CapKin

Privacy Policy

Effective date: July 22, 2026. CapKin is a shared household budgeting app. This policy explains what data we collect, why, and what you can do about it. We have tried to keep it short and plain — there is no data we collect that is not listed here.

The short version

  • We collect only what the app needs to work: your account details and the budget data your household enters.
  • We never connect to your bank. There are no bank credentials, transactions, or balances in CapKin — ever.
  • Voice recordings are transcribed and immediately deleted. We do not store audio, and we have no audio database.
  • We do not sell your data, and we do not show ads.
  • You can export your data or delete your account at any time.

What we collect

Account data. Your email address, a password (stored only as a hash) or your Google/Apple sign-in, and your language/locale setting.

Household data. What your household sets up and enters in the app: household name, timezone, currency, budget caps, categories, expenses, income entries, bills, savings goals, and the display names of household members. This data exists only because a member of your household typed or spoke it in.

Kids' learning activity. If your household uses the kids features, we store the child's entries, savings goals, and activity in the built-in lessons and quizzes. See "Children" below.

Notifications. If you turn on push notifications, we store the browser subscription needed to deliver them. Push is off by default. Email notifications can be switched off in settings.

Cookies. We use cookies only to keep you signed in. No advertising or cross-site tracking cookies.

What we do not collect. No bank or card credentials, no bank transactions, no location data, no contacts, no advertising identifiers. CapKin uses no analytics or tracking tools.

Voice input and audio

Voice entry is optional — everything you can do by voice you can also do by typing.

When you use voice input, your browser records audio and sends it to us for transcription. The audio is used for exactly one purpose: producing a text transcript that you see and can edit before anything is saved. The audio is held in memory only while transcription runs and is deleted as soon as it completes. It is never written to our database — there is no audio table. Only the text and the expense items you confirm are kept.

We do not use voice to identify anyone. No voiceprints are created or stored.

How we use your data

We use your data to run the app: showing your household its budget, totals, and history; sending the notifications you asked for; and keeping your account secure. That is the full list. We do not sell data, share it for advertising, or use it to build profiles.

AI processing

Transcription and expense parsing use the OpenAI API (Whisper for speech-to-text, a GPT model for splitting a sentence into expense items). Only the spoken/typed text and your household's category names are sent — never your credentials or unrelated personal data. We use OpenAI on an API tier where content is not retained by OpenAI and is not used to train its models.

Children

CapKin includes a "capture-only child" role designed for kids. Here is exactly how it works:

  • Only a parent can create a child account. A child account can only be created by the household owner — an adult who already has a CapKin account. The child cannot sign up on their own. We keep a record of when and by whom each child account was created.
  • What a child account stores: a display name, the expenses the child enters, their savings goals, and their activity in the built-in money lessons and quizzes. We do not ask children for their full name, age, address, or any other personal details.
  • Nothing a child enters counts until a parent approves it. Every child entry is saved as pending and reviewed by the household owner.
  • Voice input is off by default for children. Only the household owner can turn it on for a child, and this deletion policy is shown at that moment. When enabled, it works the same way as for adults: the audio is transcribed and immediately deleted, and no voiceprint is created. Voice never asks for personal information — it is only used to log expenses, as a substitute for typing.
  • No advertising. We show no ads to anyone, and we will never use children's data for advertising of any kind.
  • Parents stay in control. The household owner can review everything a child has entered, turn voice input off at any time, remove the child from the household, and export or delete the child's data (see "Your rights").

Questions about children's data: getcapkin@proton.me.

Who we share data with

We share data only with the services we need to run CapKin:

ServicePurpose
VercelHosting the app and website
OpenAISpeech-to-text and expense parsing (no data retention, no model training)

We will update this list before adding any new provider. We do not share data with anyone else, except if required by law.

Security

Data is encrypted in transit (TLS) and at rest. Each household's data is isolated by household ID on every query, and role checks (owner / member / child) are enforced on the server on every request.

Data retention

Your data is kept while your account is active. When a household is deleted, its data is deleted. Voice audio is deleted immediately after transcription, as described above.

Your rights

  • Export. You can export your household's data from the app.
  • Deletion. The household owner can delete the household and its data; deletion requires an explicit confirmation step. Individual members can leave a household.
  • Children's data. The household owner can review, export, and delete a child's data.
  • Questions and requests. Email getcapkin@proton.me and we will help.

Changes to this policy

If we change this policy, we will update the effective date and, for meaningful changes, tell you in the app.

Contact

getcapkin@proton.me