Kassento · Privacy

Privacy Policy

Last updated: 27 July 2026

Summary: Register, count, target-composition, local-staff-list, tip-split, custom-currency-definition, cash-movement, manual-terminal-reconciliation, note, history, and optional receipt-photo data is processed primarily on your device. An enabled iCloud/Finder device backup may include the database, preferences, and receipt photos. Android cloud backup includes the database and preferences but deliberately excludes receipt photos; direct Android device transfer may include them. A portable backup you create contains the complete Kassento database, existing photos, and selected preferences and is encrypted with your password. “Bank” and “safe” are local event labels only; terminal reconciliation compares only two manually entered aggregate totals. Kassento has no bank, POS, or terminal connection and collects no card, customer, or individual transaction data. Photos are stored without copied EXIF/GPS metadata. The device-specific reminder schedule and bounded redacted diagnostic log stay local and are not included in portable backups. Device and portable backups do not transfer a Pro purchase entitlement. The provider has no access to this content. Kassento has no user account, developer-operated app backend, advertising, or developer analytics. Apple or Google and RevenueCat process purchase data only for the optional Pro purchase.

This English version is provided for convenience; where legally permissible, the German version is authoritative.

1. Controller

2. Local app data

Kassento processes register names, built-in or custom versioned currency definitions, denominations and quantities, cash rolls/packages, expected balances and per-denomination target compositions, opening balance and source, completion results, tips, optional shift labels, notes, profiles, and people/approval/blind status. It may also process a local staff list with names and selection status and saved tip splits with names, shares, and amounts. Further data includes local cash movements with type, amount, optional destination/comment, confirmer, time, receipt/reversal reference and final closing confirmation, optional manual terminal reconciliations, receipt photos, and app preferences. This content is stored primarily in the app sandbox on the device. The provider has no access to it.

An optional manual terminal reconciliation stores only a local label, the user-entered expected aggregate POS total, the actual aggregate terminal settlement, the calculated difference, and an optional reason, comment, and timestamp. The card difference remains separate from the cash close. Kassento collects no card numbers, customer data, or individual transaction data for this feature.

“Bank”, “safe”, “drawer top-up”, and “tip withdrawal” are user-entered local events only. Terminal reconciliation is also a purely manual entry of aggregate totals. Kassento connects to no bank account, safe, POS, terminal, or payment system and confirms no external transfer or settlement. Corrections are stored as reversal events; the local event sequence is not a tamper-proof cash ledger or audit-certified accounting record.

A validated previous-version snapshot created before a database migration also remains inside the app sandbox and is automatically removed after three successfully validated cold launches. Temporary PDF and CSV files are stored in the app cache and removed after handoff or, at the latest, on the next app launch.

If you enabled the applicable device feature, the database and local preferences may be included in your iCloud/Finder backup, Android cloud backup, or direct device transfer. Processed receipt photos may be included in iCloud/Finder backups and direct Android device transfer. Android cloud backup deliberately excludes receipt photos because of the platform’s per-app 25 MB limit. An installation-specific guard discards a local Pro cache restored from a device backup; a valid purchase is unlocked again after the next online store check. Apple or Google processes the backup according to your account and device settings and its own privacy terms. The Kassento provider can neither read nor manage it.

Kassento Pro lets you deliberately create a portable backup file. Before opening the system share sheet, Kassento encrypts the complete database including custom currency definitions, target compositions, the staff list, tip splits, opening sources, cash movements, closing confirmations, and manual terminal reconciliations, existing receipt photos, and app preferences with a password you choose. You then select a destination such as Save to Files, iCloud Drive, or Google Drive. Kassento has no direct cloud-storage integration; the provider knows neither the password nor the destination. If the password is lost, the provider cannot recover the file. Restoring is available without Pro, replaces current local data after a content preview, and does not restore a store purchase entitlement. Older v2 backups remain readable and contain no photos.

With Pro, you may deliberately add at most one receipt photo to a completed count through the system camera or system photo picker. Android needs no app-declared camera, broad media, or storage permission for this; iOS opens the camera or photo library only after your source choice and displays a localised usage explanation. Kassento orients the image on-device, limits its longest edge to 2,048 pixels, and stores a newly encoded JPEG of no more than 1.5 MiB. It does not copy EXIF, GPS, camera, or other source metadata; all receipt photos together are limited to 256 MiB. A photo may be processed through an enabled iCloud/Finder device backup or direct Android device transfer; Android cloud backup does not include it. Beyond those paths, a photo leaves the device only after your explicit photo share or as part of a deliberately created portable backup. You can delete it individually, with the completion, or through Delete all local data; a persistent cleanup queue and launch reconciliation clean up interrupted file operations.

The live database is not additionally encrypted by the app; it is protected by the operating-system sandbox and device security. Temporary snapshot and restore working files are removed from the app cache after completion, cancellation, or failure. During a data restore, the app also keeps a recovery journal and a local rollback copy of the database, receipt photos, and preferences inside its sandbox. They are removed after a confirmed success or successful rollback; after process termination, the next app launch completes that cleanup. Only if recovery itself cannot finish because of a storage or file error is the copy retained for another launch. “Settings → Delete all local data” removes local user data, including receipt photos, the diagnostic log, and these recovery files, after two confirmation steps. Uninstalling the app or clearing app data also removes local data. Kassento cannot selectively delete device backups or portable backup files already stored outside the app; their further retention follows your settings and the applicable storage service.

For backup, receipt-photo, and reminder failures, Kassento keeps a bounded local diagnostic log. It stores no more than 200 events, 128 KiB, and 30 days, using only UTC time, fixed feature areas, fixed operations, and coarse error codes. There is no free-text field; register names, amounts, notes, file paths, passwords, photo content, and stack traces are not recorded. The log is never transmitted automatically. Only “Export local diagnostics log” creates a temporary shareable JSONL file, which is discarded after the share attempt.

The optional Pro app protection locks the whole app after a cold launch or a selected background delay using biometrics or the secure device passcode offered by the operating system. Kassento receives and stores no biometric characteristics; it only uses the success or cancellation result for the current unlock attempt. Activation and delay remain device-specific and are not included in a portable backup. The lock covers content in the app switcher but encrypts neither the local SQLite database nor files already exported or shared.

The optional Pro closing reminder stores its enabled state, local time, selected weekdays, and permission-request status as a device-specific preference. It is not included in portable backups. Kassento requests notification permission only when you deliberately enable the feature; the operating system then schedules no more than seven local weekly notifications. Their generic text contains no register names or amounts. There is no push token, Kassento push backend, or transfer of the reminder schedule to the provider. Disabling the feature and “Delete all local data” remove notifications scheduled by Kassento; you can change the system permission in device settings.

3. Pro purchase, Apple/Google, and RevenueCat

Kassento offers an optional non-consumable one-time purchase. Apple App Store or Google Play handles payment. Kassento receives neither full payment credentials nor card details.

The app uses RevenueCat (RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA) to display the offer, validate the purchase, unlock Kassento Pro, restore purchases, and account for refunds. A production store build may check Pro status on launch and during store actions. The processing includes in particular:

The app does not send register names, currency definitions, target compositions, staff lists, tip splits, cash amounts, quantities, cash movements, manual terminal reconciliations, notes, profiles, or completion history to RevenueCat. Automatic device identifier collection and RevenueCat diagnostics are disabled in Kassento’s code, and no advertising or analytics integrations are enabled in RevenueCat.

The legal basis is Article 6(1)(b) GDPR for purchase, unlocking, and restoration and Article 6(1)(f) GDPR for reliable entitlement status and prevention of misuse and errors. Our legitimate interest is secure delivery of paid functionality. RevenueCat acts as a processor for end-user information. Data may be processed in the United States; RevenueCat provides, among other safeguards, the EU Standard Contractual Clauses in its Data Processing Addendum. See also the RevenueCat Privacy Policy.

Apple and Google process storefront account, payment, and purchase data under their own privacy notices and legal obligations. Refunds and payment issues are generally handled by the store used for the purchase.

4. Sharing, exporting, and portable backups

Only when you deliberately select Share, Export, receipt-photo sharing, Export local diagnostics log, or Create encrypted backup does the operating system pass the chosen content or temporary export, diagnostic, or encrypted backup file to the destination app you select. From that point, its provider controls further processing. Do not send data to recipients who should not receive it, and inspect a diagnostic export before sharing it.

5. Website and hosting

The pages under darkstone.app are static, use no cookies, and contain no analytics, advertising, social-media, or tracking services. Your IP address is technically required to deliver the page to your device over HTTPS. The web server and reverse proxy do not maintain regular access logs. Security-critical technical errors may be processed briefly where necessary for operation and defence. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is secure and reliable website operation.

The server is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner processes technical data required for service delivery, network operation, and security as our processor. See the Hetzner Privacy Policy for further information.

6. Support contact

When you contact us by email, we process the sender address, message content, and information you provide voluntarily to handle the request. The legal basis is Article 6(1)(b) or (f) GDPR, depending on the request. Google provides our email service, which may involve processing by Google Ireland Limited and affiliated companies. See the Google Privacy Policy.

Support messages are deleted when the request is complete and no statutory retention or legitimate evidentiary interest remains, generally no later than three years after the case is closed. Do not send real register names, cash amounts, notes, receipt photos, complete store receipts, payment details, or credentials. An explicitly generated local diagnostic export contains only fixed redacted error fields; inspect it before sending it.

7. Retention and deletion

Local deletion cannot automatically remove store and transaction records retained by Apple, Google, or RevenueCat. A purchased one-time entitlement can be restored through the store.

8. Your rights

Subject to the GDPR, you may have rights of access, rectification, erasure, restriction, portability, and objection. Where processing is based on consent, you may withdraw it for the future. Contact darkstone.app@gmail.com. We may require reasonable proof of identity before disclosing or deleting data associated with a RevenueCat identifier or support request.

You may also complain to a data protection authority, in particular the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna.

9. Changes

This privacy policy will be updated when features, service providers, or legal requirements change. The current version is always available at this URL.