Privacy Policy

Last updated: 20 June 2026

This Privacy Policy explains what Chukta (“we”) collects and how we handle it. By using the Service you consent to this Policy. It forms part of our Terms & Conditions.

What we collect

  • Your email address, used only to send a one-time sign-in code and identify your account.
  • People you add (names and a veg/non-veg flag) so you can split bills with them.
  • Splits you choose to save: merchant, items, amounts, tax info, and who was assigned what.
  • Receipt images you upload, processed to extract line items.
  • A session cookie that keeps you signed in. We do not use third-party advertising or tracking cookies.

How we use it

We use your data solely to operate the Service for you: to sign you in, read your receipts, compute splits, generate UPI payment links, and show your saved history. We do not sell your data or use it for advertising.

Third parties we share with

  • An AI model provider (Anthropic), to read uploaded receipt images into line items.
  • An email provider, to deliver your sign-in code.
  • No one else — except where required by law.

These providers process data under their own terms; we are not responsible for their practices. Receipt images are sent for processing and are not used by us to build advertising profiles.

Usage & analytics logging

To run and improve the Service we keep a first-party log of page visits. For each visit we may record: the path visited, a truncated/anonymized IP (by default the last IPv4 octet is zeroed, e.g. 203.0.113.0), device type, browser and OS, the referring site, any utm_* campaign tags, your browser language and window size, and a first-party visitor id stored in a chukta_vid cookie. If you are signed in, the visit is linked to your account so we can show your last-seen time. We do not use third-party advertising or cross-site tracking, and automated bot traffic is flagged and excluded from analytics.

These logs are retained for a limited window (the log retention setting, 90 days by default) and then automatically deleted. IP anonymization is on by default; full IPs are not stored while it is enabled. You can request deletion of data tied to your account at any time (see below).

Security

Sign-in codes are stored only as one-way hashes and expire quickly. Sessions are signed, HTTP-only cookies sent over HTTPS. Email is sent over an encrypted (SSL/TLS) connection. No method of transmission or storage is perfectly secure, and we provide no guarantee — you use the Service at your own risk (see the Disclaimer).

Retention & deletion

We keep your account and saved splits until you ask us to delete them. You can request deletion of your account and associated data by emailing we@chukta.online. Expired sign-in codes are discarded.

Your responsibility

Only add other people’s details if you are entitled to. You are responsible for the accuracy and legality of the information you submit.

Changes

We may update this Policy at any time; continued use means you accept the update.

Contact

Privacy questions or deletion requests: we@chukta.online.