How Angka handles your data
Personal data notice under the Personal Data Protection Act 2010. Last changed 15 September 2026. Pilot edition.
Angka is a bookkeeping assistant for small businesses, run by REKA Inisiatif Sdn Bhd (“REKA”, “we”). You give it bank statements, invoices, receipts and notes; it works out what they mean and keeps the evidence together. This page says what we hold, why, who else sees it, and what you can do about it. A version in Bahasa Malaysia is available on request.
What we hold
- Your account: name, email address, a hashed password, and when you signed in.
- Your workspace: the business name, registration details you type in, the people you invite and their roles.
- Your records: every file you add or email in (statements, invoices, receipts, contracts, photos, recordings), the emails themselves, the bank lines read from statements, the activities, people, notes and figures Angka builds from them, and the trail of who confirmed what.
- Other people’s details inside your records: the names, account numbers and amounts of the clients, suppliers, employees and agencies that appear on your documents. You are responsible for having the right to keep those records; we process them only for you.
- How the service ran: which AI model read which document, what it cost, whether it was right, and errors the app hit. Never the contents of your books beyond what a specific error needs.
Why
- To do what you asked: read your documents, keep your books, show your figures, hand them to your accountant.
- To keep the service working: sign you in, route your emails, fix faults, stop abuse.
- To improve accuracy: a small set of made-up documents is used to test each change; your real documents are not added to it without your written yes.
We do not sell personal data, and we do not use your records to advertise anything to anyone.
Who else sees it
| Who | What they get | Where |
|---|---|---|
| Supabase | The database and the file store. Everything above lives here, encrypted at rest, one private bucket per workspace. | Singapore |
| Vercel | Runs the app. Sees requests as they pass; keeps logs for a short time. | Singapore (functions), global edge |
| Cloudflare | Receives email sent to your workspace address and hands it to the app. | Global |
| Anthropic and Google | AI models read a document or a batch of bank narrations to pull out the figures, the dates and the names. They receive the document and the business name, nothing else about you. Both are used under API terms that do not train models on what is sent. | United States |
| Resend | Sends sign-in, confirmation and password emails: your address and the link. | United States |
| People you share with | A read-only link you make shows one activity, one month or the document list to whoever holds it, until you revoke it. | Wherever they are |
Some of this data therefore leaves Malaysia. Each provider is bound by its own contract to keep it confidential and to use it only to provide the service. We will tell you on this page before adding another.
How long
For as long as your workspace exists. Delete a document and it is gone from the store at once; delete the workspace and everything in it, files included, is removed, with a backup copy expiring within thirty days. Records of what the service did (which model read what, at what cost) are kept without the documents themselves.
Your rights
- See it: everything Angka holds about your workspace can be exported in one go from Settings, as a bundle you can open without Angka.
- Correct it: every figure Angka read can be changed in the app; your own details are under Settings.
- Take it back: an owner can delete the workspace from Settings, or you can ask us to. Your account itself can be deleted on request.
- Say no: you can run a workspace with AI switched off (Settings → AI provider); Angka then keeps only what you type.
For any of these, or a question this page does not answer, write to haziqfaris@reka.re. We answer within twenty-one days, usually far sooner.
Keeping it safe
Every row in the database is tied to one workspace and the database itself refuses to show it to anyone else; that rule is tested on every deploy. Files are reachable only through links that expire. Passwords are hashed, never stored. Operators at REKA can see counts, names and costs in order to run the service, never the contents of your books.
See also the terms of use.