Juridisch
Privacy
Karet — Privacy Policy
Draft — review pending. This document is the working draft of the Karet privacy policy. The legally-binding version is the counsel-reviewed text that supersedes this draft before launch. Until the launch gate is satisfied, this file is informational only.
Effective date: TBD · Version: 0.1-draft · Maintainer: Founders, then DPO once appointed.
1. Who we are
Karet is operated by Karet Finance B.V. i.o. ("Karet", "we", "our"), registered in the Netherlands (KVK pending). You can reach our privacy team at privacy@karet.money.
2. What we collect
We collect only what we need to operate Karet:
- Account data — your name, email, password hash (we never see your password), and security state (2FA, passkeys, sessions).
- Workspace data — banks, brokers, journal entries, AI chat history, detector cards, documents you upload, voice memos.
- Operational telemetry — anonymous request logs, error reports, and (with consent) product analytics.
- Consent records — what you chose on the cookie banner and when.
We never sell your data. We never share it with advertisers. We never train an AI model on your data.
3. Why we collect it
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the Karet service | Contract |
| Sync your banks and brokers | Contract + your consent at the upstream provider |
| Send security alerts (new device, password change) | Legitimate interest |
| Send product emails (digest, watchers) | Your in-app consent (revocable) |
| Comply with bookkeeping retention law | Legal obligation |
| Product analytics | Your consent on the cookie banner |
4. How long we keep it
The full per-table policy is in
docs/security/retention.md. Highlights:
- Bank transactions, journal lines, broker activity — while your workspace exists; hard-deleted 30 days after you delete the workspace.
- AI chat history — kept while you keep it; deletable per-chat from Settings → Privacy & Data. Embeddings are deleted alongside.
- Voice memos and receipt photos — 90 days by default; tighter retention configurable per workspace.
- Security events — 24 months for breach forensics.
- AI prompt logs — anonymised after 30 days.
5. Where we keep it
All primary data is processed and stored in the EU (Frankfurt / Amsterdam). LLM endpoints route through providers under a documented EU-processing + zero-retention contract (see sub-processors and our public sub-processor page). We do not transfer your data outside the EEA.
6. Who we share it with
We share data only with the sub-processors listed at /legal/sub-processors. Each one has a DPA on file and processes data only on our documented instructions.
We never share your data with:
- Advertisers
- AI model trainers
- Data brokers
- Anyone outside the sub-processor list
7. Your rights
You have the right to:
- Access — export every byte we hold on you. Self-service via Settings → Privacy & Data → Export.
- Erasure — delete your account. Self-service via Settings → Privacy & Data → Delete. There is a 30-day grace window.
- Rectification — correct inaccurate data. Self-service in the app for most fields; mail us for the rest.
- Restrict / object — pause processing for a given purpose. Mail us.
- Portability — the export ZIP is machine-readable NDJSON / JSON.
- Withdraw consent — change cookie preferences any time via the banner; revoke email mirror via Settings → Notifications.
- Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) — autoriteitpersoonsgegevens.nl.
To exercise any of these, email privacy@karet.money or use the Settings → Privacy & Data surface.
8. AI Act disclosures
Karet uses AI to:
- Generate per-row commentary on bank transactions and trades.
- Produce daily Today briefs.
- Detect anomalies, latente claims, and other Cards.
- Power the right-rail assistant, the Ask Dock, and specialist sub-agents.
Every AI surface carries the disclosure pattern defined at /legal/ai-systems. AI output is an estimate, not professional financial or tax advice. You have the right to a human review — email privacy@karet.money with the AI output and we will respond within 10 working days.
9. Children
Karet is not directed at users under 16. We do not knowingly collect data from anyone under 16.
10. Changes to this policy
We will notify you by email at least 30 days before any material change to this policy.
11. Contact
- Privacy: privacy@karet.money
- Security: security@karet.money (PGP key at
/.well-known/security.txt) - General: jeff@karet.money