Skip to content
CoukanClosed alpha
Why “Coukan”FeaturesTester sign-inDownload Mac

Effective July 16, 2026 · Closed alpha

Privacy policy

Coukan keeps a shared financial record; that makes restraint and clarity more important than broad data collection. This policy describes the current closed alpha, including the public site, web app, iPhone app, and macOS app.

The short version

Coukan uses account and group data to provide the service. It does not sell personal data, run ads, track people across services, move money, or upload diagnostic logs automatically.

1. Who operates Coukan

Coukan is an independent hobby project operated by Andrew Jansen as an individual, not by an LLC or other company. Andrew Jansen is the data controller where that term applies. Privacy questions and requests may be sent to privacy@coukan.app.

2. Closed-alpha scope

Access is limited to invited testers who are at least 18 years old. Public registration is disabled. Coukan is not directed to children, and it does not knowingly collect personal data from anyone under 18. Contact the privacy address if data about a minor may have been added.

3. Information Coukan processes

Account and profile

Email address, display name, account identifiers, verification and session state, and an optional profile image. Supabase Auth processes password credentials; Coukan’s application database does not store plaintext passwords.

Shared group records

Group and member names; optional placeholder contact details; expense descriptions, dates, amounts, currencies, payers, and splits; payments, reconciliation, categories, budgets, estimates, activity, notices, and archived recaps.

Support communications

The sender address and content of messages sent to support, privacy, or security channels, plus the response and resolution history.

Technical and security data

Standard connection data such as IP address, browser or device type, request time, authentication events, and provider security logs. The native app also keeps size-bounded, redacted diagnostics on the device unless the tester chooses to export and send them.

Information comes from the tester, other members of the same group, the tester’s device, and the infrastructure used to deliver the service. Coukan does not collect contacts, precise location, microphone data, or advertising identifiers.

Optional receipt and invoice photos are governed by a supplemental notice. A reauthenticated privacy-right export may include live receipt metadata within the tester’s ledger scope even when optional in-app receipt access is not enabled; it excludes image bytes, storage paths, and deleted receipt tombstones.

4. Why the information is used

  • Authenticate accounts and maintain secure sessions.
  • Store and synchronize shared groups and calculate balances.
  • Record expenses, payments, reconciliation, and group history.
  • Provide optional profiles and private group-member avatars.
  • Answer support, privacy, and security requests.
  • Protect accounts, investigate abuse, and diagnose failures.
  • Comply with law and enforce the closed-alpha terms.

Where a legal basis is required, this processing is necessary to provide the tester-requested service and to pursue legitimate interests in security, reliability, and preventing misuse. Consent is used where law requires it and may be withdrawn for optional processing without affecting earlier lawful use.

5. Who can see or receive information

Members of a group can see that group’s member names and shared ledger records. They cannot browse unrelated groups. Account email, private invitation fields, and internal account status are not part of the member-visible profile. Avoid putting sensitive personal details into group names, descriptions, or notes because those fields are visible to the group.

Coukan relies on a small set of service providers:

  • Supabase provides authentication, PostgreSQL data, private avatar storage, and related security infrastructure.
  • Cloudflare provides web hosting, content delivery, and request-level security for Coukan web properties.
  • Transactional email infrastructure delivers required account messages through the configured Supabase Auth service. Coukan does not send marketing email.
  • Frankfurter supplies public reference exchange rates. A lookup sends standard network metadata, currency codes, and a date; it does not intentionally send account, group, description, or amount data.
  • Apple may process distribution and device-level data when a tester installs or uses an Apple-platform build.

Providers may process data only to deliver their contracted services or as independently disclosed by the platform. Information may also be disclosed when legally required, to protect users or the service, or in connection with a future transfer of the project after notice and appropriate safeguards. Coukan does not sell or rent personal data.

6. Cookies, sessions, and privacy signals

The public information site has no advertising or analytics trackers and does not set marketing cookies. The signed-in web application uses essential browser storage to keep an authenticated session and user preferences. Blocking that storage may prevent sign-in.

Coukan does not track people across unrelated services, so browser Do Not Track and Global Privacy Control signals do not cause a different sale, sharing, or advertising behavior. The same no-sale and no-tracking practice applies whether or not those signals are present.

7. Retention and deletion

Account and group data is kept while needed to operate the closed alpha and preserve the shared ledger. Pending placeholder contact data is kept until the owner removes it or the related membership is resolved. Support correspondence and security records are kept only as long as needed to resolve the request, protect the service, or meet legal obligations.

A verified deletion request removes or deidentifies profile data after account ownership and group responsibilities are resolved. Shared financial records may retain a neutral member label and transaction history when deletion is necessary to avoid changing another member’s ledger. An affected active member may receive a limited in-app notice about a changed group role, neutral identity, or balance action. The notice does not disclose the former account, email, deletion reason, or request status. Ordinary deletion does not send counterparty email. Provider backups and security logs expire through their normal restricted retention cycles rather than being edited in place.

Redacted native diagnostic files remain on the tester’s device, rotate when they reach their size limit, and are never uploaded automatically. The tester controls exported copies. Export and deletion requests are verified through the authenticated account and fulfilled manually through the privacy address during the closed alpha.

8. Choices and privacy rights

Testers can update their display name and optional avatar in the app. A tester may request access, correction, a portable copy, restriction, objection, or deletion by emailing the privacy address from the account email. Identity must be verified before account data is disclosed or changed. Some requests may be limited where data must be retained for another person’s rights, security, fraud prevention, or law.

Depending on location, a tester may also complain to a local privacy or data-protection authority. Coukan will not discriminate against a tester for exercising an applicable privacy right.

9. International processing

Infrastructure providers may process data in countries other than the tester’s home country. Those locations may have different privacy laws. Provider terms and any legally required transfer safeguards apply; questions about a specific transfer may be sent to the privacy address.

10. Security

Coukan uses encrypted network connections, verified accounts, private avatar storage, restricted client credentials, row-level database authorization, least-privilege operations, and redacted diagnostics. Access is limited to closed-alpha testers. No internet service can promise absolute security, and testers should use unique passwords and report suspicious activity promptly.

11. Changes and contact

This policy will be updated when Coukan’s data practices or public availability change. The effective date will change, and invited testers will receive direct notice before a material change takes effect when appropriate.

  • Privacy and data requests: privacy@coukan.app
  • Account support: support@coukan.app
  • Security reports: security@coukan.app
Coukan

An independently operated hobby project by Andrew Jansen. Closed alpha · 18+ · Invitation only.

PrivacyTermsSupportSecurity

© 2026 Coukan