Version 2026-09-20 · in force since September 20, 2026
Kova stores your bookkeeping — receipts, invoices, customers, hours and bank transactions — so that you can see it back, and nobody else can.
To answer your questions and read your receipts, Kova sends that data to AI services, most of which are based in the United States; we ask for your consent first.
If you connect your bank, Kova fetches your transactions every day — read-only, never payments, and you can disconnect at any time.
Kova never sells your data, never uses it for advertising, and places no trackers on your computer.
You can export everything at any moment, and delete your account for good with a single button.
Kova AI is a bookkeeping tool for self-employed people and small businesses. The data controller is M.M. van den Ham, trading as Kova AI, established in the Netherlands.
Dutch Chamber of Commerce (KvK) number: 97570931
Questions about this statement, or want to exercise your rights? Email miguel.morrison.business@gmail.com. You will get an answer within 30 days, as the GDPR requires.
There is no data protection officer; Kova is too small to need one.
Your account: email address and password (encrypted), or your Apple account if you sign in that way.
Your bookkeeping: receipts and their photos, invoices, quotes, customers, hours worked and your VAT overviews.
Your business details: company name, chamber of commerce number, IBAN and whatever else you enter for your invoices.
Your bank transactions: amount, date, counterparty account and description, if you connect your bank.
Your conversations with Lex, and what Lex remembers about the way you book (for example that a regular supplier always belongs in the same category).
What you say out loud, if you use Lex's voice.
Your agreement: that you are 18 or older, which version of the terms and of this statement you agreed to, when, and whether you consented to the AI services.
Technical data: your IP address and error reports, to make the service work and to fix failures.
Providing the service — showing your bookkeeping, creating invoices, calculating VAT, connecting and syncing your bank: performance of the contract (GDPR art. 6(1)(b)).
Your subscription and payments, via Stripe on the website or via Apple in the app: performance of the contract.
Lex's AI services — answering your questions, reading receipts, understanding and speaking your language: consent (GDPR art. 6(1)(a)). You give it before your first conversation with Lex and can withdraw it at any time; Kova then carries on without Lex.
The bank connection additionally runs on the consent you give at your own bank (PSD2). That lasts at most 180 days; after that your bank asks again.
Our own bookkeeping and the retention duty that comes with it: legal obligation (GDPR art. 6(1)(c), Dutch AWR art. 52).
Recording that you agreed to the terms, this statement and the AI services: legal obligation, because the GDPR requires us to be able to demonstrate it (art. 5(2) and art. 7(1)).
Security, preventing abuse and fixing crashes of the app: legitimate interest (GDPR art. 6(1)(f)) — Kova has an interest in the service staying up, which outweighs the slight intrusion of an error report that carries none of your figures.
Kova never sells your data, does not use it for advertising, and makes no decisions about you by automated means alone.
Kova does not build everything itself. Below is every party that processes data about you, what for, where that data is held, and — where that is outside the EU — on what basis the transfer is allowed (GDPR art. 44-46). This list is taken straight from the code: add a service, and the checks fail until it is listed here.
| Party | What for | Where | Basis for transfer |
|---|---|---|---|
| Supabase | Your account and all of your bookkeeping: receipts, invoices, customers, hours, bank transactions, your conversations with Lex and the photos of your receipts. | EU — Ireland | No transfer: the data stays in the EU (database in Ireland). The parent company is American; standard contractual clauses apply to that. |
| Vercel | Runs the website and the server routes. In doing so it sees technical data such as your IP address and which page you request. | EU — Frankfurt | No transfer: the data stays in the EU (region fra1). Vercel is additionally certified under the EU-U.S. Data Privacy Framework. |
| OpenAI | The main brain behind Lex: your questions, a summary of your figures and the photos of your receipts are read here to produce an answer. | United States | Standard contractual clauses (SCCs) in the data processing agreement. Kova asks OpenAI to store nothing; OpenAI keeps abuse logs for at most 30 days. |
| Anthropic | Fallback for Lex: if OpenAI does not answer, the same question goes to Claude. | United States | Standard contractual clauses (SCCs) in the data processing agreement, plus certification under the EU-U.S. Data Privacy Framework. |
| Second fallback for Lex (Gemini), and the fallback for Lex's voice when Deepgram has no voice for your language. | United States | EU-U.S. Data Privacy Framework (Google LLC). Google retains free-tier requests for up to 55 days. | |
| Deepgram | Speech: understands what you say and reads Lex's answers aloud. | United States | Standard contractual clauses (SCCs) in the data processing agreement. Deepgram offers an EU endpoint; Kova does not use it yet. |
| Enable Banking | The bank connection: with your consent it fetches your bank transactions from your own bank. Read-only — Kova can never make payments. | EU — Finland | No transfer: the data stays in the EU. |
| Stripe | Paying via the website. Your card details go straight to Stripe; Kova never sees or stores them. Kova only stores your Stripe customer number and whether there is a payment problem. | EU — Ireland (Stripe Payments Europe) | No transfer: the data stays in the EU for the European entity. For support from the US, the EU-U.S. Data Privacy Framework applies. |
| Apple | Paying inside the iPhone app (In-App Purchase) and offering the app in the App Store. Apple tells Kova whether your subscription is running; Kova stores only the transaction number. | EU — Ireland (Apple Distribution International) | No transfer: the data stays in the EU for the European entity. For your Apple account itself, Apple is its own data controller. |
| Resend | Sends email: the invoices and payment reminders you send to your own customers, and messages from Kova to you. | United States | EU-U.S. Data Privacy Framework. |
| Expo | Over-the-air updates for the app. Your device asks whether a new version exists; Expo sees your operating system and a random install number — no name and no figures. | United States | Standard contractual clauses (SCCs) in the data processing agreement. |
| Sentry | Crash reports from the app: if the app goes down, Kova receives the device, the version and the line of code. Crashes only — no usage sessions. Email addresses, IBANs and amounts are stripped out first. | EU | No transfer: the data stays in the EU (EU region). Sentry is additionally certified under the EU-U.S. Data Privacy Framework. |
In your browser Kova keeps your language, your country and a copy of your business profile, so a page does not start out empty every time. That copy knows whose it is: when you log out, everything except language and country is wiped, and another user on the same computer never sees it.
In the app the same is kept, plus whether you turned on the lock with fingerprint or face, when you last exported, and whether you have already seen the first-run explanation.
Kova uses cookies only to keep you signed in. No tracking, no advertising cookies, no analytics cookies — and therefore no cookie banner either.
Your bookkeeping and your account: for as long as you have an account.
Your conversations with Lex and what he remembers: for as long as you have an account, or until you delete them yourself.
The bank consent: at most 180 days, after which it lapses at your bank by itself.
At the AI services: Kova asks them to store nothing. OpenAI keeps requests for at most 30 days to detect abuse, Google for up to 55 days.
Crash reports: no longer than needed to fix the fault, and without your email address, IBAN or amounts.
If you delete your account, Kova first cancels your Stripe subscription, withdraws the bank consent, wipes all your photos and all your data from every table, and finally deletes your login. After that nobody can reach it — not even us. A subscription that runs through Apple you must cancel yourself in your Apple settings; Kova cannot do that for you.
Please note: the law obliges you to keep your own bookkeeping for 7 years (Dutch AWR art. 52). So export it before you delete your account — after that it is gone.
Access (art. 15): see which data Kova holds about you. Use the Export button; you get everything in one file.
Rectification (art. 16): have something corrected. Most data you change yourself in the app; if that does not work, email us.
Erasure (art. 17): have everything deleted. Use Delete account in your settings.
Restriction (art. 18): have Kova keep your data but do nothing with it, for instance while a complaint is running. Email us; we will then freeze the processing instead of letting it continue.
Portability (art. 20): take your data to another service. The export is a machine-readable file meant for exactly that.
Objection (art. 21): object to processing based on legitimate interest, such as crash reports. Email us; we will stop unless there are compelling grounds that outweigh yours, and we will explain which.
Withdrawing consent (art. 7(3)): stop your consent for the AI services or for your bank connection. You can do this at any time, and it does not make what happened before unlawful.
For anything a button cannot do: email miguel.morrison.business@gmail.com. You will get an answer within 30 days.
Not happy with our answer? You may complain to the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl), and you can go to court.
All traffic is encrypted (HTTPS). Your bookkeeping is walled off per account: the database only lets your own rows through, even if something in the code goes wrong.
The photos of your receipts sit in a private folder. They can never be fetched over a public address; a link to one is short-lived and only for you.
Kova cannot make payments from your bank — the connection is read-only.
Kova is intended for business owners of 18 years and older. When you create your account you confirm that you are 18 years or older. Kova is not aimed at children and does not knowingly process their data.
This statement carries a version number (currently 2026-09-20). If something material changes, you will see the new text the next time you open Kova and we will ask for your agreement again. Kova records which version you have seen.
Last reviewed by a lawyer: not yet.