🔒 Privacy Policy

How we collect, use, and protect your information

Last Updated: February 11, 2026

Introduction

At Hisab Expert, we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use our mobile application and services.

âš ī¸ Important:

By using Hisab Expert, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use our app.

Information We Collect

1. Personal Information

  • Phone Number: For account creation and authentication (OTP login)
  • Business Name: Name of your shop/store
  • Language Preference: Hindi or English
  • Business Type: Kirana, Medical, Hardware, etc.

2. Business Data (Stored Locally & Optionally in Cloud)

  • Transaction Records: Income and expense transactions with amounts, dates, categories
  • Inventory Data: Product names, prices, stock quantities, units
  • Customer Information: Customer names, phone numbers, credit/debit balances
  • Voice Recordings: Temporary voice data for voice command processing (deleted after processing)
  • OCR Scans: Images uploaded for text extraction (deleted after processing)

3. Automatically Collected Information

  • Device Information: Device model, OS version, app version
  • Usage Data: Features used, app crashes, error logs (anonymized)
  • UPI Notifications: If enabled, we read UPI transaction notifications to auto-add transactions

â„šī¸ Data Storage:

  • Primary Storage: All data stored locally on your device (encrypted)
  • Cloud Backup: Optional - only if you enable cloud sync
  • We DO NOT access: Your contacts, SMS, call history, or location
  • Camera/Photos: Accessed ONLY for the OCR ledger-scan feature — images are processed on-device and immediately deleted; never stored or uploaded to our servers

Permissions We Request

Hisab Expert requests the following Android permissions. Each permission is used only for the stated purpose and can be revoked at any time from Android Settings → Apps → Hisab Expert → Permissions:

PermissionWhy We Need ItOptional?
INTERNETOptional cloud backup & sync across devicesYes
RECORD_AUDIOVoice entry — speak product names & amounts to record transactions hands-freeYes
CAMERAOCR ledger scanning — photograph handwritten records to import transactions automaticallyYes
READ_MEDIA_IMAGES / READ_EXTERNAL_STORAGESelect existing photos from gallery for OCR scanning; save and share invoice PDFsYes
USE_BIOMETRIC / USE_FINGERPRINTApp Lock — fingerprint or face unlock to protect your business data from unauthorised accessYes
FOREGROUND_SERVICE / FOREGROUND_SERVICE_DATA_SYNCKeeps the UPI notification-listener running in the background. A persistent notification is shown while this service is active so you always know it is running.Yes — only active when UPI auto-detection is enabled
RECEIVE_BOOT_COMPLETEDAutomatically restarts the UPI detection service after device reboot — only if you had previously enabled UPI auto-detectionYes
REQUEST_IGNORE_BATTERY_OPTIMIZATIONSRequests battery-optimisation exemption so UPI detection works reliably without being killed by Android. You can deny or revoke this at any time from Battery Settings.Yes
POST_NOTIFICATIONSRequired on Android 13+ to display the UPI detection foreground service notificationYes
BIND_NOTIFICATION_LISTENER_SERVICEReads UPI payment notifications from Google Pay, PhonePe, Paytm, BHIM, Amazon Pay, etc. to auto-add transactions. Does NOT read SMS. Must be explicitly enabled by you via Android Settings → Special App Access → Notification Access.Yes — explicit user action required

✅ All permissions are optional:

Core bookkeeping features — adding transactions, managing inventory, and the customer ledger — work without granting any of the above permissions. Each permission unlocks an additional feature only. You can revoke any permission at any time from Android Settings without losing your existing business data.

How We Use Your Information

  • ✓ Provide Core Services: Transaction tracking, inventory management, reports
  • ✓ Authentication: Verify your identity via OTP
  • ✓ Data Sync: Sync your data across devices (if enabled)
  • ✓ Voice Commands: Process voice input to extract product information
  • ✓ OCR Scanning: Extract text from uploaded images
  • ✓ UPI Auto-Detection: Read UPI notifications to auto-add transactions
  • ✓ Improve App: Analyze anonymized usage data to fix bugs and add features
  • ✓ Customer Support: Respond to your queries and technical issues

đŸšĢ What We DON'T Do:

  • ❌ Sell your data to third parties
  • ❌ Share your business data with advertisers
  • ❌ Use your data for targeted advertising
  • ❌ Access your contacts, photos, or messages

Data Security

We implement multiple layers of security to protect your data:

  • 🔐 Encryption: All data encrypted using AES-256 (bank-level encryption)
  • 🔒 Local Security: Data stored locally using Android Keystore / iOS Secure Enclave
  • â˜ī¸ Cloud Security: Data transmitted via TLS 1.3, stored on AWS with encryption
  • 🔑 Authentication: OTP-based login, no passwords to steal
  • 📱 Device Protection: Data tied to your device - cannot be accessed from other devices without authorization

Your Rights

You have the following rights regarding your personal data:

  • ✓ Right to Access: Request a copy of your data in Excel/PDF format
  • ✓ Right to Delete: Permanently delete your account and all data (see Data Deletion page)
  • ✓ Right to Correct: Update or correct your business data anytime
  • ✓ Right to Portability: Export your data and transfer to another service
  • ✓ Right to Withdraw Consent: Disable cloud sync, UPI detection, or analytics

Data Retention

  • Active Accounts: Data retained as long as your account is active
  • Deleted Accounts: Data permanently deleted within 7 days of deletion request
  • Backups: Deleted data removed from backups within 90 days
  • Legal Retention: Some data may be retained for legal/tax compliance (anonymized)

Children's Privacy

Hisab Expert is intended for business use by adults (18+ years). We do not knowingly collect information from children under 13 years (or 16 in Europe). If you believe a child has provided us with personal information, please contact us immediately.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will:

  • Update the "Last Updated" date
  • Notify you via app notification or email
  • Require you to review and accept the updated policy

Contact Us

If you have questions about this Privacy Policy or your personal data, please contact us: