Privacy Policy

Last updated: April 15, 2026

This Privacy Policy describes how Kulta ("we," "us," or "our") collects, uses, and protects your information when you use our property accounting service. Kulta is a bookkeeping and financial management tool for real estate investors.

Information We Collect

Account Information

  • Email address
  • Name
  • Authentication credentials (managed securely by our auth provider)

Financial Data via Bank Connections

When you connect your bank accounts through Plaid or Teller, we access the following data:

  • Account information: Account name, type, and masked account numbers
  • Balance information: Current and available balances
  • Transaction data: Transaction history including dates, amounts, descriptions, and merchant information
  • Institution information: Bank name and connection status

We do not collect or store your bank login credentials. Authentication is handled securely by Plaid or Teller. By connecting your accounts, you agree to Plaid's End User Privacy Policy or Teller's Privacy Policy.

Property & Financial Records

  • Property information you enter (addresses, values, purchase details)
  • Loan and mortgage details
  • Expense categorizations and journal entries
  • Uploaded receipts and documents

Usage Data

  • IP address and device information
  • Browser type and version
  • Pages visited and features used
  • Access times and session duration

How We Use Your Information

  • To provide and maintain the Kulta service
  • To sync and display your bank transactions
  • To categorize transactions using AI assistance
  • To generate financial reports (P&L, Balance Sheet, Cash Flow)
  • To send transactional notifications (e.g., pending transactions, security alerts)
  • To comply with legal and tax record-keeping obligations
  • To improve and optimize the service

We do not sell your data. We do not use your financial data for advertising or marketing purposes.

Third-Party Service Providers

We share data with the following service providers solely to operate the service:

Plaid Technologies, Inc.bank account connectivity and transaction data. Privacy policy
Teller, Inc.bank account connectivity and transaction data. Privacy policy
Neon, Inc.database hosting. Privacy policy
Vercel, Inc.application hosting, deployment, and authentication. Privacy policy
Anthropic, PBCAI-powered transaction categorization. Privacy policy
Resend, Inc.transactional email delivery. Privacy policy

Each provider is bound by their own privacy policies and data processing agreements. We do not share your data with any other third parties except as required by law.

Data Retention

  • Financial records: Retained for 7 years to comply with IRS tax record requirements
  • Account information: Retained while your account is active, plus 24 months after deletion
  • Server logs: Retained for up to 12 months for security and troubleshooting
  • Bank access tokens: Plaid and Teller access tokens are retained until you disconnect your bank account or delete your account

Your Rights & Choices

Disconnect Bank Accounts

You can disconnect your bank accounts at any time from Settings. This revokes Kulta's access to your financial institution and deletes the associated access token.

Request Data Deletion

You may request deletion of your personal data by contacting us at support@kulta.app. Upon request, we will:

  • Delete your account and profile information
  • Revoke all bank access tokens (Plaid and Teller)
  • Remove transaction data not required for legal retention

Note: Financial records required by law (7-year IRS retention) may be retained in accordance with legal obligations.

Access Your Data

You can export your financial data at any time from the Reports section of Kulta.

Security

We implement industry-standard security measures to protect your data:

  • All data in transit is encrypted using TLS 1.2 or higher
  • Bank access tokens and sensitive PII are encrypted at rest using AES-256
  • Database access is protected with secure connection pooling
  • Secure session management and authentication via Vercel Auth
  • Regular security monitoring and logging

California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request what personal information we collect, use, and disclose
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: We do not sell personal information, so this right does not apply
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights

To exercise these rights, contact us at support@kulta.app. We will respond within 45 days as required by law.

Children's Privacy

Kulta is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and update the "Last updated" date at the top of this page. Your continued use of Kulta after changes constitutes acceptance of the updated policy.

Contact

For questions about this Privacy Policy or to exercise your data rights:
Email: support@kulta.app