1. Data We Collect
1.1 Account Information
- Email address
- Password (hashed; not stored in plain text)
- Profile info (name and settings, if provided)
1.2 User-Generated Data
- Financial records you add (accounts, categories, transactions, budgets)
- Preferences and personal configuration of the service
1.3 Technical and Usage Data
- IP address, device and browser information, log files
- Interaction data within the app
- Cookies related to authentication or session in the web version of the service
1.4 App Diagnostics, Crash, and Analytics Data
To maintain stability, diagnose errors, protect the service, and improve the product, we use Firebase Crashlytics and Firebase Analytics. These services may process:
- Crash reports, stack traces, non-fatal errors, and technical error context
- The current app screen or route, short diagnostic breadcrumbs, and the type of action that preceded an error
- App version, build number, platform, OS version, device model, language, locale, and time zone
- Internal user and family identifiers: user_id, family_id, original_family_id
- For unauthenticated users, a technical device_id or installation identifier
- Subscription status, subscription plan, subscription source, user language, and currency
- Product usage events: sign-in, registration, sign-out, screen views, paywall and subscription actions, creating, updating, and deleting core entities, integration actions, push permissions, app lock, and use of analytics screens
We do not include email address, user name, avatar, bank tokens, FCM/APNS tokens, API request or response bodies, account or category names, notes, balances, or transaction amounts in Firebase Crashlytics or Firebase Analytics events.
1.5 App Performance Data
To find slow screens, network requests, technical delays, and regressions after releases, we may use Firebase Performance Monitoring. This service may process:
- App startup time, duration of automatic and custom performance traces, and execution time of individual operations
- HTTP request duration, response codes, network payload sizes in bytes, and network URLs without URL/query parameters and without payload content
- App foreground/background state
- App version, package name, device model, OS version, language, locale, device orientation, memory, disk, CPU, and network type
- Country determined from IP address
- Firebase installation ID and Firebase session ID
We do not send API request or response bodies, URL/query parameters, tokens, email addresses, user names, account or category names, notes, balances, or transaction amounts to Firebase Performance Monitoring.
1.6 Optional Data
- Feedback, support requests, or communications with us
1.7 Subscription and Billing Data
- Google Play purchase identifiers (for example, purchase token, product ID, package name)
- Subscription verification metadata (app version, build number, and optional app-account identifier)
- For purchases through the Apple App Store, technical StoreKit identifiers, including transaction ID, original transaction ID, product ID, and appAccountToken where used
- KisoMoney does not receive the full payment card number: payments are processed by the Apple App Store or Google Play
1.8 Bank Integration Data (if connected)
- External provider account identifiers and account metadata (name/mask/currency)
- Imported transactions, including provider transaction IDs, descriptions, and raw provider payload (raw JSON) used for reconciliation and diagnostics
We do not collect full payment card credentials (for example, PAN/CVV), biometric data, or sensitive personal data unless you explicitly provide it. When bank integrations are connected, providers may transmit masked references and counterparty details as part of transaction data.
2. How We Use Personal Data
2.1 Service Operation
- Create and manage user accounts
- Provide access to KisoMoney features
- Send transactional emails (verification codes, security alerts, password reset)
- Verify subscription entitlement and prevent billing abuse/fraud
2.2 Service Improvement
- Detecting and fixing crashes, errors, and unstable app behavior
- Analyzing feature and screen usage to improve the product and prioritize development
- Checking subscription, push notification, app lock, and integration correctness
- Finding slow screens, network requests, and performance regressions after releases
- Enhancing service security, stability, and quality
2.3 Legal Compliance
- Responding to legal requests
- Fraud prevention
- Compliance with data deletion/export obligations
We do not sell, rent, or trade the financial records or account content you store in KisoMoney.
3. Advertising and Google AdMob
3.1 Advertising in the Free Plan
The free KisoMoney plan includes advertising. Users with an active paid subscription are not shown ads. If the subscription expires or is canceled, the account returns to the free plan and ads may be shown again.
3.2 Google AdMob and Data Processed
We use Google AdMob and the Google Mobile Ads SDK to deliver advertising. Depending on the platform, device settings, permissions, consent choices, region, and ad format, the SDK may collect and share:
- IP address and approximate location inferred from it
- Device advertising identifier, such as Android Advertising ID or Apple IDFA, when available and permitted
- App, installation, developer-scoped, and device identifiers
- Interactions with the app and ads, including app launches, taps, and other actions related to ad delivery
- Ad impressions, clicks, ads viewed, and video views
- Diagnostic and performance data, such as app or SDK startup time, crashes, hangs, and energy usage
3.3 Advertising Purposes
- Delivering and displaying ads
- Selecting and, where permitted and consented to, personalizing ads
- Limiting how often the same ad is shown
- Measuring impressions, clicks, video views, and advertising effectiveness
- Advertising analytics and improving ad performance
- Detecting invalid traffic, fraud, abuse, and technical errors
3.4 Personalized and Non-Personalized Ads
Depending on applicable law and your choices, KisoMoney may show personalized, non-personalized, or limited ads. Personalized ads may be based on interests or previous activity outside KisoMoney. Non-personalized ads are not based on previous behavior, but may still use contextual information, approximate location, and limited technical data for ad delivery, frequency capping, measurement, security, and fraud prevention. Declining personalized ads does not necessarily disable all advertising.
3.5 Financial Data Is Not Used for Advertising
KisoMoney does not send to Google AdMob or use for ad targeting, personalization, audience creation, or ad measurement any financial data entered or imported by users, including:
- Financial accounts, account names, and account groups
- Transactions, transaction descriptions, amounts, and notes
- Balances, budgets, categories, and plans
- Bank statements, imported bank payloads, bank access tokens, and bank connection data
3.6 Advertising Privacy Choices
- Where required, KisoMoney uses a consent message before requesting ads and respects the available consent choices.
- You can review or change available advertising privacy choices from the privacy or advertising settings provided in the KisoMoney app.
- You can also manage the device advertising identifier and tracking permissions in Android or iOS settings.
- Google Privacy Policy: https://policies.google.com/privacy
- How Google uses information from apps that use its services: https://policies.google.com/technologies/partner-sites
3.7 Google Consent Mode
For users in the European Economic Area, the United Kingdom, and Switzerland, we use the Google User Messaging Platform (UMP) to collect and store privacy choices. Where European rules apply, those choices are passed to Google Consent Mode v2 through the ad_storage, analytics_storage, ad_user_data, and ad_personalization signals. These signals control data processing by Google Mobile Ads and Firebase Analytics.
If a user does not consent to analytics or ad data storage, Google Analytics for Firebase and Google advertising services do not use the relevant device identifiers and storage. When advanced consent mode is used, Google may receive limited signals without those identifiers for basic measurement, security, and aggregate metric modeling. These signals may include consent status and limited technical information.
On iOS, before accessing the IDFA, the app may show an explanation and the App Tracking Transparency (ATT) system prompt. Declining tracking does not disable advertising completely: non-personalized or limited ads may be shown without using the IDFA.
Users can change or withdraw their choices through the “Advertising Privacy Choices” option in the app. The new choice applies to subsequent data processing. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
3.8 Rights of Residents of U.S. States
KisoMoney does not sell financial records, account content, or other user-entered data for monetary consideration. However, under the laws of certain U.S. states, sharing limited advertising identifiers and technical data with advertising partners to deliver personalized or targeted advertising may be considered a “sale” or “sharing” of personal data.
Where applicable U.S. state law provides this right, users may opt out of the sale or sharing of data for cross-context behavioral advertising through the “Advertising Privacy Choices” option in the app. Opting out does not disable all advertising, but limits ad personalization and the processing of advertising data.
The advertising technology providers that may receive data are identified in the consent interface where required by applicable law.
5. Data Sharing
- Email delivery services (transactional messages only)
- Cloud hosting providers (secure storage of user data)
- Analytics or security tools (strictly limited access)
- Google/Firebase services for analytics, crash reporting, performance monitoring, diagnostics, push infrastructure, and app technical stability
- Google AdMob and the advertising technology providers involved in delivering, measuring, securing, and preventing fraud in advertising
Third parties process data under the agreements, privacy policies, and legal roles applicable to each service. We do not sell or share KisoMoney financial data with advertising networks. Only the limited advertising and technical data described in Section 3 may be shared for advertising purposes.
7. Data Security
- Hashing and salting of passwords
- Encrypted data transmission (HTTPS)
- Restricted access to production systems
No system is completely secure; you use KisoMoney at your own risk.
8. User Rights
- Access your personal data
- Request data export, correction, or deletion
- Withdraw consent (where applicable)
- Object to certain processing
- Review or change available advertising privacy choices and opt out of personalized advertising where available
- Request restriction of processing, receive applicable data in a structured, commonly used, and machine-readable format, and lodge a complaint with a competent supervisory authority
- Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal
To exercise these rights, contact info@kisomoney.com.
9. Account and Data Deletion
9.1 In-app deletion
- You can initiate account deletion directly in the app: “Settings → Irreversible actions → Delete account”.
9.2 Email request
- If you cannot access the app, send a request to info@kisomoney.com with the subject “Account Deletion Request”.
- Include your KisoMoney account email and clearly state that you request deletion of your account and related personal data.
- Detailed account deletion instructions: https://kisomoney.com/en/account-deletion
9.3 Timeline and exceptions
- After successful verification, we process deletion requests within up to 30 calendar days.
- Data retention timelines and exceptions after deletion are specified in Section 10 “Data Retention”.
After completion, we send a confirmation email to the user.