← Knigash

Privacy Policy

Last updated: 18 August 2026

This policy explains what Knigash ("we", "us") collects, why we collect it, who we share it with, and the control you have over it. It applies to the Knigash website, the iOS app, and the Android app.

1. Who we are

Knigash is operated by Knigash. For any privacy question, or to exercise any right described below, contact [email protected].

2. What we collect

2.1 Account information

Knigash has no password of its own — you sign in with Google or with Apple. From that sign-in we receive your email address, and where available your display name and profile picture. We never receive your Google or Apple password.

If you use Sign in with Apple and choose Hide My Email, we receive only Apple's private relay address. That is sufficient to run your account — we never see your real address.

2.2 Expense and accounting data

The substance of the service: receipt images and PDFs you upload, and the expense records attached to them — amount, currency, date, vendor, description, category and status.

2.3 Camera and photo library

On mobile, the app asks permission to use your camera and photo library so you can photograph or attach a receipt. Images are used only for the receipt you are creating. We do not browse your photo library and we do not collect images you have not chosen.

2.4 Bank statement email (optional)

You may optionally connect a Gmail account so Knigash can pick up bank statements automatically. This is off by default, requires your explicit consent, and can be disconnected at any time in Settings.

When connected, we request read-only Gmail access and use it narrowly: we search for messages from the bank sender address you configure, and read the statement attachments on those messages. From those statements we extract transactions and account balances — including account numbers and IBANs shown on the statement. We do not read, index or store unrelated email.

Google API Services Limited Use disclosure. Knigash's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, we do not sell it, we do not transfer it except as needed to provide the service, and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with law, or where the data has been aggregated and de-identified.

Your Gmail refresh token is encrypted at rest and is deleted when you disconnect the mailbox or delete your account.

2.5 Technical data

Our servers keep standard operational logs — IP address, timestamp, requested URL, error diagnostics — to keep the service running, secure and debuggable.

2.6 What we do not do

We do not use advertising or analytics trackers, we do not build advertising profiles, we do not sell personal data, and we do not track you across other apps or websites.

3. Why we process it, and on what legal basis

PurposeLegal basis (GDPR Art. 6)
Creating your account and signing you inPerformance of a contract
Storing receipts and expense recordsPerformance of a contract
Sharing records with the accountant you are linked toPerformance of a contract
Importing bank statements from GmailConsent (withdrawable at any time)
Security, abuse prevention, rate limitingLegitimate interests
Retaining accounting recordsLegal obligation / legitimate interests

4. Who your data is shared with

Knigash is a shared workspace, so sharing is the point of it:

Beyond that we share data only with infrastructure providers acting on our instructions (hosting and email delivery), and where we are legally required to.

5. Where your data is stored

Data is stored on servers in the European Union. Where data is transferred outside your country, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.

6. How long we keep it

Account data is kept while your account is open. Expense records and receipts are kept while the organization they belong to needs them, and may be retained afterwards where bookkeeping or tax law requires it.

7. Deleting your account

You can delete your account at any time inside the app: Settings → Delete account. You will be asked to type your email address to confirm.

When you do, we immediately and permanently:

What is retained, and why. Expense records and receipts you created stay with the organization they belong to. They are that business's accounting records — frequently records it is legally obliged to keep, and which its accountant may already have processed — so they are not ours to erase on an individual's request. After deletion they are no longer linked to any identifiable person.

If you believe a specific record should also be erased, contact [email protected] and we will assess the request against our legal obligations.

8. Your rights

Subject to local law, you may request access to your data, correction of it, erasure, restriction of processing, portability, or object to processing. Where processing rests on consent, you may withdraw consent at any time without affecting prior processing. Write to [email protected]; we respond within 30 days. You also have the right to complain to your local data protection authority.

9. Security

Traffic is encrypted with HTTPS. Gmail refresh tokens are encrypted at rest. Access to receipts is authenticated and scoped to your organization, and file links are signed and time-limited. No system is perfectly secure, but we work to keep this one sound.

10. Children

Knigash is a business bookkeeping tool and is not directed at children under 16. We do not knowingly collect their data; if we learn that we have, we delete it.

11. Changes

If we change this policy materially we will update the date above and, where the change is significant, notify you in the app.

12. Contact

Knigash
[email protected]


Privacy Policy · Terms of Service