Tot Up. Open Tot Up

Privacy, plainly

Last updated 21 August 2026. If we change this page, the date changes with it.

This is the whole story, in plain English. It’s short because we hold little and do less with it.

What we hold

  • Your email address, used to sign you in and to keep your trips recoverable. The only email we send is the sign-in link you ask for.
  • What your group types in: the trip’s name, people’s first names, expenses and payments — descriptions, amounts, currencies, dates, notes — and the history of who changed what.
  • Payment handles, only if you add them: bank details or a payment link you want friends to pay you with. They’re shown only to people in your trips, and only when they owe you. We can’t see into any bank account — these are just the details you typed.
  • Ordinary server logs (when a request happened and whether it worked), kept briefly for keeping the service running and abuse at bay.

What we never do

  • No ads, and nothing sold or shared with advertisers or data brokers.
  • No third-party analytics and no tracking: no Google Analytics, no Facebook pixel, no session recording. The only cookie-like storage keeps you signed in.
  • No marketing emails. Sign-in links only.
  • No reading your money: Tot Up never connects to your bank and never touches, holds, or moves money.

Who can see your trip

A trip is visible to the people who hold its invite link — that’s the boundary, and the app says so where you share it. Whoever runs the trip can replace a leaked link instantly. Trips are never public or searchable, and a link shared in a messaging app previews only the trip’s name and how many people are in it — no names, no amounts.

Where it lives

Tot Up runs on Cloudflare, which processes the traffic and stores the data above on our behalf on its network; sign-in emails are delivered through Cloudflare too. Cloudflare’s Turnstile check (the “are you human?” step) runs when you ask for a sign-in link and when you start a trip. There are no other processors.

Deleting things

Deletion is in the app, not a request form. Whoever runs a trip can delete it: it disappears for everyone immediately, they have 7 days to undo a slip, and then it’s destroyed. Backups take longer to catch up — every residual copy is gone within about 37 days of the deletion, and we’d rather say so than claim “instantly”.

To take your email off a trip, ask whoever runs it to release your name: the name and its history stay on the group’s ledger — they belong to the trip, like messages in a group chat — and your account is no longer attached to it. Sign out, or “Sign out everywhere” for a lost phone, ends your sessions. Export any trip first if you want your own copy; it’s free, and it’s the full history.