Kaitier LLC
How Kaitier collects, uses, stores, and protects personal information.
Last updated August 7, 2026
Kaitier LLC ("Kaitier," "we," "our," or "us") is committed to protecting your privacy and handling your information responsibly. This Privacy Policy explains what information we collect, how we use it, how we protect it, and the choices available to you.
By using Kaitier, you agree to the practices described in this Privacy Policy.
Kaitier LLC develops software that helps individuals and businesses organize receipts, track expenses, reconcile financial transactions, and prepare financial records for accounting and tax purposes.
Contact: privacy@kaitier.com · support@kaitier.com · https://kaitier.com
Depending on the features you choose to use, Kaitier may collect account information (name, email, encrypted password credentials, preferences); receipt information (images, PDFs, OCR text, merchants, amounts, dates, categories, notes, tags, workflow status); email integration data when you connect Gmail or Outlook (message metadata, message bodies, and attachments needed to detect and import receipts — not unrelated mailbox content retained as a general email archive); financial account information via Plaid when you connect (account identifiers, names, transaction history — not your banking login credentials); and device information (browser, device, OS, IP, logs, diagnostics).
You may disconnect email or bank integrations at any time through Kaitier settings.
We use your information to organize receipts; categorize expenses; build ledgers; match receipts with bank transactions; generate reports and tax summaries; improve recognition and duplicate detection; provide support; protect against fraud and abuse; and improve product performance.
Kaitier uses automated processing — including on-server optical character recognition (OCR), pattern matching, and rule-based parsing — to extract fields from uploaded receipts and many email attachments. Standard receipt OCR and inbox receipt detection do not send receipt images or ordinary inbox message content to OpenAI or other generative AI providers.
Some optional features may send information to a configured AI provider — for example, when you use Ask Kaitier or when Kaitier uses AI as a fallback to read certain bank-statement PDFs. See our AI & Automation Disclosure for details.
You remain responsible for reviewing financial information before relying on it for tax or accounting purposes.
If you connect Gmail, Kaitier requests read-only access through Google OAuth (gmail.readonly) to scan for receipt-related messages and attachments you authorize Kaitier to process. Kaitier uses this access to list and read messages needed for receipt detection, import receipts into your Kaitier account, and maintain connection status.
Kaitier's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertisements, sell data, or train generalized AI/ML models unrelated to providing or improving user-facing Kaitier features you request.
You may disconnect Gmail in Kaitier, which stops future Kaitier access through that integration and deletes Kaitier's stored OAuth tokens. OAuth tokens used for Gmail access are stored encrypted when KAITIER_DATA_KEY is configured. When you disconnect Gmail, Kaitier also attempts to revoke the Google access token at Google's revoke endpoint. Previously imported receipts may remain in your account according to our Data Retention & Deletion Policy until you delete them or delete your account. You may also remove Kaitier under Google Account → Security → Third-party access.
If you connect Outlook or Microsoft 365 mail through Microsoft OAuth, Kaitier requests delegated Mail.Read access (with standard OpenID profile/email scopes) to scan for receipt-related messages and attachments. Microsoft may also present its own privacy notice during authorization.
Some work or school organizations require administrator approval before you can grant Mail.Read to third-party applications. If your tenant blocks user consent, contact your IT administrator or use a personal Microsoft account where permitted.
You may disconnect Outlook in Kaitier, which stops future Kaitier access through that integration. Previously imported records may remain according to our retention policy. You may also remove Kaitier from your Microsoft account permissions.
Kaitier uses service providers to operate the Service and to support optional integrations you enable. Current providers, roles, and scopes are listed on our Subprocessor List. Some providers — including Google, Microsoft, Plaid, Stripe, and Square — may also process information under their own terms when you connect them directly.
Production application hosting is currently operated on Kaitier-controlled self-hosted infrastructure as described in deployment documentation. Render Services, Inc. is used for Kaitier's non-production staging environment only unless a future public list entry states otherwise. Kaitier does not list Amazon Web Services as a direct subprocessor solely because another vendor uses AWS infrastructure.
Kaitier does not sell customer information. We may disclose information with your authorization; to service providers working on our behalf under contractual protections; to comply with law; to investigate fraud or security incidents; or in connection with a merger, acquisition, or sale of business assets.
We maintain administrative, technical, and organizational safeguards, including authentication and role-based access controls, HTTPS/TLS in production, OAuth for supported integrations, encrypted storage for integration tokens when configured, administrative access restrictions, and information security policies. No system can guarantee absolute protection.
We retain information only as long as necessary to provide services, comply with legal obligations, resolve disputes, and enforce agreements. You may delete receipts and uploaded documents through application features where supported. See our Data Retention & Deletion Policy for more detail.
When you permanently delete your Kaitier account, Kaitier removes your active account data, connected inbox credentials, and user-owned records from the active service. Disconnecting Gmail removes the stored connection and attempts to revoke Kaitier's Google authorization, but it does not automatically delete receipts already imported into Kaitier.
Deletion removes data from Kaitier's active service. It does not purge every copy that may exist in separate operator-maintained backups, if any are configured for your deployment environment. Those backups, where present, are governed by internal operations procedures and are not used to reactivate individually deleted accounts except when legally required or during disaster recovery affecting the service as a whole.
You may update account information; disconnect Gmail, Outlook, or Plaid; delete receipts and uploads; export certain records where supported; request account deletion at /account/delete; and contact us with privacy questions at privacy@kaitier.com.
Kaitier is not intended for children under 13. We do not knowingly collect personal information from children.
If you access Kaitier outside the United States, you acknowledge that information may be processed in the United States or other jurisdictions where our service providers operate, as described in our Subprocessor List and provider terms. Where applicable, we rely on contractual safeguards and provider terms for cross-border processing.
California residents may have rights under applicable law, including access, deletion, correction, and information about categories of data collected. Contact privacy@kaitier.com.
We may update this Privacy Policy periodically. Material changes will be communicated through the application or our website. The effective date above reflects the latest revision.
Privacy: privacy@kaitier.com · Security: security@kaitier.com · Support: support@kaitier.com
© 2026 Kaitier LLC. All rights reserved.
Questions? privacy@kaitier.com