Who we are
Kit Pay is a Kit Africa service. This policy covers the Kit Pay Android app (com.kit.wallet) and iOS app (africa.kit.pay.ios). In this policy, “Kit Pay”, “we”, and “us” refer to the Kit Africa team responsible for the service. Questions about this policy are handled as described under Contact; account-specific requests are made inside the Kit Pay app.
Kit is not a financial institution. Payment services are provided through RukaPay.
Data we collect
Account and identity data
We process your display name, unique Kit tag, verified phone number, optional email address, country, language, time zone, profile details, authentication factors, and identity-verification status. If identity verification is enabled and you choose to begin it, Didit may collect identity documents, facial or liveness evidence, and verification results under its own notice. Kit Pay stores the minimum session, decision, consent, and compliance evidence needed to operate and audit the process.
Device and security data
We process installation and session identifiers, device name and model, operating-system and app versions, IP address, user agent, provider-specific notification and voice-over-IP push tokens, sign-in and MFA events, trusted-device state, and security audit records. Passwords and payment PINs are stored as one-way hashes. Sensitive credentials and selected identity records are encrypted at rest.
Wallet and payment data
We process wallets, balances, immutable ledger entries, transaction and recipient details, payment requests, links, schedules, merchant activity, bank or mobile-money account references, biller or airtime details, provider references, reconciliation evidence, and fraud or compliance signals. Payment providers, banks, mobile networks, and billers may receive the information required to validate or complete an operation.
When you send or request money in a conversation, the chat can include a payment card containing the amount, currency, transaction status, reference, note, and any acceptance, rejection, cancellation, or reversal reason. The card descriptor travels inside the end-to-end encrypted conversation, while Kit Pay separately keeps the authoritative transaction, ledger, risk, and compliance records required to operate the wallet. The other participant in that conversation can see the payment card and its updates.
Contacts and communications
If you grant Contacts permission and choose to sync, we process contact names and phone numbers to help you find other Kit users. Call records include participants, timing, state, and technical connection details; LiveKit transports call media. Kit Pay does not use call audio or video for advertising. For secure messaging, the service stores encrypted message envelopes and delivery metadata; message plaintext stays on participating devices.
Chat attachments can include photos, videos, voice notes, video notes, and documents selected or captured by you. A participating device encrypts attachment content before upload. Kit Pay stores the encrypted attachment, media type, size, digest, and delivery or routing metadata, but not the attachment decryption key. Participating devices decrypt attachments for display or playback.
If you choose Save or share an attachment, Kit Pay writes a decrypted copy to the device gallery or hands it to the app you select. That new copy is outside Kit Pay's encrypted chat storage and is then controlled by your device, gallery, cloud-backup settings, and the receiving app. Kit Pay does not save received media to the gallery without your action.
During a call, you can choose to share your screen after Android shows its system screen-capture consent prompt. While sharing is active, the visible screen content is sent through LiveKit as live call video and can be seen by the other call participants. Screen sharing may reveal content from Kit Pay or another visible app, including notifications or sensitive information, so review what is visible and stop sharing when finished. Kit Pay does not create a stored copy of the shared screen as part of this feature.
If you report abuse in a one-to-one or group chat, we store the report reason, the accounts and conversation involved, and any explanation you deliberately submit. A group-message report is bound to the authenticated sender you selected. Kit Pay cannot decrypt your messages. You may separately choose up to five messages exchanged with that reported account to share as plaintext with authorized moderators; those copies are sent only after explicit consent, encrypted at rest, and treated as unverified reporter-supplied evidence. We do not automatically attach decrypted history, message ciphertext, media, device identifiers, IP addresses, or user-agent data to an abuse report.
Both mobile apps keep encrypted local communication history for offline display. On Android, a separate AES-GCM archive keeps accepted text-message history and is bound to the account and installation. It does not keep attachments, message-sending authority, an active Signal session, or account-session credentials. On iOS, an AES-GCM-encrypted, iOS file-protected state file can include conversations, messages, drafts, locally cached attachment bytes, queued delivery state, and call history. Ordinary logout removes active secure-messaging and session authority even when display history remains on that device.
Support, AI, and operational data
We process support requests, notification state, feature preferences, and bounded operational logs. AI-assisted insights use selected spending aggregates or a redacted support question and a pseudonymous safety identifier. Azure OpenAI processes that limited request on our behalf; it receives no authority to move money, and Kit Pay requests are configured not to be stored by the model endpoint.
How we use data
- create and secure your account, verify contact details, and manage sessions and authenticators;
- provide wallets, payments, provider services, contacts, calls, notifications, and support;
- verify transactions, reconcile provider outcomes, prevent fraud, and meet financial, sanctions, recordkeeping, and audit obligations;
- diagnose failures, protect the service, measure reliability, and improve user journeys; and
- send required service messages and communications you request.
Where applicable, we rely on performance of our agreement with you, your consent, compliance with law, and our legitimate interests in security, fraud prevention, and reliable service delivery.
Your choices and rights
- You can change your display name and Kit tag in Settings and manage authenticators and device sessions in Security.
- On Android, Contacts, Camera, Microphone, Notifications, and nearby Bluetooth audio permissions support contact discovery, QR scanning, calls, alerts, and connected call audio. You can change them in system settings.
- On iOS, Contacts, Camera, Microphone, and Notifications permissions support contact discovery, QR scanning, calls, and alerts. Selecting an image uses Apple's Photos picker, which shares only the items you choose instead of granting Kit Pay broad photo-library access.
- Android also uses its system photo picker to access only an image you choose. Denying an optional Android or iOS permission limits only the related feature.
- Android requires a separate system MediaProjection confirmation each time you start in-call screen sharing. You can stop sharing from Kit Pay or the system indicator.
- You can report an account or a specific message from a one-to-one or group chat and can block or unblock another user. Sharing selected message plaintext with moderators is optional and requires a separate confirmation.
- If you enable fingerprint, face, Face ID, or Touch ID approval for app unlock or payments, Android or Apple performs the biometric match on your device. Kit Pay receives the approval result or a device-bound cryptographic signature; it does not receive or store your device biometric template.
- Device biometric approval is separate from Didit's optional identity-verification process. Didit may process an identity document, face image, or liveness evidence for KYC under its own notice; enabling a device biometric for Kit Pay does not enroll you with Didit, and completing Didit verification does not give Kit Pay your device biometric template.
- You may ask to access, correct, export, object to, restrict, or delete eligible personal data. Make these requests from inside the Kit Pay app, where your signed-in session securely ties the request to your account; each request is verified before we act.
Security and retention
We use encrypted transport, protected signing and encryption keys, one-way credential hashing, scoped access, device/session revocation, audit trails, isolated provider credentials, backups, and monitoring. No system is perfectly secure. If you believe your account is at risk, open the signed-in Kit Pay app immediately: review your devices and sessions in Settings, sign out anything you do not recognise, and get help from the in-app Help section.
We keep data only while needed for the purposes above and for applicable legal, reconciliation, dispute, security, backup, and audit periods. Retention differs by record type. When retention ends, data is deleted, anonymised, or made inaccessible in ordinary systems.
Encrypted local communication history may remain after ordinary current-device logout, forced reauthentication, or remote device revocation. On Android, the account-bound display archive can remain while another account is signed in. On iOS, retained history is available only to the same account and is erased before a different account's state is adopted. Retained history has no automatic age-based expiry or individual-message deletion path. On Android, “Log out all devices” schedules the initiating Android device's local message archive for deletion. On both platforms, an accepted protected in-app account-deletion request schedules a local purge on the device that submitted it. Interrupted cleanup is retried, but one device, a remote revocation, or a support-assisted request cannot directly erase files held on another or offline device.
Clearing Kit Pay's Android storage or uninstalling the Android app removes its local archive, and Android app backup is disabled. Deleting the iOS app removes its app container and encrypted communication file; using iOS “Offload App” can retain Documents & Data and is not the same as deletion. Kit Pay marks its iOS local-state directory as excluded from device backups, and its Keychain keys use device-only protection so they do not migrate to another device. iOS may retain app-scoped Keychain credentials or keys after app deletion under Apple's platform behaviour, so uninstalling alone is not a substitute for in-app logout or account deletion when credentials must be revoked. Removing local copies from offline devices may require clearing Android storage or deleting Kit Pay from each affected device.
Children and policy changes
Kit Pay is not designed for children under 18. We may update this policy when the service, providers, or law changes. We will publish the new effective date and provide additional notice where a material change requires it.
Contact
Statutory privacy correspondence — questions or complaints about this policy — may be sent to info@kit.africa. This address is not customer support and cannot act on any account: account-specific requests, including rights requests and deletion, are made from inside the Kit Pay app. You may also complain to the data-protection authority that applies where you live.