Kalta — Privacy Policy
Kalta is a personal money ledger. It works with no account, it shows no ads, and it never moves money. This page lists what Kalta holds about you, why, where it is stored, and how long it is kept.
Who we are
Kalta is made by Luxxat Labs, IP, a sole proprietor registered in the Republic of Kazakhstan. We are the controller of the data on this page. You can write to us at hello@luxxatlabs.dev.
The short version
- You do not need an account to use the ledger.
- Signing in with Apple or Google is only for using more than one device, or for sharing a wallet.
- Usage statistics are off until you tap Yes on one question. You can change your answer at any time.
- Kalta shows no ads and does not track you across other apps or websites.
- We do not sell your data.
What we hold
| Data | Why, and the legal basis | Where it is stored | How long |
|---|---|---|---|
| An anonymous id for your phone, created the first time you open Kalta | To give your phone an identity, so your ledger can be saved and, if you choose, linked to a login. Basis: contract (the app works). | Firebase Authentication | Until you delete your account (see “Deleting your data”). |
| If you sign in: the e-mail address and name that Apple or Google share with us, and which provider you used | So you can use the same ledger on another device and share a wallet. Basis: contract. | Firebase Authentication; Apple or Google acts as the sign-in provider | Until you delete your account. |
| Your ledger: accounts, transactions (type, amount, currency, category, date, time, your note, the split, any fee), categories, budgets, recurring rules, goals, templates, asset values, and your saved exchange rates | The app’s main job: to keep your ledger, show it, and keep it in step across your devices. Basis: contract. | On your phone, and in Cloud Firestore while the phone is online (see “No account needed, and the optional sign-in”) | Until you delete your account. An entry you delete in the app stays on our server marked as deleted, so the delete can reach your other devices. It is removed when the account is deleted. |
| Your settings: home currency, first day of the month and week, theme, number format, language, and which offers you have dismissed | So your settings follow you. Basis: contract. | Cloud Firestore | Until you delete your account. |
| If you sign in: the name and model of each of your devices, when it was linked, and when it was last seen | To show your devices, and to apply the one-free-device rule. Basis: contract. | Cloud Firestore | Until you remove the device in the app, or delete your account. |
| If you sign in: one daily snapshot of your own accounts, transactions, categories, budgets, rules and goals; the last 30 are kept | So a bad edit or delete can be undone by restoring a day. Basis: contract. | Cloud Firestore | A rolling 30 days. All of them are deleted with your account. |
| Shared wallets: who is a member and their role, the name each member shows, when they joined, and the invite code | To run a shared wallet (see “The shared wallet”). Basis: contract. | Cloud Firestore | While the wallet exists. Your name and role are removed from a wallet when you leave it or delete your account. |
| Your purchase record: store, the store’s transaction id, product, your account id and the time; and your plan status | To unlock Sync + Plan, and to stop one purchase from unlocking two accounts. Basis: contract. | Cloud Firestore, after Apple or Google confirm the purchase | Until you delete your account. Deleting it releases the record (see “Purchases”). |
| Currency codes, such as EUR and KZT, when Kalta asks for a rate | To fetch today’s exchange rate. Basis: contract. | Sent to our Cloud Function, which asks the rate providers. The answer is saved with your data. | Until you delete your account. |
| Abuse counters: how often an account id, or a hash of a network address, has joined a wallet, asked for rates, or checked a purchase | To stop code guessing and other abuse. Basis: legitimate interest (keeping the service safe). | Cloud Firestore. The network address is stored only as a salted SHA-256 hash, never as the address itself. | Each counter expires after its time window plus 24 hours. A daily job at 03:30 (Asia/Almaty time) deletes expired ones. |
| Suggestions board: the title and details you post, your votes, your reports, your hidden-post and blocked-author lists, and the account id behind them. Posts show the name “Kalta user”, not your name. | To run the board and to remove abusive posts. Basis: contract and legitimate interest. | Cloud Firestore | Until you delete your account. Then your posts stay without your id, and your votes are removed (see “Deleting your data”). |
| Crash and error reports from release builds | To find and fix crashes. Basis: legitimate interest. | Firebase Crashlytics (see “Crash reports”) | 90 days. |
| Anonymous usage events, only if you tap Yes | To see which parts of Kalta are used. Basis: your consent. | Google Analytics for Firebase (see “Usage statistics”) | No longer than 14 months. Google offers 2 or 14 months. |
Scroll the table sideways on a phone.
What stays on your phone
- Receipt photos. If you attach a photo to a transaction, Kalta uses your camera or photo library after you give permission. The photo stays on your phone. It is not uploaded.
- Your passcode. A passcode, and your phone’s biometrics if you use them, can lock Kalta. They are kept on your phone and are not part of your synced settings.
- Reminders. Bill-due, budget and daily reminders are scheduled on your phone. We have no push server and we send no push messages. Kalta asks for notification permission, and re-schedules reminders after the phone restarts.
- Exports and share cards. Nothing leaves your phone until you choose where it goes.
What we never collect
Your location. Your contacts. Your phone number. Your bank details. Your health data. Your browsing history. Kalta has no bank connection, no advertising SDK and no attribution SDK. Nothing we hold is sold or shared for advertising.
No account needed, and the optional sign-in
You never have to make an account to use Kalta. The first time you open it, Firebase gives your phone an anonymous id. There is no sign-up screen. Your ledger is kept on your phone first. While the phone is online, Kalta also saves it to Cloud Firestore under that anonymous id. Nothing but that id links the saved copy to you.
Signing in with Apple or Google links that same id to your login. It lets you use the same ledger on another device, share a wallet, and restore your ledger on a new phone. It is never needed for the ledger itself. If you sign out, that phone stops syncing and keeps its own copy.
The shared wallet
A wallet can have an owner and editors. Members of a shared wallet see every transaction in it, by design. An editor can add, edit and delete transactions and see the whole history. Only the owner can invite or remove people. Your own accounts stay private, and the other members never see them. The one exception is a transfer from one of your own accounts into a shared wallet. The wallet’s members can see that transfer.
To join, a person needs an invite code or link, and must sign in with Apple or Google. When they join, Kalta stores the name that their Apple or Google login shares, and shows it to the other members. Before someone joins, anyone who holds the invite code can see a short preview: the wallet’s name, the owner’s name and how many members it has. The owner can reset the code at any time. That stops the old code and link at once.
When a member leaves, or the owner removes them, every transaction they added stays in the wallet. Only the member’s name and role are removed.
Usage statistics
Usage statistics are an opt-in choice. They are off until you tap Yes on the one question Kalta asks after setup. If you tap No, they stay off. In Settings → Your data, the “Share anonymous usage stats” switch turns them on or off at any time.
What is sent, once you say Yes: anonymous usage events, such as that a budget went over, that a setting changed, or that a purchase screen was opened. An event can carry a short label, such as which setting changed. Events never carry your ledger: no amounts, notes, names or account names. Google Analytics for Firebase also adds standard technical details, such as the app version, the phone model and system version, the language, and a random app id. If you turn the switch off, Kalta stops sending new events. Events already sent are kept for the retention period in the table above.
Crash reports
Release builds of Kalta send crash and error reports to Firebase Crashlytics. Debug builds do not. A report holds the stack trace (which code was running), the app version, the phone model and system version, and a random installation id that Crashlytics makes. Kalta does not add your account id or your ledger to a report. There is no switch for crash reports. Google keeps them for 90 days.
Purchases
Apple or Google takes the payment. We never see your card. Kalta sends the receipt from your store to our Cloud Function, which checks it with Apple’s App Store Server API or Google’s Play Developer API. If the store confirms it, we keep the purchase record and plan status described in the table. They are used to unlock Sync + Plan, and to stop one purchase from unlocking two accounts. The store keeps its own purchase records under its own rules.
Where your data is stored
Your synced data is stored in the EU (Firebase, europe-west) and leaves Kazakhstan when you sign in.
Cloud Firestore uses the eur3 multi-region in Europe. Our Cloud Functions run in europe-west1. Before you sign in, the anonymous id and the ledger saved under it are stored in the same place.
Google and Apple run networks in many countries. Data handled by their services, such as sign-in, Crashlytics, Analytics and the stores, may be processed outside the EU. They do this under their own data transfer terms, such as standard contractual clauses.
Who handles data for us
- Firebase Authentication — your anonymous id and, if you sign in, your login details.
- Cloud Firestore — your ledger, settings, devices, snapshots, shared wallets, purchase records and the Suggestions board.
- Cloud Functions — the server code for joining a wallet, rates, purchase checks, snapshots and account deletion. Like any web service, they see the network address of a caller briefly to answer the call.
- Firebase Crashlytics — crash reports.
- Google Analytics for Firebase — usage events, only if you tap Yes.
- Apple and Google — sign-in, the payment, and the receipt check. The update prompt also asks the App Store or Google Play whether a newer version of Kalta exists.
- Exchange Rate API (open.er-api.com), with Frankfurter (api.frankfurter.dev) as a fallback — exchange rates. Our Cloud Function calls them, not your phone. They get currency codes only: no account id, no names, no amounts.
- Cloudflare — serves these pages and the invite-link page.
The database rules let a person read only the accounts they are a member of, and only their own user record. The one exception is a transfer into a shared wallet, which the wallet’s members can see.
Deleting your data
- Delete an entry hides it from your ledger and your other devices. It stays on our server, marked as deleted, until the account is deleted.
- Sign out stops syncing on that phone. The ledger stays on the phone.
- Delete the app removes the copy on that phone. The copy on our server stays until you delete your account.
- Delete account and data is in Settings → Your data → Sync & account, when you are signed in. It runs on our server and removes:
- your settings, categories, budgets, recurring rules, goals, templates, saved rates, devices, and all your daily snapshots;
- every wallet where you are the last member, with all its transactions;
- your purchase records, so that you can restore the purchase later;
- your votes on the Suggestions board;
- your login, and the anonymous id behind it.
- What stays after you delete your account:
- Transactions you added to a shared wallet that other members still use. They stay for those members, and they carry an id that no longer points to anyone. If you owned that wallet, the member who joined first as an editor becomes its owner.
- Your Suggestions board posts. They stay, and show the name “Deleted user”. Your reports stay, without your id.
- Abuse counters, until they expire. This takes about three days at most.
- Server logs that name your account id. Our functions write your id to their logs, for example when you join a shared wallet, open an invite link, reset an invite code, delete your account or restore a snapshot, and when the daily snapshot runs. Invite and join attempts also log a hash of your network address. Google Cloud keeps these logs for up to 30 days by default.
- Crash reports, for up to 90 days, and usage events, for the retention period above.
- Copies in Google’s own backup systems. For Firebase Authentication, Google says it removes deleted data from live and backup systems within 180 days. For Cloud Firestore, Google gives no fixed period.
- The store’s own record of your purchases. Deleting your Kalta account does not cancel a subscription. Cancel it in the App Store or Google Play.
The ledger on your phone stays and keeps working after you delete your account. If you never signed in, there is no Delete button, because there is no login to delete. To remove the data that is saved under your anonymous id, sign in first, so that the id is linked to your login, and then delete the account.
Before you delete, use the free export in Settings → Your data → Backup & export. Your data is never locked inside Kalta.
Your rights
You can ask us for access to your data, to correct it, to erase it, to receive it in a portable form, and to object to how we use it. You can withdraw your consent to usage statistics at any time with the Settings switch. You can also complain to the data protection authority in your country.
To use a right, write to hello@luxxatlabs.dev. We answer within 30 days.
Children
Kalta is for people aged 16 and over. It is not made for children. It has no kids mode and no sign-in for a child. If you think a child’s data is in Kalta, write to hello@luxxatlabs.dev and we will delete it.
Changes to this policy
If what we collect changes, this page changes with it and the date at the top moves.
Contact
Luxxat Labs, IP — sole proprietor, Republic of Kazakhstan
Privacy and general questions: hello@luxxatlabs.dev