Privacy Policy
Last updated: August 22, 2026
What Kachink Is
Kachink is a personal finance tracker that runs as a remote MCP (Model Context Protocol) server. You interact with it through Claude or any MCP-compatible client to log transactions, view spending summaries, and manage recurring charges.
Data We Collect
When you sign in with Google, we store:
- Google account info, your name, email address, and Google user ID, used solely to identify your account.
- Transactions, amounts, currencies, categories, descriptions, and dates you provide when logging income or expenses.
- Recurring transactions, details of any recurring charges you set up.
- Preferences, your base currency setting.
- Custom categories, any spending categories you create, rename, or hide.
- Billing details, if you subscribe to Pro: your plan, subscription status, billing period, renewal date, and the customer ID assigned by our payment processor. We never see or store your card number.
Where Data Is Stored
All data is stored in Cloudflare D1, a serverless SQL database. Your finance records live in Cloudflare's infrastructure and are not copied anywhere else. The only exception is billing, which our payment processor handles separately, as described below.
Derived and Internal Data
To make the service work, we also store values we compute rather than ones you type: the equivalent amount in your base currency, and the exchange rate that applied on the transaction date. Each record additionally carries an internal identifier and created and updated timestamps, and every row is linked to your account by an internal user ID. Timestamps and internal user IDs never leave our database. The section below lists exactly what does.
What Kachink Sends Back to Your AI Client
Kachink runs inside Claude, ChatGPT, or another MCP client, so whatever a Kachink tool returns becomes visible to that assistant and to the company running it. These are the only categories we return:
- Transaction records, the type, amount, currency, category, description, and date you logged, plus the converted amount in your base currency.
- Record identifiers, the identifier of a transaction or recurring rule, returned when you list, edit, delete, or pause one so the assistant can act on the right record. These identifiers are random values that mean nothing outside your own account.
- Exchange rates, the rate we applied when converting a foreign-currency transaction into your base currency.
- Recurring transactions, the type, amount, currency, category, description, day of the month, and whether the rule is active or paused.
- Categories and summaries, your category list with the number of transactions in each, monthly income and expense totals, and category breakdowns.
- Plan and usage, your plan, how many transactions and recurring rules you have used this month, and the limits that apply to your plan.
Your name, email address, Google user ID, the customer ID from our payment processor, and your billing dates and subscription status are never returned to an AI client. Neither are created and updated timestamps, internal user IDs, or system logs. The in-chat export follows the same rule: it returns your transactions, recurring rules, custom categories, and base currency, and leaves your name and email out. The complete archive, including billing records and internal fields, is available on your account page, where you download it directly rather than through an AI client.
Third-Party Services
- Google OAuth, used for authentication only. We do not access your Google data beyond the basic profile (name, email).
- Frankfurter API, an open-source exchange rate API (frankfurter.app). When you log a transaction in a foreign currency, we fetch the exchange rate for that date. No personal data is sent to this API, only the currency pair and date.
- Google Analytics, used on the marketing site (kachink.app) to understand page views. Google Analytics does not run inside the MCP server or dashboard.
- Paddle, our payment processor and merchant of record (paddle.com). If you subscribe to Pro, Paddle handles the transaction and your payment details. Card numbers never reach Kachink's servers.
Who Receives Your Data
We do not sell or share your data. Four providers process it on our behalf, each limited to what its function requires:
- Cloudflare, hosting and database storage. Holds all of your Kachink data.
- Google, sign-in only. Receives nothing about your finances.
- Paddle, payments. Receives your billing details only if you subscribe to Pro.
- Frankfurter, exchange rates. Receives only a currency pair and a date, never an amount, a description, or anything identifying you.
How We Use Your Data
Your data is used exclusively to provide the Kachink service:
- Storing and retrieving your transactions
- Computing monthly summaries and category breakdowns
- Converting currencies at the exchange rate on the transaction date
- Auto-logging recurring transactions on their scheduled day
We do not sell, share, or monetize your data in any way. We do not train AI models on your data.
Data Retention
We keep your data until you delete your account. When you do, deletion is immediate and irreversible: your account row is removed and every associated record, transactions, recurring rules, custom categories, preferences, and billing records, is deleted along with it. Nothing is kept behind for later use.
Your Rights
Kachink provides built-in tools for exercising your data rights:
- Export your data, Use the "export my data" command to get a JSON copy of your transactions, recurring transactions, custom categories, and base currency. For a complete archive, including billing records and internal fields, use the export button on your account page.
- Delete your account, Use the "delete my account" command to permanently erase your account and all associated data. This action is irreversible.
Security
Authentication is handled via OAuth 2.0 with Google. MCP access tokens are encrypted and expire after 24 hours, with refresh tokens valid for 30 days. All communication happens over HTTPS.
Children
Kachink is not intended for use by anyone under the age of 13.
Changes to This Policy
If we make material changes to this policy, we will update the "Last updated" date at the top. Continued use of Kachink after changes constitutes acceptance of the updated policy.
Contact
If you have questions about this privacy policy, reach out at ahmad@kachink.app.