Kacha legal
Privacy Policy
Kacha handles receipts, bills and spending records — some of the most personal data you own. This policy explains exactly what we collect, why, who touches it, and how you get it back or delete it.
- Last updated
1. Who we are
Kacha is operated by PulseKaki (“Kacha”, “we”, “us”), a company incorporated in Malaysia. This policy is written to comply with the Personal Data Protection Act 2010 of Malaysia (PDPA) and its 2024 amendments. For the purposes of the PDPA we are the data user in respect of the personal data described below, and you are the data subject.
Our appointed Data Protection Officer can be reached at kacha@pulsekaki.com.
2. What we collect
2.1 Data you give us
- Account data — name or display name, email address, phone number (if you use it to sign in), and profile photo if you add one.
- Financial records you create — expense amounts, merchants, categories, dates, notes, budgets, goals and account nicknames.
- Receipt and bill images — the photos you capture, including anything else visible in the frame, and the text extracted from them.
- Voice input — audio you record for voice logging, and the transcript produced from it.
- Utility bill data (utility ledger module) — biller, total due, billing period, due date and, where present on the bill, the account number.
- Group data — group names, members you invite, split allocations, balances and settlement status.
2.2 Data collected automatically
- Device and app data — device model, operating system version, app version, language, time zone and crash diagnostics.
- Log data — IP address, timestamps and request metadata retained for security and fraud prevention.
3. Why we use it
| Purpose | Data used |
|---|---|
| Provide the core app — logging, ledger, budgets, goals | Account, financial records, images, voice |
| Extract merchant, amount, category and date from a capture | Receipt images, voice audio |
| Group splitting, balances and reminders | Group data, balances, display name |
| Tax-relief vault and Malaysian financial goals | Tagged receipts, categories, income figures you enter |
| Pulse AI coaching and monthly reports | Aggregated spending patterns |
| Security, fraud prevention, abuse investigation | Log data, device data, reports |
| Product improvement and bug fixing | Usage and crash data |
| Service emails; marketing only where you opt in | Email address |
We do not use your financial records to profile you for advertising, and we do not make any decision with legal or similarly significant effect about you by automated means alone.
4. AI processing
Kacha uses machine-learning models to read receipts, transcribe voice, categorise spending and generate coaching responses and monthly reports.
- Content is sent to the third-party providers only to produce your result, under contracts that prohibit them from using it to train their general-purpose models.
- Where we can, we minimise what is sent — for example transmitting extracted text rather than a full image.
- We may use de-identified and aggregated data to measure and improve accuracy. De-identified data is stripped of direct identifiers and is not re-associated with you.
- You can opt out of optional AI features (Pulse AI coaching, peer benchmarks) in Settings; core logging and extraction cannot be separated from the product itself.
Accuracy disclaimer. AI extraction, categorisation, tax-relief flags and coaching output are generated automatically and can be wrong or incomplete. They are informational aids, not professional financial, tax, investment or legal advice. Always review figures before you rely on them, and confirm anything with a consequence — a filing, a payment, a claim — with the relevant authority or a qualified professional.
6. How long we keep it
- While your account is active — your records stay until you delete them, because a spending history is only useful over time.
- After account deletion — personal data is deleted or irreversibly anonymised within 30 days, except as below.
- Backups — encrypted backups roll off within 90 days of deletion.
- Abuse and safety records — reports and enforcement decisions may be retained longer to prevent repeat harm.
7. Security
- Encryption in transit (TLS) and at rest for receipts, bills and financial records.
- Access to production data is role-based, logged, and limited to staff who need it for support or operations.
- Passwords are stored only as salted hashes; we can never read them.
- Optional device-level biometric or PIN lock for opening the app.
- Regular dependency patching, security review of changes, and encrypted backups.
We cannot guarantee absolute security, and we are not responsible for a compromise that originates outside our control — for example a lost or jailbroken device, malware on your phone, a reused or shared password, or someone you gave access to your group. Keep your device locked and use a unique password. If you believe your account has been accessed without permission, contact kacha@pulsekaki.com immediately.
8. Group and shared data
Bill splitting is inherently multiplayer. When you add an expense to a group, the other members — including guests who joined without an account — can see the merchant, amount, date, your display name, any receipt image you attach and how the amount was split.
- Share only what you are comfortable with the whole group seeing; crop or omit a receipt image if it reveals more than the split requires.
- Leaving a group stops future sharing but does not retroactively erase settled history that other members rely on.
- If you add another person’s details to a group, you confirm you are entitled to do so.
- We are not responsible for what other members do with information you choose to share with them.
9. Children
Kacha is intended for users aged 18 and above. It is not directed at children, we do not knowingly collect personal data from anyone under 18, and we do not build child-facing features. If we learn that a user is under 18, we will disable the account and delete the associated personal data. A parent or guardian who believes a child has provided us with data should contact kacha@pulsekaki.com. See our Child Safety Standards for the full position.
11. Changes and how to reach us
We may update this policy as the product or the law changes. The “last updated” date at the top always reflects the current version. Continued use after the effective date means you accept the updated policy.
Privacy questions, data-access requests, safety concerns and general support all reach us at kacha@pulsekaki.com.
This page is written in plain English for clarity and is provided for general information. Where a translated version exists, the English version governs. If any provision is found unenforceable, the remainder continues in force.