Presta2 · Privacy

Presta2 Privacy Policy

Last updated: 21 August 2026

This policy describes how Kitusoft ("we") collect, use and protect the information we process when you use the Presta2 application ("the App"). It is written to comply with the European Union's General Data Protection Regulation (GDPR), Ecuador's Organic Law on the Protection of Personal Data (LOPDP, 2021), Brazil's Lei Geral de Proteção de Dados (LGPD), the California Consumer Privacy Act (CCPA/CPRA), the United States Children's Online Privacy Protection Act (COPPA), and the "Data safety" requirements of Google Play and Apple's App Store "App Privacy".

1. Who is the data controller

Kitusoft (Cesar J. Santacruz), based in Quito, Ecuador. Contact for any privacy matter: soporte@kitusoft.com.

We are not required to appoint a Data Protection Officer under Article 37 GDPR, but we receive and resolve rights requests at that same address.

2. Quick summary

  • Presta2 requires an account. Unlike some of our other apps there is no local mode: your records sync to Google Firebase so they are available across your devices and survive a change of phone.
  • You store your own records (what you lent, to whom, how much) and other people's data (the contacts you lend to). Section 5 explains your responsibility for that third-party data.
  • Presta2 does not move money. It is not a financial institution, does not process payments, does not collect debts and does not report to any credit bureau. The amounts you see are your own notes, like in a paper notebook.
  • We do not sell your information. We do not use advertising or behavioural trackers today.
  • Access to your address book is optional and only happens when you tap "Sync from phone".
  • You can delete your account and all your data from inside the App, without writing to us.

3. What data we process

3.1 Account data

In Firebase Authentication:

| Category | Specific data | Source | |---|---|---| | Identification | Unique identifier (UID) | Generated by Firebase | | Sign-in method | Email address, phone number, or Google identity — whichever you choose | You, or Google OAuth | | Credentials | Password, stored encrypted by Firebase. We never see it in plain text | You | | Profile | Display name and profile picture (optional) | You |

You can link several sign-in methods to the same account (for example email + Google) and unlink them, as long as at least one remains.

3.2 Your records

In Cloud Firestore, under your user identifier and accessible only by you:

| Category | Specific data | |---|---| | Loans and borrowings | Description of what was lent, amount (optional), currency, tags, status, direction (lent / borrowed), date, due date, whether it recurs and how often, notes | | Payment ledger | Every partial payment you record: amount and date | | Your own tags | Name and the properties they enable (monetary, text, has due date, recurring) | | Trash | Records you delete are marked as deleted until you delete them permanently or restore them |

3.3 Your contacts' data (third-party data)

So the App can tell who you lent something to, it keeps its own address book with:

  • Name (required)
  • Phone, email, relationship ("sister", "work") and notes (all optional)

This data reaches the App in one of two ways: you type it in, or you import it from your phone's address book with the "Sync from phone" feature.

This is other people's information. See section 5 for what that means.

3.4 Profile picture

If you choose a picture it is uploaded to Firebase Storage at profile_photos/{your-identifier}.jpg. The download URL is attached to your account. Replacing the picture overwrites the file; deleting your account removes it.

3.5 Technical data

  • App Check token: the App proves to our backend that a request comes from a genuine installation of Presta2, using Google Play Integrity. This mechanism does not tell us who you are or what device you own, only whether the app is authentic. It exists to stop anyone from reaching the database with a tampered copy of the App.
  • Local preferences: theme (light/dark/system), language and currency are stored only on your device (SharedPreferences on Android, UserDefaults on iOS). They never leave it.

3.6 Operating-system permissions

  • Contacts (READ_CONTACTS)optional. Requested only when you tap "Sync from phone". We read the name, phone and email of your address-book entries in order to create contacts inside the App. We do not read your address book in the background, at launch, or on any schedule. If you never use that feature we never ask for the permission.
  • Photos / galleryoptional. Only when you pick a profile picture. The selected image is uploaded; we do not access the rest of your gallery.
  • Cameraoptional. Only if you choose to take a profile picture on the spot.
  • Network / Internet — required: the App syncs with Firebase.
  • We do not use the microphone, location, SMS, call log, calendar or body sensors.

4. Why we use the data and on what legal basis

| Purpose | Data | Legal basis (GDPR Art. 6) | |---|---|---| | Create and maintain your account, authenticate you | Email/phone/Google, password, UID | Performance of a contract (Art. 6(1)(b)) | | Store and sync your loans, contacts and tags across devices | Records, contacts, tags, payments | Performance of a contract (Art. 6(1)(b)) | | Show you totals, balances and overdue warnings | Records and payments | Performance of a contract (Art. 6(1)(b)) | | Import contacts from your address book when you ask | Name, phone, email of your contacts | Consent (Art. 6(1)(a)), revocable in system settings | | Display your profile picture | Image | Consent (Art. 6(1)(a)) | | Prevent access from tampered copies of the App | App Check token | Legitimate interest (Art. 6(1)(f)) | | Handle support requests | Email, message | Legitimate interest (Art. 6(1)(f)) | | Comply with legal obligations | Any of the above | Legal obligation (Art. 6(1)(c)) |

5. Your responsibility for other people's data

Presta2 is by nature a notebook about third parties: the people you lend things to. Regarding that data:

  • You decide which contacts you keep and what information about them you write down. We process it on your behalf and following your instructions.
  • If you use Presta2 for purely personal or household purposes, GDPR does not impose controller obligations on you (Art. 2(2)(c), the "household exemption"). That covers the vast majority of users.
  • If you use Presta2 in a professional or commercial context (for example, to track your business's credit), you are the data controller for those people's data under the law, and we act as processor. In that case it is on you to have a legal basis for processing it, to inform them, and to honour their rights.
  • Do not record more than you need. The notes field is free text; we ask you not to use it for other people's sensitive data (health, religion, sexual orientation, judicial matters).
  • If someone asks you to delete their data, you can do it yourself by removing that contact in the App. If that person writes to us directly at soporte@kitusoft.com we will help them locate and exercise their rights, though in many cases we will have to refer them to you, since you control that information.

6. Who accesses your data

  • Us (Kitusoft) — only authorised personnel, and only when necessary for support or maintenance.
  • Google LLC (Firebase Authentication, Cloud Firestore, Firebase Storage, App Check, Google Sign-In) — as data processor. It hosts the database, the authentication and the files. Google Firebase is certified under the EU Standard Contractual Clauses (SCC) and participates in the EU-U.S. Data Privacy Framework.

Presta2 does not share your records with anyone else. There are no social features: nobody can see your loans or your contacts, and nobody is notified about a debt. We do not sell your information and we do not pass it to data brokers or advertising networks. We do not share it with credit bureaus or debt-collection companies.

7. International transfers

Your data is stored on Google Cloud / Firebase infrastructure. The database's primary region is us-central1 (Iowa, United States), and Google may replicate the data to other regions for availability and backup.

This means that if you live in the European Union, Ecuador or Brazil, your data is transferred to the United States. These international transfers rely on the safeguards of the EU-U.S. Data Privacy Framework (in which Google LLC participates), the European Commission's Standard Contractual Clauses, and the equivalent clauses applicable under LGPD and LOPDP.

8. How long we keep your data

  • Account and content: for as long as your account is active.
  • Trash: records you delete are flagged as deleted and stay in your account until you delete them permanently from the Trash screen, or until you delete your account. They are not purged automatically — they stay there so you can recover them.
  • When you delete your account: we immediately remove your loans, contacts, tags, payment ledger, profile picture and sign-in credentials. Provider backups may take up to 30 days to rotate out.
  • Local preferences: until you uninstall the App or clear its storage.
  • Support records (emails): up to 24 months, for request traceability.
  • Data required by legal obligation: for as long as the applicable law requires.

9. Your rights

Wherever you live, we guarantee you the following rights over your personal data:

  • Access — to know what data of yours we process.
  • Rectification — to correct inaccurate data (you can edit everything from the App).
  • Erasure ("right to be forgotten") — to ask us to delete your information.
  • Portability — to receive your data in a structured, machine-readable format.
  • Objection — to object to processing based on legitimate interest.
  • Restriction — to ask us to pause processing while a dispute is resolved.
  • Withdraw consent — for the address book and the profile picture, by revoking the permission in system settings, without affecting what was already done.
  • Not to be subject to automated decisions — Presta2 makes no automated decisions with legal effect on you. We compute no credit or solvency score of any kind.
  • To lodge a complaint — with your country's data protection authority (in Ecuador, the Superintendency for the Protection of Personal Data; in the EU, your national authority; in Brazil, the ANPD; in California, the Attorney General or the CPPA).

How to exercise them: write to soporte@kitusoft.com from the email associated with your account. We answer within the legal deadlines (30 days for GDPR, 15 days for Ecuador's LOPDP, 45 days for CCPA).

To delete your account and all your data there is a direct route inside the App, with no need to write to us: Settings → Delete account. The exact steps are at Delete your Presta2 account.

For California residents: you have the additional CCPA/CPRA rights, including the right to know what personal information we collect, to delete it, to correct it, to opt out of the "sale" or "sharing" of information (we do neither), and not to be discriminated against for exercising these rights.

10. Security

  • All communication between the App and our servers goes over HTTPS/TLS.
  • Passwords are stored encrypted by Firebase Authentication; we never have access to the plain-text password.
  • The Firestore and Storage security rules are written so that each user can only read and write their own data subtree. No path exists that lets one account see another's data.
  • App Check requires every request to come from a genuine Presta2 installation, which prevents the App's keys from being used by a tampered client.
  • Although we follow industry best practice, no system is 100% impenetrable. Should a security breach affecting your data occur, we will notify it as the law requires (within 72 hours to the relevant authorities under GDPR).

11. Children and young people

Presta2 is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe your child has sent us information, write to soporte@kitusoft.com and we will delete it.

If the user is between 13 and 18 (or the applicable digital age of consent in their country: 16 in the EU by default, 14 in Ecuador), we recommend that their parents or legal guardians review this policy and supervise use of the App.

12. Advertising and analytics in the future

Today Presta2 shows no ads and uses no behavioural analytics services. We nevertheless reserve the right to add, in the future, third-party services for:

  • Personalised or non-personalised advertising (for example, Google AdMob).
  • Usage analytics and crash reporting (for example, Google Analytics for Firebase, Firebase Crashlytics).
  • Install attribution.

If we do, we will update this policy before enabling those services, state which providers we use and what data they share, and offer the consent mechanisms the applicable law requires (for example, consent forms for EU users under ePrivacy/GDPR before any advertising identifier, and Apple's ATT prompt on iOS). Under no circumstances will we use the content of your loans or your contacts' data for ad targeting.

13. Cookies and similar technologies

Presta2 is a native application and uses no cookies. It uses the operating system's local storage to keep your preferences, which is not accessible to other apps or to websites.

14. Third-party links

The App links to external sites (kitusoft.com, email support). We are not responsible for how those sites process your data. Read their privacy policies separately.

15. Changes to this policy

We may update this policy to reflect changes in the App, in the law or in our practices. When we do:

  • We will change the "Last updated" date at the top.
  • If the change is material (for example, starting to show ads or changing the purposes of processing), we will notify you in the App or by email before it takes effect.
  • Continuing to use the App after the notice constitutes your acceptance of the new version.

16. Contact

Questions, rights requests, incident reports?

Kitusoft Quito, Ecuador Email: soporte@kitusoft.com Website: kitusoft.com