1. What We Collect
Kichitto collects only the minimum information needed to provide the service:
- Google account info: email address, account ID, display name, profile image URL (required to link your Google Drive and Sheets)
- Apple ID (iOS only): email address (including Private Relay) and Apple user identifier, when you use Sign in with Apple
- Device info: OS type and version, app version, device model, language and timezone settings
- Usage logs: login timestamps, OCR usage count, error counts, and crash logs (no personally identifiable information in crash logs)
2. What We Do NOT Collect
Kichitto is built on the principle that your data stays yours. We do not collect or store:
- Receipt images — saved only to your own Google Drive
- OCR extracted text — written only to your own Google Sheets
- Bank account numbers, credit card numbers
- Home address, phone number, contacts, calendar, or photo library
- Cross-site or cross-app behavioral tracking data
3. Third Parties
We share limited data with the following services to operate Kichitto:
- Google LLC (Google Drive API & Google Sheets API) — Your receipt images are saved to your own Google Drive and OCR results are written to your own Google Sheets. This data goes directly to your personal Google account and is never stored on Kichitto's servers, sold, shared with third parties, or used for any purpose other than operating the service.
Google Privacy Policy · Google API Services User Data Policy - Google Gemini API (Google LLC) — Receipt images are sent transiently for OCR processing only. Images are not retained by Google under Gemini API terms.
Google Privacy Policy - Sentry (Functional Software, Inc.) — Crash logs and error stack traces for service reliability. No personally identifiable information is included.
Sentry Privacy Policy - Cloudflare, Inc. — CDN delivery and DDoS protection. Communication logs (IP, request URL) are processed per Cloudflare's privacy policy.
Cloudflare Privacy Policy
We do not sell your data to any third party. We do not share, transfer, or disclose Google user data to any party other than as described above.
3a. Google API Services — Limited Use Disclosure
Specifically:
- Google user data is used only to provide and improve Kichitto's receipt management features.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read your Google user data unless you explicitly request support, we have your affirmative consent, it is necessary for security purposes, or it is required by law.
- We do not transfer Google user data to third parties except as necessary to provide and improve Kichitto, as described in this policy.
3b. AI Integration (MCP Connector)
If you choose to enable the AI integration (MCP connector), we read ledger data from your Google Drive and return it to the AI service you connected (such as Anthropic Claude or OpenAI ChatGPT) in response to that service's requests.
- What is sent: the ledger data relevant to your request (expense and income records, business profile, contacts, and the text of issued documents)
- Where it goes: the AI service you connected yourself. Its handling of that data is governed by that service's own privacy policy
- Permanent storage by us: none. Ledger data passes between Google Drive and the AI service; we do not store it permanently. The following temporary processing does occur:
- Temporary cache (up to 5 minutes): when an AI makes several consecutive requests, reading your entire Google Sheet each time would hit Google's rate limits and break the feature, so we hold the ledger data in our cache for up to 5 minutes. It is erased automatically after that, and immediately when a record is added or deleted
- Exception 1 — confirmation step: before an entry is appended, we hold the proposed content on our server for up to 10 minutes, erased on execution or expiry
- Exception 2 — management data for appended entries: for entries added through the AI, we store the management data defined in Section 1 (amount, date, reference number) in our database so the app can delete them and detect duplicates (subject to Section 5). Vendor names, memos and other content are not stored
- Usage statistics: we record only the name of the function called and a hashed user identifier. Ledger content is not recorded
- Error records: for troubleshooting we send only the error type and the function name to our error-monitoring service (Sentry). Error message bodies are discarded before sending so that ledger content is never included
- Authentication and revocation: connecting requires Google sign-in and your approval on a consent screen. You can disconnect at any time from the AI service
- Scope of writes: new entries only. Existing records can never be modified or deleted, and an entry is only appended after you confirm it
4. Your Data Rights
You have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Delete your account and associated data
- Stop data processing or third-party sharing
To exercise these rights: use the in-app Settings > Delete Account flow, or email [email protected]. Account data is deleted within 30 days of your request.
5. Data Retention
- Account information: retained until account deletion
- Usage logs: 13 months from collection
- Crash logs: 90 days from collection
6. Contact
Privacy questions: [email protected]