Privacy policy
Last updated: 4 October 2026 · Türkçe
Kasa is an income and expense ledger for small businesses. This page says what data Kasa stores, how it gets it, what it is used for, how long it is kept and how you delete it. The data controller is Kaan Amanvermez, reachable at kuratowskiapp+kasa@gmail.com.
What we collect
- Your account. If you sign up on kasa.kuratowski.app: your email address, your password stored only as a bcrypt hash, and your business name. If you open Kasa inside the Kuratowski marketplace: a pseudonymous ID the marketplace creates for Kasa only, and the business name you type. The marketplace does not give us your name or email.
- Your ledger. The entries you record: amount, income or expense, date, category and the description you write. Your recurring entries (rent, salaries and so on) and their schedule.
- Records sent by your integrations. When your online store calls your private integration address, we keep the order total, the payment date and the order number. The store's request also contains customer details and order lines; we do not store them. When a marketplace connection sends payments to Kasa, we keep the payment ID, direction, amount, currency and date. When it sends sale documents, we keep the document number, type, total, currency, date and payment status; the document lines arrive but are not stored. Kasa does not ask connections for customer details or notes, so it does not receive them.
- Technical records. Sign-in sessions (stored as hashes, expire after 30 days), a summary of each delivery from your integrations (how many records were written or rejected and why), and server error logs kept by our hosting provider.
We do not use analytics, advertising or tracking tools. Kasa loads no third-party scripts or fonts. On the website a single session cookie keeps you signed in; inside the marketplace no cookie is set.
How we collect it
- What you type into Kasa.
- What your online store or your own system sends to the integration address shown in Kasa. You can change that address at any time, and the old one stops working at once.
- What a marketplace connection you created sends to Kasa. You choose which apps connect; deleting the connection stops it.
Excel and CSV exports are generated when you ask for them and are not stored on our side. Descriptions are left out of exports unless you tick “Açıklamaları da ekle”.
What we use it for
Only to run your ledger: showing your entries and monthly totals, writing recurring entries on their due date, recording sales your integrations send and producing your exports. We do not sell your data, use it for advertising, combine it across users, share it with anyone you did not connect it to, or use it to train models. Our hosting provider, Railway, stores and processes the data on our behalf; its servers may be located outside Türkiye.
Sending your entries to other apps you connect
If, in the Kuratowski marketplace, you connect Kasa's "Ledger entries" output to another app, Kasa sends your income and expense entries to that app through the marketplace: first the existing entries, then every new or corrected entry. Each entry goes as a payment with its amount, income or expense, date, category and an entry number. The description goes only if you allowed that field on the connection. Entries you mark "Öteki uygulamalarla paylaşma" are not delivered. Entries that came into Kasa through another app's payments are not sent back out. The app you connect becomes responsible for what it receives; read its privacy policy. Deleting the connection stops the flow. Entries already delivered stay in the other app: marking or deleting them in Kasa later does not recall them.
How long we keep it
- Your ledger is kept until you delete it.
- A ledger opened through the marketplace that has not been opened or received a delivery for 24 months is deleted automatically. The marketplace does not tell us when you uninstall Kasa, so this rule exists to avoid keeping data forever.
- Sessions expire after 30 days, summaries of incoming deliveries after 90 days, and records of outgoing deliveries after 30 days.
- Deleted data leaves database backups when those backups expire, within 30 days.
Deleting your data and your other rights
Open Kasa, go to Ayarlar → Hesabı sil. Your entries, recurring entries and integration address are deleted immediately. Export the months you need first. You can also write to kuratowskiapp+kasa@gmail.com to ask for a copy of your data, a correction or deletion; we answer within 30 days. Under the Turkish Personal Data Protection Law (KVKK) you also have the right to learn whether your data is processed and to object to processing.
Changes
If this policy changes, the date at the top changes and the new text applies from that date.