Privacy
Antemate is a record of money between people who know each other, which
makes it one of the more personal things on your phone. This page says
what we hold, who else can see it, and how to make it go away. It is
written to be read, not to be defensible.
Antemate is a product of Yanvara Pty Ltd, Melbourne, Australia. Any
question about anything below:
[email protected].
What we hold
Your name and the email address or phone number you signed up with.
The groups you are in and the people in them. Every expense you or
they record: what it was, what it cost, who paid, how it split, and
anything written in its comments. The devices you are signed in on,
with the date each was last used. If you have bought Pro, a receipt
from the store confirming it — never a card number, which we are
never shown.
What we never touch
Your bank. Your card. Your contacts — finding a friend compares
scrambled codes and stores none of them, so an address book never
leaves your phone. Your location. Your other apps. We do not buy
data about you and we have nothing to sell about you.
The ledger is shared, so the group can see it
Everyone in a group sees its expenses, its balances, who paid what,
and every edit anybody made. That is the product working. It also
means an expense you add is not private to you, and the person you
add by email will be able to read the whole group's history once
they join.
When someone at Antemate looks
A small number of staff can see an account and the groups it is in
through an internal tool: to answer a question you have sent us, to
act on a request to delete an account or stop emails, to look into
abuse or a security problem, or when the law requires it. Nobody
browses it for any other reason.
Every time staff open an account or a group, it is recorded — who
looked, what, and when — along with every change they make and the
reason they gave. Signing in to the tool takes a password and a
code from an authenticator app. The tool cannot add, edit or delete
anybody's expenses, payments or balances: the ledger's history is
the group's, and not even we can rewrite it.
What we measure, and what we don't
The app reports crashes and some usage to three services, so we can
find out that it broke before you have to tell us, and see which
parts of it people actually use. It is switched on by default and
you can switch it off in Settings, on the phone, whenever you like.
Sentry receives a report when the app crashes or
hits an error: what went wrong, where in the code, which version
and what kind of device. PostHog and
Firebase Analytics receive events like "opened a
group" or "added an expense", with a random identifier for your
install so two events can be known to come from the same phone.
What none of them receive is the ledger. Not an amount, not a
description, not a group or a person's name, not an email address
or a phone number. We do not sell any of it, we do not use it for
advertising, and there is no advertising SDK in the app. If that
ever changes it will be on this page before it is in a release.
Turning it off in Settings stops the app sending anything to all
three. Crash reports are the one thing worth leaving on if you are
undecided — a crash we never hear about is a crash that stays.
When a photograph leaves your phone
Scanning a receipt or translating a menu sends that one image to
OpenAI, which reads it and sends back text. It is the only time
anything you capture goes anywhere, it only happens when you tap
the button, and we do not keep the image afterwards — you confirm
the reading and the photograph is done with. Nothing else in the
app sends anything to a model: the ledger itself is never given to
one.
What a notification says, and who carries it
When someone adds an expense you are on, records a payment to or
from you, a repeating expense lands, or someone you owe sends a
reminder (by tapping Remind, or on the group's weekly or monthly
schedule), the app can tell you. The
notification says which group, who did it, what it was for and
your share — "Jo added Dinner — your share AUD 30.00" — because
that is the point of it. It appears wherever your phone shows
notifications, including the lock screen.
When someone comments on an expense you are on, or replies in a
thread you have written in, the notification also carries the
first 120 characters or so of what they wrote — "Sam on Dinner:
'Wasn't this $16 each?'". So a comment you write can appear on the
lock screens of the people the expense is split between and of
anyone already in its thread. Nobody else in the group is sent it.
To reach your phone it passes through Google's Firebase
Cloud Messaging and, on an iPhone, Apple's push
notification service. They deliver it; they are not given
anything else from the ledger or the thread. We keep the notification for a week
so a question about one can be answered, then delete it.
Each kind can be switched off in the app under Account →
Notifications, and all of them in your phone's own settings. A
phone that signs out stops receiving them straight away.
Who else is involved
Amazon Web Services hosts the servers and sends our email, in
Sydney. OpenAI reads a photograph when you ask it to. Apple and
Google take the payment for Pro and tell us only that it happened.
Sentry takes the crash reports, and PostHog and Firebase Analytics
take the usage events described above — none of them ever sees the
ledger. Google and Apple deliver notifications, which carry the
short line described above — including the start of a comment —
and nothing more. That is the whole
list. If you link Yanvara, the two apps exchange
exactly what you switched on and nothing else — you can see it and
revoke it in the app.
Cookies on this website
This website sets two cookies, and both are strictly necessary. There is
no analytics, advertising or tracking on antemate.com, which is why you
were not asked to accept anything.
- antemate-session keeps the waitlist
form working between the page and the submission. The cookie itself
holds only a random identifier. If the form turns down what you
typed, the address is kept against it briefly so you do not have to
type it again. It expires 2 hours
after your last visit.
- XSRF-TOKEN proves that a form submission came from
this site and not from another one pretending to be it.
The app is a different thing: what it measures, and who receives it, is
described in What we measure, and what we don't above.
We keep what you have recorded for as long as your account exists,
because a ledger with a gap in it is not a ledger. When you delete your
account it goes, apart from the part described above. We will change
this page when the product changes, and the change will be the product
catching up with the page rather than the other way round.