This Privacy Policy explains how Keshio ("we", "us") collects, uses, stores, and shares information when you use our mobile app, website, and Pro services. By using Keshio you acknowledge this Policy. For how the product works contractually, see our Terms of Use.
1. Who is responsible
Controller contact for privacy requests: [email protected] — Website: https://keshio.app.
2. Information we collect
2.1 Account and identity
- When you sign in with Google, we receive identifiers from Firebase Authentication such as your user ID, display name, email address, and profile photo URL (if provided by Google).
- We use this to recognise your account, restore Pro entitlements, process referrals, and communicate about the Service.
2.2 On-device financial data
- Transactions, categories, budgets, savings goals, recurring series, and similar ledger data are stored primarily on your device.
- If you enable SMS analysis, the app may read SMS messages you permit (typically mobile-money and bank alerts) to suggest transactions. SMS content is processed on-device for that purpose and is not uploaded to Keshio servers as a default ledger sync.
2.3 Optional cloud backup
- If you use Google Drive backup, a copy of your ledger snapshot is stored in your Google Drive under permissions you grant. Access is through Google's APIs under your Google account.
2.4 Pro, payments, and referrals
- To check or grant Pro status we may store on our servers: Firebase user ID, email, subscription end date, referral codes and claims, and payment records (amount, currency, status, provider reference).
- Card and mobile-money details are handled by our payment processor (Paystack). We do not store full card numbers on Keshio servers.
2.5 Website and operations
- Server logs may include IP address, user agent, timestamps, and request paths needed for security, rate limiting, and debugging.
- If you email us, we process the content of that correspondence.
- Admin portal accounts (operators only) use separate credentials and are not the same as Google Sign-In for end users.
2.6 Diagnostics
- Where enabled, crash and performance tools (for example Firebase Crashlytics) may collect device and app diagnostics to improve stability. These typically do not include your full ledger.
3. How we use information
- Provide and secure the Service (sign-in, Pro entitlement, referrals, admin operations)
- Process payments and send related notices (for example subscription confirmation email)
- Respond to support requests
- Detect abuse, fraud, and technical issues
- Improve product features and reliability
- Comply with law and enforce our Terms
4. Legal bases (where applicable)
Depending on your location, we rely on: performance of a contract (providing the app and Pro), consent (for example optional SMS or Drive permissions), legitimate interests (security, product improvement, limited analytics), and legal obligation where required.
5. Sharing
We do not sell your personal information. We share data only as needed with:
- Google / Firebase — authentication, optional crash reporting, optional Drive backup under your account
- Paystack — payment processing for Pro
- Hosting and mail infrastructure — servers and email delivery for keshio.app
- Authorities — when required by law or to protect rights and safety
Providers act under their own privacy terms when they are independent controllers (for example Google regarding your Google account).
6. Retention
- On-device data remains until you delete it or uninstall the app (subject to OS backups you control).
- Server account and subscription records are kept while your account is active and for a reasonable period afterward for billing disputes, security, and legal compliance.
- Payment references and audit logs may be retained as required for financial and security records.
7. Security
We use industry-standard measures appropriate to our Service (TLS in transit to our servers, access controls, hashed passwords for admin accounts, verification of app tokens for APIs). No method of transmission or storage is 100% secure. Protect your Google account and device lock.
8. International transfers
Infrastructure and subprocessors (including Google and Paystack) may process data outside Kenya. Where required, we rely on appropriate safeguards and provider terms.
9. Your choices and rights
- Revoke SMS, notification, biometric, or Drive permissions in system settings
- Sign out or stop using the app; clear local app data via OS settings
- Request access, correction, or deletion of personal data we hold on our servers by emailing [email protected] (we may need to verify your identity)
- Opt out of non-essential marketing email if we send any (transactional mail such as receipts may still be sent)
Kenyan data protection law and, where applicable, other privacy laws may grant additional rights. We will respond within a reasonable time.
10. Children
Keshio is not directed at children under 18. We do not knowingly collect personal information from children. If you believe a child has provided data, contact us and we will take appropriate steps.
11. Cookies and similar technologies
The website may use essential cookies or similar storage for security (for example CSRF/session cookies on the admin portal). We do not use advertising trackers on keshio.app as part of the core product experience described here.
12. Changes
We may update this Policy and will revise the "Last updated" date. Significant changes may be noted on keshio.app or in the app. Continued use after changes means you accept the updated Policy.
13. Contact
Privacy questions or requests: [email protected].