Legal

Privacy

ShareLess keeps its privacy scans on your device and encrypts vault values before they sync. When you choose to disclose a value, who can open it depends on whether you use a local connector, the hosted remote connector, or checkout. Those paths are explained below.

Last updated: July 2026

What we collect

  • Account basics. If you sign in, we receive your email, name, and a stable user id from your sign-in provider (Apple or Google). We use these to operate your account. If you use Apple Hide My Email, the address may be an Apple relay address.
  • Your vault catalog and encrypted vault data. To sync your vault and let an AI app discover what it can request, your device sends field names and types (such as "email" or "card") together with encrypted vault data. Our account database does not receive the plaintext values.
  • A disclosure ledger. When a connected app requests a field and you approve it, we record who asked, why, when, and the outcome, so you have an audit trail. The ledger never stores the released value.
  • Device tokens. If you enable notifications, we store a push token so we can alert your device to a pending request.
  • Product telemetry. We collect a limited set of product events to understand whether features work and how they are used. When you are signed in, these events are linked to your account and may include a device identifier, platform, feature used, outcome, timing, and bounded counts or categories. They do not include the text you scan, vault values, encryption keys, or merchant names.

What stays local, and when plaintext is opened

  • Privacy scans stay local. Make Private and Fingerprint analyze text on your device. The text they scan is not uploaded to ShareLess.
  • Local connectors stay blind to ShareLess. With the desktop connector or browser extension, an approved value is opened on your computer or in the extension. ShareLess servers relay ciphertext and do not open the value.
  • The hosted remote connector opens approved values briefly. For an AI surface that cannot hold the key locally, the hosted connector creates a fresh key for the request, opens the approved value in server memory, and returns it to the connected AI. ShareLess does not log or store that plaintext. The AI provider receives a value when its model uses it and handles it under that provider's terms.
  • Checkout depends on the path. On-device checkout opens and fills your card on your phone. For supported cloud checkout, your device seals approved details to a one-purchase runner. That runner opens them in memory long enough to fill and submit the checkout, then discards them. The ShareLess account database does not store your raw card number; the merchant and its payment providers receive the details needed to complete the purchase.

Approvals, standing rules, and payments

Your device asks before releasing a field unless a matching non-payment request is covered by a standing rule you created. A standing rule is revocable prior approval and may allow future matching requests without another prompt. Payments are never covered by a standing rule: each purchase requires a fresh hold on your device for the selected card and displayed amount. You can revoke connectors and standing rules at any time.

Service providers

We rely on a small set of providers to run the service: sign-in providers (Apple and Google), cloud hosting and a database for your account, catalog, and ledger, and push-notification providers (Apple Push Notification service and Firebase Cloud Messaging) to alert your devices. If you explicitly choose cloud assist, cloud processing and storage providers handle the item you submit. If you purchase premium, a payment processor handles that transaction.

Keeping and deleting your data

You can delete your account at any time from Account → Danger zone (or the Account screen in the apps). Account deletion removes your account and its database records, including your catalog, connectors, approvals, audit history, packs, rules, telemetry, and plan. The app you use to delete the account also wipes its local vault; remove ShareLess data separately from any offline or unused device.

If you used optional cloud assist for a file, account deletion currently removes its database record but does not immediately delete the corresponding encrypted temporary file object from external object storage. Contact us if you need us to confirm its removal. Canceling premium does not delete your data; advanced features pause instead.

Children

ShareLess is not directed to children under 13, and we do not knowingly collect their data.

Changes

We may update this policy as the product evolves. We'll revise the date above and, for material changes, surface a notice in the app.

Contact

Questions about privacy? Email skulk@shareless.ai.