Privacy Policy
In plain words
This policy explains what data Kasa Home collects, why, who it's shared with, and what your rights are. It applies to anyone using the Kasa Home app at kasahome.pt, whether as a landlord or a tenant.
Kasa Home is operated by Tiago Oliveira (Portuguese tax ID 250976293, Rua Herlander Matias, 19, 2580-571 Lisboa), as a sole individual/independent activity — the "data controller" for the purposes of the GDPR. Contact: suporte@kasahome.pt.
What data we collect
Account data: name, email and password (the password is never stored as plain text — it's handled by Supabase Auth, which stores it encrypted). If you sign in with Google, we receive the name and email tied to that account.
House data: house name, address/city/country (optional, filled in by the landlord), rooms and their rent amounts.
Financial data: rent, household bills, deposits and private expenses between roommates — amounts, dates, and each payment's status ("Paid"/"Received"). We never ask for or store credit card or bank account details — Kasa Home doesn't process real payments (see section 3).
Receipt/invoice photos you attach to a bill or expense, kept in a private space only accessible to the people involved in that expense.
Notification data: if you enable push notifications, we store a technical identifier for your device/browser (not your phone number or location) so we can send you alerts.
Technical data: IP address and browser information processed temporarily by the underlying infrastructure (Vercel/Supabase) for the app to function and for security purposes; cookies — see section 8.
What we use the data for
To provide the service: create and manage your account, your house, your rent/bills/expenses, and show you only the information relevant to you (the landlord never sees the tenants' private space; each tenant only sees their own rent status, never a roommate's). This doesn't cover a room's listed rent amount, which works like an asking price: the landlord can choose to show it, even for already-occupied rooms, to someone picking a room while accepting an invite.
To communicate with you: transactional emails (account confirmation, password recovery, invites) and push notifications, when enabled.
For security: preventing unauthorized access, detecting abuse, and keeping an audit trail of financial actions (who did what and when).
To provide customer support when you contact us.
Kasa Home doesn't process real payments
Important: the "Paid" and "Received" buttons are a mutual declaration between the people involved — a record, not a money transfer processed by Kasa Home. Money changes hands outside the app (bank transfer, MB Way, cash, etc.); Kasa Home only stores the record that it happened, as reported by the users involved.
Legal basis for processing
Contract performance: we process your account and financial data because it's necessary to provide the service you requested (managing your shared house).
Consent: for push notifications, which you enable manually and can disable at any time in Settings; and for analytics (PostHog), which only collects data after you accept the cookie notice (see section 8).
Legitimate interest: for security, fraud prevention and improving the service, proportionately and without overriding your rights.
We don't make fully automated decisions about you that produce legal effects or significantly affect you (e.g. there's no automated "scoring" system for tenants or landlords) — all information shown in the app is what you or the other members of your house entered directly.
Who we share data with
We never sell your data or use it for advertising. We only share data with service providers that help us run Kasa Home, to the extent necessary to provide the service:
Supabase (database, authentication and file storage, servers in the Europe region) — the app's core infrastructure.
Vercel (web app hosting).
Resend (transactional email delivery, from the kasahome.pt domain).
Google ("Continue with Google" sign-in, only if you choose that login method).
Your own browser/OS push services (e.g. Google, Mozilla, Apple), needed to deliver notifications — only if you enable that option.
Cloudflare (DNS management and support email routing).
PostHog (product analytics — what pages you visit and what you interact with, servers in the Europe region), only after you accept the cookie notice. We don't use screen recording (session replay); see section 8.
These providers may only use the data to provide the contracted service to us, never for their own purposes.
International data transfers
Supabase hosts your data in the Europe region — there's no transfer outside the European Economic Area (EEA) in that case. PostHog is configured for the same region (EU Cloud), for the same reason.
Vercel, Resend, Google and Cloudflare are based in the United States. Whenever these providers process data outside the EEA, it's covered by the Standard Contractual Clauses approved by the European Commission (Decision 2021/914); Vercel and Google are additionally certified under the EU-U.S. Data Privacy Framework.
You can ask for more detail about these safeguards, including a copy of the relevant data protection agreements, by contacting suporte@kasahome.pt.
How long we keep data
For as long as your account and house(s) exist, we keep the data needed for the app to work.
If you leave a house (stop being a tenant), we keep read access to your financial history in that house — so you have proof of your own payments — until you request account deletion.
When you delete your account (self-service, in Settings), your profile is anonymized immediately — we can no longer link your name/email to financial rows. The financial rows themselves aren't deleted when doing so would break other people's history in the same house (e.g. shared-expense balances with roommates, or records a landlord needs to keep for tax purposes) — we only keep the amount and date, with no way to identify you, for the legal retention period applicable to tax and accounting records in Portugal.
If you're still an active landlord of a house, or still occupy a room as a tenant, account deletion is blocked until you resolve that first (delete the house, or leave the room) — to make sure no open rent, bill or deposit is left orphaned.
When a landlord deletes a house (self-service, with confirmation by typing the house's name), all associated data — rent, bills, announcements, rooms and memberships — is permanently and immediately deleted for every member of that house.
Cookies
We use two essential cookies, always active, and an analytics tool that only starts after you accept the cookie notice — we never use advertising cookies:
Auth session (Supabase): keeps you signed in.
Language preference (NEXT_LOCALE): remembers whether you picked Portuguese or English.
Analytics (PostHog): after you accept the notice, records what pages you visit and what you interact with, so we understand how the app is used and where to improve it. We don't use screen recording (session replay) — the app shows real financial values, and we deliberately minimize the data we capture. If you haven't accepted the notice yet, nothing is sent to PostHog.
If we introduce advertising cookies in the future, we'll update this policy before that happens and ask for consent where the law requires it.
Your rights
Under the GDPR, you have the right to: access your data, correct it, request its deletion, request portability (as a structured copy), object to certain processing, request restriction of processing, and withdraw your consent at any time (e.g. by disabling push notifications or declining the cookie notice) without affecting the lawfulness of processing carried out before that withdrawal.
The right to erasure and to portability are already self-service: in Settings → My account → Edit profile, you can delete your account directly (blocked only if you're still an active landlord of a house or still occupy a room — in those cases, resolve that first) or download a structured copy of all your data (profile, rent, bills, expenses) as a .json file. For the remaining rights, email suporte@kasahome.pt; we respond within 30 days.
You also have the right to file a complaint with Portugal's data protection authority (CNPD), at www.cnpd.pt, if you feel your rights weren't respected.
Security
Privacy between landlords and tenants, and between tenants of different houses, is enforced directly in the database (Row Level Security), not just in how the app looks — even a direct request to the database can't bypass these rules.
All communication happens over HTTPS (encrypted connection). Passwords are never stored as plain text.
Minimum age
Kasa Home is intended for people 18 and older, as it involves managing rental agreements and money between adults.
Changes to this policy
We may update this policy as the app evolves. The date at the top shows the last update. For material changes, we'll notify you by email.
Contact
Questions about this policy or your data: suporte@kasahome.pt.
Questions? suporte@kasahome.pt
Terms of Service