Privacy Policy
Last updated: 18 August 2026
ChaarPaisa (“the app”) is an income and expense tracker for Android, published by Ramdas Gat (“we”, “us”). This policy explains what the app does with your information.
1. Information that stays on your device
Everything below is written to a private database inside the app’s own storage. It is not uploaded to us, and no other app on your phone can read it:
- Transactions — amount, date, type, category, note, payment mode
- Details taken from bank SMS — UPI ID, reference number, the last digits of an account number, available balance, and the other person’s name where the message contains it
- Categories you create and the UPI-sender-to-category rules you build up
- Receipt images and PDFs you attach
- Assets, liabilities, credit cards, subscriptions, recurring entries and budgets
- Your settings, chosen language, and your app PIN (stored as a one-way hash)
- Raw bank SMS text, kept for 10 days to help diagnose parsing problems, then deleted automatically
Uninstalling the app deletes all of it.
2. SMS permission — what we do and do not do
ChaarPaisa requests RECEIVE_SMS and READ_SMS for one purpose only: to recognise bank, UPI and payment messages so that transactions are recorded for you automatically. On Google Play’s permitted-use list this is the SMS-based money management use case.
- Messages are read and interpreted entirely on your phone.
- No SMS content is transmitted to us or to anyone else at any time.
- The app looks only for transaction messages. It has no interest in and makes no separate use of personal conversations.
- Granting SMS access is optional. Deny it and every other part of the app still works — you simply add entries yourself.
The one exception is entirely under your control: if you choose Report Unmatched SMS or Report a bug, the app opens a Google Form in your browser with a message you can read and edit before sending. Nothing is submitted unless you tap Submit yourself. See section 3.
3. Information that leaves your device
The app is usable fully offline. These are the only cases where data goes out, and who receives it:
a) Advertising — Google AdMob
Free installations display ads supplied by Google AdMob. To serve them, Google may collect your advertising ID, IP address, coarse device and app information, and ad interaction data. We never see your financial records through this, and AdMob receives none of them.
In the European Economic Area and the UK, a consent form appears before any personalised ad is requested. Buying the one-time “Remove ads forever” option, or earning ad-free days, stops ads being requested at all.
Google’s handling of this data: policies.google.com/technologies/partner-sites
b) Purchases — Google Play Billing
The “Remove ads forever” purchase is processed entirely by Google Play. We never receive your card, UPI or payment details — only whether the purchase is active on your device.
c) Ratings — Google Play In-App Review
If you rate the app, your review goes to Google Play under Google’s terms.
d) Bank message patterns — GitHub
The app periodically downloads an updated list of bank SMS formats so that newly supported banks work without an app update. This is a download only; nothing about you or your messages is sent. The host (GitHub) can see your IP address, as with any web request.
e) Feedback you choose to send — Google Forms
If you open Report a bug, Report Unmatched SMS or Send feedback, the app builds a Google Forms link pre-filled with what you typed, your optional star rating, your device model and Android version, and the app version. It opens in your browser and you decide whether to submit it. The app never posts anything on its own. If you paste an SMS into that form, you are choosing to share that text with us.
4. Backups you create
Backup Data produces an encrypted, password-protected file. You choose where it goes — your own storage, Google Drive, WhatsApp, email or anywhere else. Once you place that file somewhere, it is governed by that service’s terms, not ours. We never receive it. If you lose the password, the backup cannot be recovered — not even by us.
5. Permissions and why each one is needed
| Permission | Why |
|---|---|
RECEIVE_SMS, READ_SMS | Detect bank and UPI transaction messages to record them automatically (optional) |
INTERNET | Serve ads, process the purchase, and download bank message patterns |
CAMERA | Photograph a receipt to attach to a transaction (only when you tap it) |
POST_NOTIFICATIONS | Alert you about a captured payment or a due reminder |
VIBRATE | Feedback while typing your PIN |
USE_BIOMETRIC | Unlock the app with a fingerprint or face, if you enable it |
WAKE_LOCK | Finish processing an incoming SMS while the screen is off |
READ_EXTERNAL_STORAGE / WRITE_EXTERNAL_STORAGE (older Android only) | Save and reopen backup and export files |
The Google Mobile Ads SDK adds a few permissions of its own — such as network state and advertising-services access — which Android lists under the app. They are used by Google to deliver ads, as described in section 3(a), and disappear from use once ads are removed.
6. Selling and sharing
We do not sell your personal information. We do not share your financial records with anyone, because we never hold them.
7. Children
ChaarPaisa is a personal finance tool intended for adults. It is not directed at children under 13, and we do not knowingly collect information from them.
8. Security
Your records sit in the app’s private storage, which Android keeps isolated from other apps. You can add a PIN lock and biometric unlock. Backup files are encrypted with the password you set. No system is perfectly secure, but because your data never reaches a server of ours, there is no central database of ChaarPaisa users’ finances to be breached.
9. Your choices
- Deny or revoke SMS access in Android Settings → Apps → ChaarPaisa → Permissions, at any time
- Delete any transaction, or all of them, from inside the app
- Uninstall to erase everything the app holds
- Remove ads to stop ad requests entirely
- Reset your advertising ID in Android Settings → Privacy → Ads
10. Changes to this policy
If this policy changes, the date at the top changes with it, and the current version will always be at this address.
11. Contact
Questions or requests about privacy:
Email: ramdasgat@gmail.com