Your data stays yours.

No ads. No selling. No weird stuff. Here's exactly what we collect and why.

Privacy Policy · March 9, 2026 · v1.1

What we collect

1.1

Account information.

When you sign up, we collect your display name and email address. Passwords are managed securely by Firebase Authentication and are never accessible to us in plain text. If you sign up with Google, we receive your name and email from them instead.
1.2

Payment identifiers.

If you add payment methods, we store your DuitNow ID, Touch 'n Go number, or GrabPay number. These are encrypted at rest and only shown to members of bills you create. We do not use them to move money.
1.3

Bill and expense data.

We store the bills you create, items you add, amounts recorded, and contribution history. This is the core of what Kira does — without it, there's no app.
1.4

Basic usage data.

We collect crash logs and error reports via Sentry, and anonymous usage analytics via Umami. This includes pages visited, general interaction patterns, and error context. No personally identifying information is collected by either service. Sentry may capture device, browser, and OS context attached to error events. Umami is cookieless and does not track you across sites.
1.6

Anonymous analytics.

We use Umami to collect anonymous, cookieless usage data — including pages visited, device type, browser, and country. This data is aggregated and cannot be used to identify you. It is used solely to understand how the app is being used and to improve it. We do not use it for advertising or share it with third parties.

Why we collect it

2.1

To run the app.

Your account data lets you log in. Your bill data is the product. Your payment identifiers let others know how to pay you. None of this is collected for any other reason.
2.2

Not for ads. Ever.

We do not serve ads. We do not build advertising profiles. We do not share your data with ad networks. Kira makes money when people find it useful — not by monetising your information.

Who we share it with

3.1

Other Kira users — intentionally.

Your display name and payment methods are visible to members of bills you create or join. That's the point. You control what you add.
3.2

Infrastructure providers.

We use third-party services to host and run Kira — cloud storage, authentication, crash reporting (Sentry), and anonymous analytics (Umami). These providers process data on our behalf under strict agreements. They do not own your data and cannot use it independently.
3.3

Legal obligations.

We may disclose data if required by Malaysian law or a valid court order. We don't do this voluntarily and we'll tell you if we can.

Retention

4.1

As long as your account is active.

We keep your data for as long as you use Kira. We don't archive old bills or hold onto data you've deleted within the app.
4.2

When you delete your account.

Deleting your account permanently removes your profile, payment methods, and all bills you created. This cannot be undone. Contribution records on bills created by others may be anonymised rather than deleted, to preserve the integrity of those bills.

Your rights

5.1

You have rights under PDPA 2010.

Under Malaysia's Personal Data Protection Act, you have the right to:
  • Access the personal data we hold about you
  • Correct inaccurate or outdated data
  • Withdraw consent and request deletion
  • Know how your data is being used
5.2

How to exercise them.

Email us at [email protected] with your request. We'll respond within 14 days. No hoops, no runaround.

Questions about your data? [email protected]
This policy is governed by the laws of Malaysia.