Tika Finance

Privacy Policy

Last updated: May 26, 2026

1. Overview

Tika Finance ("Tika", "we", "us") provides personal finance software for accounts, statement imports, transaction review, budgets, debts, goals, reports, support, and billing. This Privacy Policy explains what information we collect, how we use it, how long we keep it, and the choices available to you.

Tika is a software service. We do not sell your personal information, and we do not store raw card numbers, CVCs, or bank login credentials.

2. Information We Collect

  • Account and profile information: name, email address, selected currency, authentication metadata, two-factor authentication state, recovery status, and account preferences.
  • Financial workspace data: accounts, balances you enter or import, categories, tags, transactions, budgets, budget alerts, recurring transactions, goals, debts, loans, transfers, reconciliation decisions, and report settings.
  • Statement upload data: uploaded CSV/PDF statement files, parsed transaction rows, parser status, import errors, staged review records, and statement metadata such as bank profile, account, date range, currency, and upload status.
  • PDF password data: if you save an account-level PDF password to process password-protected statements, Tika stores it encrypted at rest and uses it only to unlock statement files for import workflows. It is not returned in normal API responses or shown back in the interface.
  • Support and communication data: support tickets, replies, internal routing metadata, feature request votes, contact inquiries, newsletter requests, and related notification delivery logs.
  • Billing data: plan, subscription status, billing timestamps, Stripe customer/subscription/price/session IDs, payment status, and non-sensitive payment method display data from Stripe such as card brand, last four digits, funding type, and expiry. Stripe processes payment details directly.
  • Export, deletion, and privacy request data: GDPR-style export/deletion requests, generated export metadata, deletion manifests, request status, audit records, and operator notes needed to process and prove privacy actions.
  • Security, device, and operations data: IP address, user agent, device/session metadata, push notification tokens, audit logs, impersonation reason records, failed login or step-up attempts, queue/job status, application logs, release crash diagnostics, and diagnostic information needed to protect and operate the service.
  • Optional parser consent samples: if you submit sample statements or consent uploads for unsupported bank-parser support, we store the files and metadata only for the parser support workflow described at submission time.

3. How We Use Information

  • Operate the core product, including imports, categorization, reconciliation, budgeting, goals, debts, loans, reports, exports, and account sharing.
  • Process statement files and, when you have saved one, use the encrypted PDF password associated with the selected account to unlock supported statement files.
  • Enforce Free/Paid plan limits, manage subscriptions, create Stripe Checkout and Customer Portal sessions, and keep subscription status in sync with Stripe webhooks.
  • Send transactional notifications, support replies, security notices, billing notices, and operational messages.
  • Detect abuse, investigate suspicious activity, protect accounts, enforce admin step-up controls, maintain audit trails, and troubleshoot incidents.
  • Improve reliability, parser quality, performance, product workflows, and customer support.
  • Provide exports, process account deletion requests, satisfy legal obligations, and preserve records required for security, billing, accounting, dispute, or compliance purposes.

4. Service Providers And Processors

We do not sell personal information. We share information only when needed to provide, secure, bill, support, or legally operate Tika. These processors may include:

  • Hosting, storage, database, backup, logging, queue, and infrastructure providers.
  • Email, notification, support, and customer communication providers.
  • Firebase (Google) for mobile push notification delivery, including device tokens and notification payloads, and release-only mobile crash diagnostics. Tika does not configure app-defined user IDs or financial breadcrumbs in crash reports.
  • Realtime infrastructure providers for private authenticated app updates, where configured.
  • Stripe for payment processing, hosted Checkout, Customer Portal, billing events, and payment method metadata.
  • Analytics or product diagnostics providers, where enabled, using privacy-aware configuration and only for product reliability and launch funnel measurement. Website analytics can load when configured; the current mobile app uses release-only crash reporting and does not include a mobile analytics SDK.
  • Professional advisers, authorities, or counterparties when required by law, security investigation, dispute resolution, or compliance obligation.

Processors may handle data in countries different from your own. We use contractual, technical, and organizational safeguards appropriate for the service and the data involved.

5. Statement Files, PDF Passwords, And Parser Data

Statement files and parser consent samples are stored outside the public web root and are accessed through authenticated workflows. Parsed records may be staged for review before becoming transactions.

If you save an account-level PDF password, it is stored encrypted and retained while the related account exists or until you remove or replace it. Tika uses saved PDF passwords only to process statement imports for that account. You should only upload statements and provide passwords for accounts you are authorized to access.

Parser results can contain mistakes because bank statement formats vary. Tika provides review and correction tools, and you remain responsible for checking imported data before relying on reports or budgets.

6. Data Retention

We retain data for as long as your account is active, as needed to provide the service, or as required for security, billing, accounting, compliance, backup, and dispute purposes.

Typical retention behavior:

  • Financial workspace data remains until you delete it, close the account, or request deletion.
  • Uploaded statement files, generated report exports, parser consent samples, and saved PDF passwords are removed during account deletion or privacy deletion workflows where technically and legally applicable.
  • Support, billing, audit, security, and deletion-request records may be retained longer when needed to protect users, prove compliance, resolve disputes, prevent abuse, or satisfy legal obligations.
  • Backups are retained for a limited operational window and expire through the backup retention process; deleted records may remain in backups until those backups rotate out.
  • Aggregated or de-identified operational metrics may be kept after account deletion if they no longer identify you.

7. Exports, Deletion, And Your Choices

You can access and update account information in the product. Depending on account state and legal requirements, you may also request:

  • A copy of your user-owned data.
  • Correction of inaccurate profile or workspace information.
  • Deletion of your account and user-owned data.
  • Removal of uploaded statement files, generated exports, parser consent samples, and saved PDF passwords.
  • Support for billing, privacy, or data access questions.

Deletion workflows remove application tokens, private files, parser consent files, generated exports, and user-owned records where applicable. Some records may be retained if required for security, billing, legal, tax, accounting, audit, fraud prevention, or dispute-resolution obligations.

If you cannot access the app, you can request account or data deletion from the public web page at https://tika.finance/account-deletion or by emailing support@tika.finance.

8. Security

We use technical and organizational safeguards designed for sensitive financial workspace data, including private file storage, encrypted sensitive fields where applicable, access controls, audit logs, admin step-up verification, and short-lived impersonation controls.

No internet service can be guaranteed 100% secure. You are responsible for keeping your password, two-factor device, recovery codes, and account access secure.

9. Children

Tika is not intended for children. If you believe a child has provided personal information to Tika, contact us so we can review and take appropriate action.

10. Changes To This Policy

We may update this Privacy Policy as the product, legal requirements, processors, or launch configuration changes. We will update the date above and, when appropriate, provide notice in the product or by email.

11. Contact

For privacy-related requests, email support@tika.finance.