Back to Home

Privacy Policy

English (Authoritative)

Effective Date: August 9, 2026 | Last Updated: August 9, 2026

1. Introduction & Legal Entity

Kamiara ("the Application") is an independent software application developed, owned, and operated solely by Pavly Boules, an individual software developer based in Ravenna (RA), Italy (hereinafter referred to as "the Developer", "we", "us", or "our"). "Kamiara" is used as an unregistered trade name for the application.

We are committed to processing your data in full compliance with the European Union General Data Protection Regulation (GDPR) (Regulation EU 2016/679) and applicable Italian data protection legislation (Decreto Legislativo 196/2003 as amended).

2. Our Core Commitment: 100% Ad-Free & Zero Ad Tracking

  • No Advertisements: Kamiara is 100% ad-free across all supported platforms (Web, Android, and iOS).
  • No Advertising SDKs: We do not incorporate any advertising SDKs (such as Google AdMob, Google AdSense, or Meta Audience Network) and we do not collect or process device Advertising Identifiers (such as IDFA on iOS or GAID on Android).
  • No Third-Party Analytics Trackers: We do not utilize commercial behavioral tracking or web analytics services (such as Google Analytics, Mixpanel, or PostHog).
  • Strictly Necessary Cookies Only: On the Web version, we utilize strictly necessary browser LocalStorage and session cookies exclusively to maintain your authenticated login session and enable local offline synchronization. We do not deploy marketing, targeting, or profiling cookies.

3. Data We Collect & Processing Purposes

We collect and process the following categories of data strictly to deliver our expense tracking and financial management services:

  • Account Credentials: Your email address, chosen username, and a securely hashed version of your password (processed using non-reversible bcrypt hashing via Supabase Auth).
  • Financial Records: Financial transactions, amounts, currencies, merchant names, custom category labels, text notes, wallet definitions, budget thresholds, and uploaded receipt image files.
  • Technical & Push Data (Mobile Applications Only): Mobile device push notification tokens (APNs / FCM), operating system version, and device model, collected solely to send automated transactional alerts, bill reminders, and budget notifications.
  • Location Data: We do not collect, request, or store your geographical location (GPS data).

4. Artificial Intelligence & Contractual Model Training Opt-Out

Kamiara integrates artificial intelligence capabilities for optical character recognition (OCR) on receipts and financial insights ("Captain Cash"):

  • AI Service Providers: AI processing requests are executed via secure server-side API endpoints hosted by Google Cloud (Gemini API) and Mistral AI (La Plateforme API).
  • Data Payload: AI prompts include transaction amounts, dates, merchant names, notes, and custom category names.
  • Excluded Data: Personally Identifiable Information (PII)—including your real name, email address, raw account credentials, or banking details—is never transmitted to AI providers.
  • Contractual Zero-Training Guarantee: We explicitly configure our developer API accounts with Google Cloud and Mistral AI with data privacy opt-out settings enforced. Under our contractual API agreements with Google and Mistral AI, all data transmitted through our API integration is strictly processed statelessly to deliver response payloads and is contractually prohibited from being utilized by Google or Mistral AI to train, retrain, or improve their foundation AI models.

5. Data Security & Encryption Architecture

  • In Transit: All data transmitted between your device, our web servers, and third-party APIs is encrypted using industry-standard HTTPS (TLS 1.2/1.3) protocols.
  • At Rest: Database records and cloud storage volumes are encrypted at rest using AES-256 encryption. Our infrastructure uses standard server-side encryption rather than client-side end-to-end encryption, meaning your data remains accessible to our systems to enable features like cross-device sync and AI-powered insights.
  • On-Device Mobile Storage: Mobile session authentication tokens and local credentials are protected using hardware-backed encryption (Expo SecureStore / iOS Keychain / Android Keystore).
  • No 100% Security Guarantee: While we employ standard technical and organizational security measures to protect your data, no method of transmission over the Internet or method of electronic storage is 100% secure, and we cannot guarantee absolute data security.

6. Third-Party Infrastructure Sub-processors

We engage a limited number of trusted sub-processors strictly for backend infrastructure, database hosting, and payment processing:

  1. Supabase Inc. (USA / EU): Cloud database, object storage, and user authentication backend.
  2. PowerSync (Journeyapps Inc., USA): Offline-first database synchronization engine connecting client-side SQLite to our cloud database.
  3. Expo / Firebase Cloud Messaging (FCM, Google LLC) / Apple Push Notification service (APNs, Apple Inc.): Mobile push notification delivery.
  4. Paddle Payments Ltd. (UK) / Paddle.com Market Ltd. (USA): Merchant of Record handling web subscription billing and tax compliance. Paddle processes payment card details directly; Pavly Boules never stores or receives your raw credit card numbers.
  5. Apple Inc. (App Store) & Google LLC (Google Play Store): In-app purchase and subscription fulfillment on mobile platforms.

7. Data Retention & Right to Erasure (GDPR)

  • Retention Period: We retain your financial data for as long as your account remains active.
  • Account Deletion (Right to be Forgotten): You may permanently delete your account and all associated financial records at any time via the "Profile Management" screen in the application or by emailing our support address.
  • Erasure Timeline: Account deletion immediately and permanently purges your account details, transactions, budgets, wallets, and receipt images from our active production databases (Supabase and PowerSync). Encrypted automated cloud backups are fully overwritten and expunged within a maximum of 30 days.

8. Your Legal Rights Under GDPR

Under EU Regulation 2016/679, you hold the following rights:

  • Right to Access & Data Portability: You can export your recorded financial data in structured formats (CSV/JSON) directly within Application Settings at any time. For a comprehensive account archive export, you may submit a formal request via email.
  • Right to Rectification: You may update or correct inaccurate profile or financial data directly within the application interface.
  • Right to Erasure: You may request full erasure of your personal data as set out in Section 7.
  • Right to Restriction & Objection: You may object to specific processing activities or request processing restrictions.
  • Right to Lodge a Complaint: You have the right to lodge a formal complaint with a competent supervisory authority (such as the Italian Garante per la protezione dei dati personali or your local EU Data Protection Authority).

9. International Data Transfers

Data processed by our infrastructure sub-processors (Supabase, Google, Mistral AI, PowerSync) may be transferred to and stored in servers located in the European Union or the United States under valid international transfer mechanisms, including standard contractual clauses (SCCs) approved by the European Commission.

10. Strict Age Limit & Minors' Privacy

Kamiara is strictly intended for individuals who are 18 years of age or older. We do not knowingly collect, solicit, or process personal data from anyone under the age of 18. Registration or submission of personal data by anyone under 18 is strictly prohibited. If we discover or are notified that an individual under 18 has created an account or submitted personal data, we will immediately terminate the account and permanently delete all associated data from our systems. If you believe an individual under 18 has provided us with personal data, please contact us immediately at Kamiara.support@gmail.com.

11. Amendments to This Policy

We reserve the right to amend this Privacy Policy. If material changes are made, we will notify you by sending an email to your registered address or by posting a prominent notice within the Application at least 14 days prior to the effective date of the changes.

12. Contact Information & Data Protection Queries

For any questions regarding this Privacy Policy or to exercise your GDPR rights, please contact:

Developer & Controller: Pavly Boules

Location: Ravenna (RA), Italy

Contact Email: Kamiara.support@gmail.com