Kosh
Get Kosh

How Kosh keeps your plan safe

Kosh holds your family’s money plan, not your money. This page says how sign-in works, where data is stored, what happens to statements and how to tell us about a problem.

Signing in

Each Member signs in on their own iPhone with a one-time code sent to their email. There is no password to reuse or leak.

Sign-in codes are sent by Cloudflare Email Service from no-reply@ourkosh.com. Kosh never asks for bank or broker logins and cannot move money.

Who can see the plan

The Koshadhyaksha, the treasurer of the Household, sets it up and invites others by email. Every Member can see and edit the Household’s plan.

When a Member is removed from the Household, their sign-in stops at once.

Where data is stored

Household data is stored on Cloudflare, in Workers and a D1 database. Your iPhone keeps a local copy so you can read your plan offline.

Statement files

When you import a statement, the file is read on the server. Kosh keeps the numbers, then deletes the file and its password at once. They are never stored.

CAS PDFs from CAMS or KFintech are read without AI. For loan, insurance, ULIP, PPF and NPS statements, Kosh removes identifiers first, then sends the text to an AI model through OpenCode Console.

Per the model provider’s terms, the data is not used for training.

Access for AI assistants

A Member can create a token so an AI assistant can work with the Household’s plan over MCP. Each token belongs to one Member.

  • The secret is shown once, when you create the token.
  • Kosh stores only a hash of the secret.
  • A token lasts 90 days at most.
  • You can revoke a token at any time.

In transit

The app and the website talk to Kosh over HTTPS only. Plain HTTP connections are not used.

Report a problem

If you find a security problem, write to hello@ourkosh.com with the steps to see it. Please don’t open or change other people’s data while you test.