Privacy
What we collect, what we do not, and what you can take back. Written from what the software actually does, not from a template.
Last updated
The short version
Our apps are local-first. What you enter — a budget in Lunas, a set of books in Arus — lives on your device, and only reaches our servers if you choose to sign in so it can follow you between devices.
We never ask for your online banking credentials. That is a commitment, not a current limitation — there is nothing to hand over, so there is nothing for us to lose.
We do not sell your data or pass it to data brokers, and we do not build a profile of you from it.
Who we are
KapiX builds KapiX Learning, Lunas and Arus, and is the data controller for the information described here.
For anything in this policy, write to hello@kapix.io. A person reads it.
What we collect
It depends entirely on whether you sign in.
Used without an account, the apps store everything in your browser and send us nothing. No account, no server copy, and no way for us to see your figures — the trade is that the data lives on that one device only.
If you create an account, we hold the following:
- Your email address, and your name and profile picture if you signed in with Google. That is what the sign-in provider gives us, and we ask for nothing beyond it.
- What you enter into the apps — in Lunas, your income, bills, savings goals, balances and transactions; in Arus, your business's journal entries. This is the data the apps exist to hold, and it is stored so it can reach your other devices.
- Session records, so you stay signed in. A session is a row in our database rather than a token, which is why signing out takes effect everywhere at once.
- Push notification subscriptions, but only if you turn expense reminders on.
- Short-lived rate-limiting counters keyed to your email address or user id, which stop the sign-in form being used to mail strangers.
What we do not collect
Some of this is worth stating explicitly, because other money apps do it.
- Banking credentials. None of our software asks for them, and none of it has any facility to use them.
- Bank or card account numbers. You tell the app what happened; it does not read your accounts.
- Your location.
- Your contacts, photos, files or anything else on your device outside the app.
How we use it
To run the products, and for nothing else. Concretely: to sign you in, to keep your data in step across your devices, to send the reminders you asked for, and to protect the service from abuse.
We do not use your financial data to train machine learning models, and we do not profile you, score you, or pass anything to a credit reference agency or a data broker.
Who else touches it
We use a small number of service providers to run the product. Each one is named here, along with what it actually sees:
- Vercel — hosting. Serves the site and the app, and processes request metadata such as IP address in the ordinary course of serving a web request.
- Vercel Web Analytics — page view counts on this marketing site only. It is cookieless and does not track you between sites or build a profile. It does not run inside the apps.
- Neon — the Postgres database that holds accounts, sessions and budget documents.
- Google — only if you choose to sign in with Google, and only to confirm who you are.
- Resend — sends the one-time sign-in links. It sees the address the link goes to.
- Exchange rate data (open.er-api.com) — when you record spending in a foreign currency, we look up a rate. The request contains a currency code and nothing else: no amount, no account, no identifier. You can turn this off in settings.
- Push delivery services operated by Apple, Google and Mozilla, if you enable reminders. They carry the notification, and a reminder never contains your figures.
Where it is held, and for how long
Data is held on servers operated by the providers above, which may be outside your country. Where a transfer leaves a jurisdiction with data transfer rules, it relies on the provider's standard contractual protections.
We keep your account data for as long as the account exists. We do not operate a separate archive, and we do not keep a shadow copy of a deleted account.
Sessions expire after 30 days without use. Rate-limiting counters are transient and measured in minutes. Deleting your account removes the user record, and sessions, linked sign-in providers and the budget document are removed with it automatically.
What you can do about it
These are built into the app rather than being a request you have to make and wait on:
- Export — download everything held for your account as a JSON file, from within the app. Not a summary: the actual stored document.
- Deletion — delete your account from within the app. It is immediate and it cascades, so nothing is left orphaned. It is not reversible.
- Correction — every figure you have entered is editable by you, directly, at any time.
- Withdrawing consent — turn reminders off, turn exchange rate lookups off, or stop using the account entirely and delete it.
How it is protected
In outline: there are no passwords anywhere, because sign-in is Google OAuth or a one-time emailed link — there is nothing to reuse, leak or phish a reset for. Sessions are database rows rather than tokens, so revoking one is immediate everywhere. Session cookies are Secure, HttpOnly and SameSite in production.
Every database query that touches user data takes a user id from the verified session as its first argument. No endpoint accepts a user id from a URL, header or request body. User ids are UUIDs rather than sequential numbers, so they cannot be guessed or walked.
No system is perfectly secure, and we would rather say so than imply otherwise. If you find a problem, please write to us before disclosing it publicly.
Children
Lunas is not directed at children, and we do not knowingly collect data from anyone under 13. If you believe a child has created an account, write to us and we will remove it.
Changes to this policy
If this policy changes in a way that materially affects you, we will say so in the app rather than quietly editing this page and relying on the date at the top. The date at the top still tells you when it last changed.
Contact and complaints
Write to hello@kapix.io about anything here, including a request to exercise a right that the in-app tools do not already cover.
This policy is governed by the laws of Brunei Darussalam.
If you are in a jurisdiction with a data protection authority and we have not resolved your concern between us, you have the right to complain to it.

