Play Store Policy Compliant

Privacy Policy & Data Governance

Effective: Aug 21, 2026
App: BeHisabi
Offline-First & Encrypted

1. Introduction & Developer Commitment

This Privacy Policy describes how BeHisabi ("we," "our," or "the Application"), developed by Takbir A. Himu, collects, handles, and protects your financial information and personal data when you use our Android mobile application.

Zero-Monetization Commitment: BeHisabi does not sell, rent, broker, trade, or monetize your transaction entries, account balances, or personal identifiers under any circumstances.

2. Information Handled by the Application

To deliver effortless bookkeeping and financial tracking, BeHisabi processes the following data categories:

Financial Records & Transactions
Income amounts, expenses, custom categories, wallet tags, notes, dates, and timestamps entered manually or scanned via AI.
Google Account Profile & Demographics (Optional)
When opting into cloud sync or personalizing your profile, we receive your Google display name, email, avatar URL via Credential Manager, and optional user profile preferences such as gender or demographic selections configured in account settings.
Device Hardware, Telemetry & Session Duration
We collect basic technical device telemetry such as manufacturer, device model, Android OS version, app version, session duration metrics, and visit timestamps during cloud sync, session tracking, and remote config checks to ensure robust performance, app stability, and backup consistency.
Receipt Images & Camera (Optional)
When capturing a photo for AI smart parsing, the image is transmitted securely over TLS to Google Gemini API strictly to extract transaction parameters (merchant name, itemized amounts, total amount, and timestamp). BeHisabi never scans or extracts banking passwords, card PINs, CVVs, or OTPs.
Strict Zero Banking Access
BeHisabi never requests, scans, or touches your bank credentials, ATM PINs, credit card numbers, or SMS one-time passwords (OTP).

3. Data Storage, Security & Retention Lifecycle

BeHisabi is engineered with an Offline-First Architecture. Your records are stored primarily in a sandboxed local SQLite database managed by Android Room.

  • Sandboxed SQLite Storage: All financial entries stay strictly on your local device storage by default.
  • Encrypted Cloud Sync: If enabled, records sync with Google Firebase Firestore using standard Transport Layer Security (TLS 1.3) and strict Firestore security rules bound exclusively to your verified user ID.
  • Retention & Purge Guarantees: Active cloud Firestore records are deleted within 24 to 48 hours upon verified deletion request. Cloud server rolling snapshot backups cycle out and age out completely within a standard 30-day retention window, during which they remain strictly isolated and inaccessible for operational use.
  • Local Biometric Lock: The app supports Android hardware-backed Biometric Authentication (Fingerprint / Face Unlock) to guard against unauthorized access on shared devices.

4. Third-Party Service Providers, Analytics & AI Processing

We integrate selected industry-standard developer SDKs to maintain security, performance monitoring, cloud sync, and OCR parsing:

  • Google Play Services: Core application delivery, licensing, in-app updates, and integrity verification. Governed by Google Privacy Policy.
  • Google Firebase (Cloud Firestore & Auth): Encrypted cloud database and authentication token verification for optional multi-device backup. Governed by Firebase Privacy & Security Policies.
  • Google Analytics for Firebase: Aggregated, non-personally identifiable diagnostic and engagement analytics (such as session counts, daily active duration, screen views, and retention rates) to evaluate app performance and stability.
  • Firebase Crashlytics: Automated, real-time crash reporting and stack traces collected strictly during unexpected runtime errors to facilitate rapid bug fixing.
  • Firebase Cloud Messaging (FCM): Delivers optional in-app notices, budget reminders, and critical system announcements directly to your device.
  • Google Gemini API: Instant image parsing for smart receipt extraction. Receipt images sent through the scanner are transmitted securely over TLS exclusively to perform Optical Character Recognition (OCR) and extract structured transaction details (merchant name, item totals, and date). No banking credentials, credit card numbers, or PINs are processed. Data processing is governed by Google Gemini API Terms of Service and Google Privacy Policy.

5. Your Rights & Data Deletion

You retain 100% ownership and control over your financial records at all times:

  • Instant Local Wipe: Erase all local databases anytime via Settings > Data Management > Delete All Data.
  • Cloud Purge Request: You may request complete erasure of cloud backup records at any time using our dedicated Data Deletion Portal. For user safety and account protection, deletion requests undergo an ownership confirmation verification step before permanent cloud database purging (executed within 24 to 48 hours).

6. Children's Privacy Protection (COPPA / GDPR-K)

Protecting the privacy of children is of paramount importance. BeHisabi is intended for general audiences and personal financial tracking by adults and youth above the age of consent.

  • No Direct Targeting: BeHisabi does not knowingly solicit or collect personal information from children under 13 years of age (or under 16 in the European Union).
  • Parental Action: If a parent, guardian, or legal representative discovers that a minor has submitted personal data or linked a Google Account without parental consent, please contact us immediately at hello@takbirhimu.me or via our Data Deletion Portal. We will promptly verify and permanently delete the information from our servers.

7. Your Data Protection Rights (Global Users)

Regardless of your country of residence, you have the right to:

  • Access — request a copy of your data (export via in-app CSV/JSON).
  • Rectification — correct inaccurate data directly within the app.
  • Erasure — delete your data instantly (see our Data Deletion Portal).
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to cloud sync processing at any time by disabling it in Settings.
  • Lodge a Complaint — if you are in the EU/EEA/UK, you may lodge a complaint with your local Data Protection Authority.

8. International Data Transfers

BeHisabi is available globally. If you enable cloud sync, your data (via Google Firebase/Firestore) and receipt images (via Google Gemini API) may be processed on servers located outside your country of residence, including the United States, under Google's own data protection safeguards.

9. Contact & Legal Compliance

For inquiries, clarification, or compliance audits regarding this Privacy Policy, please reach out directly:

Lead Developer: Takbir A. Himu
Support Email: hello@takbirhimu.me
Application Package: com.neonbhoot.behisabi

Questions About Privacy or Data Governance?

For questions regarding data encryption, compliance auditing, or feature feedback, contact our support team.