CaltashCaltashBack to Caltash

Privacy Policy

Last updated 28 September 2026

This policy explains what personal information Caltash ("Caltash", "we", "us") collects when you use Caltash, why, who sees it, and the choices you have. We are the controller of the personal information described here. Contact us at support@caltash.com.

1. What we collect

WhatExamplesWhy
Account detailsName, email address, username, password (stored only as a salted hash), role, last sign-in time, two-factor settings (the authenticator secret is stored encrypted and recovery codes are stored hashed)To create and secure your account and sign you in
Workspace data you enterAccounts, transactions, categories, budgets, journal entries, imports, reconciliations, team members and roles, and an audit log of changesTo provide the Service
Billing informationPlan, subscription status, Stripe customer and subscription IDs, invoice amounts and dates. Card details are entered on Stripe's pages and never reach us.To charge for paid plans and manage subscriptions
Usage and security dataSign-in attempts, feature usage counts (for example AI requests per month), technical logs, and the IP address used to slow down repeated failed sign-insTo keep the Service secure, enforce plan limits and fix problems
Website analyticsWhich public pages are viewed (home, sign-in, sign-up, terms, privacy, support), the referring website, campaign tags such as utm_source, whether the device is mobile or desktop, and an anonymous visitor code that changes every day and is derived from your IP address and browser detailsTo count visitors and understand which sources bring people to Caltash, without using cookies. The source of your sign-up is saved with your account.
MessagesEmails you send us, and the account emails we send you (verification, password reset, security alerts)To support you and keep your account safe

2. How we use it, and our legal bases

We use personal information to run the Service, secure it, process payments, provide support, and improve the product. If you are in the EEA or UK, our legal bases are: performing our contract with you (providing the Service and billing); our legitimate interests in security, preventing abuse and understanding how the Service is found and used; complying with legal obligations such as tax and accounting rules; and your consent where we ask for it. We do not sell your personal information and we do not use it for advertising.

3. AI features

When you use an AI feature (asking questions, spending summaries, forecast explanations or category suggestions) we send the information needed for that request to Google's Gemini API. This can include transaction descriptions, amounts, dates, account and category names and, for business workspaces, chart-of-accounts and journal information. We do not send your password or payment details. AI features are optional, and each plan limits how many requests you can make.

4. Who we share information with

ProviderWhat they doWhat they receive
StripePayments, invoices, billing portalYour email, name, workspace name and payment details
Google (Gemini)AI featuresThe workspace data needed for the request you make
Oracle Cloud InfrastructureHosting and databaseAll data we store
Email delivery providerSending account emailsYour email address and the message

We may also disclose information if the law requires it, to protect people and the Service from harm, or in connection with a sale or reorganisation of the business, in which case this policy will continue to protect your information. Within a workspace, other members can see the data and the audit log according to their role.

5. Cookies and third-party requests

Caltash sets one cookie, a signed session cookie called "session". It is essential: it keeps you signed in and protects forms from forgery. It expires after at most 8 hours, and you are signed out after 30 minutes of inactivity. We do not use advertising or analytics cookies, so we do not show a cookie banner.

Your browser also loads fonts from Google Fonts and the Chart.js and PapaParse libraries from cdnjs (Cloudflare). Those providers receive your IP address and browser details when your browser requests those files.

6. International transfers

Caltash and its providers may process information in the United States and other countries, which may have different data-protection laws from yours. Where required we rely on safeguards such as the standard contractual clauses our providers offer.

7. How long we keep information

InformationKept for
Account and workspace dataUntil you or the workspace administrator deletes it. After a verified deletion request we delete it within 30 days. Copies in backups are removed as backups are replaced, within 90 days.
Website analytics13 months
Billing recordsAs long as tax and accounting law requires
Technical and server logsA limited period, usually up to 30 days

8. Your rights

Depending on where you live, you may have the right to access your personal information, receive a copy in a portable format, correct it, delete it, restrict or object to how we use it, and withdraw consent. You also have the right to complain to your data-protection authority.

California residents. You have the right to know what personal information we collect and how it is used, to request deletion or correction, and not to be discriminated against for using these rights. We do not sell or share personal information for cross-context advertising.

9. Security

We protect information with encryption in transit, hashed passwords, encrypted two-factor secrets, role-based access, sign-in rate limiting and an audit log. No system is perfectly secure, but we work to protect your information and will notify you and the authorities of a breach where the law requires it.

10. Business workspaces

For the financial data a business puts into its workspace, the business decides why and how it is used and is responsible for having a lawful basis to use it. In that role Caltash acts as its service provider (processor) and processes the data only on the business's instructions. A data processing agreement is available on request at support@caltash.com.

11. Children

Caltash is not intended for anyone under 16, and we do not knowingly collect information from children. If you think a child has given us information, contact us and we will delete it.

12. Changes and contact

If we change this policy in a material way we will tell you by email or in the app before the change applies. Questions? Email support@caltash.com.