badly, tell us first — it is usually faster.
You also have the right to complain to a supervisory authority. Ours is the Agencia Española de
Protección de Datos (aepd.es, C/ Jorge Juan 6, 28001 Madrid). If you live elsewhere in the
European Economic Area, you may complain to the authority in your own country instead.
10. What deletion actually means
Deleting an event removes the event and everything in it, for everybody.
Deleting you from an event other people still use is different, and we want to be plain about it. Your name and your identifiers are removed. The amounts stay. They are also the financial record of everyone else in that event, and removing them would silently change what other people are owed — so your name goes and the arithmetic stays.
What stays no longer carries your name or any identifier, so it no longer identifies you to us. We keep it because the other members’ interest in a correct ledger (Art. 6(1)(f) GDPR) outweighs your interest in removing a number that no longer names you, and it is why the app was built with no link between a member and an account in the first place. If you want the whole event gone, ask the host, or ask us and we will contact them.
This does not apply to purchase and billing records — section 11 says how long those are kept.
10.1 Deleting your account
If you created a CabuTally account, you can delete it yourself in the app: Profile → your account → Delete account. To confirm, you type your account’s email address. It happens at once and cannot be undone. You need no account and no app to ask us instead: write to atencion@azurblade.com (section 9) and we will do the same for you.
- What is deleted: your account (its email address, the Google link if you used one, and the preferred name), your anonymous identifier, the access every one of your devices had to your events, any recovery link, and every event nobody else could see.
- What changes: in every other event, your name becomes “Deleted user”, in the event’s history and its payments too. Nobody can take over your place in the event.
- What stays: the amounts, for the reason above; text you wrote inside a shared event, such as an expense description, because it is part of the group’s record; and purchase and billing records (section 11). An event holding a purchase record is kept with your name removed, rather than deleted.
- A subscription that renews must be cancelled first, so that you are not charged for an account that no longer exists.
11. How long we keep it
Nothing expires automatically except sample events, and we would rather say so than promise a retention period that nothing enforces.
| Data | Kept |
|---|---|
| Events and everything in them | Until deleted on request. An archived event stays readable to its members. |
| Sample events | A sample event is the example trip created when you open “See a sample event”. It is deleted after 60 days with no activity, unless an Event Pass was bought for it or someone else joined it. |
| Deleted items inside a live event | Removing an expense, a to-do or a member hides it and keeps the row, so the action can be undone and the ledger can be audited. It is destroyed when the event is deleted. |
| The anonymous account identifier | Until you delete your account in the app (section 10.1), or ask us to delete it. |
| Account email address | Until you delete the account. |
| Purchase and billing records | Our record of a purchase (product, date, status, the seller’s reference) is kept while the event or account it belongs to exists, and after an account is deleted for as long as a refund, a payment dispute or a claim about it is still possible — at most 5 years, the general limitation period for claims in Spain (Art. 1964 of the Código Civil). Deleting an event deletes its Event Pass record. The seller keeps its own transaction records under its own legal obligations. |
| Error and performance reports | Sentry’s retention: at most 90 days for error reports, and 30 days for performance measurements and log lines. |
| Delivery logs | Cloudflare’s and Supabase’s own short retention periods. |
| Plugin requests from AI assistants | Not kept: each is answered and discarded. Only the count of how often each tool is used remains, with nothing from the request in it. |
| Visit statistics | Cloudflare keeps the individual reports for 7 days, then only sampled totals. |
| Records of privacy requests | Up to 3 years, to show we handled them — Art. 5(2) accountability. |
If automatic expiry reaches other data, this section changes with it and the date at the top changes too.
12. No profiling, no automated decisions
Nothing here profiles you, scores you, or makes a decision about you automatically within the meaning of Art. 22 GDPR. The app works out splits from the amounts people enter, which is arithmetic you can check rather than a decision made about you.
13. Children
CabuTally is not intended for anyone under 16, and we do not knowingly collect data from anyone under that age. If you believe a child’s data is in an event, write to atencion@azurblade.com and we will remove it.
14. Security
- Connections are encrypted in transit, between your device and us and between us and our providers.
- Data is encrypted at rest by our database provider.
- Access is enforced by the database itself, not only by the app: every table has row-level security, and a request that should see nothing receives nothing rather than being filtered later.
- Event links are stripped from error reports, because a link grants access.
- We do not store passwords. Sign-in is a one-time code or Google.
- We do not handle your card or bank details at all — Google or Stripe collects and holds those directly; see section 1.
- Administrative access is limited to us, protected by two-factor authentication.
If a breach occurs that is likely to risk your rights and freedoms, we will notify the AEPD within 72 hours as Art. 33 requires, and tell affected users directly where Art. 34 requires it.
No system is perfectly secure. The largest risk to your data in this product is not technical: it is an event link being forwarded to someone it was not meant for.
15. Cookies and local storage
We use no cookies for tracking, advertising or analytics, and there is therefore no cookie banner. What is stored on your device is strictly necessary for a service you have requested, which is exempt from the consent requirement under Art. 22.2 of Spanish Law 34/2002 (LSSI) and Art. 5(3) of the ePrivacy Directive.
The error and performance reports in section 3.4 store nothing on your device. They are sent from it, and only to Sentry.
The visit statistics in section 3.4 also store nothing on your device, but they do make it send a report, so they are covered by the same rule. They are audience measurement that produces anonymous totals for us alone, which the AEPD’s guidance on audience-measurement tools (January 2024) treats as exempt from consent under Art. 22.2 LSSI. A content blocker stops them without costing you anything in the app.
| Stored | Why | Kind |
|---|---|---|
| Your session | Keeps you signed in to your seat | Local storage, until sign-out |
| A copy of your event data | So the app works offline, which is a feature you asked for | Local storage |
| Language and theme | Remembers your choices | Local storage |
| Default currency | Prefills the currency when you create an event | Local storage |
| Dismissed notices | Stops the app repeating a message you closed | Local storage |
| Sign-in return address | Brings you back to the right page after signing in | Local storage, momentary |
| An unfinished purchase | Finishes a Google Play purchase that was interrupted, so what you paid for still reaches you | Local storage, until it completes |
| Whether you opened the app from Google Play | Shows the buying and cancelling options that match how you installed it | Local storage |
| Moving to a new device | Carries your seats over when you sign in with your account on another device | Local storage, momentary |
| A sign-in in progress | Remembers which sign-in you started, so it can finish after Google sends you back | Local storage, momentary |
| What you have already seen, and how you left a screen | Marks activity as read, and remembers filters and collapsed sections | Local storage |
You can clear all of it through your browser’s site-data controls. Doing so signs you out, and if you have no account and no saved link, it can cost you your seat in an event — see section 3.3.
16. Changes to this policy
We may update this policy — when a feature changes, or when the law does. The date at the top always reflects the current version. If a change materially affects your rights, we will say so prominently in the app rather than relying on you to notice a date.
17. Contact
Wilfredo Oswaldo Hernández Argueta · Calle Ruiz Zorrilla 20 1 p6, 39009 Santander, Cantabria, España · atencion@azurblade.com
Supervisory authority: Agencia Española de Protección de Datos, aepd.es.
18. Who is responsible
CabuTally is run by Wilfredo Oswaldo Hernández Argueta, working as self-employed (autónomo), established in Spain, at Calle Ruiz Zorrilla 20 1 p6, 39009 Santander, Cantabria, España.
CabuTally is published under the name Azurblade, a brand of the person identified above. Azurblade is not a separate company and does not change who is responsible for the service or for your personal data.
We are the data controller for the processing described in this policy, under Regulation (EU) 2016/679 (the GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Contact for anything in this document, including privacy requests: atencion@azurblade.com.
We have not appointed a Data Protection Officer. We are not required to: we are not a public authority, our core activity is not large-scale monitoring, and we process no special-category data. Requests go to the address above and are handled by us directly.