Privacy Policy
Last Updated: September 21, 2026 Effective Date: September 21, 2026
This Privacy Policy explains how Koffr Inc., a Delaware corporation (“Koffr,” “we,” “us,” or “our”), collects, uses, discloses, and protects information when you use the Koffr mobile application, website at koffr.ai, and related services (collectively, the “Service”).
Koffr is an educational tool that generates hypothetical tax-planning projections from information you provide. It is not financial, tax, legal, or investment advice. See our Terms of Service for the full disclaimer.
By using the Service, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.
The Service is designed for U.S.-based users. We do not target or knowingly market the Service outside the United States. If you access the Service from outside the U.S., you do so on your own initiative, and you understand that your information will be processed in the United States, where data protection laws may differ from those of your home country.
1. Information We Collect
We collect information in the following ways:
a. Information you provide
Account information. When you create an account, we collect your email address and authentication credentials through Firebase Authentication.
Tax and financial inputs. To generate hypothetical tax-planning projections, you provide information such as filing status, salary, pay frequency, 401(k) participation and contribution figures, employer match details, state of residence, age, spousal income (if applicable), and similar tax-planning inputs (“User Inputs”). We do not ask for your Social Security number, bank account credentials, brokerage credentials, or government-issued IDs.
Answers you enter before creating an account. On our website, you can complete the questionnaire without creating an account. While you do, your answers are stored in your web browser’s session storage, associated with the website tab you are using. Your browser may restore them if you reopen that tab or restore your browsing session. To authorize calculation requests, Firebase Authentication creates an anonymous technical identifier that does not by itself contain your name or email. To produce your results, your answers and that identifier are sent to our servers to run the calculation; before you create an account we do not write the answers to our application database. Calculation requests may also generate security and operational logs, including the anonymous identifier and a limited eligibility summary. If you create an account, the answers then held in your browser are saved to that account and are treated as User Inputs under this Policy.
Payment information. If you subscribe to PRO, payment is processed by Stripe. We do not collect or store your full payment card number, CVV, or bank account number. Stripe provides us with a transaction identifier, the last four digits of your card, card brand, expiration, and billing zip code for receipt and customer-support purposes. Stripe’s processing of your payment information is governed by Stripe’s Privacy Policy.
Communications. If you contact us for support, feedback, or other reasons, we collect the information you provide (such as your email address and the content of your message).
b. Information collected automatically
Device, usage, and error information. When you use the Service, we automatically collect certain technical information, such as device type, operating system and version, app version, IP address, crash reports, performance traces, and basic usage events (such as sessions, page or screen visits, and feature interactions). We use Google / Firebase for service infrastructure, Amplitude for product analytics, and Sentry for error and performance monitoring. For signed-in users, we may associate an account ID and email address with Amplitude analytics and Sentry reports so we can diagnose account-specific problems. Amplitude may restore a previously stored analytics identifier when you return to the website.
Cookies and similar technologies. Our website uses essential cookies and browser storage for authentication and session management, and analytics identifiers used by Amplitude to recognize sessions and returning browsers. We do not currently use advertising cookies or sell behavioral data.
c. Information from third parties
If you sign in using a third-party authentication provider (such as Google Sign-In or Apple Sign In), that provider shares limited profile information (such as your name and email) with us, subject to your authorization with that provider.
2. How We Use Information
We use the information we collect to:
- provide, operate, and maintain the Service, including generating hypothetical tax-planning projections from your User Inputs;
- create and manage your account and authenticate you;
- process subscription payments and send transactional communications (such as receipts, renewal reminders, and account notices);
- respond to your support requests;
- monitor and improve the Service, including diagnosing technical issues, debugging, and analyzing aggregated usage patterns;
- detect, prevent, and address fraud, abuse, security incidents, and violations of our Terms;
- comply with legal obligations and enforce our rights;
- with your consent, send you product updates, tips, or marketing communications (you can opt out at any time).
We do not use your User Inputs to train machine-learning models or to build advertising profiles.
3. How We Share Information
We do not sell your personal information. We share information only as described below.
Service providers. We share information with third-party vendors who help us operate the Service, including:
- Google / Firebase — authentication, database (Firestore), serverless functions, hosting, and basic analytics;
- Amplitude — product usage and session analytics;
- Sentry — error reporting and performance monitoring;
- Stripe — payment processing;
- Apple App Store / Google Play — app distribution and (where applicable) in-app purchase processing;
- Email and customer-support providers — for sending transactional emails and handling support tickets.
These providers are bound by contractual obligations to use the information only to provide services to us.
Legal and safety. We may disclose information if we believe in good faith that disclosure is necessary to (a) comply with a law, regulation, subpoena, court order, or other legal process; (b) enforce our Terms; © protect the rights, property, or safety of Koffr, our users, or the public; or (d) investigate fraud or security issues.
Business transfers. If Koffr is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, your information may be transferred as part of that transaction. We will notify you (such as by email or in-app notice) before your information becomes subject to a different privacy policy.
With your consent. We may share information for other purposes with your consent.
Aggregated or de-identified information. We may share aggregated or de-identified information that cannot reasonably be used to identify you, provided we maintain and use such information in de-identified form and do not attempt to re-identify it.
4. How We Protect Information
We use commercially reasonable administrative, technical, and physical safeguards designed to protect your information, including encryption in transit (TLS) and access controls on our backend systems hosted on Google Cloud / Firebase. Authentication is handled by Firebase Authentication; payment information is handled by Stripe.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
If we become aware of a security incident affecting your information, we will notify you and applicable authorities as required by law.
5. Data Retention
We retain your information for as long as your account is active and for the periods described below afterward, to comply with legal, tax, accounting, fraud-prevention, and dispute-resolution obligations:
- Answers entered on our website before an account is created: stored in your web browser’s session storage, associated with the website tab you are using; your browser may restore them if you reopen that tab or restore your browsing session. Answers sent to our servers to produce your results are not written to our application database before an account exists. An anonymous Firebase Authentication identifier and operational logs may still be created as described in §1. We do not state a fixed deletion period for those anonymous identifiers.
- Account information and User Inputs: retained while your account is active; deleted within 90 days of account deletion, except where longer retention is required by law.
- Payment and transaction records: retained for at least 7 years from the date of the transaction to satisfy tax and accounting obligations.
- Communications and support tickets: retained for 3 years from the date of the last interaction.
- Device, usage, and crash data: retained in identifiable form for 12 months, then aggregated or deleted.
You may request deletion of your account and associated data at any time through the in-app account settings or by emailing support@koffr.ai. After deletion, we may retain limited information as required by law (for example, transaction records for tax purposes) or in backup archives that are deleted on a routine schedule (typically within 90 days).
6. Your Choices
Account information. You can review and update most account information through the in-app settings.
Marketing emails. You can unsubscribe from marketing emails using the link in any such email. We will still send transactional emails (such as receipts and account notices).
Push notifications. You can disable push notifications through your device settings.
Account deletion. You can delete your account through the app or by emailing support@koffr.ai.
7. State Privacy Rights
If you are a resident of a U.S. state with a comprehensive privacy law, including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), or any other state that grants substantially similar rights, you have the rights described below. The specific scope of each right depends on your state’s law. To exercise these rights, email legal@koffr.ai from the email address associated with your account, putting your state’s name in the subject line (for example, “California Privacy Request”). We may need to verify your identity before responding. You may also designate an authorized agent to make a request on your behalf.
We will respond to verifiable requests within the timeframe required by your state’s law (generally 45 days, with a possible 45-day extension where reasonably necessary).
a. Rights summary
Subject to certain exceptions, you have the right to:
- Know / access what personal information we have collected about you, the sources, the purposes, and the categories of recipients;
- Port a copy of the personal information we have collected;
- Delete your personal information;
- Correct inaccurate personal information;
- Limit the use of sensitive personal information (where applicable);
- Opt out of the sale or sharing of personal information (not applicable, as we do not sell or share);
- Opt out of profiling for decisions producing legal or significant effects (not applicable, as we do not engage in such profiling);
- Non-discrimination — we will not discriminate against you for exercising these rights.
b. California-specific disclosures (CCPA/CPRA)
In the past 12 months, we have collected the following categories of personal information, as defined by the CCPA:
| CCPA Category | Examples we collect | Source | Purpose | Retention |
|---|---|---|---|---|
| Identifiers | Email, account ID, IP address | You; auth provider | Account, security, support | Per §5 |
| Customer records | Email, billing zip, last four of card | You; Stripe | Payment, support | Per §5 |
| Commercial information | Subscription status, transaction history | You; Stripe | Service operation | Per §5 |
| Internet/network activity | App usage events, device info, crash logs | Automatically | Service operation, debugging | Per §5 |
| Geolocation (coarse) | IP-derived approximate location | Automatically | Security, fraud prevention | Per §5 |
| Sensitive personal information | Account credentials (authentication); tax filing status, salary, retirement contributions, age | You | Authentication; generating projections | Per §5 |
We do not collect Social Security numbers, driver’s license numbers, biometric information, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic data, or health-condition data.
The “Sensitive Personal Information” we collect is limited to account credentials (used solely to authenticate you) and financial information you provide (used solely to generate the projections you have requested). We do not use either category for purposes that would require an opt-out under CCPA, and we do not infer characteristics about you from this information beyond what is necessary to provide the Service.
Sale or sharing. We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising. We have not sold or shared personal information in the past 12 months.
8. Children’s Privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, please contact us at legal@koffr.ai and we will take steps to delete the information.
9. International Users
The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to that transfer and processing. We do not represent that the Service complies with the GDPR, UK GDPR, or other non-U.S. privacy regimes, and we do not target users outside the United States.
10. Third-Party Links and Services
The Service may contain links to third-party websites or services (for example, the IRS, plan administrators, or financial-product issuers). We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing them with information.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If the changes are material, we will provide notice (such as by email or in-app notice) at least 30 days before they take effect, where reasonably practicable. The “Last Updated” date at the top reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
12. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us at:
Koffr Inc. 300 Delaware Avenue Wilmington, DE 19801 United States legal@koffr.ai
For state privacy rights requests, please use the email above and put your state’s name in the subject line (for example, “California Privacy Request”).