Kalta — Privacy Policy

Effective 2 October 2026 · Last updated 2 October 2026

Read the Terms of Use · Support

Kalta is a personal money ledger. It works with no account, it shows no ads, and it never moves money. This page lists what Kalta holds about you, why, where it is stored, and how long it is kept.

Who we are

Kalta is made by Luxxat Labs, IP, a sole proprietor registered in the Republic of Kazakhstan. We are the controller of the data on this page. You can write to us at hello@luxxatlabs.dev.

The short version

What we hold

DataWhy, and the legal basisWhere it is storedHow long
An anonymous id for your phone, created the first time you open KaltaTo give your phone an identity, so your ledger can be saved and, if you choose, linked to a login. Basis: contract (the app works).Firebase AuthenticationUntil you delete your account (see “Deleting your data”).
If you sign in: the e-mail address and name that Apple or Google share with us, and which provider you usedSo you can use the same ledger on another device and share a wallet. Basis: contract.Firebase Authentication; Apple or Google acts as the sign-in providerUntil you delete your account.
Your ledger: accounts, transactions (type, amount, currency, category, date, time, your note, the split, any fee), categories, budgets, recurring rules, goals, templates, asset values, and your saved exchange ratesThe app’s main job: to keep your ledger, show it, and keep it in step across your devices. Basis: contract.On your phone, and in Cloud Firestore while the phone is online (see “No account needed, and the optional sign-in”)Until you delete your account. An entry you delete in the app stays on our server marked as deleted, so the delete can reach your other devices. It is removed when the account is deleted.
Your settings: home currency, first day of the month and week, theme, number format, language, and which offers you have dismissedSo your settings follow you. Basis: contract.Cloud FirestoreUntil you delete your account.
If you sign in: the name and model of each of your devices, when it was linked, and when it was last seenTo show your devices, and to apply the one-free-device rule. Basis: contract.Cloud FirestoreUntil you remove the device in the app, or delete your account.
If you sign in: one daily snapshot of your own accounts, transactions, categories, budgets, rules and goals; the last 30 are keptSo a bad edit or delete can be undone by restoring a day. Basis: contract.Cloud FirestoreA rolling 30 days. All of them are deleted with your account.
Shared wallets: who is a member and their role, the name each member shows, when they joined, and the invite codeTo run a shared wallet (see “The shared wallet”). Basis: contract.Cloud FirestoreWhile the wallet exists. Your name and role are removed from a wallet when you leave it or delete your account.
Your purchase record: store, the store’s transaction id, product, your account id and the time; and your plan statusTo unlock Sync + Plan, and to stop one purchase from unlocking two accounts. Basis: contract.Cloud Firestore, after Apple or Google confirm the purchaseUntil you delete your account. Deleting it releases the record (see “Purchases”).
Currency codes, such as EUR and KZT, when Kalta asks for a rateTo fetch today’s exchange rate. Basis: contract.Sent to our Cloud Function, which asks the rate providers. The answer is saved with your data.Until you delete your account.
Abuse counters: how often an account id, or a hash of a network address, has joined a wallet, asked for rates, or checked a purchaseTo stop code guessing and other abuse. Basis: legitimate interest (keeping the service safe).Cloud Firestore. The network address is stored only as a salted SHA-256 hash, never as the address itself.Each counter expires after its time window plus 24 hours. A daily job at 03:30 (Asia/Almaty time) deletes expired ones.
Suggestions board: the title and details you post, your votes, your reports, your hidden-post and blocked-author lists, and the account id behind them. Posts show the name “Kalta user”, not your name.To run the board and to remove abusive posts. Basis: contract and legitimate interest.Cloud FirestoreUntil you delete your account. Then your posts stay without your id, and your votes are removed (see “Deleting your data”).
Crash and error reports from release buildsTo find and fix crashes. Basis: legitimate interest.Firebase Crashlytics (see “Crash reports”)90 days.
Anonymous usage events, only if you tap YesTo see which parts of Kalta are used. Basis: your consent.Google Analytics for Firebase (see “Usage statistics”)No longer than 14 months. Google offers 2 or 14 months.

Scroll the table sideways on a phone.

What stays on your phone

What we never collect

Your location. Your contacts. Your phone number. Your bank details. Your health data. Your browsing history. Kalta has no bank connection, no advertising SDK and no attribution SDK. Nothing we hold is sold or shared for advertising.

No account needed, and the optional sign-in

You never have to make an account to use Kalta. The first time you open it, Firebase gives your phone an anonymous id. There is no sign-up screen. Your ledger is kept on your phone first. While the phone is online, Kalta also saves it to Cloud Firestore under that anonymous id. Nothing but that id links the saved copy to you.

Signing in with Apple or Google links that same id to your login. It lets you use the same ledger on another device, share a wallet, and restore your ledger on a new phone. It is never needed for the ledger itself. If you sign out, that phone stops syncing and keeps its own copy.

The shared wallet

A wallet can have an owner and editors. Members of a shared wallet see every transaction in it, by design. An editor can add, edit and delete transactions and see the whole history. Only the owner can invite or remove people. Your own accounts stay private, and the other members never see them. The one exception is a transfer from one of your own accounts into a shared wallet. The wallet’s members can see that transfer.

To join, a person needs an invite code or link, and must sign in with Apple or Google. When they join, Kalta stores the name that their Apple or Google login shares, and shows it to the other members. Before someone joins, anyone who holds the invite code can see a short preview: the wallet’s name, the owner’s name and how many members it has. The owner can reset the code at any time. That stops the old code and link at once.

When a member leaves, or the owner removes them, every transaction they added stays in the wallet. Only the member’s name and role are removed.

Usage statistics

Usage statistics are an opt-in choice. They are off until you tap Yes on the one question Kalta asks after setup. If you tap No, they stay off. In Settings → Your data, the “Share anonymous usage stats” switch turns them on or off at any time.

What is sent, once you say Yes: anonymous usage events, such as that a budget went over, that a setting changed, or that a purchase screen was opened. An event can carry a short label, such as which setting changed. Events never carry your ledger: no amounts, notes, names or account names. Google Analytics for Firebase also adds standard technical details, such as the app version, the phone model and system version, the language, and a random app id. If you turn the switch off, Kalta stops sending new events. Events already sent are kept for the retention period in the table above.

Crash reports

Release builds of Kalta send crash and error reports to Firebase Crashlytics. Debug builds do not. A report holds the stack trace (which code was running), the app version, the phone model and system version, and a random installation id that Crashlytics makes. Kalta does not add your account id or your ledger to a report. There is no switch for crash reports. Google keeps them for 90 days.

Purchases

Apple or Google takes the payment. We never see your card. Kalta sends the receipt from your store to our Cloud Function, which checks it with Apple’s App Store Server API or Google’s Play Developer API. If the store confirms it, we keep the purchase record and plan status described in the table. They are used to unlock Sync + Plan, and to stop one purchase from unlocking two accounts. The store keeps its own purchase records under its own rules.

Where your data is stored

Your synced data is stored in the EU (Firebase, europe-west) and leaves Kazakhstan when you sign in.

Cloud Firestore uses the eur3 multi-region in Europe. Our Cloud Functions run in europe-west1. Before you sign in, the anonymous id and the ledger saved under it are stored in the same place.

Google and Apple run networks in many countries. Data handled by their services, such as sign-in, Crashlytics, Analytics and the stores, may be processed outside the EU. They do this under their own data transfer terms, such as standard contractual clauses.

Who handles data for us

The database rules let a person read only the accounts they are a member of, and only their own user record. The one exception is a transfer into a shared wallet, which the wallet’s members can see.

Deleting your data

The ledger on your phone stays and keeps working after you delete your account. If you never signed in, there is no Delete button, because there is no login to delete. To remove the data that is saved under your anonymous id, sign in first, so that the id is linked to your login, and then delete the account.

Before you delete, use the free export in Settings → Your data → Backup & export. Your data is never locked inside Kalta.

Your rights

You can ask us for access to your data, to correct it, to erase it, to receive it in a portable form, and to object to how we use it. You can withdraw your consent to usage statistics at any time with the Settings switch. You can also complain to the data protection authority in your country.

To use a right, write to hello@luxxatlabs.dev. We answer within 30 days.

Children

Kalta is for people aged 16 and over. It is not made for children. It has no kids mode and no sign-in for a child. If you think a child’s data is in Kalta, write to hello@luxxatlabs.dev and we will delete it.

Changes to this policy

If what we collect changes, this page changes with it and the date at the top moves.

Contact

Luxxat Labs, IP — sole proprietor, Republic of Kazakhstan
Privacy and general questions: hello@luxxatlabs.dev