Privacy Policy
Last updated: March 22, 2026
What we collect
- Phone number — used solely for OTP authentication. Not shared with third parties.
- Profile information — optional name and email address for account customisation.
- SMS text — processed by our self-hosted LLM to classify transactions. SMS content is never stored, or logged to external services.
- Merchant rules — user-defined category mappings for specific merchants.
Data storage
Kharcha stores minimal data server-side:
- Phone number (for authentication)
- Optional name and email
- Custom merchant category rules
Transaction data is stored only on your device. Our servers never keep a copy of your transactions.
How SMS is used. When a message arrives from a known bank, the app sends it over an encrypted connection to our servers, where an AI model reads out the amount, merchant and category. The message is then deleted — it is never stored in a database, never logged, and never shared with anyone. Messages from anyone other than a recognised bank are never sent. If our servers are unreachable, the app categorises the transaction on your phone instead.
Anonymised learning. To improve categorisation we keep aggregate counts of normalised merchant names and their categories (for example, “swiggy” → food). These aggregates contain no phone numbers, amounts, dates or message text, and cannot be traced back to an individual user.
Third-party services
- Twilio — delivers OTP SMS messages. Subject to Twilio’s Privacy Policy.
- Ollama — the AI model, running on our own servers. SMS is processed and deleted, never stored in a database.
- Google Firebase Crashlytics — crash and error reporting. Receives device model, OS version, app version and a device identifier when the app crashes. Subject to Google’s Privacy Policy.
- RevenueCat — manages subscriptions and purchase validation. Receives a pseudonymous user identifier and your purchase history. Subject to RevenueCat’s Privacy Policy.
- Google Play Billing — processes subscription payments. We never see or store your payment details.
- Exchange rate APIs — used for currency conversion. No personal data is sent.
Security
- JWT-based authentication; sessions renew automatically and expire after at most one year
- OTP codes are single-use with 10-minute expiry
- Rate limiting on all endpoints
- Security headers on all responses
Data retention
Your account data is kept until you delete your account. Dedup cache entries expire in 5 minutes; OTP codes expire in 10 minutes. SMS is never stored in a database. Anonymised merchant-category counts, which cannot identify you, are kept indefinitely.
Data deletion
Delete your account at any time from the app’s Settings page, or by emailing us at the address below. Deletion removes your phone number, name, email and category rules from our servers immediately and irreversibly. Transaction data on your device is cleared at the same time, and uninstalling the app removes any remainder. Crash reports held by Firebase and subscription records held by RevenueCat and Google Play are deleted in line with those providers’ own retention schedules. Anonymised merchant-category aggregates, which cannot identify you, are not deleted.
Contact
For questions, email lovlinthakkar99@gmail.com.