Skip to content

Privacy notice

Your data, in short

Updated 9 Oct 2026

Who runs Kvita

Kvita is run by Błażej Kuśmirek (Wrocław, Poland), who is responsible for your data (the data controller). Any question about your data:

privacy@kvita.app

What we keep, and why

  • Your name and email: to sign you in and show friends who you are.
  • Payment details you add, like a bank account or BLIK number: so friends can pay you.
  • What you and your friends record: subscriptions, payments, adjustments and their history, kept as your shared record.
  • Your settings and devices: language, region, time zone, and the devices you turn notifications on for.
  • Sign-in and security data: the IP address and browser of each device you’re signed in on, and a log of sign-ins, to keep your account safe.
  • If you sign in with Google, we get your name, email address, profile picture and Google account ID from Google, only to sign you in and as your starting name in Kvita, which you can change.
  • If a friend adds you before you join, we keep the name they added you under and what they record with you, as part of their shared history (their legitimate interest, GDPR art. 6(1)(f)), for as long as that history is kept. To object to this, email privacy@kvita.app.
  • Why we’re allowed to: to run Kvita for you (GDPR art. 6(1)(b)); error reports, logs and backups keep it working and secure (our legitimate interest, art. 6(1)(f)).

No ads, and we never sell data.

Who sees it

Only people you share a subscription with, and only what you share with them. Anyone you send an invite link to sees what that invite shows.

Who else is involved

These companies work for us, only on our instructions:

  • Vercel: hosting
  • Supabase: database and sign-in
  • Amazon Web Services: sending and receiving emails, and encrypted backups
  • Sentry: error reports and page-speed data
  • GitHub: runs our nightly backup job

Also involved, under their own terms:

  • Google, only if you sign in with Google or email us, as our inbox is with Gmail
  • Your browser’s push service, if you turn on notifications: they’re encrypted, so it can’t read them

Where data is kept

Our database, backups and error reports are on servers in the EU (Frankfurt).

Some data may leave the EU: to Google if you sign in with Google or email us, to your browser’s push service, to GitHub while the nightly backup runs, and to Vercel, which serves pages from near you. Amazon Web Services, Supabase and Sentry have data processing agreements with us that protect it with the EU’s standard contractual clauses; we’ll have the same with the others before Kvita opens to everyone.

Kvita uses only the cookies it needs to work, such as keeping you signed in and remembering your language.

How long we keep data

  • Your account and records: until you delete your account. A device’s sign-in data goes when you sign out there. After you delete your account, friends keep your shared history, under the name they already see.
  • Backups: each is kept for 30 days and then deleted, so data from a deleted account is gone from them within 35 days.
  • Error reports, the sign-in log and other logs: for at most 30 days.
  • Emails you send us: for as long as we need them to answer you.

What you can do

  • Get a copy, in a format another service can read (data portability): email privacy@kvita.app from the address you sign in with. You’ll have it within a month.
  • Delete your account at any time in Profile › Account.
  • Correct your data: change your name and payment details in Profile › Details and payment methods; for anything else, email privacy@kvita.app.
  • Limit or object: you can ask us to limit how we use your data, or object to it.
  • Complain to the Polish data protection office (UODO).
Email privacy@kvita.app

The full privacy policy and terms of use will be published before Kvita opens to everyone.