Privacy policy
Last updated 5 October 2026
This policy explains what personal information Khula collects, why, who helps us process it, where it is kept, how long we keep it, and your rights. It follows the Protection of Personal Information Act (POPIA). Khula is used by parents and guardians: children don't have accounts of their own.
Who we are
Khula is run by Krikdex (Pty) Ltd in South Africa (“we” and “us”), the responsible party for your personal information under POPIA.
- Name
- Krikdex (Pty) Ltd
- Legal status
- Private company registered in South Africa
- Registration number
- 2022/421139/07
- Director
- Leon Daniel Scheepers
- Physical address (also for legal notices)
- 22 Church Street, Graaff-Reinet, Eastern Cape, 6280
- Phone
- 077 438 9014
- hello@khulabucks.co.za
- Website
- khulabucks.co.za
- Information Officer
- Leon Daniel Scheepers (hello@khulabucks.co.za)
Our PAIA manual explains how to ask for access to the records we hold.
What we collect
About you
- Your account: your name and email address, and your password, which Google's Firebase Authentication stores only as a one-way hash. If you sign in with Google, Google gives us your name, email address and a link to your profile picture (Khula doesn't use the picture).
- Billing: your plan, subscription status and payment dates, and the card brand, last four digits and expiry date that Paystack gives us. Paystack handles the card itself: we never see or store the full card number or CVV.
- Your agreement: when you accepted our terms and this policy, and which versions.
- Messages: what you write when you email us.
- Technical: security and error logs on our servers, which can include your IP address, browser type and account ID, and your email address if an email to you fails to send, and what your browser stores to make Khula work (the cookie policy lists all of it).
- Usage, only if you allow it: with your consent on the cookie banner, Google Analytics records which pages of the website and the parent screens are visited, the device and browser type, the rough location (city level), how you found us, and steps such as signing up or starting the trial. It never receives names, email addresses, PINs, amounts you type or anything about your children, apart from how many children you added when you set up.
About your family
This is what you, another adult using your family's sign-in, or your children on a device you have signed in, enter: the family name; each child's first name, avatar and colour, and if you like their date of birth; pocket money amounts; chores and when they are due; ticks and approvals, and any note you add when you send a chore back; bonuses and demerits and the reasons you give; school terms, goals and results; payouts, savings and savings goals; and parent and child PINs, which are stored only as one-way hashes.
You decide what to enter about your children. A first name is enough: a date of birth is optional and only used to suggest avatars that suit their age. Without an email address and password (or a Google account) we can't give you an account.
Children's information
- POPIA only allows us to process a child's personal information with the prior consent of a parent or legal guardian. You give that consent when you set up your family, and we record when you gave it. If you add a child who isn't yours, you confirm that you have their parent or guardian's permission.
- Children have no email address, password or account. They choose their profile in the family room on a device you have signed in, and can have a PIN.
- We use children's information only to run Khula for your family. We never use it for marketing or advertising, never sell it, never send it to analytics, and share it only with the service providers below that store and run Khula for us.
- You can change a child's details at any time, and delete everything under Settings → Account. To delete one child's information for good while keeping the rest of your family, email us.
Why we use it
- To run Khula for your family: chores, pocket money, the ledger, savings and school goals. We need this to provide the service you signed up for, and for your children's details it rests on your consent as their parent or guardian.
- To bill your subscription through Paystack, and to keep the financial records the law requires.
- To email you about your account: verification codes, trial and payment notices, deletion confirmations and, if you leave them on, reminders about chores waiting at the end of a cycle (switch those off in Settings). We don't send marketing emails unless you have asked for them, and each one would let you unsubscribe.
- To keep Khula secure, prevent abuse and fix problems, which is in our legitimate interest and yours.
- To understand how Khula is used, only if you allow analytics cookies. You can withdraw that consent at any time.
- To meet legal obligations, such as keeping tax records or answering a lawful request from an authority.
We never sell personal information and we don't show advertising.
Who helps us
These service providers (“operators” under POPIA) process personal information for us, under written agreements that require them to keep it secure and use it only to provide their service:
- Google (Firebase and Google Cloud): hosting the website and app, sign-in, the database and our server functions.
- Resend: sending our emails.
- Cloudflare: our domain's DNS, and passing on email you send to hello@khulabucks.co.za.
- Google (Gmail): the mailbox where we read and keep email you send us.
- Paystack (a Stripe company): card payments and subscriptions. Paystack also processes your payment information under its own privacy policy.
- Google Analytics: only if you allow analytics cookies.
We also disclose information when the law requires it, for example under a court order.
Where it is kept
Your family's data (the children's details, chores, money and school goals) is stored in Google Cloud's Johannesburg region, and most of the server functions that work with it run there too. Some processing happens outside South Africa:
- Sign-in details (your name, email address and password hash) are held by Firebase Authentication, which Google runs only from data centres in the United States.
- A few daily automated jobs run in Google Cloud's Belgium region: setting out each day's chores and working out pocket money when a pay period ends, reminders, billing checks and the clean-up described below. They read and update your family's data from there, but it stays stored in Johannesburg.
- Emails are sent through Resend, in the United States.
- Email you send us passes through Cloudflare and is kept in our Gmail mailbox, on Google's servers outside South Africa.
- Paystack may process payment information outside South Africa.
- Analytics data, if you allow it, is processed by Google, mainly in the United States.
As section 72 of POPIA requires, we only use providers bound by agreements or laws that protect personal information to a standard similar to POPIA.
How long we keep it
- While your account is open, we keep your family's data so Khula can work.
- After your subscription ends (or after you set up your family, if you never start one), we keep it for six months in case you come back. Two weeks before the six months are up we email you, and then we delete your account and your family's data. If you sign up but never finish setting up a family, email us and we delete your sign-in details.
- When you delete your account under Settings → Account, your account and family are deleted straight away. We keep a short record with no name or email address in it (your account and family ID, when and why the account was deleted, and the Paystack customer and subscription codes, so a later payment query can still be traced) for 13 months.
- Backups: deleted information can stay in our database's recovery copies for up to 7 days before it is gone for good.
- Server logs are kept for up to 30 days.
- Financial records of payments are kept for five years, as South African tax law requires. Paystack keeps its own transaction records under its policies.
- Analytics data, if you allowed it, is kept by Google for two months.
How we protect it
- Everything travels encrypted (HTTPS) and is encrypted at rest in Google Cloud.
- Every request is checked against security rules, so a family can only ever reach its own data.
- PINs are stored as one-way hashes, and passwords are handled by Firebase Authentication: we never see them.
- Only the people who run Khula can reach our systems, and only when they need to.
- If we have reasonable grounds to believe your personal information has been accessed or acquired by someone not authorised to, we will tell you and the Information Regulator as soon as reasonably possible, as section 22 of POPIA requires.
Your rights
- Access: ask what personal information we hold about you and who has had it.
- Correction and deletion: correct most details yourself in the app, or ask us. Delete your account and family at any time under Settings → Account, or on the billing page if your access has lapsed.
- Objecting and withdrawing consent: object to processing based on our legitimate interests, or withdraw a consent you gave. Withdrawing consent for your children's details means deleting them, because Khula can't work without them.
- Emails: switch off reminder emails in Settings. Emails about billing, security and your account still come while you have one.
- Complaints: tell us first if you can, and we will try to put it right. You can also complain to the Information Regulator (South Africa) at POPIAComplaints@inforegulator.org.za or 010 023 5200 (Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg; inforegulator.org.za).
Every one of these requests is free. Email hello@khulabucks.co.za, ideally from the address on your account, or write to us at the address above. We may ask you to confirm who you are, and we reply within 30 days.
Cookies
Khula keeps what it needs to work in your browser (sign-in, your light or dark choice, who is using the device) and sets analytics cookies only after you say yes. The cookie policy lists every one, and you can change your answer there, from “Cookie settings” at the foot of the website, or in Settings → Privacy.
Changes
We post any change here with a new date. If a change matters (a new kind of information, a new purpose or a new provider, for example), we email account holders before it takes effect.
Questions: hello@khulabucks.co.za