Skip to content

Privacy Policy

How Nettat handles
money and data.

Nettat keeps shared expense records. If you turn on collaboration, it also processes personal data. This policy explains what happens, what does not happen, and what you can control.

Version 2.3 Effective 6 September 2026 Scope Nettat and its optional services

The rules Nettat follows.

A plan is not a payment

Nettat never treats a Payment Plan as proof that money moved. Only saved expenses and recorded payments change a balance.

Private unless you share

A private Group or Expense works without an account. Collaboration and read-only web links stay off until you choose them.

No ads or tracking

No ads, third-party analytics, cross-app tracking, sale of personal data, or marketing profiles.

01

Scope and status

This policy covers the Nettat iPhone app, its optional collaboration service, read-only secure Group and Expense pages, and the Nettat website. Nettat is offered in the European Union and is marketed primarily in Sweden. It describes the verified behavior of the source prepared for the next release and the services it can use.

Private and collaborative Groups and Expenses use different services. The sections that apply depend on the features you turn on. This policy does not reduce rights you have under applicable data-protection law or replace Apple’s terms for TestFlight, iCloud, or your Apple Account.

Alexander da Silva owns, runs, and maintains Nettat as a private individual based in Sweden and is the controller for personal data processed through Nettat’s collaboration service and website. The public privacy contact is hello@nettat.com.

Nettat is not directed or marketed to children and does not ask for a user’s age. Minors may use Nettat where permitted; a parent or guardian should assist when applicable law requires it.

02

Financial accuracy

Nettat is a record-keeping and calculation tool. It does not hold, send, receive, or confirm money.

  • A Payment Plan is calculated from the Group’s or Expense’s recorded balances. It suggests how to bring them to zero.
  • Record Payment is used only after a person confirms that money actually moved. Nettat does not infer a payment from a message, link, price, or intention.
  • A Group or Expense is settled only when its recorded balances are zero. Editing or undoing an expense or payment recalculates the plan.
  • Nettat keeps the original expense amount and its settlement-currency value visible. Rounding is an explicit Group or Expense setting and must remain balanced.

Nettat does not profile people or make automated decisions with legal or similarly significant effects. A Payment Plan is only a calculation based on the records in the Group or Expense.

03

What data is handled, and why

Private Groups and Expenses

Private Groups and Expenses use SwiftData on your device and may use your private iCloud and CloudKit storage when those Apple features are available and enabled. They do not require a Nettat collaboration identity and can work offline. On-device receipt recognition and optional Apple Intelligence refinement are not developer collection.

Collaborative Groups and Expenses

Collaboration starts only when you turn it on. The owner creates or imports a shared copy. Nettat then processes the data needed to synchronize the Group or Expense and control access:

  • a private, account-free collaboration identity, device sessions, recovery, and records of who made a change;
  • display names, optional phone numbers, Group or Expense settings, roles and memberships;
  • expenses, payers, splits, line items, currencies, balances, Payment Plans and recorded payments;
  • size-limited receipt images and the records needed to authorize, attach, download and delete them; and
  • limited records used for security, request limits, change history, and audits.

Optional receiving details and payment services

You can add a Swish receiving number, PayPal.Me handle, or personal Revolut.me link. These optional details are stored in your private profile and private Person records on your device and may sync through your private iCloud storage. When collaboration is active, your own profile details also sync to an owner-controlled directory in Cloudflare D1. You can clear them; deleting your collaboration identity removes its directory entry.

The directory is not included in ordinary Group sync, invitations, notifications, or Group Web Access. For a current Payment Plan transfer, Nettat can disclose the recipient’s receiving methods to the authenticated sender after checking that exact transfer. A recipient can also explicitly share their own Swish number through a single-payment link, as described below. Group membership alone does not give directory access, and admins cannot change or share another member’s private receiving details.

Opening a payment service is your choice. Swish receives the receiving number, amount and a return link; PayPal receives the recipient handle and supported amount and currency; Revolut receives the personal link. The provider controls its own profile, authentication, fees and payment approval and may receive ordinary connection metadata. Nettat does not read provider credentials or automatically record a payment when you return. You still confirm and use Record Payment after money has moved.

Public exchange rates

Automatic currency conversion can fetch the European Central Bank’s public daily reference rates directly over HTTPS. The request contains no Group, Expense, person, selected currency, amount, receipt, or Nettat identity. It still exposes ordinary network metadata, such as the apparent public IP address and request timing, to the network and the ECB. The app caches only public rates and their dates on your device; this cache is not synced to iCloud or Nettat’s collaboration service.

Optional collaboration notifications

If you enable notifications on a device, Nettat creates a random installation identifier and receives an opaque Apple Push Notification service token. The collaboration service links them to your Nettat collaboration identity only to notify that device about activity by another active member in a shared Group. The token is encrypted at rest and is not used for advertising, analytics, tracking, or device fingerprinting.

A notification may name the Group, the member who acted, an Expense title, or the people in a recorded payment. It never includes amounts, balances, phone numbers, collaboration codes, or receipt content. The notification carries only validated identifiers used to refresh authoritative Group data before Nettat opens an Expense, the Payment Plan, or the Group.

Nettat uses this data for app functionality, synchronization, collaboration, access control, security, recovery and support. It is not used for advertising, cross-app tracking, marketing profiles, or sale.

Legal bases

  • Contract: processing is necessary to provide collaboration, recovery, secure Web Access, and the other features a user requests.
  • Legitimate interests: Nettat processes limited data to keep the service secure, prevent abuse, answer support and privacy messages, maintain accurate shared-expense records, and handle details another member enters before a person joins. These interests are limited by data minimization, role-based access, and the correction and deletion controls described below.
  • Legal obligation: data may be processed or retained when applicable law requires it.

Infrastructure

Nettat uses Apple, Cloudflare, and STRATO for its app and service infrastructure. Optional payment handoffs and public exchange-rate requests are described separately above. Apple provides the App Store, TestFlight, private iCloud and CloudKit services, device Keychain features, on-device receipt services, Apple Push Notification service delivery, and the iCloud Mail inbox used for privacy contact. Cloudflare provides the website, optional collaboration through Cloudflare Workers and Cloudflare D1, private R2 receipt storage, notification queues, secure pages, and request limiting. STRATO provides domain administration and does not receive Group or Expense content through Nettat. The app contains no third-party advertising or analytics SDK.

Apple and Cloudflare may process data outside the EU or EEA. Apple states that EEA personal data is controlled by Apple Distribution International in Ireland and that its international transfers use Standard Contractual Clauses. For developer-side data processed by Cloudflare, Nettat relies on Cloudflare’s Data Processing Addendum, including its EU Standard Contractual Clauses where required. Their current privacy and subprocessor information is available from Apple and Cloudflare.

Email contact

The website provides a direct email link to hello@nettat.com, not a web form. If you choose to email, your mail service sends your email address, message, and any name you include to Nettat’s Apple iCloud Mail inbox. Cloudflare serves the page and link but does not receive the email content from that link. Nettat does not write the message to D1, use it for marketing, or share it with Group or Expense members.

04

Contacts and receipts

Contacts

Nettat uses Apple’s one-off Contacts picker rather than requesting access to browse your address book. iOS owns browsing and search. Nettat uses only the name and phone number you explicitly select and keeps no Contacts identifier. The collaboration service never receives a copy of your address book or a list of its contacts.

Phone numbers are optional. They can help with invitations and payment messages and may identify the recipient of a current transfer in a secure read-only page. They are never used for sign-in, discovery, identity recovery, or access to a Group or Expense.

If you have not joined Nettat, a Group or Expense member may have entered your name, optional phone number, and share of an expense. That member is the source of the data. It is used only for the shared-expense record and related invitation or payment message, and you can request correction or deletion through the privacy contact.

Receipts

Receipt recognition uses Apple Vision on the iPhone. Apple Intelligence refinement starts only when you choose it for that receipt and stays on the device. Nettat keeps a size-limited copy of the receipt image with source metadata removed.

In a private Group or Expense, that derivative follows its local and optional private iCloud storage. In a collaborative Group or Expense, it is uploaded to a private R2 bucket so authorized members can view it through short-lived, membership-authorized URLs. If Web Access is active, anyone with that secure link can also open an attached receipt from the read-only expense details.

05

Collaboration, sharing and access

Each collaborative Group or Expense has roles and a rotatable code. A person who knows the current code can review the item and explicitly accept access; that acceptance creates or restores their membership without a separate owner or admin approval. Owners and admins can replace the code without changing existing members.

A secure read-only web link is a separate sharing choice. The link is reusable and forwardable. Anyone who receives it can read the limited set of Group or Expense details listed below until an owner or admin replaces or revokes the link, or archives the item.

The secure page can show display names, expense titles and dates, paid and share amounts, line-item details, attached receipt images, recorded payments, balances, and the selected Payment Plan. A current transfer may show the receiving person’s full stored phone number. It excludes notes, collaboration codes, memberships, authorship, receipt storage details, and internal identifiers.

The active secret is stored in the device Keychain, and the active service record stores a cryptographic hash that cannot be used to recover the link. To make a mutation safely replayable, an encrypted response can temporarily contain a newly issued link for up to seven days. Share a secure link only with the people who should read it.

Single-payment links

For one current transfer in a shared Payment Plan, the recipient, owner or admin can choose to create a separate seven-day payment link. Before sharing, Nettat explains that anyone with the link, including someone it is forwarded to, can see the sender and recipient display names, exact amount and currency, expiry and any included Swish number. The link does not give access to the Group, other transfers, receipts or history and cannot record a payment. The recipient may share their own configured Swish number; otherwise, only an eligible saved contact number can be included, without overriding cleared receiving preferences.

Message previews contain generic Nettat information, not payment details. The service stores only the link’s hash and transfer references, not a copy of its destination. The app and browser hold the token only in temporary memory; the browser removes it from the address bar. Your chosen message or sharing service can retain the link. Links stop working after expiry, revocation or relevant plan, access or receiving-detail changes. Expired link records are removed by scheduled cleanup. Cancellation of the native message composer requests revocation; cancelling another share sheet may leave a copied link active. Opening Swish is a separate confirmation and is never proof of payment. The web handoff sends no return link or Nettat access token to Swish.

06

Security commitments

  • Production collaboration and secure-page URLs are required to use HTTPS.
  • Recovery credentials, sessions, invitations, and secure-link access use long, randomly generated secrets. The service stores only keyed hashes or SHA-256 hashes.
  • The collaboration recovery credential uses synchronizable iCloud Keychain. Sessions, pending invitation credentials, and Group Web Access links use device-local Keychain storage; single-payment links use temporary memory. Private and shared stores remain separate.
  • Roles, version checks, change locks, size-limited uploads, short-lived member receipt URLs, and capability-checked no-store web receipt streams restrict access and conflicting changes.
  • Secure-link and collaborator-lookup attempts use keyed connection or token values for rate limiting. Those attempt rows are deleted after 24 hours.
  • The website email link opens the visitor’s chosen mail service and does not send message content through the Nettat website or collaboration service.
  • Credentials, phone numbers and receipt URLs are excluded from audit logging.

No service can promise absolute security. During beta testing, suspected security or privacy problems should be reported through TestFlight feedback so they can be investigated.

07

Retention and deletion

  • An active collaborative Group or Expense is retained while its owner keeps it. A deleted item has a 30-day recovery window. It is then permanently deleted with its people, invitations, expenses, receipts, and change records that contain phone numbers.
  • Receipt objects queued for deletion remain inaccessible and are retried until storage deletion is confirmed. Pending or unattached uploads expire after 24 hours.
  • Invitations expire after 14 days and can be revoked earlier. Secure-link and collaborator-lookup attempt rows expire after 24 hours.
  • Completed mutation-replay records, including encrypted responses, expire after seven days. Incomplete processing records expire after 24 hours.
  • Sessions expire after the configured session period, which is 30 days by default and can be set from 1 to 90 days. Expired session rows are removed after a further 30 days.
  • Turning notifications off removes that device’s installation from Nettat without changing the iOS permission. Invalid Apple push tokens are removed immediately. Installations not seen for 180 days are deleted. Completed notification text is removed after seven days, and content-free delivery status is deleted after 30 days.
  • Deleting a collaboration identity first requires transferring or deleting Groups and Expenses it owns. The deletion revokes sessions and invitations, disables recovery, leaves joined items and anonymizes the profile. Non-personal financial and audit references may remain where recorded history requires them.
  • Deleting a collaboration identity does not delete private iCloud Groups, Expenses, or receipts. Those remain under the app and Apple storage controls for the relevant devices and Apple Account.
  • When a Group or Expense is archived, the service may temporarily retain only the secure-link hash needed to show a generic archived state to that exact link. Restoring the item deletes that row and does not reactivate the old link.
  • Privacy and support emails are kept only while needed to handle the matter and are deleted within 12 months after it is closed. They may be kept longer only when needed for a legal obligation or legal claim.

08

Your choices and rights

  • Use Nettat privately and offline without enabling collaboration.
  • Skip the notification prompt, enable it later for one device in Profile, turn it off for that device, or manage the iOS permission in Settings.
  • Skip or cancel the one-off Contacts picker, choose only the person and phone property you want, or enter people manually.
  • Edit Group or Expense data, correct expenses, undo recorded payments, remove optional phone numbers, and replace or revoke secure links when your role permits it.
  • Leave a collaborative Group or Expense, or delete your collaboration identity. Saved financial history can require expenses or payments to be corrected first so the record remains accurate.
  • Owners can transfer ownership or delete a collaborative Group or Expense.

Depending on applicable law, you may also have rights to information, access, correction, erasure, restriction, portability, objection and complaint. Email hello@nettat.com for a privacy request or privacy question. Nettat may request limited information to verify the requester and protect other people’s data, and normally responds within one month. You may lodge a complaint with Sweden’s privacy regulator, the Swedish Authority for Privacy Protection (IMY). Invited testers can also use TestFlight’s Send Beta Feedback.

09

Contact, accountability and changes

Nettat is owned, run, and maintained by Alexander da Silva as a private individual based in Sweden. He is the data controller for Nettat’s collaboration service and website. For privacy questions or requests, email hello@nettat.com. Invited testers can also use Send Beta Feedback from Nettat’s TestFlight page.

Nettat gives this policy a version and effective date whenever it changes. Material changes will be explained before they apply. If a change affects data already collected, Nettat will not quietly reduce the promises made here.

Last reviewed6 September 2026