Kwenta logoKWENTA
Bumalik sa Kwenta

Privacy Policy

Huling na-update: 8 September 2026

Kwenta is a personal finance tracker. This policy explains what we collect, why we collect it, who we share it with, and what you can do about it. We wrote it to be read — not to be skipped. It follows the Philippine Data Privacy Act of 2012 (RA 10173) and its implementing rules.

1. Who we are

Kwenta (“we”, “us”) operates the Kwenta web and mobile apps and this website. For the purposes of RA 10173, we are the personal information controller for the data described below. You can reach us at app.kwenta@gmail.com.

2. What we collect

Account information

  • Your name and email address, and a profile photo if you upload one.
  • Your password, stored only as a one-way hash — we cannot read it, and neither can anyone with access to our database.
  • Your language and display-currency preferences, and, if you enable two-factor authentication, the secret and backup codes needed to verify your codes.

Financial records you enter

  • Wallets and balances, transactions (amount, date, category, merchant, and any note you write), budgets, savings goals, investments, debts, bill reminders, categories, and tags.
  • Receipt images and attachments, if you upload them on a plan that includes attachments.
  • An account number we generate for you, so another Kwenta user can find you for a wallet invite or transfer — and the wallets you choose to share with other people.

We do not connect to your bank, and we do not read your bank transactions. Everything in your Kwenta account is there because you or someone you shared a wallet with entered it.

Billing information

Paid plans are currently arranged manually: you contact us, you send payment, and you submit a proof-of-payment image that a person reviews by hand. We keep that image and a record of your plan, its status, and your payments for as long as we need them as financial records.

If we enable online checkout, card and e-wallet payments will be handled by Xendit, a licensed payment processor. We would never see or store your card details — they go straight to the processor, and we only receive the result.

Support and marketing

  • Feedback you send us, including an optional screenshot.
  • Your email address if you subscribe to our newsletter on this website. That is all we store for a newsletter subscription — no name, no browsing history.

Technical data

Our servers keep short-lived logs (including IP addresses) to operate the service, enforce rate limits, and investigate abuse or errors. We do not use advertising or analytics cookies on this website, and we do not track you across other sites.

3. Cookies

The Kwenta app sets one essential cookie: an httpOnly session cookie that keeps you signed in. It is not used for advertising or analytics, and the app cannot work without it. This marketing website sets no cookies of its own. If we ever add analytics or advertising cookies, we will ask for your consent first and update this policy.

4. Why we process your data

  • To provide the service — storing your records, computing your balances, budgets, and reports, sending the emails the app depends on (verification, password reset, bill reminders, notifications).
  • To keep accounts secure — verifying email addresses, rotating session tokens, rate-limiting, and investigating suspicious activity.
  • To take payment for paid plans and keep the records the law requires.
  • To improve Kwenta — reading the feedback you choose to send us.

Our legal bases under RA 10173 are your consent (which you can withdraw), the performance of our contract with you, our legal obligations, and our legitimate interests in keeping the service running and secure.

5. Who we share it with

We do not sell your data, and we do not share it for advertising. We use these service providers, each with access only to what their job requires:

  • Supabase — hosts our database and the storage bucket for uploaded images.
  • Vercel — hosts the website, the app, and the API.
  • Xendit — would process card and e-wallet payments if we enable online checkout. Not used while plans are arranged manually.
  • Gmail (Google) SMTP — delivers our transactional emails.
  • Google (Gemini API) — only for open-ended questions you ask the AI Financial Advisor, and only when our own servers cannot answer them. See the section below.
  • Exchange-rate providers — we request published currency rates. We send them a currency code, never your data.

Some of these providers process data outside the Philippines. When they do, we rely on their contractual commitments to protect it, as RA 10173 requires. We may also disclose data when a valid legal order compels us to.

6. The AI Financial Advisor

Most questions are answered by calculations that run on our own servers, plus a set of answers we wrote ourselves — questions about your spending, budgets, goals, bills, and balances never leave our infrastructure.

For an open-ended question that neither of those can answer, we send your question together with a summary of your finances — monthly totals, wallet names and balances, budget names and amounts, goals, and upcoming bills — to Google’s Gemini API, which phrases the reply. We do not send your full transaction history, your name, or your email address. Under the API terms we use, Google does not use this data to train its models.

If you would rather nothing be sent to Google at all, do not use the advisor — every other part of Kwenta works without it.

7. How long we keep it

  • While your account is open — your records stay until you delete them.
  • When you delete your account — we delete your account and the financial records attached to it. Deletion is immediate and permanent, so export anything you want to keep first (Settings → export, on plans that include it).
  • When you reset your account — this clears your financial data and uploaded images but keeps your login, security settings, and billing history.
  • Billing records — we keep these for as long as tax and accounting rules require, even after an account closes.
  • Newsletter emails — until you ask us to remove you.

8. Your rights

Under RA 10173 you have the right to:

  • be informed about how your data is processed — this page;
  • access a copy of your data, and to have it corrected if it is wrong;
  • object to processing, and to withdraw consent — including by deleting your account;
  • erasure or blocking, in the cases the law provides for;
  • data portability — an export of your data in a usable format;
  • damages, if you suffer harm from a violation of the Act.

Most of these you can exercise yourself in the app: edit your profile, export your transactions, reset your account, or delete it outright. For anything else, email app.kwenta@gmail.com and we will respond within a reasonable period. If you are not satisfied, you may complain to the National Privacy Commission.

9. Security

Passwords are hashed, sessions use rotating tokens tied to each device, two-factor authentication is available, and email addresses must be verified before sign-in. Traffic is encrypted in transit. No system is perfectly secure — if a breach ever affects your personal data, we will notify you and the National Privacy Commission as the law requires.

10. Children

Kwenta is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, tell us and we will remove it.

11. Shared wallets

If you invite someone to a wallet, they can see that wallet’s transactions, balances, and the notes on them. Only share wallets with people you trust, and remove members when they no longer need access.

12. Changes to this policy

If we change how we handle your data, we will update this page and the date at the top. For significant changes, we will tell you in the app or by email before they take effect.

13. Contact

Questions, requests, or complaints about your data: app.kwenta@gmail.com. For anything about plans or billing, you can also use our contact form.