1. Introduction and Scope
This Privacy Policy explains how [LEGAL ENTITY NAME — set in Company Info] ("the Company," "we," "us," "our") collects, uses, discloses, and protects information in connection with KaiKap — the website, and the iOS and Android applications (together, the "Service"). It applies to everyone who visits our website, creates an account, or otherwise uses the Service. This Policy is incorporated into, and should be read together with, our Terms of Service.
KaiKap is built around a simple stance on your financial data: it is yours. We do not sell your personal data, and we do not use your financial data to serve you advertising.
2. Data Controller
The data controller responsible for your information is [LEGAL ENTITY NAME — set in Company Info], [REGISTERED OFFICE ADDRESS — set in Company Info]. You can reach us at [PRIVACY EMAIL — set in Company Info] for any question about this Policy or your data.
3. Information We Collect
3.1 Information You Provide
- Account information: email address, password (stored only as a salted, irreversible cryptographic hash — we never store or can see your plaintext password), and, if you enable it, a two-factor authentication secret and/or a quick-unlock PIN (also stored only as a hash).
- Financial data you enter: accounts, balances, transactions, income and expense records, investment holdings and trades, loans, term deposits, goals, life events, and any note or free-text description you attach to them.
- Profile and household context: information you choose to provide about dependents, life stage, income stability, or risk tolerance, used to calibrate the guidance features you opt into.
- Communications: messages you send to K, support emails, and feature requests you submit.
3.2 Information from Third-Party Sign-In
If you sign in using Google, we receive your name, email address, and profile identifier from Google, consistent with the permissions you grant during that sign-in flow.
3.3 Information Collected Automatically
- Device and usage data: IP address, browser or app version, operating system, device type, pages or screens viewed, and timestamps of activity, collected for security, abuse prevention, and reliability purposes.
- Cookies and local storage: see Section 12.
- Diagnostic and crash data: if the app crashes or errors, technical details about the failure (not the content of your financial records) may be logged to help us fix it.
3.4 Information We Do Not Collect
We do not ask for or knowingly collect government identification numbers, passport numbers, or biometric data. We do not require or process payment-card numbers or bank credentials — KaiKap records what you report about your accounts; it does not connect to or authenticate with your bank on your behalf.
4. How We Use Information
We use the information described above to:
- provide, operate, and maintain the Service, including deriving the summaries, trends, and projections you see from the events you record;
- power the AI assistant and AI-generated narrative features, as described in Section 5;
- authenticate you, secure your account, and detect and prevent fraud, abuse, and unauthorized access;
- send you service communications (e.g., email verification, password reset, security alerts) and, if you opt in, product updates;
- diagnose problems, monitor performance, and improve the Service; and
- comply with our legal obligations and enforce our Terms of Service.
5. AI Processing Disclosure
When you use K or another AI-generated feature, the relevant portion of your message and the financial data needed to answer it are sent to a third-party large-language-model provider (currently Google, for its Gemini models) for processing, and the generated response is returned to you through our Service. We do not permit these providers to use your data to train their general-purpose models, to the extent such a restriction is available under our commercial agreement with them; where such an option is not contractually guaranteed by a provider, we will disclose that fact prominently in-product before you first use the affected feature.
We recommend you avoid entering government identification numbers, passwords, or other highly sensitive personal data into chat messages, even though KaiKap does not require them. Deterministic figures K states about your own recorded data (balances, totals, trends) are computed by our own servers, not invented by the AI model; narrative commentary, market discussion, and general guidance are generated text and should be independently verified, as described in Section 7 of our Terms of Service.
6. Legal Bases for Processing
Where applicable data-protection law requires a stated legal basis, we process your information on the following bases: (a) performance of a contract — to provide the Service you signed up for; (b) consent — for optional features such as AI chat, foreign- holdings tracking, or marketing communications, which you may withdraw at any time; (c) legitimate interests — for security, fraud prevention, and improving the Service, balanced against your rights; and (d) legal obligation — where we must retain or disclose information to comply with applicable law.
7. How We Share Information
We do not sell your personal data. We share information only with:
- Service providers ("processors") who perform functions on our behalf under contractual confidentiality and data-protection obligations, currently including: cloud hosting and database infrastructure providers; a transactional email delivery provider; and the AI-model providers described in Section 5;
- Legal and safety disclosures — where required to comply with a valid legal process, to protect the rights, property, or safety of the Company, our users, or the public, or to investigate fraud or a security incident;
- Business transfers — if the Company is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to the acquiring party's commitment to honor this Policy or provide equivalent protection; and
- With your direction — where you explicitly choose to export or share your data.
We do not use your financial data to serve you third-party advertising, and we do not share it with data brokers.
8. International Data Transfers
Our infrastructure providers may process and store data outside Bangladesh, including in the United States and the European Union. Where we transfer personal data internationally, we rely on our processors' standard contractual and security commitments to protect it, and we take reasonable steps to ensure it receives a level of protection consistent with this Policy regardless of where it is processed.
9. Data Security
We apply layered technical safeguards appropriate to the sensitivity of financial data, including:
- passwords hashed with Argon2id, never stored or logged in plaintext;
- encryption of data in transit (TLS) between your device and our servers;
- strict tenant-level data isolation at the database layer (row-level security), so that even a bug in application logic cannot return one account's data to another;
- optional two-factor authentication and a device-scoped quick-unlock PIN;
- rate limiting and account-lockout protections against automated attacks; and
- internal access controls limiting who at the Company can access production data, and only for legitimate operational or support purposes.
No system is perfectly secure, and we cannot guarantee absolute security. See Section 15 for what we do if a breach occurs.
10. Data Retention and Deletion
10.1 Why We Retain Financial Records the Way We Do
KaiKap records your financial history as an append-only ledger — a design chosen deliberately so that every number you see always has a verifiable history and cannot be silently altered, including by us. Correcting a mistaken entry adds an offsetting correction record rather than erasing the original; this is a data-integrity feature of the product, not a limitation on your privacy rights, which we address directly below.
10.2 While Your Account Is Active
We retain your information for as long as your account is active and as needed to provide the Service.
10.3 Closing Your Account
You may close your account at any time from Settings. The moment you do: your account is deactivated and immediately inaccessible (including to you, until restored as described below), all new processing stops (no further AI processing, no logins, every active session ends), and directly identifying account fields — your email address and display name — are replaced with opaque placeholders. We email you, at the moment of closure, a complete copy of your data for your own records, and separately keep an encrypted archive as the only way back in.
10.4 The 90-Day Self-Service Recovery Window, and What Happens After
For 90 days after closing your account, a link emailed at the moment of closure restores it exactly as it was, same login, same data, with no further action from us needed. After that window, self-service restoration is no longer available, but restoration is still possible by contacting us directly to verify your identity.
Unlike an ordinary "delete my account" request, we do not permanently destroy this archive after the 90 days. It is retained, encrypted, for up to 7 years, specifically so that we can respond honestly and completely if a court order, regulator, or other legitimate legal process asks for it years after you've left — we never want to have to tell such a request "we no longer have that data." The archive is protected against accidental or casual deletion by a retention rule on our storage provider; removing that protection before the retention date is a deliberate, logged action reserved for a genuine legal/compliance need, not something that happens as a side effect of normal operations. The archive is otherwise never accessed, read, or used for any purpose other than responding to that kind of request or restoring your account at your instruction. If you would prefer this archive be destroyed sooner — for example, because you're confident you'll never need it back and want it gone regardless of the 7-year legal-hold reasoning above — contact [PRIVACY EMAIL — set in Company Info] and we'll consider an early, exceptional destruction on a case-by-case legal/compliance review; we cannot guarantee it will always be possible.
10.4a What We Keep for Win-Back Communications
Separately from the archive above, we deliberately retain your email address after closure — unless you tell us not to at the time you close your account — so that we can occasionally reach out about improvements relevant to why you left, or invite you back. This is the one exception to the identity-clearing described in Section 10.3, and it's opt-out by default: every such email includes a way to stop receiving them, and you can also opt out at the moment you close your account. Nothing else about your closed account (no financial data, no transaction history, no balances) is used for this purpose.
10.5 A Direct Note on the Underlying Transaction History
KaiKap's financial ledger is deliberately append-only at the database level — even we cannot silently edit or delete a recorded transaction; corrections are only ever additional, offsetting records, never in-place changes. This is what makes every figure in the Service independently verifiable, but it also means that closing your account does not, by itself, erase the free-text notes or counterparty names inside your own transaction history the way it erases your account identity above. That history remains stored, isolated from every other account, and — once you close your account — permanently inaccessible to any user (including you, absent the recovery window above); it is not separately deleted line-by-line. If this distinction matters to you, contact [PRIVACY EMAIL — set in Company Info] before closing your account, and we'll work through it with you directly.
10.6 Export Before Closing
We strongly recommend exporting a full copy of your data (available at any time from Settings) before closing your account, and keeping the copy we email you at closure — self-service restoration only works for 90 days, and while the underlying archive is kept far longer for legal purposes, day-to-day access to it after that window requires contacting us directly.
11. Your Rights
Depending on your jurisdiction, you have some or all of the following rights, which you can exercise by contacting [PRIVACY EMAIL — set in Company Info]:
- Access — request a copy of the personal data we hold about you (also available at any time via in-product export);
- Correction — correct inaccurate information (for financial records, via the in-product correction/reversal mechanism, which preserves an audit trail rather than silently overwriting history);
- Erasure — close your account from Settings at any time, as described in Section 10;
- Portability — receive your data in a structured, machine-readable format;
- Objection and restriction — object to or request that we restrict certain processing, including AI processing, which you can also disable at any time in Settings;
- Withdraw consent — withdraw any consent you previously gave, without affecting the lawfulness of processing before withdrawal; and
- Complain — lodge a complaint with your local data-protection authority, where one exists, in addition to contacting us directly.
We will respond to a verified rights request within 30 days.
12. Cookies and Similar Technologies
We use a single essential session cookie to keep you signed in, set to be inaccessible to JavaScript, sent only over encrypted connections, and restricted to first-party requests. We do not use third-party advertising or tracking cookies. The web app also stores a small amount of non-sensitive interface preference data (such as your dark/light theme choice and whether figures are currently shown or masked on screen) in your browser's local storage, which never leaves your device.
13. Mobile Application Data and Permissions
The iOS and Android apps process the same account and financial data described in Section 3, synced with our servers over an encrypted connection. The apps may request the following device permissions, each strictly to enable the feature named and never used for any other purpose:
- Push notifications — to deliver security alerts and, if you opt in, product or reminder notifications. You can disable these at any time in your device settings.
- Biometric unlock (Face ID / fingerprint) — if you enable app-lock, to authenticate you locally on your device; biometric data itself is handled entirely by your device's operating system and is never transmitted to us.
The apps do not request access to your contacts, camera, photo library, location, or microphone. If a future version adds a feature requiring one of these, we will update this Policy and request the permission explicitly, with a clear explanation, before it is used.
14. Children's Privacy
The Service is not directed to, and must not be used by, anyone under 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have, we will delete it promptly. If you believe a child has provided us with personal data, contact [PRIVACY EMAIL — set in Company Info].
15. Data Breach Notification
If we become aware of a security incident that results in unauthorized access to your personal data and creates a real risk of harm to you, we will notify you without undue delay by email and/or a prominent in-app notice, describing the nature of the incident, the data involved, and the steps we are taking and recommend you take, and we will notify any applicable regulator within the timeframe required by law.
16. Changes to This Policy
We may update this Policy from time to time. If we make a material change, we will provide reasonable advance notice, such as an in-app notice or an email to the address on your account, before the change takes effect. The "Last updated" date at the top of this page always reflects the current version.
17. Contact and Grievance Officer
[LEGAL ENTITY NAME — set in Company Info]
[REGISTERED OFFICE ADDRESS — set in Company Info]
Privacy / data requests: [PRIVACY EMAIL — set in Company Info]
Grievance Officer: [GRIEVANCE OFFICER NAME — set in Company Info], reachable at the address above, for any complaint regarding the handling of your personal data.