Kaitier LLC
What we retain, how long we keep it, and how deletion requests work.
Last updated August 7, 2026
Version: 1.3 · Effective date: August 7, 2026 · Owner: Joseph Omara, Founder & Managing Member
Review frequency: Annually, or upon significant changes to applicable laws, infrastructure, or business operations.
This Data Retention and Deletion Policy defines how Kaitier LLC ("Kaitier") collects, retains, archives, and securely deletes customer information. The policy is intended to protect customer privacy, support legitimate business operations, comply with applicable legal obligations, and minimize unnecessary data retention.
This policy applies to all information collected, processed, or stored by Kaitier, including user account information; uploaded receipts; OCR extracted receipt data; email-imported receipts; bank transaction data; expense categories; manual income entries; notes and tags; customer support communications; authentication records; application logs; and backup data.
Kaitier collects only the information necessary to provide requested services.
Information is retained only for legitimate business purposes, customer-requested functionality, legal obligations, fraud prevention, security investigations, or system recovery.
Kaitier does not intentionally retain unnecessary personal information.
User accounts: Account information is retained while an account remains active. Users may delete their account at any time through Account settings.
Receipts: Receipts uploaded or imported through authorized email integrations remain available until deleted by the user or until the user's account is permanently deleted.
Bank transactions: Transaction data imported through authorized financial integrations (including Plaid) is retained while the user's account remains active or until the user disconnects the financial account and deletes their account.
Email integration data: Receipt-related email data processed through Gmail or Microsoft Outlook integrations is retained only as necessary to provide receipt management services. Gmail and Outlook OAuth tokens are stored while a connection remains active and are deleted when the user disconnects the integration or deletes their account; Kaitier attempts Google token revocation on Gmail disconnect and account deletion. Users may disconnect integrations at any time.
Support communications: Customer support emails and support requests may be retained for up to 24 months following resolution for customer service, fraud prevention, and legal compliance.
Security logs: Authentication logs, administrative actions, and security-related events may be retained for up to 12 months to support incident response, security monitoring, and abuse prevention.
Operator-maintained backups: Where configured for a deployment environment, Kaitier may maintain separate backup copies under internal operations procedures. Backup retention periods and encryption vary by environment. Production Windows deployments currently use timestamped local backups with automated pruning (default 14 days per `ops/backup.ps1`). Render staging uses a persistent application disk; scheduled backup jobs are not defined in the staging deployment blueprint.
Users may permanently delete their Kaitier account from Account settings. Account deletion requires password confirmation and deliberate confirmation text.
When you permanently delete your Kaitier account, Kaitier removes your active account data, connected inbox credentials, and user-owned records from the active service. Disconnecting Gmail removes the stored connection and attempts to revoke Kaitier's Google authorization, but it does not automatically delete receipts already imported into Kaitier.
Confirmed account deletion is processed immediately on the active service. Kaitier does not maintain a separate 30-day soft-delete queue for deleted accounts.
Deletion removes data from Kaitier's active service. It does not purge every copy that may exist in separate operator-maintained backups, if any are configured for your deployment environment. Those backups are not used to reactivate individually deleted accounts except when legally required or during disaster recovery affecting the service as a whole.
Upon confirmed account deletion, personal information is removed from active production systems and user-owned files are removed from active application storage paths. Residual copies in operator-maintained backups, if any, expire according to the backup procedures for that environment.
Certain information may be retained beyond normal retention periods when required to comply with legal obligations; resolve disputes; prevent fraud; enforce agreements; or respond to lawful government requests.
Only the minimum information necessary will be retained.
Users maintain control over their information through available application features, including deleting receipts; disconnecting integrations; updating account information; exporting available records where supported; and permanently deleting their account.
Where technically feasible, deletion requests on the active service are honored promptly after successful confirmation.
Retained information is protected through administrative, technical, and organizational safeguards appropriate to the sensitivity of the data.
These safeguards include authentication controls; role-based access restrictions; HTTPS/TLS encryption for production communications; administrative access controls; security monitoring; and periodic review of access permissions.
When Kaitier uses third-party providers (such as Google, Microsoft, Plaid, OpenAI, Resend, or cloud infrastructure providers), those providers may retain information according to their own documented retention policies.
Kaitier reviews third-party providers during service selection and limits data sharing to what is necessary to provide requested functionality.
This policy is reviewed at least annually, or sooner if there are significant infrastructure changes; new products or services; regulatory changes; security incidents; or material changes in data processing practices.
Updates are approved by Kaitier management before implementation.
Questions regarding this policy or requests concerning personal data: Privacy — privacy@kaitier.com · Security — security@kaitier.com · Support — support@kaitier.com
Approved by Joseph Omara, Founder & Managing Member, Kaitier LLC.
Effective date: August 7, 2026. © 2026 Kaitier LLC. All rights reserved.
Questions? privacy@kaitier.com