Privacy Policy

Your financial data stays on your device — always.

Effective Date: April 18, 2026  |  Version 1.0

The short version

1. Introduction

MyPaisa ("the App") is a personal finance management application developed for individual use in India. This Privacy Policy explains how the App handles information on your device. Because MyPaisa is designed as an entirely offline-first app, the principles here are simpler than most: your data does not leave your phone.

By installing or using MyPaisa you agree to the practices described in this policy. If you do not agree, please uninstall the App.

2. Information the App Accesses

MyPaisa requests the following Android permissions. All data accessed through these permissions is processed entirely on your device.

Permission Why it is needed Data stored?
READ_SMS / RECEIVE_SMS Automatically detects bank credit/debit notifications so you don't have to enter transactions manually. The App scans incoming SMS messages from known bank sender IDs for transaction amounts and account numbers. Message content is never transmitted off-device. On-device only
USE_BIOMETRIC / USE_FINGERPRINT Allows you to unlock the App using fingerprint or face recognition as an alternative to your PIN. Biometric data itself is managed entirely by the Android operating system; the App never sees or stores raw biometric data. OS-managed
INTERNET / ACCESS_NETWORK_STATE Fetches publicly available mutual fund NAV prices from mfapi.in and stock prices from Yahoo Finance APIs. Only ticker symbols and scheme codes (not your holdings details) are sent as query parameters in these requests. No user data sent
POST_NOTIFICATIONS Sends local reminders for upcoming bill due dates. Notifications are generated on-device by Android's WorkManager; no notification content is transmitted externally. On-device only
RECEIVE_BOOT_COMPLETED Reschedules bill-reminder alarms after the device reboots so you don't miss payment deadlines. On-device only
VIBRATE Provides haptic feedback on button taps for a better user experience. On-device only

3. How Your Data is Stored

All financial information you enter — accounts, transactions, investments, budgets, loans, bills — is stored in a local SQLite database on your device. This database is encrypted using SQLCipher (AES-256) with a unique encryption key generated on your device and secured inside the Android KeyStore. Neither the data nor the encryption key ever leaves your phone.

Your PIN is never stored in plain text. It is hashed using SHA-256 with a fixed application-level salt before being saved to Android DataStore Preferences. The App cannot recover your original PIN.

No cloud backup. The App sets android:allowBackup="false" and explicitly excludes sensitive files from Android's Auto Backup service. Your financial data is not automatically backed up to Google Drive or any other cloud service.

Retention: your data remains on your device until you uninstall the App or manually delete records within it. Uninstalling the App removes all locally stored data.

4. What We Do Not Collect

MyPaisa does not:

5. Network Requests

The App makes outbound network requests for the sole purpose of fetching publicly available market prices:

All network communication uses HTTPS (TLS) exclusively. Plaintext HTTP traffic is blocked by the App's network security configuration.

These third-party services have their own privacy policies independent of MyPaisa.

6. SMS Access — Detailed Explanation

Because READ_SMS and RECEIVE_SMS are considered sensitive permissions by Google Play, we explain exactly how the App uses them:

The permission is used in accordance with Google Play's SMS and Call Log Permissions policy. You may deny this permission; doing so simply means you will need to enter transactions manually.

7. Security Measures

MyPaisa implements multiple layers of security appropriate for a financial application:

While we have taken reasonable precautions to protect your data, no security system is infallible. We recommend keeping your device PIN/password enabled and keeping the App up to date.

8. Children's Privacy

MyPaisa is not intended for use by children under the age of 18. We do not knowingly collect any information from minors. If you believe a minor has used this App, please contact us at the address below and we will provide guidance on removing locally stored data.

9. Your Rights Under Indian Law

MyPaisa complies with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 (including the IT (Reasonable Security Practices and Procedures) Rules, 2011).

Because all data is stored exclusively on your own device and we do not collect or process your personal data on any server, most data-subject rights (access, correction, portability, erasure) are exercised directly by you within the App or by uninstalling it. Specifically:

If you have any questions about exercising these rights, please contact us using the details in Section 11.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Effective Date" at the top of this page and release an updated version of the App. Your continued use of the App after an update constitutes acceptance of the revised policy. Material changes will be highlighted in the App's release notes on Google Play.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your data, please reach out:

Developer: Ashish Kapoor
Email: kapoorashish213@gmail.com
App: MyPaisa — Personal Finance Manager
Country: India

We aim to respond to all privacy-related enquiries within 30 days.