The Napkin

Privacy Policy

The Napkin is built to keep your group's memory, not to profile you. This page describes what the app does and does not do with data.

What we never do

What stays on your device

Your Napkins, receipts, Quick Picks, and obligations are stored locally on your device. A group chat is recognized only by a salted, non-reversible fingerprint — never raw message content or participant identifiers.

What is synced (when you sign in)

In builds where syncing is set up, The Napkin asks you to sign in with Apple when you open the app — signing in is what shares a group across devices and claims your spot on a receipt. When you sign in, the receipts and Quick Picks of your shared groups, your chosen display name, and your Apple account identifier are synced to enable those features. This data is linked to your account solely to make sync work; it is never sold or used for advertising.

Money amounts you put on the line are part of receipt content. They are records of your agreement — The Napkin has no access to your bank accounts, cards, Venmo balance, or Apple Cash balance.

A receipt card can carry a share link. While that link is valid, anyone who has it can view that one receipt's public page — treat the link like the receipt itself. Links can expire, and support can revoke a link on request.

Analytics

The Napkin sends no analytics. Nothing about your use of the app leaves your device except the sync data described above.

Hosting and service logs

Synced data is hosted by Supabase, our hosting and infrastructure provider. Like most hosting providers, Supabase keeps short-lived operational logs of API and database requests that may include IP addresses, timestamps, request paths, and user-agent information. On our current plan those logs are retained for up to one day under the provider's current policy. Operational logs are never used for advertising or cross-app tracking.

Your choices