How split-cash keeps your data safe
Money between friends is personal. Here is what split-cash does to protect it, and the one thing it doesn't do.
-
Encrypted connections
Every page and request goes over HTTPS. Plain http is redirected, so nothing travels unencrypted.
-
Encrypted storage
Your groups, costs and photos are stored with Cloudflare, which encrypts them on disk.
-
Passwords are never stored
split-cash keeps only a salted hash of your password (PBKDF2 with SHA-256, 100,000 rounds). Nobody can read it back, including us.
-
Sessions you control
Signing in sets a random token in a cookie that page scripts can't read; the server keeps only its hash. Unused sessions end after 30 days, signing out ends the one on that device, and changing your password signs out every other device.
-
Guessing passwords doesn't work
After 10 wrong passwords, sign-in for that email is blocked for 15 minutes.
-
Private groups
Only the people in a group can see it. Invite links are long random codes, and you can replace a link at any time so the old one stops working.
-
Protected photos
Receipt photos and pictures are shown only to people in the group, never at a public address.
-
No ads, trackers or outside scripts
There are no ads and no third-party trackers. Fonts and scripts load from split-cash itself, and requests from other websites are refused.
What split-cash doesn't do
split-cash is not end-to-end encrypted. Like most web apps, the server reads the amounts in your groups so it can work out balances. The person who runs split-cash can access the database to keep the service running and to answer requests you send, and doesn't look at your groups otherwise.
Your email address is never shown to other members. The privacy policy lists everything that is stored and how to have it erased.
Found a problem?
If you think you've found a security issue, write to hello@split-cash.org . You'll get a reply, and a thank-you on the blog if you'd like one.