Privacy Policy / GDPR

This is the English translation of the Privacy Policy. The German version is the legally authoritative one.

1. Controller and Contact

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Zealos Energy GmbH Zur Mühle 20 01983 Großräschen OT Dörrwalde Germany

Represented by the managing director: Georgios Bakouros
Register court: HRB 8162 CB
VAT ID: DE 262710012
Email: datenschutz@twofair.com

This Privacy Policy applies to the web application twofair, accessible at app.twofair.com. The same Privacy Policy applies to the marketing website at twofair.com.

2. Overview: What is twofair, and what data do we process?

twofair is a digital tool that lets separated parents jointly track child-related expenses and split them fairly according to a configurable ratio. The app displays a live balance (who owes whom, and how much) and maintains a traceable, tamper-evident history.

We primarily process:

  • account data of the parents using the app (account, authentication),
  • data about your children that you enter (e.g. name/label, date of birth),
  • financial and transaction data (expenses, payments, split ratio),
  • payment data in connection with the paid “twofair Plus” subscription,
  • technical usage data and — only with your consent — analytics data.


twofair is not tax, accounting, or receipt-archiving software and does not fulfil any statutory tax or commercial-law retention obligations.

3. Categories of data processed, purposes, and legal bases

3.1 Account and profile data

  • Data: Email address, password (stored exclusively as a cryptographic hash), freely chosen display name/nickname, optional profile photo.
  • Purpose: Setting up and managing your account, authentication, display in the shared feed.
  • Legal basis: Article 6(1)(b) GDPR (performance of the usage contract).

3.2 Data about your children

  • Data: Name or generic label (e.g. “child”, “son”, “daughter”), date of birth, optional photo.
  • Purpose: Assigning expenses to individual children and applying child-specific split ratios.
  • Special feature: Children are not users of the app and have no account of their own. Their data is entered and managed exclusively by the parents.
  • Legal basis: Article 6(1)(b) GDPR in relation to the parent using the app.

3.3 Financial and transaction data

  • Data: Expenses (amount, currency, date, category, free-text description, paying person, optional child assignment, optional receipt upload), settlement payments between the parents, split ratio and resulting balance.
  • Purpose: Core function of the app – recording, splitting, and balancing child-related costs.
  • Legal basis: Article 6(1)(b) GDPR.

3.4 Info bank (freely definable fields) and documents

  • Data: Freely definable key–value pairs (family- or child-related) as well as optional file uploads (up to 50 MB per family).
  • Purpose: Structured storage of child-related information at the parents’ own discretion.
  • Legal basis: Article 6(1)(b) GDPR.

Important note on sensitive data: The free-text and info bank fields are filled in exclusively by you. twofair is not intended for the storage of special categories of personal data within the meaning of Article 9 GDPR (e.g. health data). Please do not enter such data into free-text fields. Should you nevertheless, on your own responsibility, enter special categories of personal data, this occurs on your own initiative and on the basis of your consent under Article 9(2)(a) GDPR.

3.5 Payment data (subscription “twofair Plus”)

  • Data: Name, billing address, email address, payment method. Card data is not stored by twofair, but processed exclusively by our payment service provider Stripe (see section 5). twofair only stores reference identifiers (customer/subscription ID) and the subscription status.
  • Purpose: Processing and management of the paid subscription, invoicing.
  • Legal basis: Article 6(1)(b) GDPR (performance of contract); with regard to statutory retention obligations, Article 6(1)(c) GDPR.

3.6 Notification settings

  • Data: Desired notification frequency (instant, weekly, monthly, off).
  • Purpose: Sending notifications about new entries/payments as well as system-related notices.
  • Legal basis: Article 6(1)(b) GDPR.
  • WhatsApp feature: If you share a notification via WhatsApp, twofair only generates a pre-filled link, which you send manually via your own WhatsApp app. twofair does not transmit any data to Meta/WhatsApp in this process.

3.7 Log/audit data

  • Data: Append-only log of all relevant changes (acting person, timestamp, scope of change) to ensure transparency and traceability between the parents, and to demonstrate compliance with legal obligations.
  • Purpose: Integrity, traceability, accountability (Article 5(2) GDPR).
  • Legal basis: Article 6(1)(b) and (f) GDPR. Our legitimate interest lies in the tamper-evident traceability of the jointly used data.

3.8 Technical access data

  • Data: Server/log data generated on each access (e.g. IP address, timestamp, resource accessed, technical identifiers), insofar as required for operating the app and its underlying infrastructure.
  • Purpose: Provision, stability, and security of the service.
  • Legal basis: Article 6(1)(f) GDPR (legitimate interest in secure, uninterrupted operation).

3.9 Analytics data (only with consent)

  • Data: Pseudonymous usage events (e.g. family identifier, anonymised funnel). No directly identifying data (no name, no email) is transmitted to the analytics system.
  • Purpose: Improving the product and user guidance.
  • Legal basis: Article 6(1)(a) GDPR (consent) as well as Section 25(1) TTDSG for storing/reading information on your device. Processing only takes place after your consent via the consent banner; you can withdraw it at any time in the settings.
  • To manage the cookies and similar technologies used (tracking pixels, web beacons, etc.) and the related consents, we use the consent tool “Real Cookie Banner”. Details on how “Real Cookie Banner” works can be found at https://devowl.io/de/rcb/datenverarbeitung/.
  • The legal bases for processing personal data in this context are Article 6(1)(c) GDPR and Article 6(1)(f) GDPR. Our legitimate interest is managing the cookies and similar technologies used and the related consents.
  • Providing this personal data is neither contractually required nor necessary for concluding a contract. You are not obliged to provide it. If you do not provide the personal data, we cannot manage your consents.

4. Data constellation in shared use (co-parenting)

twofair is designed for shared use by two parents/guardians. Both parents see the same shared data set (feed, balance, history). When one parent records an entry or piece of information, it may also contain details relating to the other parent (e.g. “paid by parent A”).

twofair is designed so that two parents/guardians jointly maintain a shared data set. This constellation is unusual from a data protection perspective, because both people see the same data and each of them can enter information that also concerns the other. We therefore explain it here in detail.

4.1 How shared use works

A “Family” in twofair consists of up to two adult members. Both members see the same shared data set: all recorded expenses and payments, the split ratio, the resulting balance, the assigned children, uploaded receipts, and the change log.

In practice, this means: if one parent records an entry, it is permanently visible to the other parent – including who created it, when it was created or changed, and its content. Entries may also contain information about the other parent (for example, that a particular expense was paid by them). This mutual visibility is not a side effect but the core purpose of the service: it establishes traceability and trust between the parents.

4.2 Who is responsible for what

  • For operating the service – i.e. for provision, storage, security, access control, and the service providers used – Zealos Energy GmbH is the controller within the meaning of Article 4(7) GDPR.
  • For the content of their own entries, each parent decides for themselves: they determine which expenses, descriptions, receipts, and information they record, and whether this information concerns other people. We have no influence over this content decision and do not review the entries.

In our assessment, there is no joint controllership under Article 26 GDPR between us and the parents using the app. Insofar as the parents use the app for their personal and family matters, the household exemption under Article 2(2)(c) GDPR may apply to them; this exemption expressly does not apply to us as the operator.

4.3 How the invited parent is informed

If a parent is invited by the other to an existing Family, they receive, before joining, an overview of what has already been set up for shared use – including information already recorded that concerns them. Only after that do they decide whether to join.

This means every data subject learns which data concerning them already exists and where it came from (Article 14 GDPR). After joining, they have full insight into the entire shared data set at any time, as well as access to the data export (section 8).

4.4 Access and data export for shared data

The data export available in settings covers all entries of the Family, not only those you created yourself. This is intentional: the balance only results from the entirety of the entries, so an access request limited to one’s own entries would be worthless to the data subject.

Since both parents can permanently and fully view this data in the app anyway, the export does not create any disclosure beyond the level of knowledge that already exists. In our assessment, the rights and freedoms of the other parent (Article 15(4) GDPR) are therefore not affected. Not included are the other parent’s access and profile data (such as their password hash or payment information).

4.5 Changes and deletions in the shared history

Entries in twofair can be edited: the creator of an entry can subsequently change its details (such as amount, date, category, or description). The other parent cannot edit the content of an entry. The split ratio assigned to an entry can also be deliberately updated to the currently valid ratio when editing; without such an explicit change, each entry retains the ratio stored at the time it was recorded, so later changes to the ratio do not automatically affect entries already recorded.

Permanent deletion of individual entries is, by contrast, not provided for. If a parent deletes an entry – both parents can do this – it is merely marked as deleted and excluded from the ongoing balance calculation. The entry remains in the data set, can still be viewed via a separate view, and can be restored at any time. All edits, deletions, and restorations are additionally recorded in the change log.

This approach serves the integrity and traceability of the shared history: since both parents use the same data set and must be able to rely on its completeness, an entry should not be unilaterally and untraceably removed from the shared history. The legal basis for this is Article 6(1)(b) GDPR as well as Article 6(1)(f) GDPR (legitimate interest of both parents in a traceable, shared history that cannot be unilaterally altered).

Your rights as a data subject remain unaffected:

The right to erasure (Article 17 GDPR) relates to your personal data as a whole and is fulfilled via account deletion (sections 6 and 6.1). For any request to delete individual entries beyond this, please contact the address given in section 1; we review such requests on a case-by-case basis, weighing them against the interests of the other parent.

The right to rectification (Article 16 GDPR) is fulfilled through the editing function and – where an entry does not originate from you – through a corrective counter-entry, so that the accurate state is visible at all times.

4.6 Children’s data

Children are not users of twofair; they have no account of their own and no access. Their data is entered and managed exclusively by the parents (see section 3.2).

Nevertheless, a child is also a data subject with their own rights under the GDPR; children enjoy special protection in this regard (Recital 38 GDPR). As we have no contact details of our own for the children and cannot reach them directly, information is provided via this Privacy Policy (cf. Article 14(5) GDPR).

A child’s rights are generally exercised by their legal guardians. As a child’s capacity for understanding increases, they may also assert their rights themselves; please direct any such requests to the address given in section 1. We review such requests on a case-by-case basis.

5. Recipients / processors and other recipients

To provide twofair, we use carefully selected service providers. We have data processing agreements in place with processors in accordance with Article 28 GDPR.

5.1 Hosting and backend – Lovable / Supabase

The app runs on the Lovable platform; the backend (“Lovable Cloud”) uses Supabase‘s infrastructure (database, authentication, file storage). Your user data is stored here.

  • Role: Lovable is the processor; Supabase is the sub-processor.
  • Provider: Lovable Labs Incorporated (Delaware, USA) with an EU establishment in Sweden; Supabase Inc. (USA).
  • Storage location: EU region.
  • Third-country relevance: These are US companies; see section 7.

5.2 Payment processing – Stripe

The paid subscription is processed via Stripe. Stripe processes your payment and billing data.

  • Role: Stripe processes payment data partly as an independent or joint controller (among other things, for regulatory purposes and fraud prevention).
  • Provider (EU): Stripe Technology Company Ltd. / Stripe Payment Europe Ltd. (Ireland).
  • Third-country relevance: Stripe is certified under the EU-US Data Privacy Framework and additionally uses standard contractual clauses.
  • Further information: https://stripe.com/privacy

5.3 Email delivery – Lovable Email

We send transactional emails (e.g. sign-up/confirmation emails, notifications about new entries/payments, system-related notices) via the email system integrated into Lovable, Lovable Email. Sender address: noreply@app.twofair.com.

  • Role: Processor (under the Lovable data processing agreement).
  • Data processed: Recipient’s email address and the content of the respective email.

5.4 Product analytics – PostHog (EU)

With your consent, we use PostHog for pseudonymous product analytics.

  • Role: Processor.
  • Storage location: PostHog Cloud EU (servers in Frankfurt). EU user data does not generally leave the EU.
  • Cookies/TTDSG: This is only used after your consent via the consent banner (equivalent “Accept”/”Decline” options; withdrawal possible at any time in settings).

6. Retention period and deletion concept

We only store personal data for as long as necessary for the stated purposes, or as long as statutory retention obligations require.

  • Active accounts: Data is stored for the duration of use.
  • After cancelling the subscription: Your data remains available in read-only mode for 90 days (a “grace period”), so that you can export your data. You receive an advance warning by email seven days before final deletion.
  • After this period expires: GDPR-compliant cascading deletion of all family data, including stored files.
  • Account deletion by you: Can be triggered by you at any time (two-step confirmation with prior re-authentication). For the special case of deletion while part of a shared Family, see section 6.1.
  • Audit log: The record of the deletion itself remains in the log, but no longer contains any personal content thereafter (fulfilling the accountability obligation, Article 5(2) GDPR).
  • Subscription invoices: Invoices are created by Stripe and retained there in accordance with statutory obligations; they are not part of the app-side deletion.

6.1 Account deletion while part of a shared Family

twofair is designed for shared use by two parents/guardians. The financial data maintained within a “Family” (expenses, payments, split ratios, child assignments, receipts, and the change log) is, by its nature, shared data of both parents – comparable to a jointly held account. If one parent deletes their account while the other parent remains a member of the Family, we proceed as follows:

What is deleted completely and irrevocably:

  • Your access credentials (email/password login, and any linked Google/Apple sign-in),
  • your personal profile (display name, profile picture),
  • entries created solely by you that are not yet finalised and have no relevance to the other parent (e.g. only planned, not-yet-booked expenses, and invitations you sent that are still pending).

What is retained, but anonymised:

The shared financial data you left behind in the Family remains fully and unchanged in content for the remaining parent (amounts, dates, descriptions). However, your previous identification as the author, editor, or acting person is replaced by a neutral, system-wide placeholder (“Former member”).

This is a genuine anonymisation, not pseudonymisation: there is no mapping table by which the placeholder could later be re-linked to you. Once the process is complete, it is no longer technically possible to determine which specific person originally created the relevant entries. From that point on, this data no longer constitutes personal data within the meaning of the GDPR (cf. Recital 26 GDPR).

Why we proceed this way: The remaining parent has a legitimate interest in a complete, unaltered shared financial history – for example, to trace payments and to assert, exercise, or defend their own legal claims (cf. Article 17(3)(e) GDPR). The solution chosen fulfils your erasure request to the extent possible (your personal identifiability is completely removed) and limits the exception from erasure to what is strictly necessary for the integrity of the shared history. The legal basis for the anonymisation as such is Article 6(1)(c) GDPR in conjunction with Article 17 GDPR (fulfilment of the erasure obligation), or Article 6(1)(f) GDPR (legitimate interest in data integrity).

Withdrawal documentation: A withdrawal you have already declared (14-day right of withdrawal) is likewise anonymised, not deleted, upon account deletion. The information required as evidence is stored independently within the withdrawal record; only the link to your user account is removed.

In short: If you delete your account while you are part of a shared Family, your access credentials and profile are completely removed. Shared expenses and payments you created remain in place for the other parent, but no longer appear there under your name — instead, they appear as “Former member”.

7. Transfers to third countries

Several of the service providers used are US companies or belong to US corporate groups (Lovable, Supabase, Stripe, PostHog), even though data processing physically takes place within the EU. A transfer to a third country can therefore not be entirely ruled out.

The safeguards used include: EU-US Data Privacy Framework certifications (where available) as well as standard contractual clauses under Article 46(2)(c) GDPR.

8. Your rights as a data subject

Under the GDPR, you have the following rights:

  • Access (Art. 15): confirmation and a copy of the data processed about you.
  • Rectification (Art. 16): correction of inaccurate data.
  • Erasure (Art. 17): the “right to be forgotten”. Can be exercised in the app via self-service account deletion. If you are part of a shared Family, the arrangement described in section 6.1 applies: your identity is completely removed (anonymised), while the shared financial data remains for the other parent.
  • Restriction of processing (Art. 18).
  • Data portability (Art. 20): you can download a full export of your data in a machine-readable format (JSON) at any time in settings.
  • Objection (Art. 21) to processing based on legitimate interests.
  • Withdrawal of consent (Art. 7(3)): at any time with effect for the future, e.g. the analytics consent in settings.
  • Right to lodge a complaint with a supervisory authority (Art. 77): the competent authority is the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg (LDA Brandenburg), Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany, email: poststelle@lda.brandenburg.de.

To exercise your rights, please contact: datenschutz@twofair.com.

9. Data security (technical and organisational measures)

Among other things, we use the following measures:

  • strict tenant separation with row-level access control (Row Level Security) on all data tables;
  • encryption in transit (TLS/HTTPS) and at rest (infrastructure standard);
  • data minimisation in analytics (no directly identifying data);
  • tamper-evident, traceable data history (soft delete + log);
  • re-authentication before security-critical actions.

10. No automated decision-making

No decision-making based solely on automated processing, including profiling, that produces legal effects within the meaning of Article 22 GDPR takes place.

11. Changes to this Privacy Policy

We update this Privacy Policy whenever data processing or the legal situation changes. The version currently published in the app applies.

Last updated: July 2026

Scroll to Top