Trust Center

Trust is the product.

Kinta exists because people hand us their receipts. Here is exactly what we do with them — and what we refuse to do.

For shoppers

Your receipts, in plain terms.

What we collect
The receipts you choose to scan, and how you set up your budgets. Nothing from your bank, nothing in the background.
What partners see
Only anonymized, aggregated patterns — how a category or product behaves across many households.
What they never see
Your name. Your e-mail. Any single receipt. You.
Your controls
Export everything any time. Delete your account and it all cascades — nothing retained.

The rule that governs everything: k ≥ 20.

No number Kinta publishes or sells ever comes from fewer than 20 households. If only a handful of people bought something, it stays invisible — to partners, to the public, to us in any report. Aggregation isn't a setting we can loosen for a good client; it's built into the pipeline.

one aggregate
"If fewer than 20 households bought it, we don't show it. To anyone."
For partners

How the data is protected, technically.

Pseudonymization at ingestion
Identities are replaced with salted hashes before storage.
Aggregation-only outputs
The k≥20 floor applies to every cell of every export, dashboard and API response.
Fiscal verification
Every source receipt is verified against the tax authority (suf.purs.gov.rs).
ZZPL alignment
Serbia's data-protection law, GDPR-equivalent — processing is aligned end to end.
Data residency
All data is hosted within the EU, on infrastructure aligned with GDPR and Serbia's ZZPL.
Deletion propagates
Account deletion cascades to aggregates — nothing retained.
Security questions or a DPA?
Privacy Policy Terms of Use Data requests