Privacy
Last updated: April 2026
Kitta is a tool you trust with your MeroShare credentials. We treat that like a loan, not a gift — here's exactly what we hold, what we don't, and what we do with it.
What we store
- Your email, name, and hashed password (bcrypt, cost factor 12). We never see your plaintext Kitta password.
- Each MeroShare account you add: username, bank, and your MeroShare password, PIN, and CRN — all encrypted with AES-256-GCM before they reach the database.
- A history of your applications, allotments, and holdings, so you can read the morning report and the historical charts.
- Sync logs and audit events (login, password change, credential reveal) for diagnostics and your own forensics.
What we don't store
- Your MeroShare session tokens past their TTL.
- Any third-party tracking pixels, ad identifiers, or behavioural profiles.
- Payment info — while Kitta is free, we don't take cards at all. If paid tiers launch, we'll process through a PCI-DSS-compliant partner and tell you first.
Who sees your data
No one outside the Kitta team. We don't sell, rent, or share credentials or holdings data. Operators with database access are bound by a signed confidentiality obligation; access is gated and logged.
Encryption
The master key used for credential encryption lives in our secrets manager — not in source control, not in the database. A full database dump, if ever leaked, would still not expose your MeroShare credentials.
Deletion
Delete your account and we wipe everything — user record, credentials, applications, holdings, logs — within 30 days. No retention policy, no "analytics" residue. Email hello@kitta.app if you want a confirmation.
Questions
Write to hello@kitta.app — we read every message.