kaicorplabs.com / privacy

05 Privacy

What each tool stores, where it lives, and the two times something leaves.

Not a promise that nothing ever leaves this hardware — that would be easy to write and false. This is the list: what each tool keeps, what it refuses to keep, how long, and the exact cases where data is handed to somebody else. Where the honest answer is uncomfortable, it is here too.

The short version

There is no analytics, no advertising, no profiling and nothing sold or shared for money — there is no business model that would pay for it. The services run on hardware we own and administer, not on rented compute. What we hold is what the tools need to work, and it is deleted when the thing it belonged to is deleted.

The machine is in Spain, so what it holds sits in the European Union. Two things do leave, and both are named below: email and the network in front of everything — neither of which we can promise keeps to the EU, because both are companies operating worldwide.

Tool by tool

TabUp

Shared expenses

Your groups, expenses, payments, comments and the record of who did what. Receipt photos are re-encoded on upload, which strips EXIF and the GPS coordinates inside it before anything reaches disk. Exchange rates come from a public reference API — it is asked about currencies and dates, never about you.

What it stores in detail →

TabUp · what we turned off

Receipts are kept, not read

Photographing a receipt attaches it to the expense — and that is all it does here. Having a model read the amounts for you is switched off on our instance: the model that reads a creased receipt well is far too large for this machine, and the alternative was sending your photo to somebody else's. Until there is a paid tier with hardware behind it, off is the honest answer.

SecretDrop

We cannot read your secrets

The text is encrypted in your browser and the key travels in the part of the link that browsers never send to a server. What is stored is ciphertext we have no way to open, and it deletes itself when read or when it expires. Reading one needs no account.

What it stores in detail →

DocDrop

Files, until they expire

The file as you uploaded it, until its expiry or its download limit — then deleted for real. Knowing the link is what grants access, so treat it like the file itself. There is deliberately no backup: a copy that outlives the expiry would make the expiry a decoration.

What it stores in detail →

QR-Forge

Counted, not identified

Your codes and where they point, plus a scan count. A scan records the date, the country the network says it came from and a shortened browser name — never the IP address, never the page you came from, and nothing that follows a person between scans.

What it stores in detail →

Pixelforge

Images processed here

Background removal and vectorisation run on this machine, not on anybody's API: the image is not sent anywhere. What you upload is deleted when the job finishes — what you keep is the result you downloaded.

What it stores in detail →

Your account

One sign-in covers the five tools. It holds your email address, the name you chose, your password as a hash — never the password itself — and your second-factor settings. Each tool also keeps a small copy of your identity so it can put your name next to your things.

You can change or delete what is in the sign-in yourself, from your account page. Deleting the sign-in stops you getting in; it does not, on its own, erase what each tool holds — today only TabUp closes an account from inside. If you want everything gone, say so and it gets done by hand, in every tool.

The two exceptions

Email. Messages about your account — the request, the approval, a password reset — are delivered by an email provider, which therefore sees the address and the message. Mail written to us is routed to a mailbox held with a mail provider, like anybody's.

The network in front. Traffic reaches this machine through a content delivery network, which terminates the encryption of the connection and can see the requests as any such network can. It is what lets these services be published without opening a port at home.

Both are ordinary companies with worldwide operations, so those two hops are the part of this we cannot place inside the EU by saying so. Everything the tools themselves store stays on the machine in Spain.

What we cannot promise

Whoever operates this hardware can technically read what is on it. The protection is not a technical impossibility, it is that we do not, and that the tools are built so that most of it is not worth reading — SecretDrop's contents are unreadable by design, and DocDrop's are gone on expiry.

Backups are taken nightly of the two tools that hold lasting data (TabUp and QR-Forge) and kept for about two weeks, so something you delete today can survive in a backup until it rotates out. DocDrop and SecretDrop have no backup at all, on purpose.

Server errors are recorded so that a failure is not invisible; they carry what broke and where, not your content. Ordinary request logs rotate and are not analysed.

Asking us anything about this

Write to contact@kaicorplabs.com — to get a copy of what a tool holds about you, to correct it, or to have it deleted. There is no form and no ticket queue; a person reads it. Every claim on this page can be checked against the source, which is where the detail lives.