dimesum

Privacy notice

Last updated 21 September 2026

Dimesum keeps the score for groups of friends who share money. This page says what we keep about you to do that, why we keep it, how long, who else touches it, and how you see, correct or delete it. There is no advertising and nothing is sold.

Who we are

Dimesum is operated by the Dimesum team, reachable at support@dimesum.com. Under India's Digital Personal Data Protection Act 2023 we are the data fiduciary for the personal data described here, and that address is also our grievance contact. If you write to us about your data we answer from a mailbox a person reads.

What we keep, and why

The personal data Dimesum holds, in the order you meet it
DataWhy we hold itHow long
Your email addressIt is your account. A sign in code is sent to it, and it is the only identifier we verify.Life of the account, then deleted
Your display name and, if you add one, a photoSo the people at your tables know who paid.Life of the account, then deleted
A phone number, only if you add oneSo friends who have your number in their phone can offer you a seat. It is never verified by us and never shown to strangers. We also store a one way hash of it for that matching.Until you remove it or delete the account
A Google account identifier, only if you sign in with GoogleTo recognise the same person on the next sign in.Life of the account, then deleted
The bills, splits, comments and settlements you and your group recordThis is the product. Everyone at a table sees that table's records.See "What deletion keeps" below
The ways you like to be paid (for example a PayPal handle or bank details)Shown to the people at your tables when they settle with you. Stored encrypted; the server opens them only to show them to you and your co-members.Until you remove them or delete the account
Contacts matching, if you tap "Find people from your contacts" on a phoneYour phone hashes the numbers in your address book and sends only the hashes. We answer with the accounts that match and keep nothing from the request.Not stored. The matches are cached on your phone until you refresh.
Device push tokensTo send a notification when money moves at one of your tables, once push is switched on.Until you sign out on that device or delete the account
Sign in records: the code you were sent (hashed), the address and network address it went to, the timeTo let you in, and to stop somebody guessing codes or flooding a mailbox.Codes expire in minutes. Rate limit records are purged automatically after their window.
Session and refresh tokensTo keep you signed in on your devices.Until you sign out, or the token expires
Server logs and error reportsTo know when the service breaks. Logs mask the secret parts of links. Error reports carry no bill text and no addresses.A few weeks, then gone

What we do not do

When a line you type is read by a model

If you type a bill as a sentence, such as "coffee 12 with Lucas", a language model turns it into a draft you confirm. Before the sentence leaves our server, phone numbers, email addresses and payment handles in it are replaced with placeholders, and government identifiers are removed outright. The names of the people at your table are sent, because matching them is the point. The model provider is Groq, Inc., under terms that forbid training on the text and bound how long it is retained. Nothing a model returns posts on its own; a person always confirms.

Who processes data for us

Service providers that touch personal data, and what each one sees
ProviderUsed forWhat it sees
Oracle Cloud Infrastructure (Mumbai region)The servers and databaseEverything in the table above, encrypted at rest
ResendSending your sign in codeYour email address and the code
GroqReading a typed bill into a draftThe masked sentence and the names at the table
CloudflareThis website, DNS, encrypted backups and profile photosWebsite visits (no cookies from us); backups are encrypted before they leave our server
SentryCrash and error reportsTechnical details of a failure, your account identifier, never bill text
Grafana CloudPerformance tracesRequest timings with secrets masked
GoogleSign in with Google, if you choose itGoogle tells us your verified address and identifier
Expo (Apple and Google push services behind it)Notifications on your phoneYour device token and the short notification text

Where it lives

Our servers are in Mumbai, India. This website is served from Cloudflare's network worldwide. Backups are encrypted on our server before they are stored and kept for at most 35 days.

Your choices and rights

What deletion keeps

A bill is a shared record. When you delete your account we delete your email, name, photo, phone, payment details, sessions and devices, and your seats at every table become "Former member". The amounts on the bills you shared stay, attached to that anonymous seat, because your flatmates' balances are their records too and would be wrong without them. This is the arithmetic of the table without the person. Backups age out within 35 days.

Children

Dimesum is for adults. You must be 18 or older to open an account.

Cookies

This website sets no cookies. The web app keeps your sign in in your browser's storage on your own device, and nothing else.

Changes

When this notice changes we update the date at the top and, for a change that matters, tell you in the app before it takes effect.