1. Introduction & Developer Commitment
This Privacy Policy describes how BeHisabi ("we," "our," or "the Application"), developed by Takbir A. Himu, collects, handles, and protects your financial information and personal data when you use our Android mobile application.
2. Information Handled by the Application
To deliver effortless bookkeeping and financial tracking, BeHisabi processes the following data categories:
3. Data Storage, Security & Retention Lifecycle
BeHisabi is engineered with an Offline-First Architecture. Your records are stored primarily in a sandboxed local SQLite database managed by Android Room.
- Sandboxed SQLite Storage: All financial entries stay strictly on your local device storage by default.
- Encrypted Cloud Sync: If enabled, records sync with Google Firebase Firestore using standard Transport Layer Security (TLS 1.3) and strict Firestore security rules bound exclusively to your verified user ID.
- Retention & Purge Guarantees: Active cloud Firestore records are deleted within 24 to 48 hours upon verified deletion request. Cloud server rolling snapshot backups cycle out and age out completely within a standard 30-day retention window, during which they remain strictly isolated and inaccessible for operational use.
- Local Biometric Lock: The app supports Android hardware-backed Biometric Authentication (Fingerprint / Face Unlock) to guard against unauthorized access on shared devices.
4. Third-Party Service Providers, Analytics & AI Processing
We integrate selected industry-standard developer SDKs to maintain security, performance monitoring, cloud sync, and OCR parsing:
- Google Play Services: Core application delivery, licensing, in-app updates, and integrity verification. Governed by Google Privacy Policy.
- Google Firebase (Cloud Firestore & Auth): Encrypted cloud database and authentication token verification for optional multi-device backup. Governed by Firebase Privacy & Security Policies.
- Google Analytics for Firebase: Aggregated, non-personally identifiable diagnostic and engagement analytics (such as session counts, daily active duration, screen views, and retention rates) to evaluate app performance and stability.
- Firebase Crashlytics: Automated, real-time crash reporting and stack traces collected strictly during unexpected runtime errors to facilitate rapid bug fixing.
- Firebase Cloud Messaging (FCM): Delivers optional in-app notices, budget reminders, and critical system announcements directly to your device.
- Google Gemini API: Instant image parsing for smart receipt extraction. Receipt images sent through the scanner are transmitted securely over TLS exclusively to perform Optical Character Recognition (OCR) and extract structured transaction details (merchant name, item totals, and date). No banking credentials, credit card numbers, or PINs are processed. Data processing is governed by Google Gemini API Terms of Service and Google Privacy Policy.
5. Your Rights & Data Deletion
You retain 100% ownership and control over your financial records at all times:
- Instant Local Wipe: Erase all local databases anytime via Settings > Data Management > Delete All Data.
- Cloud Purge Request: You may request complete erasure of cloud backup records at any time using our dedicated Data Deletion Portal. For user safety and account protection, deletion requests undergo an ownership confirmation verification step before permanent cloud database purging (executed within 24 to 48 hours).
6. Children's Privacy Protection (COPPA / GDPR-K)
Protecting the privacy of children is of paramount importance. BeHisabi is intended for general audiences and personal financial tracking by adults and youth above the age of consent.
- No Direct Targeting: BeHisabi does not knowingly solicit or collect personal information from children under 13 years of age (or under 16 in the European Union).
- Parental Action: If a parent, guardian, or legal representative discovers that a minor has submitted personal data or linked a Google Account without parental consent, please contact us immediately at hello@takbirhimu.me or via our Data Deletion Portal. We will promptly verify and permanently delete the information from our servers.
7. Your Data Protection Rights (Global Users)
Regardless of your country of residence, you have the right to:
- Access — request a copy of your data (export via in-app CSV/JSON).
- Rectification — correct inaccurate data directly within the app.
- Erasure — delete your data instantly (see our Data Deletion Portal).
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to cloud sync processing at any time by disabling it in Settings.
- Lodge a Complaint — if you are in the EU/EEA/UK, you may lodge a complaint with your local Data Protection Authority.
8. International Data Transfers
BeHisabi is available globally. If you enable cloud sync, your data (via Google Firebase/Firestore) and receipt images (via Google Gemini API) may be processed on servers located outside your country of residence, including the United States, under Google's own data protection safeguards.
9. Contact & Legal Compliance
For inquiries, clarification, or compliance audits regarding this Privacy Policy, please reach out directly:
Support Email: hello@takbirhimu.me
Application Package:
com.neonbhoot.behisabi