Privacy
Last updated 3 September 2026
PayUp splits restaurant bills. To do that it stores your receipts and who owes what. This page says exactly what is collected, who it reaches, how long it is kept, and how to get rid of it — in plain terms, with no claims that aren't true of the running app.
What PayUp stores
Your account. Your email address, and either a password (stored hashed, never in plain text) or the fact that you signed in with Google. If you set them: your theme, your accent colour, and a default tip percentage.
Your trips. The trip name and the list of participant names you type in. Note that participants are just names — adding “Sam” to a trip stores the text “Sam”; it does not create an account for anyone or contact them.
Your receipts. The photo you upload, the line items read from it (names and prices), who paid, tax and tip, and who is assigned to each item.
Support and diagnostics. If you use the help widget to report an error or suggest a feature, PayUp stores your message, the page you were on, the trip or receipt in view, and your browser's user-agent string. When the app hits an error it records the error message, a stack trace, the page, and the user-agent — automatically, so problems can be fixed without you having to report them.
Access requests. If you ask for expanded access, PayUp stores that request against your email.
A copy kept on your device. So that you can still look at your trips with no signal, PayUp keeps a copy of the trip and receipt details you have opened in your browser's own storage on that device. It holds the same text you already see on screen — names, amounts, who paid, who shared what — and not your receipt photos. It is stored separately for each signed-in account, and it is deleted when you sign out, when a different account signs in on the same device, and automatically once it is more than 30 days old. Nothing in it is sent anywhere: it exists only to be read back on the device that saved it.
PayUp does not collect payment card details, location data, contacts, or advertising identifiers, and there are no ads or third-party analytics or tracking scripts.
A note about receipt photos
Receipt photos are the most revealing thing PayUp holds. A receipt can show the merchant, its address, the date and time, what was bought, and sometimes the last four digits of a card.
This was not always the case. Receipt images used to be stored so that anyone holding the direct link could open one without signing in. That is no longer how it works.
Profile pictures are the exception — any picture uploaded before the feature was retired is still stored, and anyone with the direct link can view it. They are not listed anywhere and the addresses are not guessable. PayUp no longer offers a way to upload one, and there is no longer a control to remove one either — if you uploaded a picture and would rather it were gone, ask through the help widget and it will be deleted.
Who else your data reaches
- People you invite. Anyone who joins a trip can see that trip's receipts, images, items and totals. Only share an invite link with people you want to have that access.
- Supabase — hosts the database, file storage and sign-in for PayUp. All stored data lives there.
- Railway — runs the PayUp application itself.
- Google Gemini — your receipt photo is sent to Google's Gemini API to read the line items off it. This is how scanning works; there is no way to use the scan feature without the image being processed there.
- Google — only if you choose “Continue with Google” to sign in.
PayUp does not sell your data, and does not share it with anyone beyond the services above.
How long it is kept
Receipt photos are deleted automatically. Free-plan receipts keep their image for 30 days; on the paid plan it is 90 days. The window is fixed when you upload, so a change of plan never shortens it. Each receipt shows its own countdown.
When that window passes, the image is deleted and item names are replaced with Item 1, Item 2 and so on — removing what was bought. Prices, who owes whom, and the settle-up totals are kept, so old trips still add up. See the help page for more.
Everything else is kept until you delete it. Trips, participants, splits, your profile, and support or error records have no automatic expiry.
Removing your data
- A receipt — delete it from the receipt, and its image goes too.
- A trip — deleting a trip removes its receipts.
- Your profile details — display names and profile pictures have been retired, so there is nothing left to set and no control to clear. If you set either before that, ask through the help widget and it will be removed.
If you cannot sign in — you have lost the password and the mailbox it would reset to — email privacy@payup.cloud. Say which email address the account uses. Expect to be asked something only the account holder would know before anything is deleted: the same reason a request has to come from the account also means an unverified one cannot simply be acted on.
Deletion is permanent — deleted receipts and images cannot be restored. If you need a receipt for expenses or a warranty, save your own copy before it expires.
PayUp is in beta
PayUp is a small project run by one person and is currently in beta testing. It is not a bank and does not move money — it only works out who owes what. Please don't rely on it as the only record of anything financially important to you.
If this policy changes in a way that affects what is collected or how long it is kept, the date at the top of this page changes with it.
Questions
Signed in, use the help button in the bottom-left corner of any screen inside the app and choose Report an error — that reaches us directly, and carries the page you were on, so it is the better route when it is available to you. It is also how a data-deletion request is made.
For anything about your data that the widget cannot carry — or if you cannot sign in to reach it — privacy@payup.cloud is read by the person who maintains PayUp.