Privacy Policy
Last updated: 12 April 2026
Karui ("we", "us", or "our") is a Singapore-focused financial planning tool available at karui.sg. This Privacy Policy explains how we collect, use, store, share, and delete your personal data — including data received through third-party authentication providers — when you use our service ("the Service").
1. Data We Collect
a) Account Data
When you sign in using a third-party authentication provider (e.g., Google), we receive and store:
- Email address — to identify your account.
- Display name and profile picture — to personalise your experience.
We do not access your contacts, files, calendar, email content, or any data from other services connected to your authentication provider. We do not request any sensitive or restricted API scopes.
b) Financial Data
When you use the Service, you voluntarily enter financial information including but not limited to income, expenses, savings, CPF balances, property details, and investment holdings. This data is stored to generate your financial plan.
c) Usage Data
We collect basic, anonymised usage data such as page views and feature usage through Vercel Analytics to maintain and improve the Service. This analytics service is privacy-friendly, does not use cookies, does not collect personally identifiable information, and is compliant with GDPR and PDPA. We do not use advertising trackers.
2. How We Use Your Data
Your data is used solely for:
- Providing the Service: Generating financial projections, calculations, and AI-powered informational content based on your inputs.
- Authentication: Identifying you and securing access to your saved plans.
- Service improvement: Fixing bugs, improving performance, and enhancing features.
- Communication: Responding to your support requests.
Your data is never used for advertising, profiling, marketing, credit scoring, or any purpose unrelated to providing the Service.
3. Data Sharing
We do not sell, rent, lease, or trade your personal data or financial information to any third party.
Your data may be processed by trusted infrastructure providers that we use to operate the Service, including:
- Authentication and database provider — stores your account credentials and financial plan data as a data processor on our behalf.
- Hosting provider — serves the application and may process server logs containing your IP address as part of normal web hosting operations.
- AI provider — when you use the AI Coach feature, your financial plan data (not your authentication account data) is sent to an AI service provider to generate personalised informational content. This provider does not use your data for model training.
All service providers are bound by their respective data processing agreements. We will not share your data with any other third parties unless required by applicable law, regulation, or court order, or with your explicit prior consent.
4. Data Security
We implement the following security measures:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted via TLS/HTTPS.
- Encryption at rest: Your data is stored in a managed database with encryption at rest enabled.
- Access control: Row-level security policies ensure you can only access your own data. No user can view, modify, or delete another user's information.
- Credential security: Authentication tokens are managed by our authentication provider and are not stored in browser local storage by Karui.
While we take reasonable measures to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
5. Data Retention and Deletion
We retain your data for as long as your account is active and as necessary to provide the Service. You may:
- Export your data: Download your financial plan from the Settings page at any time.
- Delete your data: Use the "Delete All Data" option in Settings, or email support@karui.sg to request full account deletion. We will process deletion requests within 30 days.
- Revoke third-party access: You can revoke Karui's access to your authentication provider at any time through your provider's permissions settings. This prevents future sign-ins but does not automatically delete your stored data.
Upon account deletion, all personal data, financial plans, and AI interaction history are permanently removed from our systems within 30 days. Aggregated, anonymised data that cannot be used to identify you may be retained for analytical purposes.
6. Google API Services Disclosure
Karui's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. Cookies
Karui uses only essential, first-party cookies required for authentication and session management. We do not use analytics, advertising, or third-party tracking cookies.
8. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 18, we will delete it promptly.
9. International Data Transfers
Your data may be processed and stored in data centres located outside of Singapore. By using the Service, you consent to the transfer of your data to these locations. We ensure that any such transfers comply with applicable data protection requirements.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Your continued use of the Service after any changes constitutes acceptance of the revised policy.
11. Contact Us
If you have questions or concerns about this Privacy Policy or your personal data, contact us at: support@karui.sg