This policy explains how GharHisab handles personal data. It is written to meet the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), and section 43A of the Information Technology Act, 2000 with the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").
A short, itemised notice is also available: Privacy Notice (DPDP) · हिन्दी.
1. Who we are
GharHisab is operated by Lokhande Ventures (proprietor: Shivhari Lokhande), Jalna, Maharashtra, India. For the DPDP Act we are the Data Fiduciary for the personal data described here.
Grievance Officer and data protection contact: Shivhari Lokhande — shivhari.lokhande06@gmail.com (see Grievance Redressal).
2. The short version
- Your money stays on your phone. Your financial ledger is stored only on your device, in an encrypted database.
- Our servers run your account, subscription, family sharing, notifications and support. They never receive your transactions, balances, accounts, loans, investments, budgets, goals, net worth or forecasts.
- We show no ads, we do not sell personal data, and our website uses no cookies and no trackers.
- Optional features (bank SMS reading, Gmail, analytics) each need your separate consent and are off until you turn them on.
3. What stays only on your phone
Stored in an encrypted vault on your device and never sent to our servers:
- transactions, income, expenses, merchants and notes;
- bank, cash and card accounts and their balances;
- loans, EMIs, investments and their values;
- budgets, goals, net worth and cash-flow forecasts;
- the contents of bank SMS, emails and receipts used for auto-capture (read and parsed on the device; the message text is not stored, only the transaction found in it).
Financial information is "sensitive personal data" under the SPDI Rules. Because we do not collect your ledger, we do not hold it on our servers. If you make a backup, it is encrypted with a password only you know, and you choose where the file is saved.
4. What our servers keep, why, and for how long
| Data | Purpose | Retention |
|---|---|---|
| Account id, email, mobile number, display name | Sign-in, account recovery, support | While your account exists |
| Plan, trial and subscription status (no card numbers; only what the app store tells us) | Billing and entitlements | As long as tax and billing law requires |
| Referral code and reward status | Running referral rewards | While your account exists; with billing records if a reward was given |
| Household membership metadata (who belongs, roles), invites (hashed token, expiry), join requests (device name you type, key fingerprint, public keys) | Family sharing and access control | While the household exists; invite links expire within 72 hours |
| Guardian consent records for members under 18 | Proof of verifiable parental consent (DPDP Act s.9) | Append-only; while the household exists |
| Device id, public encryption keys (never private keys), last-seen time | End-to-end encrypted sync, key rotation | Until the device is removed |
| Push notification token and platform | Sending notifications (Firebase Cloud Messaging) | Until you sign out on that device or the token changes |
| App version, language, platform | Showing the right notices and announcements | Overwritten on each check-in |
| Encrypted family-sync messages | Delivering changes between your family's phones. They are end-to-end encrypted — we cannot read them | Deleted after 30 days |
| Support tickets and attachments (numbers are redacted before sending), with app version, OS and device model | Helping you | Closed tickets purged on our schedule (default 365 days) |
| Security audit log (actor id, action, outcome, target id, time; no financial values) | Security, fraud and abuse prevention, accountability | At least 1 year (DPDP Rules), default up to 7 years |
| Feature-usage analytics (opt-in only) | Learning which features work | Not linked to your account; groups smaller than 50 people are never shown |
| Job telemetry for sync, import and backup (opt-in only) | Spotting failures | Type, status, timing, error code only — 29 days |
None of this is financial data. Logs are scrubbed on the device before anything is sent; a log line can never contain amounts, balances, account or card numbers, merchant names, notes, SMS or email text, passwords, tokens or PINs. Crash reporting is currently off.
5. Optional features
Bank SMS (Android only). If you allow it, GharHisab reads bank, card and UPI alert SMS on your phone to add transactions. Personal chats and OTPs are ignored. Messages never leave your phone. You can switch this off at any time in Android settings or in Capture settings.
Gmail (optional, read-only). If you choose "Connect Gmail", the app asks Google for read-only access and, on your phone only, finds bank alert emails and extracts transaction details. Nothing from Gmail is sent to our servers. Our use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. We never use Gmail data for advertising, never sell or transfer it, and never use it to train AI or machine-learning models. Disconnect any time in Capture settings → Gmail or at https://myaccount.google.com/permissions.
Analytics and job telemetry. Off by default. Turn on or off in Settings at any time.
6. Legal basis and consent
We process account and operational data on the basis of your consent, given when you create an account, and for legitimate uses allowed by section 7 of the DPDP Act (for example, complying with law or preventing fraud). Every consent request is clear and itemised; nothing is pre-ticked. You can withdraw any consent as easily as you gave it (Settings, or by writing to us). Withdrawal does not affect processing already done, and some features may stop working.
If, in future, you choose to manage consents through a Consent Manager registered with the Data Protection Board of India, we will honour consent given or withdrawn through it.
7. Children and family members
GharHisab is meant for adults running a household. A person under 18 can only be added to a household by their parent or lawful guardian (the family head), after verifiable consent is given in the family flow. We do not track, profile, or target advertising at children. See Children and Family.
8. Who we share data with
We do not sell personal data or share it for advertising. We use these service providers (Data Processors) only to run the service, under contracts that limit them to our instructions:
| Provider | What it does | Location |
|---|---|---|
| Amazon Web Services (Cognito, SES) | Sign-in and service email | Mumbai, India |
| Render | App servers | Singapore |
| Neon | Operational Postgres database | Singapore |
| Cloudflare (Pages, Workers, R2) | Website, admin console, storage of support attachments and encrypted sync envelopes | Cloudflare network (Asia-Pacific for R2) |
| Google Firebase Cloud Messaging | Push notifications | Google global infrastructure |
| Google Play / Apple App Store | Purchases, billing, refunds | As per the store |
We may disclose data when the law requires it (for example, a lawful order from a court or government agency). Family-sync data is shared only between members of your household, encrypted end to end.
9. Transfers outside India
Your financial ledger never leaves your phone. Some account and operational data is processed in Singapore (Render and Neon have no India region today). Section 16 of the DPDP Act permits transfer outside India except to countries the Central Government restricts by notification; Singapore is not restricted. We will update this policy before moving data to another country.
10. Your rights
Under the DPDP Act (sections 11–14) you can:
- Access a summary of the personal data we process and how, and the identities of those we share it with (write to us; export your on-device data from Settings → Export or delete data).
- Correct, complete or update your account details in the app or by writing to us.
- Erase your data: delete your account and on-device data (see Data Deletion). We keep only what the law requires.
- Withdraw consent for any optional feature at any time.
- Nominate another person to exercise your rights if you die or become unable to do so (write to us with the nominee's name and contact).
- Grievance redressal with our Grievance Officer. We acknowledge within 48 hours and resolve within 30 days (the DPDP Rules allow up to 90 days).
- Complain to the Data Protection Board of India if you are not satisfied, after using our grievance process.
To use a right, email shivhari.lokhande06@gmail.com from your registered email (or use Settings → Help & Support). We may ask you to confirm your identity.
11. Security
Your ledger is stored in a SQLCipher-encrypted database with a random 256-bit key held in your phone's Keychain/Keystore, and the app can be locked with a PIN or biometrics. Family sync is end-to-end encrypted. Server data is encrypted in transit and at rest; access is limited to people who need it; sensitive fields are blocked from logs by a single deny-list enforced in the app, on the server and in our build pipeline. These are our reasonable security practices under section 43A of the IT Act and Rule 8 of the SPDI Rules. See Security.
12. Personal data breach
If a breach affects your personal data, we will tell you without delay — what happened, the likely impact, what we are doing, and what you can do — and inform the Data Protection Board of India (with a detailed report within 72 hours) and CERT-In as the law requires.
13. Retention and erasure
We keep personal data only as long as needed for the purpose, then delete it, unless the law requires us to keep it. Under the DPDP Rules we keep certain logs for at least one year. Billing records are kept for the period tax law requires.
14. Changes
We will post changes here with a new version and "Last updated" date. If a change materially affects how we use your data, we will tell you in the app before it takes effect and ask for consent again where required.
15. Contact
Lokhande Ventures (proprietor: Shivhari Lokhande), Jalna, Maharashtra, India Email: shivhari.lokhande06@gmail.com · In the app: Settings → Help & Support
Note on the law: the DPDP Rules were notified on 14 November 2025. Most obligations (notice, rights, breach reporting) apply from 13 May 2027. We follow them now.