Privacy
This describes what Kamino accesses in your accounting records, what it does with it, and how you stop it. It is written to be understood, not to reassure.
Last updated
9 August 2026
What we access
Kamino reads from the sources you connect, and nothing is connected unless you connect it. Eight data domains are connected, each by a direct API or by the spreadsheet connector:
- Accounting — your ledger: invoices, bills, journal entries, accounts, projects, clients and departments. The supported accounting platform is QuickBooks Online today, with further accounting platforms opening.
- CRM — pipeline, deals, win/loss and the client records attached to them.
- Accounts payable — vendor bills, approvals and committed spend.
- Resourcing — assignments, allocations and capacity by person and project.
- HR — employee records used for the operating picture: name, role, department, employment status and start and end dates.
- Payroll — pay and employment-cost data used to compute a true cost rate and burden. This is sensitive personal data, and it is read for that purpose only.
- Expenses — expense claims, card spend and client recharges.
- Time tracking — timesheet hours by person, project and task, billable and non-billable.
AR & Collections is a ninth domain and is not available yet; nothing is read from it until it is, and you connect it.
In every domain we read only what the source you connected exposes to us, and only what the figures are made of.
Access is read-only, and it is yours to grant
Access is granted through your own OAuth consent with the source system, and it is read-only. Kamino does not write back to your ledger. You can revoke that consent at any time, either in Kamino or directly in the source system, and the connection stops.
What we do with it
Your records are processed to compute and display your own operating figures — revenue, margin, hours, contribution, by project, client and department — and to show you the records each figure was derived from.
That is the whole purpose. Specifically:
- We do not sell your data, and we do not share it for advertising.
- We do not use your data to train models.
- We do not use your data to build benchmarks or datasets about other companies.
Sub-processors
These are the third parties that process anything on Kamino's behalf, and what each one does:
- Cloud hosting — stores and processes the data on our behalf. Named provider and hosting region: [TO BE CONFIRMED: hosting provider and region]
- Stripe — subscription billing. Stripe does not receive your accounting records: a checkout session carries your organisation id and a plan code, nothing from your ledger.
- Resend — transactional email, limited to teammate invitations. The only outbound email Kamino sends is the invitation hand-off when an admin invites a teammate. Resend does not receive your accounting records, and when it is not configured the feature sends nothing rather than failing.
Revoking access and deleting your data
To revoke access, disconnect the integration in Kamino, or remove Kamino's authorisation in your accounting platform or the relevant source system. Revoking stops all further reading immediately.
To request deletion of the data we already hold, contact us and ask for it. We will confirm when it is done.
Retention period for data after account closure or a deletion request: [TO BE CONFIRMED: retention window after account closure or deletion request to be confirmed]
Contact
Questions about this policy, access, or deletion go to info@kamino.app.
Contracting and responsible entity: Kamino App LLC. Kamino App LLC is a Florida limited liability company and a subsidiary of Connected Strategies LLC, an Illinois limited liability company. Registered address: [TO BE CONFIRMED: registered address for Kamino App LLC (Florida) to be confirmed]
Governing law and jurisdiction for this policy: [TO BE CONFIRMED: governing law and jurisdiction to be confirmed — formation in Florida does not by itself determine choice of law]