PrivacyPrivacy Policy — KisoMoney
We are committed to protecting your privacy and keeping our data practices transparent. If you disagree with this Policy, please stop using KisoMoney.
Effective date: December 2025Last updated: February 2026
1. Data We Collect
1.1 Account Information
- Email address
- Password (hashed; not stored in plain text)
- Profile info (name and settings, if provided)
1.2 User-Generated Data
- Financial records you add (accounts, categories, transactions, budgets)
- Preferences and personal configuration of the service
1.3 Technical and Usage Data
- IP address, device and browser information, log files
- Interaction data within the app
- Cookies related to authentication or session in the web version of the service
1.4 Optional Data
- Feedback, support requests, or communications with us
1.5 Subscription and Billing Data
- Google Play purchase identifiers (for example, purchase token, product ID, package name)
- Subscription verification metadata (app version, build number, and optional app-account identifier)
1.6 Bank Integration Data (if connected)
- External provider account identifiers and account metadata (name/mask/currency)
- Imported transactions, including provider transaction IDs, descriptions, and raw provider payload (raw JSON) used for reconciliation and diagnostics
We do not collect full payment card credentials (for example, PAN/CVV), biometric data, or sensitive personal data unless you explicitly provide it. When bank integrations are connected, providers may transmit masked references and counterparty details as part of transaction data.
2. How We Use Personal Data
2.1 Service Operation
- Create and manage user accounts
- Provide access to KisoMoney features
- Send transactional emails (verification codes, security alerts, password reset)
- Verify subscription entitlement and prevent billing abuse/fraud
2.2 Service Improvement
- Debugging, analytics, and performance optimization
- Enhancing security and stability
2.3 Legal Compliance
- Responding to legal requests
- Fraud prevention
- Compliance with data deletion/export obligations
We do not sell, rent, or trade personal data.
3. Lawful Basis (GDPR)
- Contractual necessity: to provide the service you requested
- Legitimate interest: to maintain and secure the platform
- Legal obligation: when required by applicable law
- Consent: when you explicitly provide optional data
4. Data Sharing
- Email delivery services (transactional messages only)
- Cloud hosting providers (secure storage of user data)
- Analytics or security tools (strictly limited access)
All third parties operate under data protection agreements. We do not share data with advertisers.
5. International Data Transfers
- Standard Contractual Clauses (SCC)
- GDPR-compliant processors
- Secure encrypted connections
6. Data Security
- Hashing and salting of passwords
- Encrypted data transmission (HTTPS)
- Restricted access to production systems
No system is completely secure; you use KisoMoney at your own risk.
7. User Rights
- Access your personal data
- Request data export, correction, or deletion
- Withdraw consent (where applicable)
- Object to certain processing
To exercise these rights, contact info@kisomoney.com.
8. Account and Data Deletion
8.1 In-app deletion
- You can initiate account deletion directly in the app: “Налаштування → Необоротні дії → Delete account”.
8.2 Email request
- If you cannot access the app, send a request to info@kisomoney.com with the subject “Account Deletion Request”.
- Include your KisoMoney account email and clearly state that you request deletion of your account and related personal data.
- Detailed account deletion instructions: https://kisomoney.com/en/account-deletion
8.3 Timeline and exceptions
- After successful verification, we process deletion requests within up to 30 calendar days.
- Data retention timelines and exceptions after deletion are specified in Section 9 “Data Retention”.
After completion, we send a confirmation email to the user.
9. Data Retention
- We retain personal data while your account is active or as needed to provide the service.
- After a verified deletion request, data is deleted or anonymized within up to 30 calendar days.
- Only security logs and backup copies may be retained for up to 90 days, after which they are deleted or anonymized.
- Subscription verification technical records and integration sync logs are retained only to the extent and duration needed for security, fraud prevention, support, and legal obligations, then deleted or anonymized.
10. Changes to This Policy
- We may update this Policy; new versions will include an updated "Last updated" date.
11. Contact
- Privacy inquiries: info@kisomoney.com