Privacy Policy

Last updated: July 29, 2026

This policy explains what data Karchu collects, why we collect it, where it lives, who can see it, and how you can retrieve or delete it. It is written to be understood, not to hide behind lawyer-speak. If any section is unclear, email privacy@karchu.com and we’ll rewrite it.

Who this policy applies to

This policy applies to everyone who visits karchu.com, signs up for a Karchu account, uploads a bank statement, or joins a Karchu workspace by invitation. It applies globally. If you are in the European Economic Area, the United Kingdom, Switzerland, or California, additional rights described below apply to you specifically.

Data we collect

Account data

When you create an account we collect the email address you sign up with, the display name you choose, and the authentication identifiers issued by our sign-in provider (either an email/password pair or a Google OAuth identifier). We store a hashed session token in your browser so you don’t have to sign in on every visit; that token can be revoked from Settings at any time.

Financial documents you upload

When you upload a bank statement, receipt, or transaction file, we store the file itself and the parsed data extracted from it (dates, descriptions, merchants, amounts, categories, balances). CSV and Excel statements are parsed in your browser first, so the raw file contents don’t need to leave your device unless you deliberately choose to save them into your private vault. PDFs and scanned images are processed through a parsing pipeline that extracts tabular data; extracted transactions land in your workspace only after you confirm the import.

Workspace metadata

We store the name of each organization you create, the members you invite, the roles you assign, and the audit trail of who did what inside the workspace (who invited whom, who changed which rule, who exported which report).

Operational data

We collect minimal operational telemetry: error reports so we can fix bugs, usage counters used to enforce plan limits (documents parsed this month, storage consumed), and standard server-side request logs (IP address, user agent, path, response code, timestamp) kept for a short rolling window for abuse prevention and debugging.

Payment data

Paid plans are billed through Stripe. Karchu never sees or stores your card number, expiry, or CVC - those fields live inside Stripe’s hosted checkout. We receive a customer identifier, the subscription status, and the last four digits of the card for display purposes only. This keeps Karchu out of PCI scope for cardholder data.

How we use it

  • To provide the service - parsing files, categorizing transactions, computing dashboards, and delivering exports.
  • To enforce plan limits and process subscription payments.
  • To communicate transactional and product email (receipts, invitation notifications, security alerts, and important product changes). We do not send marketing email unless you opt in.
  • To detect abuse, prevent fraud, and respond to security incidents.
  • To debug the service. Error reports contain enough context to reproduce a bug and no financial data.

What we don’t do

  • We don’t sell your data. Not to advertisers, not to data brokers, not to any third party.
  • We don’t train third-party AI models on your data. Your uploaded documents, extracted transactions, and workspace content are not used as training data for any external model.
  • We don’t connect to your bank on your behalf. Karchu never asks for your online-banking password and doesn’t use bank-aggregation services.
  • We don’t use cross-site tracking cookies. The only cookies we set are strictly necessary for authentication, session state, and consent preferences.

Cookies and similar technologies

Karchu uses a small number of strictly-necessary cookies for authentication and session state. If you visit from the European Economic Area or the United Kingdom, a consent banner asks you to accept or reject optional cookies before any non-essential technology loads. Advertising is served by Google AdSense on some public marketing pages; when advertising loads, standard AdSense cookies are used. Consent Mode v2 signals are set to denied by default for EEA/UK visitors until consent is explicitly granted.

Where your data lives

Karchu runs on a managed cloud backend located in the United States. Data is encrypted in transit (TLS 1.2+) and at rest at the storage layer. Every database read is scoped to your organization at the row level, which means a user in one workspace cannot read another workspace’s transactions, receipts, or rules. Isolation is enforced by the database, not just by application code.

Sub-processors

Karchu relies on a small number of vetted sub-processors to run the service. Each one is contractually bound to process your data only for the purpose we retain them for.

  • Managed cloud backend - hosting, database, file storage, authentication.
  • Stripe - subscription billing and hosted checkout.
  • Email delivery provider - transactional email (receipts, invitations, security alerts).
  • Google AdSense - advertising on public marketing pages only, subject to your consent choices.

We update this list when it changes. If a new sub-processor is added, workspace owners receive email notice.

Data retention

  • Active account data is kept for as long as your account exists.
  • Deleted content (documents, receipts, transactions you remove from within the app) is removed from active systems immediately and from short-lived backups on their normal rotation.
  • Deleted accounts - contact us to close an account entirely. We remove active-system data within a reasonable window; short-lived backups age out on their normal rotation.
  • Billing records - retained as required by tax and accounting law in the relevant jurisdiction.
  • Server logs - retained for a short rolling window (typically 30 days) for abuse prevention.

Your rights

You have the right to:

  • Access the personal data we hold about you.
  • Correct any inaccurate personal data.
  • Export your data - most exports are available directly from the app; for anything else, email us.
  • Delete your account and associated data.
  • Object to or restrict specific processing activities.
  • Withdraw consent for optional cookies and email at any time.
  • Lodge a complaint with your local data-protection authority (for EEA, UK, and Swiss residents).

To exercise any of these rights, email privacy@karchu.com from the address on your account. We aim to respond within 30 days and do not charge for reasonable requests.

California residents (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information (we do not sell or share personal information as defined by the CCPA), and the right to non-discrimination for exercising any of these rights.

Children

Karchu is not intended for use by children under 16 and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, please contact us and we will delete it.

International transfers

Karchu is hosted in the United States. If you access the service from outside the United States, your data is transferred to and processed in the United States. Where applicable law requires, we rely on Standard Contractual Clauses and equivalent transfer mechanisms to lawfully transfer personal data from the EEA, UK, and Switzerland.

Changes to this policy

We’ll post material changes on this page and update the “Last updated” date at the top. Substantive changes are announced to active workspace owners by email at least seven days before they take effect.

Contact

Privacy questions, data-subject requests, or complaints: privacy@karchu.com. Security disclosures: /.well-known/security.txt.