kasama.loan
Whitepaper · v1.0

Settling casual debts without the awkwardness.

A two-way verification ledger for the loans friends and family actually make — built mobile-first for the Philippines, open to everywhere.

Author: kasama.loan Status: Live Updated: June 2026
01 — Abstract

Abstract

Most money lent between people who know each other leaves no trace. A friend covers your share of dinner; a cousin borrows for tuition; a workmate spots you for a concert ticket. The amounts are small enough to be informal and large enough to quietly corrode a relationship when memory and goodwill diverge.

kasama.loan is a free, mobile-first ledger for exactly these loans. Its defining mechanism is a two-way confirmation loop: a debt is only “real” once both parties have acknowledged it, turning a one-sided claim into a mutually agreed record. From that shared record, kasama can generate calendar reminders and tamper-evident PDF documents that either party — or a neutral third party — can verify. The service runs entirely on edge infrastructure, keeps money in integer centavos to avoid rounding drift, and is sustained by an unobtrusive free tier plus an optional Pro subscription.

In one sentence

kasama replaces “I’m pretty sure you owe me” with a record both people already agreed to.

02 — Problem

The quiet cost of an informal “utang”

In Filipino, utang is a casual debt, and lending within one’s circle is woven into daily life. That informality is a feature socially and a bug financially. Three failures recur:

Spreadsheets and notes apps solve only the lender’s memory — they are still one-sided. Formal lending apps over-solve it, importing credit checks, interest-by-default and collections energy that have no place between a parent and child. kasama sits deliberately in the gap: structured enough to be a record, light enough to use between people who love each other.

03 — Positioning

What kasama is

Kasama is the Filipino word for a companion — the person you are with. The name is the thesis: this is a tool for money between people who are already on the same side.

kasama is a tracker and an agreement layer, not a lender. No money moves through it. It never advances funds, charges interest, or pursues collection. It records what two people decided, helps them remember it, and — when they want — gives them a document to prove it. It is Philippine-first in language, currency formatting, and payment vernacular (GCash, Maya, bank transfer, cash), but nothing about it is country-locked.

Track casual loans and more, settled without the awkwardness.
04 — Core mechanism

The Confirmation Wall

The heart of kasama is a refusal to let one person unilaterally define a debt. When a lender logs a loan, it does not enter the ledger as fact. It enters as a pending request addressed to the borrower, who must explicitly confirm or reject it. Only on confirmation does the loan become active and start counting in either person’s totals.

Lender logs loan Borrower sees request Both agreed · active

This single design choice produces most of kasama’s value:

Why a wall, not a notification

A notification can be ignored; an unconfirmed loan simply isn’t counted. The friction is the point — it guarantees that everything in the ledger was mutually acknowledged.

05 — State model

The ledger lifecycle

Every loan is a small state machine. Beyond the active path, kasama models the full social reality of casual debt — including the graceful ways debts end without being repaid.

pending active settled
alternate endings → rejected forgiven hidden
Pay
The borrower marks a payment — in full, or a partial amount — and the lender confirms it. Only confirmed payments move the balance.
Partial
A debt can be paid down in instalments: each confirmed payment shrinks the remaining balance until it reaches zero and settles.
Dispute
If a claimed payment never actually arrived, the lender marks “no payment received” and the loan returns to active — nothing settles on one side’s say-so.
Forgive
The lender writes the debt off deliberately — a first-class action, because “never mind it” is how a great many real loans actually end.
Hide
Remove a loan from your totals without forgiving it — a middle ground for debts you’re not chasing but don’t want to formally cancel.
Reject
The borrower disputes the request before it ever becomes active. Nothing enters the ledger.

Balances are computed from the event history rather than stored as a mutable number, and every amount is held in integer centavos — so repeated interest or split-the-bill math never accumulates floating-point drift.

06 — Scope

Beyond one-to-one

Casual debt is rarely a clean pair of people. kasama scales the same confirmation principle up to groups and out to people who haven’t joined yet.

🤝

Friends

Add people by a stable User ID. Friendship is a request the other side accepts — with a cooldown to stop repeat spam.

Circles

Reusable groups (housemates, the barkada) for one-tap selection. A person can belong to any number of circles.

🧾

Events & splits

Log what you paid on a trip or dinner — you can only enter your own spending, never someone else’s. Or scan a receipt: it’s read into line items everyone can tap to claim, with tax and service split proportionally. “Settle up” turns each person’s share into individual loans, minimised to the fewest transfers, each still confirmed both ways.

🔗

Invite links

Lend or invite to an event via a share link or QR — it works whether the person is already on kasama or brand new, and binds to their account the moment they open it. One link can onboard several people.

Joining an event is opt-in: a friend’s invite waits in a tray for you to accept, and a QR or share link lets anyone join directly. Settling is per-person and incremental — you clear only what you currently owe, a payment is final only once the person receiving it confirms, and a late expense re-opens just the people it affects while settled transfers stay put. The organiser can close an event to new expenses once the spending is done.

Receipt scanning sends the photo to a scanning AI only to read it into text, then discards the image — it is never stored. The parsed items are always shown in an editable list before anything is added, so a misread never silently becomes a debt.

Loans can be cash or an item (with an optional declared value for the record). Interest and instalments exist for the rarer, larger loan that genuinely needs them — opt-in, never the default, with custom repayment intervals bounded to a sensible 7–30 days.

07 — Proof

Verifiable documents

For loans that warrant it, kasama generates a clean, formal PDF acknowledgement of the debt. Each document carries a SHA-256 fingerprint of its canonical loan data and a QR linking to a public verification page.

It is worth being precise about what this does and does not prove:

Honest framing

kasama is not a notary and a kasama PDF is not a court instrument. It is strong, checkable evidence that both parties agreed to a specific record — which for the overwhelming majority of personal loans is exactly the assurance that was missing.

Showing a counterparty’s verified email on a document is strictly opt-in, requested per loan from each party. Separately, when paying, a borrower may attach an optional payment-proof image for the lender to check — it auto-deletes about a week after the payment is confirmed, unless the lender keeps it.

08 — Reminders

Reminders & notifications

Chasing a debt is the awkward part, so kasama offloads it to tools people already trust. Each loan with a due date exports an iCalendar (.ics) entry — compatible with Google, Apple, and Outlook calendars — and every user gets a private, subscribable feed of all their upcoming due dates that refreshes on its own.

The reminder then comes from the borrower’s own calendar, not a guilt-laden message from the lender. Inside the app, a notification feed separates what needs you (a loan to confirm, a claimed payment to confirm) from what just happened (your loan was accepted, your payment confirmed, a debt forgiven) — the first is always derived from live state so it’s never stale; the second is a short, self-clearing history.

09 — Trust

Trust & data ownership

A ledger of who-owes-whom is sensitive by nature, so the defaults lean private.

10 — Security

Security posture

kasama runs as a single application on globally-distributed edge infrastructure, for low latency worldwide and cost that scales to near-zero at rest. Platform and implementation specifics are intentionally left out of this document — what matters to users is the security model, and that model is designed so the worst case stays small.

No funds
kasama never moves, holds, or can access money. There is no balance to drain, freeze, or breach — the blast radius of any incident is a record, not a peso.
Minimal data
Accounts are created through a trusted identity provider; kasama stores no passwords. Sensitive details such as a verified email are revealed only with explicit, per-loan consent.
Encrypted secrets
Every credential lives in an encrypted secret store — never in source, configuration, or logs.
Exact money math
All amounts are integer minor units (centavos) end-to-end, so interest and split math never drifts.
Tamper-evident records
Formal documents carry a content fingerprint anyone can re-check; the live ledger is the source of truth, not any copy of a document.
Bounded storage
Uploaded images sit in object storage behind a hard cap and automatic lifecycle cleanup, so cost and exposure stay bounded; payment proofs auto-delete shortly after a payment is confirmed.
Capability links
Invite/claim links are unguessable, single-purpose, and time-limited — holding one only lets a signed-in person claim that one record.

The core logic — the verification state machine, balance computation, and group clearing — is isolated from infrastructure and covered by a deterministic test suite on every change, so correctness never depends on any single platform.

11 — Sustainability

Sustainability & pricing

kasama must pay for itself without compromising the casual experience. The prime directive on monetisation is restraint: ads are inline and unobtrusive only — never pop-ups, interstitials, or anything that interrupts the core flow — and Pro removes them entirely.

PlanPriceWhat you get
Free ₱0 The full ledger, friends, circles, events, guests, reminders. Supported by unobtrusive inline ads. One interest-bearing loan included; pay-per-document for formal PDFs.
Pro · monthly ₱150/mo Ad-free, unlimited interest/installment loans, and formal verifiable PDFs included.

Three revenue lines — restrained ads on the free tier, the Pro subscription, and pay-per-document — are deliberately layered so the product can cover its edge-infrastructure costs before it is widely known, while keeping the essential tracker free.

12 — Roadmap

Roadmap