Legal
Privacy Policy
Last updated: 22 March 2026
1. Who We Are
KASHO ("we", "our", "us") is a subscription tracking and management service operated at kashoapp.com. We help individuals identify, track, and cancel unwanted recurring subscriptions. For questions about this policy, contact us at business.macoumba@gmail.com.
2. What Data We Collect
We collect only what is necessary to provide the service:
• Account data: your email address and name (provided when you sign up)
• Subscription data: names, prices, billing cycles, and renewal dates of subscriptions you manually enter
• Usage preferences: display currency, dark mode preference, notification settings — stored locally on your device
• Authentication data: managed by Supabase Auth (secure, encrypted)
• Payment data: processed by Stripe — we never see or store your card details
We do NOT connect to your bank account. We do NOT scan your emails or transactions. Everything you enter is entered manually by you.
3. How We Use Your Data
Your data is used exclusively to provide KASHO's service:
• To display your subscriptions and calculate your spending
• To send renewal reminder emails (7 days and 1 day before renewal dates you set)
• To process Pro plan payments via Stripe
• To restore your data when you log in on a new device
We do not use your data for advertising. We do not sell your data to third parties. We do not use your subscription data to make inferences about you beyond what the service requires.
4. Data Storage & Security
Your data is stored on Supabase's EU servers (eu-west-1, Ireland). Supabase uses PostgreSQL with row-level security — meaning your data is cryptographically isolated from other users' data. Access to the database requires authentication for every operation.
We use HTTPS for all data transmission. Passwords are hashed and never stored in plain text. Authentication tokens are short-lived and rotated automatically.
5. Cookies & Local Storage
KASHO uses browser localStorage (not traditional cookies) to store your display preferences (currency, dark mode, view settings). These are stored on your device only and never transmitted to our servers unless you explicitly save them.
We use Supabase authentication session cookies which are strictly necessary for you to stay logged in. These are functional cookies and do not require your consent under GDPR.
We do not use advertising cookies. We do not use tracking pixels. We do not use Google Analytics or any third-party analytics that profile you.
6. Email Communications
If you have an active subscription with a renewal date set, KASHO may send you transactional renewal reminder emails. These are service emails, not marketing emails, and do not require an unsubscribe option under GDPR.
If we ever send promotional emails, they will include an unsubscribe link. We use Resend to deliver emails. Resend processes your email address to deliver messages on our behalf and is bound by their own privacy policy.
7. Third-Party Services
KASHO uses the following third-party services:
• Supabase (supabase.com) — database and authentication, EU servers
• Stripe (stripe.com) — payment processing for Pro subscriptions
• Resend (resend.com) — transactional email delivery
• DuckDuckGo (duckduckgo.com) — service logo images (no personal data sent)
• Vercel (vercel.com) — hosting and CDN
None of these providers receive your subscription data for their own purposes.
8. Your Rights (GDPR)
As a user in the EU or UK, you have the following rights:
• Right to access: request a copy of all data we hold about you
• Right to rectification: correct inaccurate data
• Right to erasure: delete your account and all associated data (available directly in the app under Profile → Delete Account)
• Right to data portability: export your subscription data as CSV (available in the app)
• Right to restrict processing: contact us to pause processing of your data
• Right to object: object to any processing you disagree with
To exercise any of these rights, contact us at business.macoumba@gmail.com. We will respond within 30 days.
9. Data Retention
We retain your data for as long as your account is active. When you delete your account, all your data (profile, subscriptions, alerts, settings) is permanently deleted immediately. We do not keep backups of deleted user data after 30 days.
10. Children
KASHO is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us at business.macoumba@gmail.com and we will delete it immediately.
11. Changes to This Policy
We may update this policy as the service evolves. When we make significant changes, we will notify you by email or by displaying a notice in the app. The "Last updated" date at the top of this page always reflects the most recent version.
12. Contact
For any privacy-related questions or requests:
Email: business.macoumba@gmail.com
Website: https://kashoapp.com