PRIVACY POLICY

Last updated August 22, 2026

This Privacy Policy describes how we collect, use, store, and share your personal data when you use our website at https://www.kontu.io and any related services (collectively, the 'Services').

Please read this Privacy Policy carefully. By using the Services, you acknowledge that you have read and understood this Privacy Policy.

TABLE OF CONTENTS

  1. WHO WE ARE
  2. WHAT DATA WE COLLECT
  3. HOW WE COLLECT YOUR DATA
  4. DATA ABOUT OTHER PEOPLE, AND WHAT OTHERS SEE ABOUT YOU
  5. WHY WE PROCESS YOUR DATA
  6. WHO WE SHARE YOUR DATA WITH
  7. INTERNATIONAL DATA TRANSFERS
  8. HOW LONG WE KEEP YOUR DATA
  9. COOKIES, USAGE DATA, AND SESSION RECORDING
  10. HOW WE PROTECT YOUR DATA
  11. YOUR RIGHTS
  12. CHILDREN'S PRIVACY
  13. CHANGES TO THIS POLICY
  14. CONTACT US

1. WHO WE ARE

Kontu is operated by Andrey Mitko, a sole trader established in the United Kingdom, trading as Kontu ('we', 'us', or 'our'). We are the data controller for the personal data described in this Privacy Policy.

Our postal address is 4 Lewis Cubitt Walk, London, N1C 4EQ, United Kingdom, and you can reach us at [email protected].

We process personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where you are located in the European Economic Area, we also process your personal data under the EU General Data Protection Regulation (EU GDPR). References in this policy to a GDPR Article apply to whichever of the two regimes covers you.

2. WHAT DATA WE COLLECT

We collect the following categories of personal data:

Account data

When you create an account, we collect your email address, name, and a securely hashed version of your password. If you sign in using Google, we receive your name and email address from Google.

Payment data

Payments are processed by our third-party payment processor, Polar.sh. We do not collect or store your full card number or banking details. We create a customer record with Polar.sh containing your name and email address when you register, whether or not you go on to subscribe. Polar.sh may share with us limited information such as your billing name, email address, the last four digits of your card, and transaction history. Please refer to Polar.sh's own privacy policy for details on how they handle your payment data.

Financial planning data

You input financial information into the Services as part of using the planning features. This includes amounts of income and expenses, currencies, dates, and any free text you choose to enter, such as budget titles, allocation names, transaction descriptions, notes, and links. Because these fields are free text, they contain whatever you put in them. We ask that you do not enter data revealing your health, religious or philosophical beliefs, political opinions, trade union membership, sex life, sexual orientation, racial or ethnic origin, or biometric or genetic data, as we do not intend to process special category data.

Server and network logs

When you visit the Services, our hosting and network providers log your IP address, browser type and version, operating system, device type, referring URL, and the pages requested. We use these to keep the Services running and secure. They are not part of the choice described in the cookies section below.

Usage data

If you allow usage data, PostHog records the pages you open, what you click, form interactions, time spent on pages, and error reports, linked to an identifier stored on your device. If you do not allow it, none of this is collected.

Session recordings

If you allow session recording, we record sessions on the Services. A session recording is a replay of your visit that reconstructs the pages you saw and how you interacted with them, including clicks, scrolling, navigation, and text displayed on screen. Monetary amounts are masked and are not captured. Other text is captured, which means a recording of your visit can include budget titles, allocation names, transaction descriptions, notes, and the email addresses of people you share a budget with. We record only if you allow session recording, and you can change that at any time. See the 'COOKIES, USAGE DATA, AND SESSION RECORDING' section.

Communications data

If you contact us via email, we collect your email address and the contents of your message. We also record your marketing and notification preferences, and a history of when you changed them.

3. HOW WE COLLECT YOUR DATA

We collect data in the following ways:

4. DATA ABOUT OTHER PEOPLE, AND WHAT OTHERS SEE ABOUT YOU

The Services let you share a budget with other people, which means personal data moves between users as well as between you and us.

If you invite someone

When you invite someone to a budget, you give us their email address and we store it so we can send the invitation and record whether it was accepted. You are responsible for having a proper reason to share their address with us. We rely on our legitimate interest in operating a sharing feature that people ask for. You can withdraw an invitation at any time, and you can ask us to delete an invitation record by contacting us.

If you were invited

If someone invited you to a budget, we hold your email address because they gave it to us. You have the same rights over that data as any other person described in this policy, including the right to ask us to delete it. Contact us at [email protected] and we will remove the invitation.

What other members of a shared budget can see

When you are a member of a shared budget, every other member of that budget can see your name and your email address, along with all of the planning data in that budget. This is how the sharing feature works, and it is not something we can limit once you have joined a shared budget. If you do not want other members to see your email address, do not join a shared budget.

5. WHY WE PROCESS YOUR DATA

We must have a lawful basis for processing your personal data. The bases we rely on are:

Performance of a contract (Article 6(1)(b))

We process your account data, financial planning data, and payment data as necessary to provide the Services to you, manage your subscription, and fulfil our contractual obligations.

Legitimate interests (Article 6(1)(f))

We process server and network log data and invitation data for our legitimate interests in:

Where storing or reading information on your device is involved, the Privacy and Electronic Communications Regulations (PECR) apply on top of the lawful basis. See the 'COOKIES, USAGE DATA, AND SESSION RECORDING' section.

Consent (Article 6(1)(a))

We process usage data and session recordings only where you have given us consent to do so, and you can withdraw it at any time as described in the 'COOKIES, USAGE DATA, AND SESSION RECORDING' section. Withdrawing does not affect the lawfulness of anything we processed before you withdrew.

Where we send you marketing communications, we obtain your consent first and you may withdraw it at any time, either from your account settings or using the unsubscribe link in any marketing email.

Legal obligation (Article 6(1)(c))

We may process your data where necessary to comply with legal obligations, such as tax reporting requirements or responding to lawful requests from authorities.

We do not use your personal data to make decisions about you by automated means alone, and we do not use it to train machine learning or artificial intelligence models.

6. WHO WE SHARE YOUR DATA WITH

We do not sell your personal data. Besides other members of a shared budget, described above, we share your data with the following service providers who process it on our behalf:

Each of these providers processes your data on our behalf under the data processing terms that form part of our agreement with them. If we change the providers we use, we will update this policy and the 'Last updated' date above.

We may also disclose your data if required to do so by law, or if we believe in good faith that such action is necessary to comply with a legal obligation, protect our rights or safety, or investigate potential violations of our Terms of Service.

7. INTERNATIONAL DATA TRANSFERS

The Services are hosted in the United States. Our application servers run in the AWS US East (Northern Virginia) region and our database is hosted by PlanetScale in that same region. This means your account data and financial planning data are stored and processed in the United States. Polar.sh, Resend, and Cloudflare also process data outside the United Kingdom and the European Economic Area. PostHog processes data on its European Union cloud.

Where your data is transferred out of the United Kingdom or the European Economic Area, we rely on the following safeguards:

You can request a copy of the safeguards that apply to a particular transfer by contacting us at [email protected].

8. HOW LONG WE KEEP YOUR DATA

We retain your personal data only for as long as is necessary for the purposes set out in this Privacy Policy:

Backups are kept by our hosting providers for a limited period, so data you delete may persist in a backup for a short time after it disappears from the Services.

9. COOKIES, USAGE DATA, AND SESSION RECORDING

Cookies are small text files placed on your device. We also use browser storage, which works similarly. We use these for two purposes.

Strictly necessary cookies

These are essential for the Services to function and cannot be switched off. They include session cookies that keep you signed in and protect against cross-site request forgery. These do not require your consent under the Privacy and Electronic Communications Regulations (PECR).

Usage data and session recording

We use PostHog for usage data and session recording. PostHog stores an identifier in a cookie and in browser storage so that your activity can be linked across pages and visits. This covers pageviews, clicks and form interactions, error reports, and a replay of your visit as described in the 'Session recordings' section above. When you are signed in, this activity is associated with your account, and your email address and name are sent to PostHog. PostHog processes this on its European Union cloud.

These are not strictly necessary cookies, so we ask before any of them run. When you first visit, nothing is sent to PostHog and nothing is written to your device until you choose one of these:

If your browser sends a Do Not Track or Global Privacy Control signal, we point it out in the notice and still ask. Nothing runs unless you choose to allow it. We do not sell your information and we do not use cookies for advertising.

We remember your choice for 6 months, after which we ask again. You can change it at any time: on this website, use the 'Cookie choices' link in the footer. In the app, open Settings and use the Privacy section. Withdrawing is as easy as giving consent, and it takes effect immediately. It does not affect anything we collected while your consent was in place.

Stored whichever choice you make

We have to remember your answer even when the answer is no, so these are stored whichever option you pick. They are strictly necessary and do not need your consent.

  • kontu_consent_usage_dataCookie. 6 months.

    Remembers your choice about usage data.

  • kontu_consent_session_recordingCookie. 6 months.

    Remembers your choice about session recording.

  • kontu_posthog_consentCookie. 6 months.

    PostHog's own copy of your usage data choice, so it can act on it.

Stored only if you allow usage data

  • ph_..._posthogCookie. 6 months.

    PostHog identifier that links your activity across pages and visits.

  • ph_..._posthogBrowser storage. Until you clear your browser storage.

    The same identifier, plus the current session and the pages seen in it.

  • ph_..._window_idBrowser storage. Until you close the tab.

    Tells one browser tab apart from another within the same visit.

Managing cookies in your browser

Most web browsers allow you to control cookies through their settings. You can set your browser to refuse all cookies or to indicate when a cookie is being sent. If you block strictly necessary cookies, you will not be able to sign in and parts of the Services will not work.

10. HOW WE PROTECT YOUR DATA

We take appropriate technical and organisational measures to protect your personal data. Traffic to and from the Services is encrypted in transit. Data is encrypted at rest by our hosting providers. Passwords are stored only as a secure hash, never in a form we can read. Access to production systems is restricted and protected by multi-factor authentication.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office, or the relevant European supervisory authority, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to you, we will tell you as well, without undue delay.

11. YOUR RIGHTS

You have the following rights in relation to your personal data:

To exercise any of these rights, please contact us at [email protected]. We may ask you for information to confirm your identity before we act, so that we do not disclose your data to someone else. We will respond within one month. If your request is complex or you have made several, we may extend that by a further two months, and we will tell you within the first month if we do. Exercising these rights is free. If we decide not to act on your request, we will tell you why, and we will tell you how to complain.

If you are not satisfied with how we handle your request, you have the right to lodge a complaint with a supervisory authority. In the United Kingdom, this is the Information Commissioner's Office (ICO), which you can contact at ico.org.uk or by telephone on 0303 123 1113. If you are in the European Economic Area, you can complain to the supervisory authority in the country where you live, where you work, or where the issue arose.

12. CHILDREN'S PRIVACY

The Services are intended for people aged 18 and over, and our Terms of Service require you to be 18 to hold an account. The Services are not directed at children, and we do not knowingly collect personal data from anyone under 18. If you are a parent or guardian and believe a child has provided us with personal data, please contact us at [email protected] and we will delete the account and the data associated with it.

13. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. We will update the 'Last updated' date at the top of this page whenever we do. If a change materially affects how we use your personal data, or introduces a new provider that receives it, we will tell you by email before the change takes effect.

14. CONTACT US

If you have any questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact us at:

Andrey Mitko, trading as Kontu
Data Controller
4 Lewis Cubitt Walk
London, N1C 4EQ
United Kingdom
[email protected]