Counted

Privacy policy

Last updated: 27 September 2026

Counted is a service for splitting expenses among friends, built around one simple principle: the server never sees your data in the clear. This policy describes what information we collect, why, and what rights you have.

1. Publisher and data controller

Counted is published by Jonathan Bosi - see the Legal notice. For any question about your personal data, you can write to contact@counted.fr

2. Data collected

  • Email address (required to create an account).
  • Password hash your device turns the password into a login proof with argon2id and sends only that proof; we store a hash of it. The password itself is never transmitted or stored.
  • Key derivation salt used to generate your encryption key on the client.
  • Encrypted project content (names, expenses, participants, amounts). This data is encrypted on your device before being sent to the server, which stores nothing but an unintelligible version of it.
  • Your encrypted preferences (interface language), so you find them again on your other devices. Encrypted on your device with the same key as the rest: the server cannot read which language you use.
  • Your project keys, wrapped so that signing in on a new device gives you back projects you can actually read, instead of a list you cannot open. Each one is encrypted on your device with the key derived from your password; the server stores them and cannot unwrap them. The trade-off is real and we would rather state it: someone holding both our database and your password could reach your projects. That is why the password is never transmitted and never stored: what we receive at sign-in is a separate proof it cannot be recovered from, and we keep only a hash of that.
  • Hash of an invited participant’s email (SHA-256), when you invite someone by email. It serves only to attach the invitation to their account should they create one, and disappears with the participant.
  • Your friends when you use the friends list: which accounts you are friends with, a hash (SHA-256) of an address you sent a request to before it had an account, and which friend you invited into which project. The name you give a request and the project key an invitation carries are encrypted on your device - the key with your friend’s public key, which we store in the clear because it is public by nature - and the server cannot read either.
  • Technical logs (IP address, user agent, timestamp) kept for security and abuse prevention.

3. Purposes

  • Authenticate your sessions and protect your account.
  • Sync your projects between your devices.
  • Send you a verification email when you sign up.
  • Detect and prevent abuse (brute force, scraping).

4. Legal basis

Processing rests on performance of the contract between us (creating and providing the service) and on our legitimate interest in securing the platform.

5. End-to-end encryption

Counted applies a zero-knowledge model: your encryption key is derived from your password and never leaves your device. The server stores only encrypted blobs it is unable to read.

An important consequence: if you forget your password, nobody - not even us - can recover your data. No reset procedure is possible.

6. Processors and hosting

  • Hetzner Online GmbH (Germany, EU) - hosting of the servers and the database.
  • Scaleway TEM (France, EU) - sending transactional email (email verification).
  • Bunq / Tricount - contacted only if you trigger an import from Tricount yourself, in order to fetch the project you want to import.
  • Grafana Labs (EU region) - technical monitoring of the server. Only infrastructure metrics (CPU, memory, disk, service state) and daily aggregate usage counts (numbers of accounts, projects, memberships and sign-ups, and how many sign-ups and logins were made in each interface language) are sent there: no content, no identifier, no visitor IP address.

No personal data is transferred outside the European Union.

7. Retention

Your data is kept for as long as your account is active. Deleting the account causes an immediate and permanent deletion of the corresponding database records (cascading deletion, with no recycle bin).

A daily automatic sweep additionally deletes:

  • expired sessions and verification links;
  • accounts created but never verified, after 24 hours;
  • projects no member belongs to any more, after 24 hours.

Technical logs are kept for 30 days at most and then deleted automatically. They are neither archived, nor exported, nor analysed for any purpose other than security.

Expenses you entered in a shared project do not disappear with your account: they are part of the other members’ books, and they alone can still decrypt them.

8. Cookies and local storage

A single session cookie (HttpOnly, SameSite=Lax, Secure) is set after signing in to keep you authenticated. No tracking cookie, no third-party analytics.

A language cookie (counted_lang) stores the interface language you picked, so the page is served in it from the first render. It carries a two-letter language code and no identifier.

The app also keeps information in your browser’s (or the mobile app’s) local storage. It is never sent to the server:

  • Your decryption keys - your account’s and each project’s. Without them, the app can display nothing.
  • The list of your projects and the random identifier representing you in a project joined without an account.
  • A cache of the projects (expenses, participants) for offline display and to avoid re-downloading what has not changed.
  • A queue of the changes made offline, sent to the server when the network comes back.
  • Your display preferences (archived projects, onboarding already seen, interface language).

These items are strictly necessary for the service to work and therefore require no consent. You can erase them at any time by clearing the site data - careful: erasing your keys without knowing your password makes your projects unreadable.

9. Your rights

Under the GDPR, you have the following rights:

  • right of access and rectification;
  • right to erasure: the “Delete my account” button on the “My account” page removes everything immediately, without going through us;
  • right to portability: every project exports to decrypted CSV or JSON from its own menu;
  • right to object and to restriction;
  • right to withdraw your consent at any time;
  • right to lodge a complaint with the French data protection authority, the CNIL

To exercise these rights, write to contact@counted.fr

10. Security

TLS 1.2+ communications, passwords stored as argon2id hashes, user data encrypted end to end, rate limiting at the reverse proxy, permanent deletion with no recycle bin.

11. Receipt scanning

On the mobile app you can photograph a receipt, or pick a photo already on your phone, to pre-fill an expense. The recognition model ships inside the app and runs on your phone: the image is held in memory, read, and discarded. No photograph and no recognised text is ever sent to our servers or to anyone else, and no network request is made to perform it.

The copy your phone makes of the photo, whether you take it or pick it from your gallery, is deleted as soon as the scan ends - whether it succeeded, failed, or you backed out. Your original photo is never altered or removed. Only the fields you confirm are saved, as an ordinary expense, encrypted on your device like every other.

12. Changes

This policy may change. Any substantial change will be notified through the app or by email.