Last updated: June 2026
Privacy
This document explains what data Kirje collects and how we process it.
In plain English: we store the data you give us (account, company, transactions), we process it only to provide Kirje, we don't sell it. We do use a few cookies — see the table below.
1. What we collect
Account data: name, email, hashed password, optional avatar.
Company data: the e-Financials companies you connect, including their bank statements, receipts, invoices, and journal entries.
Service data: logs, IP addresses (truncated to /24), browser type, and usage telemetry.
2. How we use your data
We process the data you give us to provide the Service. We don't sell your data. We don't share it with third parties except as needed to provide the Service (e.g., the OpenRouter API for the AI extraction, e-Financials to post entries, the bank parser to read your statement).
3. e-Financials credentials
You paste your e-Financials API key during onboarding. We encrypt it with AES-256-GCM using a per-tenant data key. We decrypt your API key only in memory at the moment of posting — never log it, never echo it back to the UI.
You can revoke the key from e-Financials anytime; Kirje stops posting immediately.
4. Where your data lives
Database: Neon Postgres (eu-central-1). Receipt files: S3 (eu-central-1). AI calls: routed through OpenRouter to EU-resident models when available; fall back to US-resident models otherwise.
5. How long we keep your data
While your account is active. After account deletion we wipe personal data within 30 days, except where retention is required by law (tax records: 7 years in Estonia). Consent log entries are kept for the duration of the consent (max 1 year) plus 1 year for audit.
6. Your rights
You have the right to access, correct, and delete your data; export your data; and lodge a complaint with the Estonian Data Protection Inspectorate (AKI). You can also change or revoke your cookie consent at any time via the Cookie settings link in the footer.
7. Security
Encryption at rest and in transit. Per-tenant data isolation. Annual third-party security audit. Report vulnerabilities to security@kirje.ee
9. Contact
Questions? Email privacy@kirje.ee.