Last updated 26 September 2026

Privacy policy

How the two cats iPhone app handles your data.

In short

two cats is made and run by Liam Sbarro (“we” in this policy). It's an iPhone app for keeping track of shared expenses.

  • There are no ads, no analytics and no tracking. We don't sell your data or share it with advertisers or data brokers.
  • You can use two cats without an account. If you do, your ledger stays on your iPhone and isn't sent to us.
  • If you sign in with your phone number, your ledger is synced to our server so you can restore it on a new iPhone and share expenses with other people who use two cats.
  • You can delete your account in the app at any time: Settings → Delete account.

What we collect

On your iPhone

Your ledger (the people you add, expenses, splits, settlements, groups and receipts) is stored in the app on your iPhone and protected by iOS data protection. two cats doesn't access your contacts: you add people by typing a name. It uses the camera only when you scan a receipt, and the photo picker gives it only the photo you choose.

When you sign in

  • Your phone number, to send you a sign-in code and find your account. We store it encrypted (AES-256-GCM, with a key held only by our API server), next to a one-way SHA-256 hash of the number that we use to look your account up.
  • Sign-in records. For each device you sign in on: a device identifier, the IP address it signed in from, the app's user agent (which names the app and iOS versions), and when it was last used. The sign-in token itself is stored only as a hash.
  • Your ledger: expenses (descriptions, amounts, dates and notes), splits, settlements, the names you give people, groups and the activity history. We store these so you can restore them and share them. They are not end-to-end encrypted: they're readable on our server. Our database provider encrypts them at rest, and every connection uses TLS. We don't store the phone numbers of people you add.
  • Receipt photos, when you scan a receipt. The photo is uploaded to our storage so it stays with the expense, and it's sent to Taggun to read the items (see Service providers).
  • Invitations. When you invite someone to link with you, we store your display name, so they can see who invited them, and, if the invitation is for a specific number, a one-way hash of their phone number, so only they can accept it. Invitation links expire after 7 days.
  • Server logs. Each request to our server is logged with the address requested, the result, how long it took and a network address. Logs never contain phone numbers, sign-in tokens or your ledger.

What we don't collect

Your location, your contacts, your advertising identifier, usage analytics or push-notification tokens.

Diagnostic reports

If something goes wrong, the app may offer to “Send a report”. A report holds the app and iOS versions, the device model and identifier, sync state and recent log lines, with no names, amounts or phone numbers. It goes only where you send it from the share sheet; the app never sends it on its own.

How it's used

We use your data only to run two cats:

  • to verify your phone number and keep you signed in;
  • to back up, sync and restore your ledger;
  • to share expenses and settlements with the people you link with;
  • to read the items on receipts you scan;
  • to protect the service from abuse, for example by limiting how many sign-in codes a number or network can request;
  • to fix problems you report to us.

We don't use it for advertising or profiling, and the only text messages we send are sign-in codes you ask for.

What other people see

When you link with someone through an invitation, or share a group, they receive the shared expenses, splits and settlements you record, with your display name on them, and you receive theirs. Expenses you don't share stay private to you.

Shared records are part of the other person's ledger too, so they stay in their app, with your display name, even after you delete your account. See Deleting your account.

Service providers

These companies process data for us, only to run two cats:

ProviderWhat it receivesWhy
TwilioYour phone numberSends and checks your sign-in code by SMS
TaggunReceipt photos you scanReads the items and prices. Sent with Taggun's incognito setting, so Taggun doesn't keep the image to train its models
CloudflareAll traffic to our server, including your IP address; receipt photosNetwork protection, and storage for receipt photos (Cloudflare R2)
RenderAll traffic to our server, and its logsRuns our server in Oregon, USA, and hosts this website
PlanetScaleOur database: accounts, sign-in records, synced ledgers and invitationsDatabase hosting, on Amazon Web Services in Oregon, USA
BackblazeNightly database backups, encrypted before upload with a key Backblaze doesn't holdDisaster recovery
AppleIf you're in the beta: crash reports and feedback you choose to send, and the tester details App Store Connect shows us (such as your email address, if you were invited by email)Distributing the beta through TestFlight

Each provider may use this data only to provide its service to us, and is bound by its data-processing terms to protect it with safeguards at least as strong as the ones this policy describes. Apple also handles TestFlight data under its own privacy policy.

Where it's stored

Our server, database, backups and receipt photos are all in the United States. If you use two cats from another country, your data is transferred to and stored in the United States. Twilio and Taggun process what they receive on their own infrastructure, which may be in other countries.

How long we keep it

DataKept
Phone number and its hashUntil you delete your account
Ledger items only you can seeUntil you delete your account, when they're erased
Shared expenses and settlementsKept, because they're part of other people's ledgers
Receipt photosUntil you delete your account
Sign-in recordsThe IP address and user agent are kept while the sign-in is active, then cleared 30 days after it is signed out, revoked or expires. When you delete your account, every one is signed out and none can be linked to your phone number again.
InvitationsThe link stops working after 7 days. The invitee's hashed phone number and the inviter's display name are kept until 30 days after the invite is accepted or expires, then cleared. Deleting your account removes your name from invitations you sent.
Server logs7 days
Backups2 days (database provider) and up to 30 days (encrypted nightly backups)
Data on your iPhoneUntil you delete your account in the app or delete the app

Deleting your account

In the app, go to Settings → Delete account. If you're signed in, the app asks our server to delete your account first and only erases your iPhone once the server confirms. If that fails, nothing is deleted and you can try again.

On our server, deleting your account:

  • erases your phone number and its hash, so the account can never be signed into again (signing in later with the same number starts a new, empty account);
  • signs out every device;
  • removes you from every shared group;
  • cancels pending invitations you sent and removes your name from all of them;
  • erases the ledger items only you could see;
  • deletes your receipt photos.

What stays: shared expenses and settlements, with your display name, in the ledgers of the people you shared them with, so their balances still add up; and an internal account record with no phone number attached. Backups taken before the deletion are removed within 30 days. If we ever restore from one, we delete your account again.

Deleting the app from your iPhone erases the data on that iPhone but doesn't delete your account on our server. Signing out keeps your data on that iPhone.

Can't use the app? Email [email protected] with the phone number on the account. We'll check that the number is yours and delete the account within 30 days.

Your choices

  • Use two cats without signing in, and nothing leaves your iPhone.
  • Change your display name in Settings, and edit or delete your expenses in the app.
  • Ask for a copy of the data we hold about you, or ask us to correct or delete it, by emailing [email protected]. We reply within 30 days.

Children

two cats isn't meant for children under 13, and we don't knowingly collect their data. If you think a child has signed in, email us and we'll delete the account.

This website

This site sets no cookies and has no analytics, tracking or third-party scripts. Our host, Render, keeps standard request logs (such as IP address and the page requested) to run the service.

Changes to this policy

When we change this policy, we update the date at the top. If a change is significant, we'll also tell you in the app or in the TestFlight release notes before it takes effect.

Contact

Questions about this policy, or about your data: Liam Sbarro, [email protected]. For help with the app, see Support.

↑ Back to top