Kassento · Privacy
Privacy Policy
Summary: Register, count, target-composition, local-staff-list, tip-split, custom-currency-definition, cash-movement, manual-terminal-reconciliation, note, history, and optional receipt-photo data is processed primarily on your device. An enabled iCloud/Finder device backup may include the database, preferences, and receipt photos. Android cloud backup includes the database and preferences but deliberately excludes receipt photos; direct Android device transfer may include them. A portable backup you create contains the complete Kassento database, existing photos, and selected preferences and is encrypted with your password. “Bank” and “safe” are local event labels only; terminal reconciliation compares only two manually entered aggregate totals. Kassento has no bank, POS, or terminal connection and collects no card, customer, or individual transaction data. Photos are stored without copied EXIF/GPS metadata. The device-specific reminder schedule and bounded redacted diagnostic log stay local and are not included in portable backups. Device and portable backups do not transfer a Pro purchase entitlement. The provider has no access to this content. Kassento has no user account, developer-operated app backend, advertising, or developer analytics. Apple or Google and RevenueCat process purchase data only for the optional Pro purchase.
1. Controller
Darkstone / Kassento
Uttendorf 13
3385 Prinzersdorf
Austria
Email: darkstone.app@gmail.com
2. Local app data
- Live app state: the local SQLite database and local preferences in the app sandbox; not an independent backup.
- Device backup: only through the Apple/Google device feature you enable and under operating-system control. iCloud/Finder backups may include processed receipt photos; Android cloud backup deliberately excludes them, while direct Android device transfer may include them. A Pro purchase entitlement is not carried over.
- Portable data backup: only after your deliberate action and encrypted with your password. Format v3 includes existing receipt photos; readable format v2 does not. Neither includes a Pro purchase entitlement, device-specific app protection, diagnostic log, or closing-reminder schedule.
- Store purchase restore: checks only the Pro entitlement and restores no register, count, or history data.
Kassento processes register names, built-in or custom versioned currency definitions, denominations and quantities, cash rolls/packages, expected balances and per-denomination target compositions, opening balance and source, completion results, tips, optional shift labels, notes, profiles, and people/approval/blind status. It may also process a local staff list with names and selection status and saved tip splits with names, shares, and amounts. Further data includes local cash movements with type, amount, optional destination/comment, confirmer, time, receipt/reversal reference and final closing confirmation, optional manual terminal reconciliations, receipt photos, and app preferences. This content is stored primarily in the app sandbox on the device. The provider has no access to it.
An optional manual terminal reconciliation stores only a local label, the user-entered expected aggregate POS total, the actual aggregate terminal settlement, the calculated difference, and an optional reason, comment, and timestamp. The card difference remains separate from the cash close. Kassento collects no card numbers, customer data, or individual transaction data for this feature.
“Bank”, “safe”, “drawer top-up”, and “tip withdrawal” are user-entered local events only. Terminal reconciliation is also a purely manual entry of aggregate totals. Kassento connects to no bank account, safe, POS, terminal, or payment system and confirms no external transfer or settlement. Corrections are stored as reversal events; the local event sequence is not a tamper-proof cash ledger or audit-certified accounting record.
A validated previous-version snapshot created before a database migration also remains inside the app sandbox and is automatically removed after three successfully validated cold launches. Temporary PDF and CSV files are stored in the app cache and removed after handoff or, at the latest, on the next app launch.
If you enabled the applicable device feature, the database and local preferences may be included in your iCloud/Finder backup, Android cloud backup, or direct device transfer. Processed receipt photos may be included in iCloud/Finder backups and direct Android device transfer. Android cloud backup deliberately excludes receipt photos because of the platform’s per-app 25 MB limit. An installation-specific guard discards a local Pro cache restored from a device backup; a valid purchase is unlocked again after the next online store check. Apple or Google processes the backup according to your account and device settings and its own privacy terms. The Kassento provider can neither read nor manage it.
Kassento Pro lets you deliberately create a portable backup file. Before opening the system share sheet, Kassento encrypts the complete database including custom currency definitions, target compositions, the staff list, tip splits, opening sources, cash movements, closing confirmations, and manual terminal reconciliations, existing receipt photos, and app preferences with a password you choose. You then select a destination such as Save to Files, iCloud Drive, or Google Drive. Kassento has no direct cloud-storage integration; the provider knows neither the password nor the destination. If the password is lost, the provider cannot recover the file. Restoring is available without Pro, replaces current local data after a content preview, and does not restore a store purchase entitlement. Older v2 backups remain readable and contain no photos.
With Pro, you may deliberately add at most one receipt photo to a completed count through the system camera or system photo picker. Android needs no app-declared camera, broad media, or storage permission for this; iOS opens the camera or photo library only after your source choice and displays a localised usage explanation. Kassento orients the image on-device, limits its longest edge to 2,048 pixels, and stores a newly encoded JPEG of no more than 1.5 MiB. It does not copy EXIF, GPS, camera, or other source metadata; all receipt photos together are limited to 256 MiB. A photo may be processed through an enabled iCloud/Finder device backup or direct Android device transfer; Android cloud backup does not include it. Beyond those paths, a photo leaves the device only after your explicit photo share or as part of a deliberately created portable backup. You can delete it individually, with the completion, or through Delete all local data; a persistent cleanup queue and launch reconciliation clean up interrupted file operations.
The live database is not additionally encrypted by the app; it is protected by the operating-system sandbox and device security. Temporary snapshot and restore working files are removed from the app cache after completion, cancellation, or failure. During a data restore, the app also keeps a recovery journal and a local rollback copy of the database, receipt photos, and preferences inside its sandbox. They are removed after a confirmed success or successful rollback; after process termination, the next app launch completes that cleanup. Only if recovery itself cannot finish because of a storage or file error is the copy retained for another launch. “Settings → Delete all local data” removes local user data, including receipt photos, the diagnostic log, and these recovery files, after two confirmation steps. Uninstalling the app or clearing app data also removes local data. Kassento cannot selectively delete device backups or portable backup files already stored outside the app; their further retention follows your settings and the applicable storage service.
For backup, receipt-photo, and reminder failures, Kassento keeps a bounded local diagnostic log. It stores no more than 200 events, 128 KiB, and 30 days, using only UTC time, fixed feature areas, fixed operations, and coarse error codes. There is no free-text field; register names, amounts, notes, file paths, passwords, photo content, and stack traces are not recorded. The log is never transmitted automatically. Only “Export local diagnostics log” creates a temporary shareable JSONL file, which is discarded after the share attempt.
The optional Pro app protection locks the whole app after a cold launch or a selected background delay using biometrics or the secure device passcode offered by the operating system. Kassento receives and stores no biometric characteristics; it only uses the success or cancellation result for the current unlock attempt. Activation and delay remain device-specific and are not included in a portable backup. The lock covers content in the app switcher but encrypts neither the local SQLite database nor files already exported or shared.
The optional Pro closing reminder stores its enabled state, local time, selected weekdays, and permission-request status as a device-specific preference. It is not included in portable backups. Kassento requests notification permission only when you deliberately enable the feature; the operating system then schedules no more than seven local weekly notifications. Their generic text contains no register names or amounts. There is no push token, Kassento push backend, or transfer of the reminder schedule to the provider. Disabling the feature and “Delete all local data” remove notifications scheduled by Kassento; you can change the system permission in device settings.
3. Pro purchase, Apple/Google, and RevenueCat
Kassento offers an optional non-consumable one-time purchase. Apple App Store or Google Play handles payment. Kassento receives neither full payment credentials nor card details.
The app uses RevenueCat (RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA) to display the offer, validate the purchase, unlock Kassento Pro, restore purchases, and account for refunds. A production store build may check Pro status on launch and during store actions. The processing includes in particular:
- a randomly generated, pseudonymous RevenueCat App User ID,
- product identifier, purchase history, entitlement status, store, price, currency, and transaction timestamps,
- the Apple receipt or Google purchase token,
- necessary technical connection and app data such as IP address, platform, app/OS version, locale, and storefront country.
The app does not send register names, currency definitions, target compositions, staff lists, tip splits, cash amounts, quantities, cash movements, manual terminal reconciliations, notes, profiles, or completion history to RevenueCat. Automatic device identifier collection and RevenueCat diagnostics are disabled in Kassento’s code, and no advertising or analytics integrations are enabled in RevenueCat.
The legal basis is Article 6(1)(b) GDPR for purchase, unlocking, and restoration and Article 6(1)(f) GDPR for reliable entitlement status and prevention of misuse and errors. Our legitimate interest is secure delivery of paid functionality. RevenueCat acts as a processor for end-user information. Data may be processed in the United States; RevenueCat provides, among other safeguards, the EU Standard Contractual Clauses in its Data Processing Addendum. See also the RevenueCat Privacy Policy.
Apple and Google process storefront account, payment, and purchase data under their own privacy notices and legal obligations. Refunds and payment issues are generally handled by the store used for the purchase.
4. Sharing, exporting, and portable backups
Only when you deliberately select Share, Export, receipt-photo sharing, Export local diagnostics log, or Create encrypted backup does the operating system pass the chosen content or temporary export, diagnostic, or encrypted backup file to the destination app you select. From that point, its provider controls further processing. Do not send data to recipients who should not receive it, and inspect a diagnostic export before sharing it.
5. Website and hosting
The pages under darkstone.app are static, use no cookies, and contain no analytics, advertising, social-media, or tracking services. Your IP address is technically required to deliver the page to your device over HTTPS. The web server and reverse proxy do not maintain regular access logs. Security-critical technical errors may be processed briefly where necessary for operation and defence. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is secure and reliable website operation.
The server is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner processes technical data required for service delivery, network operation, and security as our processor. See the Hetzner Privacy Policy for further information.
6. Support contact
When you contact us by email, we process the sender address, message content, and information you provide voluntarily to handle the request. The legal basis is Article 6(1)(b) or (f) GDPR, depending on the request. Google provides our email service, which may involve processing by Google Ireland Limited and affiliated companies. See the Google Privacy Policy.
Support messages are deleted when the request is complete and no statutory retention or legitimate evidentiary interest remains, generally no later than three years after the case is closed. Do not send real register names, cash amounts, notes, receipt photos, complete store receipts, payment details, or credentials. An explicitly generated local diagnostic export contains only fixed redacted error fields; inspect it before sending it.
7. Retention and deletion
- Local app data including receipt photos: until individual/completion deletion, Delete all local data, clearing app data, or uninstalling.
- Local diagnostic log: no more than 200 events, 128 KiB, and 30 days; until Delete all local data, clearing app data, or uninstalling.
- Device backups: according to your Apple or Google account settings and retention rules.
- Portable backup files: until you delete them at the destination you selected.
- Temporary snapshot and restore working files: until the operation completes, is cancelled, or fails.
- Restore journal and rollback copy of the database, receipt photos, and preferences: until a confirmed commit or successful rollback; after process termination until recovery on the next launch, and after a recovery error until the next successful attempt, local deletion, or uninstall.
- Temporary exports including diagnostic exports: after handoff or on the next launch.
- RevenueCat and store purchase data: as long as necessary for entitlement, restoration, refunds, misuse prevention, and legal obligations. You may request deletion through the contact above.
- Support data: according to section 6.
Local deletion cannot automatically remove store and transaction records retained by Apple, Google, or RevenueCat. A purchased one-time entitlement can be restored through the store.
8. Your rights
Subject to the GDPR, you may have rights of access, rectification, erasure, restriction, portability, and objection. Where processing is based on consent, you may withdraw it for the future. Contact darkstone.app@gmail.com. We may require reasonable proof of identity before disclosing or deleting data associated with a RevenueCat identifier or support request.
You may also complain to a data protection authority, in particular the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna.
9. Changes
This privacy policy will be updated when features, service providers, or legal requirements change. The current version is always available at this URL.