01Information we collect
We collect the minimum information needed to run the Service.
Information you provide directly
- Onboarding inputs: approximate income, fixed cost estimates, end-of-month feeling, payment method preference, and similar self-reported financial snapshots.
- Budget and tracking data (Pro / Explorer): budget categories, expense entries, notes, planned versus actual amounts.
- Account information (optional): if you create an account for cloud sync, Group & Family, or subscription management, we collect your email and a hashed password (or Apple / Google sign-in identifier).
- Support requests: any information you send us when contacting support@kullriyal.com.
Information collected automatically
- Device and app data: device model, OS version, app version, language, time zone.
- Diagnostic and crash logs, scrubbed of personally identifying details where possible.
- Subscription status from Apple App Store or Google Play (via RevenueCat). We do not receive your full payment card details.
Information we do NOT collect
- We do not require or request bank account credentials.
- We do not collect contact lists, photos, calendars, or location.
- We do not sell or rent your personal information to anyone.
02Where your data lives
- Local-first by default: most of your financial data is stored on your device using the OS's secure storage.
- Cloud sync (optional, Pro): your data is stored on our secure backend (e.g. Supabase). Encrypted in transit (TLS) and at rest.
- Subscription data: stored with our subscription provider (RevenueCat) and the relevant app store.
03How we use your information
We use the information we collect to:
- Provide, maintain, and improve the Service.
- Process subscription purchases, renewals, and restores.
- Send transactional emails (password resets, subscription receipts).
- Respond to your support requests.
- Detect, investigate, and prevent fraud, abuse, or security incidents.
- Comply with legal obligations.
We do not use your financial data to train AI models, build advertising profiles, or share with third-party advertisers.
04Legal bases for processing (GDPR users)
If you are in a region where the GDPR applies, we rely on the following bases:
- Contract — to provide the Service you signed up for.
- Legitimate interests — to keep the Service secure and improve it.
- Consent — for optional features that require it (notifications, cloud sync).
- Legal obligation — when required by law.
06Data retention
- On-device data: stays until you delete the app or clear it from within the app.
- Cloud-synced data: retained while your account is active. After account deletion, removed or anonymized within 30 days (except where legally required).
- Diagnostic logs: typically retained for up to 90 days.
07Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data.
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent for optional processing.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email privacy@kullriyal.com. We will respond within 30 days.
08Children's privacy
KullRiyal is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, please contact privacy@kullriyal.com so we can delete it.
09International data transfers
If you use the Service from a country outside the one where our servers are located, your information may be transferred internationally. Where required, we use safeguards such as Standard Contractual Clauses.
10Security
We use industry-standard safeguards — including encryption in transit, encryption at rest, access controls, and audit logging — to protect your information. No system is 100% secure, but we work hard to keep yours safe.
11Changes to this Privacy Policy
We may update this policy from time to time. If changes are material, we will notify you in the app or by email before they take effect. The effective date above will always reflect the latest version.
12Contact us
Questions, requests, or concerns? Email privacy@kullriyal.com or write to:
KullRiyal Technologies
Riyadh, Kingdom of Saudi Arabia