Guides

Privacy and encryption

What TmCount stores, how server-side amount encryption differs from optional end-to-end encryption, and where ads fit on the free web app.

01

What we store to run the app

Your account needs an email, a display name, and a hashed password. Groups store members, categories, expenses, and the history of changes. Invite links and notification tokens exist so people can join and so you can hear about new activity. Billing providers handle card details; TmCount keeps plan status, not your full card number.

The Privacy Policy is the legal description of this. These paragraphs are the practical version: the app cannot split a bill it cannot store, and it cannot notify you without a way to reach your device.

02

Amount encryption by default

Expense amounts are encrypted at rest on the server for every group. That protects a database dump of raw totals better than storing amounts in plaintext. The server still decrypts amounts when it needs to show you a balance, compute stats, or build a notification, because those features need numbers.

Descriptions and other metadata are not in that default amount encryption. If you need the server not to read expense contents, that is a different mode.

03

Optional end-to-end encryption

Premium and partner plans can enable end-to-end encryption on a group. In that mode, expense contents are encrypted on your devices. The server stores ciphertext and the routing metadata it needs to deliver the row to the right group. Members who should read the group receive keys on their devices. If every device that holds a key is lost and you have no recovery path, that data can become unreadable.

Placeholder members without an account cannot receive a device key. Strict end-to-end groups work best when everyone who needs access has a real TmCount account. Enabling this mode is a group decision with trade-offs; read the in-app notices before you turn it on for a trip that already has a long history.

04

Advertising on the free web app

The free web app may show Google AdSense ads. Native iOS and Android builds do not use AdSense. Premium and partner accounts are ad-free on the web. Google and its partners may use cookies or device identifiers as described in the Privacy Policy and in Google’s advertising policies.

In the European Economic Area, the United Kingdom, and Switzerland, a consent message appears where required before personalized ads. You can change or withdraw consent through that message or your browser settings. Ads are not the reason to use TmCount; they offset the free tier. If you do not want them, Premium removes them.

All help articlesBrowse all guides →