Privacy policy

Koshac is a personal finance app, so almost everything in it is sensitive. This page says exactly what leaves your phone, what does not, and what you can make us delete.

Updated 21 September 2026

1. What this notice covers

In short

This notice covers the Koshac mobile app and this website. The grey boxes are a plain-language reading aid; the paragraphs beside them are the policy.

This privacy notice describes how we collect, store, use and share your information when you use the Koshac app for iOS and Android, when you visit this website, or when you contact us. "We", "us" and "our" mean the individual developer who builds and operates Koshac, reachable at support@koshac.com.

Koshac is built and operated by an individual developer in India, not by a company. That person is the data fiduciary under India's DPDP Act and the data controller under the GDPR and UK GDPR, and is who "we" means throughout this notice. There is no separate corporate entity standing behind the app, and no other organisation shares responsibility for your data. The contact route is support@koshac.com.

Reading this notice will tell you what we do and what choices you have. If you do not agree with it, the remedy is to stop using Koshac and delete your account, which takes about a minute and needs nobody's permission but yours.

2. Summary of key points

In short

The short answers. Every one of them links to the section that is actually binding.

QuestionAnswer
What do you collect? Your sign-in identifier, an optional name and photo, and the financial records you enter or approve. Section 3.
Do you process sensitive personal information? Financial records are sensitive in the ordinary sense, and we treat them that way. We hold no bank credentials, no account numbers, no card numbers, no biometrics, no health data and no location. Section 4.
Do you get data about me from anyone else? No. We buy no data, run no data-broker code, and receive nothing from marketing partners or public databases. The only third-party data is what Google passes us when you choose to sign in with Google or Apple. Section 11.
Does anything go to a company other than Google? Yes. The database itself is hosted by Supabase, in Mumbai. Two exchange-rate services are also contacted when you record a transaction in a foreign currency, by your phone directly, so they see your IP address. Section 11.
Do you sell or share my data? No. Not for money, not for advertising, not for profiling, not for credit scoring, and not in exchange for anything else of value. Section 11.
Do you read my text messages? Bank alerts are parsed on your phone. The message text never reaches our servers. Section 8.
Where is it kept? An encrypted copy on your device, and a database in Mumbai, India. Section 12.
How is it protected? SQLCipher on the device, TLS in transit, and AES-256-GCM encryption of the most identifying fields inside the database itself. Section 14.
What are my rights? Access, correction, portability, erasure, withdrawal of consent, and complaint to a regulator. Section 17.
How do I use them? Delete your account in the app yourself, or email us for anything else. Section 22.

3. What we collect

In short

An identifier to sign you in, and the financial records you enter or approve. That is close to all of it.

Information you give us

DataWhy
Phone number Your account identifier if you sign in by phone. It is also how other people can add you to a group.
Email address If you sign in with Google, or with Apple and choose to share your address rather than hide it. Apple's private relay address is fine and we do not try to resolve it.
Display name and profile photo Only if you set them. Other members of your groups can see them.
Transactions Amount, date, category, tag, note, account and payment mode, for every entry you make or approve.
Accounts, banks, bills, budgets, categories, tags The structure you build around those transactions, including the labels and bank names you choose.
Groups, splits and settlements Shared with the other members of that group, because a shared balance is not private to one side of it.
App settings Currency, theme, accent colour, notification preferences and similar, so they follow you to a new device.
Support correspondence If you email us, we have your message and your address until the matter is closed.

Information collected automatically

DataWhy
Firebase account identifier An opaque user ID issued at sign-up. Every record we hold is keyed on it.
Device push token and platform So a reminder can reach you when the app is closed. Deleted when you sign out of that device.
Sign-in security signals When you sign in by phone, Firebase Authentication performs an abuse check before sending an OTP, which involves device and network signals it collects under Google's own privacy policy.
Crash diagnostics The app ships Firebase Crashlytics. If it crashes, a report may be sent containing the crash trace, device model, OS version and app version. It carries none of your transactions. Crash reporting is on by default and you can turn it off at any time in Settings.
API request logs When the app talks to our servers we record the time, the method, the path, the response status and your account identifier. We do not log request bodies or query strings, because those carry your records. Your IP address reaches the server and is used to rate-limit sign-in attempts; we do not store it against your account or derive your location from it.
Connection presence While the app holds a live sync connection, a short-lived row records your account identifier and when the connection was last seen, so a reminder is not pushed to a device that is already showing it. Rows are swept within about a minute and a half of the connection ending.
Website request logs Cloudflare, which serves this website, records standard request logs, including IP address and user agent, for security and abuse prevention. Section 15.

We do not receive personal information about you from data brokers, marketing partners, public databases, affiliate programmes or social networks, and we do not enrich what you give us with anything bought from a third party.

4. What we never collect

In short

No ads, no location, no behavioural analytics, no bank credentials, no biometrics.

  • Advertising identifiers. There is no advertising in Koshac, no ad SDK, no offer wall and no retargeting pixel.
  • Your location. The app never asks for it, has no location permission, and holds no GPS or IP-derived location for app users.
  • Usage or behavioural analytics. We do not record which screens you open, how long you spend, or what you tap. There is no analytics SDK in the app. Two things are analytics-shaped and worth naming rather than leaving you to find: crash reports carry your device model, OS version and app version, and Crashlytics counts sessions to work out how many are crash-free (section 3); and once the app is on the App Store and Google Play, Apple and Google give us their own aggregate figures - installs, deletions, crashes, retention - which we cannot switch off, which come from the stores rather than from the app, and which never identify you to us.
  • Bank credentials. Koshac never connects to a bank or a payment network. It cannot move money, and it never asks for a card number, CVV, net-banking password or UPI PIN. Nobody legitimate will ask you for those inside an app like this one.
  • Biometric data. If you lock the app with Face ID, Touch ID or a fingerprint, your device performs the check and tells the app yes or no. No fingerprint or face template is ever sent to the app or to us.
  • Your message inbox. Parsing happens on your phone. Section 8.
  • Your contacts' names, apart from the people you add to a group. The rest are read on the phone and never uploaded. When you add someone to a group, the name you have for them is uploaded and kept with that group, because a group member cannot exist without a name to show. Phone numbers are sent only for the people you actually select, checked against our account list, and kept only for the people you add. Section 9.
  • Inferences and profiles. The budgets and charts in the app are arithmetic on your own records, shown back to you. We build no profile of you, and we run no automated decision-making that produces legal or similarly significant effects.

5. Permissions the app asks for

In short

Every one is optional, asked for in context, and revocable in your device settings.

PermissionWhat it is for
NotificationsBill reminders, budget alerts and group activity. Decline and the app still works.
ContactsPicking a person to add to a group instead of typing a phone number. Section 9.
Camera and photo librarySetting a profile photo. Nothing else uses them.
SMS (Android only)Reading bank transaction alerts to draft transactions. Off by default. Section 8.
Face ID, Touch ID or fingerprintLocking the app. The check happens on the device and returns only a yes or no.

Refusing a permission disables the feature that needs it and nothing else. You can change your mind at any time in your device settings, and the app will stop using that capability immediately.

6. How we use your information

In short

To run the app you asked for, keep it secure, and answer you when you write. Nothing else.

  • To create and maintain your account, and to sign you in.
  • To provide the service - storing your records, syncing them between your devices, and computing balances, budgets and reports for you.
  • To let groups work - showing your name, photo and shared entries to the other members of a group you joined.
  • To send you the notifications you enabled, such as bill reminders and budget alerts. These are service messages, not marketing.
  • To answer your support requests and to act on your privacy requests.
  • To keep the service secure - detecting and preventing abuse, fraud against the service, and unauthorised access.
  • To fix the app - diagnosing crashes so they stop happening.
  • To comply with the law, and to establish, exercise or defend legal claims.

We do not use your information for advertising, for targeted or behavioural marketing, for profiling, for credit scoring, or to train machine-learning models. We do not send marketing email to app users. If you joined the launch list on this website, we use that address once, to tell you the app has launched.

7. Our legal grounds

In short

Mostly because you asked us to run the app. Consent for the optional parts, which you can take back.

Where the GDPR or UK GDPR applies to you, these are the legal bases we rely on. Where India's Digital Personal Data Protection Act, 2023 applies, we rely on your consent, given through the notice shown at sign-up and through the in-app switches for the optional features, and on the legitimate uses that Act permits.

What we doOn what basis
Run your account and store, sync and compute your recordsPerformance of a contract - this is the service you signed up for
Bank-message capture, contacts access, notifications, profile photoConsent - each is off until you switch it on, and withdrawable
Security, abuse prevention and crash diagnosticsLegitimate interests - keeping a financial app safe and working, weighed against your interests
Responding to legal process and keeping records we must keepLegal obligation

Withdrawing consent does not affect anything we lawfully did before you withdrew it, and it does not cost you access to the rest of the app.

8. Bank messages

In short

Messages are read and parsed on your phone. The text never reaches our servers - only the transaction you approve does.

Koshac can turn bank and UPI transaction alerts into draft transactions so you do not have to type them. This is off by default, has to be switched on per account, and only understands Indian bank and UPI message formats.

How it works differs by platform, and the difference matters:

  • Android. With the SMS permission, the app reads incoming messages and matches them against known bank sender formats. Messages that do not match are discarded.
  • iOS. Apple gives no app permission to read your messages, and Koshac does not have one. Instead you build a Shortcuts automation once, and it forwards matching messages into the app.

On both platforms the parsing happens on the device. Detected messages are stored in a local-only table that is never synced, and the message text is never transmitted to us. What reaches the server is the transaction you approve, in the same form as one you typed yourself. Turning the feature off, or signing out, deletes the stored message data along with your consent flag.

Some privacy laws treat the contents of a message as sensitive where the recipient is not the intended party. We have designed this feature so that we are never a recipient at all: we hold no copy, we cannot read one, and there is nothing on our side for us to disclose, sell or be compelled to produce.

9. Your contacts

In short

Your contact list stays on your phone. We see only the people you pick, and we keep the name and number of the ones you actually add to a group.

When you add someone to a group, the app can show your contacts so you can pick a person rather than type a phone number. With your permission it reads names and phone numbers only - not photos, not email addresses, not postal addresses, not notes.

We never receive your address book. Contact names are matched to people on the device, and no contact name is used to suggest people to anyone else. One name does reach us: the name of a person you go on to add to a group, which is the last paragraph of this section.

Phone numbers leave your phone only for the people you pick. When you select someone and confirm, the app sends that person's number - and only that number - to our server to ask whether it matches an existing account. The rest of your contact list is never transmitted. The server converts each number it receives to a keyed one-way hash, compares the hashes against the accounts we hold, and returns only the matches. The numbers sent for that check are not written to our database, not written to our logs, and not retained after the answer is sent. They exist on our side only for the moment the comparison takes.

When you then choose someone and add them to a group, their name and phone number are stored, because the group needs a member to show and an invitation to send. There is no way to add someone without a name: a group member cannot be created without one. The name is encrypted in our database in the same way your own is (section 14). That is the only contact information we keep.

10. Groups and other people

In short

Shared expenses are shared. Group members see your name, photo and the entries you add to that group.

A shared expense has more than one owner. Everyone in a group can see the group's expenses, who paid, how each was split, the resulting balances, and the display name and photo of every member. Your personal transactions outside that group stay private to you.

When you add someone who does not have Koshac, we create a placeholder record holding the name and phone number you entered, so the group's arithmetic works before they join. If they never join, you can remove them and that record goes.

When you delete your account, the shared entries stay so that the remaining members' balances stay correct, and your membership row is marked deleted while keeping the name the group already knew you by. Everything else that identifies you is removed. This is the one place where deletion is not total, and the deletion page explains exactly why.

Two things travel with those shared entries, and we would rather list them than let "everything else is removed" cover more ground than it should:

  • The group's activity history. Each group keeps a log of what happened in it - who added a member, who changed an expense, what the amount was before and after. Entries recording your actions stay in that log for as long as the group exists, under the name the group knows you by, because removing them would leave the other members with a history that no longer explains their own balances.
  • Deleted groups keep a snapshot for 60 days. When a group is deleted it becomes a restorable archive before it is purged, and that archive holds the member list as it stood, including you. It is deleted automatically at the end of the 60 days. Where that archive is the last thing referring to a closed account, the account's empty placeholder record is removed in the same nightly pass that purges the archive - so the placeholder cannot outlive the data that justified keeping it.

11. Who else processes it

In short

Supabase, which hosts the database; Google, for everything else we run; and two exchange-rate services your phone calls directly. Nobody else, and never for marketing.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the past twelve months, and we have no plans to. We do not disclose it to advertising networks, affiliate programmes, data brokers, analytics vendors, retargeting platforms or social networks, because we use none of them.

The services below process your data because the app cannot work without them. Each acts on our instructions, and none of them is permitted to use your data for its own purposes. For the Google services, that obligation is Google's Cloud Data Processing Addendum. Two are not Google. Supabase, which holds the database, stands under its own data processing addendum: Supabase addendum to be confirmed. Cloudflare serves this website only; it holds none of your account data and stands under its own terms: Cloudflare addendum to be confirmed.

ServiceWhat it handles
Firebase AuthenticationSign-in by phone, Google or Apple, and OTP delivery
SupabaseThe PostgreSQL database your synced records live in, hosted in Mumbai. It is the one service in this table that is not Google
Google Cloud Functions and Cloud RunThe API, and the real-time sync connection
Google Cloud StorageProfile photos, if you upload one
Google Cloud KMS and Secret ManagerThe keys that encrypt the most identifying fields in the database
Firebase Cloud MessagingPush notifications for reminders
Firebase CrashlyticsCrash reports
Cloudflare PagesThis website. Like Supabase it is not Google, and it holds none of your account data - only the request logs any host keeps

Exchange rates, which are not Google and not our processors

When you record a transaction in a currency other than your own, the app needs a conversion rate. It asks one of two public exchange-rate services: Frankfurter (api.frankfurter.app) and ExchangeRate-API's open endpoint (open.er-api.com). Frankfurter is asked for a rate on a past date; the other is asked for today's.

Your phone contacts them directly, not through our servers. That distinction is the whole reason this has its own heading, so here is exactly what each request contains and what it does not:

  • What we send: the two currency codes, and for a historical rate, the date. Nothing else is in the request.
  • What they can see anyway: your device's IP address, because that is how any internet request works, and a header identifying the app as Koshac. So the operator of that service can tell that a device at that address uses Koshac and looked up a currency pair on a date.
  • What they never receive: your name, phone number, email address, account identifier, the amount, the merchant, the note, or anything else from the transaction. They are asked what a rupee is worth, not what you spent.
  • Their status: these are free public endpoints used without an account or a contract. They are not our processors and we cannot instruct them. Whether they log requests is their decision, governed by their own terms, not ours.
  • Where: we do not control where these services run, so a rate lookup may leave India.
  • How to avoid it entirely: the request is only made for a foreign-currency entry. If every transaction you record is in your own currency, the app never contacts either service. Answers are cached on your device for 24 hours, so a repeated lookup does not repeat the request.

We are looking at moving these lookups behind our own servers, so that the rate services see us rather than you. Until then, this section describes what happens.

We may also disclose personal information in these situations, and no others:

  • Legal requirement. Where a valid court order, warrant or lawful demand compels it, or to establish, exercise or defend a legal claim. We will tell you unless we are prohibited from doing so.
  • Safety and abuse. Where it is necessary to investigate abuse of the service or a threat to someone's safety.
  • Business transfer. If Koshac is ever merged, acquired or wound up, your data may transfer to the successor. That successor would be bound by this notice, and we would tell you before anything changed.

12. Where your data lives

In short

An encrypted copy on your device, and a PostgreSQL database hosted by Supabase in Mumbai.

On your phone

Koshac is offline-first. Your own records land in a local database on your device first and sync afterwards, which is why the app keeps working on a flight or in a basement. Group expenses go to the server as you make them, because the balances are shared. That local database is encrypted at rest with SQLCipher. Uninstalling the app removes the local copy; it does not delete your account.

On our servers

Synced data is stored in a PostgreSQL database hosted by Supabase in its ap-south-1 region, which is Mumbai, India. The API, the real-time connection and the encryption keys run on Google Cloud in its asia-south1 region, which is also Mumbai. Your records are held in India by both providers.

International transfers

Your records are stored in India. Some of the Google services listed above are global by design: Firebase Authentication, Firebase Cloud Messaging and Crashlytics may process data on Google infrastructure outside India, including in the United States and the European Union. The two exchange-rate services in section 11 are contacted by your phone directly and may run anywhere; the only thing that reaches them is a currency pair, a date and your IP address.

Where personal data of people in the EEA, the UK or Switzerland is transferred out of those areas, the transfer is covered by the European Commission's Standard Contractual Clauses, and the UK Addendum where applicable. For the Google services those clauses come in through Google's Cloud Data Processing Addendum. That addendum does not reach Supabase, which hosts the database and is a separate company, so the clauses covering the database are the ones in Supabase addendum to be confirmed. If you are outside India, using Koshac means your data is transferred to and stored in India, which may not have data protection law equivalent to your own; the safeguards in this notice apply to it wherever it is.

13. How long we keep it

In short

Until you delete it. Then immediately, with backups rotating out within 30 days.

We keep personal data only as long as we need it for the purposes in this notice, unless a law requires us to keep it longer. In practice:

  • Your records: kept while your account exists, because that is the product.
  • After you delete your account: personal data is removed from the live database in a single transaction on confirmation. Encrypted backups rotate on their own schedule, and any residual copies are gone within 30 days.
  • Push tokens: deleted when you sign out of that device.
  • Detected bank messages: local to your phone only, and deleted when you turn the feature off or sign out.
  • Shared group entries and the group's activity history: kept for as long as the group exists, so the other members' balances remain correct and still explain themselves, with your membership marked deleted. Section 10.
  • Deleted groups: held as a restorable archive, including the member list, and purged automatically 60 days after deletion.
  • The placeholder left behind by a deleted account: when you delete your account while you are still named in someone else's group, we keep an empty placeholder row carrying no personal data - no name, no phone number, no email - purely so the other members' entries still add up. It is not kept indefinitely: it is removed automatically once the last group entry naming you is gone. If the only thing holding it was a deleted group's archive, that is within 60 days of the group's deletion.
  • Connection presence rows: swept within about 90 seconds of the sync connection ending.
  • Crash reports: kept on Firebase Crashlytics' own retention schedule, currently 90 days.
  • Website request logs: kept on Cloudflare's own schedule, and used only for security and abuse prevention.
  • Support email: kept until the matter is closed, and then for as long as we may need it to defend a claim.

Where we cannot delete something immediately because it sits in a backup, we isolate it from any further use until the backup rotates out.

14. How we protect it

In short

Encrypted on the device, encrypted in transit, and the most identifying fields encrypted again inside the database.

  • On the device. The local database - which is where your transactions, bills, budgets, groups and captured bank messages live - is encrypted at rest with SQLCipher. Tokens and your frequently-used contacts are held in the platform keystore. You can also lock the app behind a PIN, Face ID, Touch ID or a fingerprint; that lock is optional and off until you turn it on.
  • In transit. Everything between your phone and our servers travels over TLS, including the real-time sync connection.
  • In the database. We encrypt the most identifying fields in the application itself, before they are written, with AES-256-GCM: your phone number, email address, display name, push tokens, device identifiers and group member names. Someone holding a copy of the database still cannot read them.
  • Key management. The data encryption key is itself encrypted by Google Cloud KMS in the Mumbai region and stored in Secret Manager. It is never checked into source control, and the code refuses to start in production if it finds local key material substituted for it.
  • Searchable without being readable. Finding you by phone number uses a keyed one-way hash, so the lookup works without the plaintext number being present in an index. Profile photos are stored under random object keys rather than guessable URLs.
  • Written down only where needed. Push notification history records that a notification was sent, and to whom, but not its title or body, because those contained names and amounts.
  • Access. Administrative access to production is limited to the people who operate the service. For the Google services - the API, storage, the keys and the secrets - it is authenticated through Google Cloud IAM. The database is reached through Supabase, whose dashboard has its own separate sign-in outside Google IAM, and that is the most privileged route to the data.

No electronic transmission or storage is ever completely secure, and we will not claim otherwise. If a personal data breach occurs that is likely to affect you, we will notify you and the relevant supervisory authority - the Data Protection Board of India, and any EEA or UK authority with jurisdiction - within the periods those laws require.

15. This website

In short

No cookies, no trackers, no analytics, nothing embedded from anyone else.

This site sets no cookies, runs no analytics, uses no tracking pixels, web beacons or session-replay tools, and embeds nothing from a third party. Its fonts are served from this domain rather than from a font CDN, specifically so that reading this page does not tell anyone else that you read it.

Because we set no cookies and do not sell or share personal information, there is nothing here for a Global Privacy Control or Do Not Track signal to switch off. We state that rather than the usual "no common standard exists" formula, because in our case the honest answer is that the setting has nothing to act on.

Cloudflare, which serves this website, keeps standard request logs, which include IP addresses, for security and abuse prevention. If you give us an email address for the launch list, we use it once, to tell you the app has launched, and we do not pass it on.

This site links to a small number of external pages, such as the app stores and regulators. We do not control those sites, their privacy practices are their own, and a link is not an endorsement.

16. Children

In short

Not for under-13s.

Koshac is not directed at children and is not intended for anyone under 13. We do not knowingly collect personal data from children, and we do not use children's data for tracking or advertising in any circumstances. By using the app you confirm you are 13 or older.

If you believe a child has given us their data, email support@koshac.com and we will delete the account and the data.

17. Your rights

In short

Access, correct, export and delete. Email us and we will do it, or do it yourself in the app.

These rights are available to everyone who uses Koshac, regardless of where you live. Sections 18 to 20 add what specific laws give you on top.

  • Access. Ask what personal data we hold about you and get a copy.
  • Correction. Fix anything inaccurate or incomplete. Most of it you can edit directly in the app.
  • Portability. Get your data in a portable, machine-readable form, without asking us. The app exports your transactions as a CSV file and your groups as a separate CSV, both of which open in any spreadsheet and can be imported back into Koshac on another device, and it produces a PDF statement for reading rather than re-importing.
  • Erasure. Delete your account and data from inside the app, at any time, without asking anyone.
  • Withdraw consent for optional processing such as bank-message capture, contacts or notifications, by turning it off in Settings or in your device settings.
  • Object or restrict. Object to processing we base on legitimate interests, or ask us to restrict it while a dispute is resolved.
  • Complain to a regulator, without going through us first.
  • No retaliation. We will never degrade the service, charge you more, or treat you differently because you exercised a privacy right.

Email support@koshac.com to exercise any of these. We respond within 30 days. We may first ask you to verify your identity, usually by asking you to write from the address or confirm from the phone number on the account, so that nobody else can exercise your rights for you. We will only use what you send for that verification, and we delete it afterwards. Where the law allows an authorised agent to act for you, we will ask for proof of that authorisation.

18. India: the DPDP Act

In short

India is our home jurisdiction and the Digital Personal Data Protection Act, 2023 is the law we build to.

Under the Digital Personal Data Protection Act, 2023 and the rules made under it, we act as a Data Fiduciary and you are a Data Principal. In addition to the rights in section 17, you have:

  • The right to a summary of the personal data we process and the processing activities we undertake, and the identities of anyone we have shared it with.
  • The right to nominate another person to exercise your rights if you die or become incapacitated. Email us to record a nomination.
  • The right of grievance redressal - to raise a complaint with us and get an answer, before going to the Board.
  • The right to complain to the Data Protection Board of India if our answer does not satisfy you.

The Act also places duties on you: not to impersonate someone else when giving personal data, not to suppress material information, and not to file a false or frivolous grievance.

Koshac is run by one person, so the Grievance Officer for DPDP purposes is that same individual developer, grievance officer name to be filled in, contactable at support@koshac.com. Grievances are acknowledged within 5 working days and answered within 30 days.

19. EEA, UK and Switzerland

In short

GDPR and UK GDPR rights apply, and you can complain to your own authority.

We are the data controller of the personal data described here. Our legal bases are set out in section 7, and your rights of access, rectification, erasure, restriction, objection and portability are in section 17. Transfers out of the EEA and the UK are covered in section 12.

You have the right to lodge a complaint with your local supervisory authority. In the EEA you can find yours through the European Data Protection Board; in the UK it is the Information Commissioner's Office; in Switzerland it is the Federal Data Protection and Information Commissioner. You do not have to contact us first, though we would rather you did, because we can usually fix it faster.

We do not carry out automated decision-making that produces legal or similarly significant effects, so no right to human review arises. We are not currently required to appoint an EU or UK representative under Article 27; if that changes, this section will name one.

20. United States

In short

We do not sell or share personal information, so the opt-out most of these laws are built around has nothing to switch off.

If you live in a US state with a comprehensive privacy law - California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and the others that have followed them - you have the rights in section 17, plus the right to appeal a refusal. To appeal, reply to our decision and say you are appealing; we will answer in writing within 45 days, and if we still refuse we will tell you how to complain to your state Attorney General.

We do not sell personal information, do not share it for cross-context behavioural advertising, and do not use it for targeted advertising or for profiling with legal or similarly significant effects. There is therefore no opt-out to offer and no "Do Not Sell or Share My Personal Information" link, because there is nothing behind it. We offer no financial incentive in exchange for personal information.

California

For CCPA purposes, these are the statutory categories of personal information, and whether we have collected them in the past twelve months.

CategoryCollected
A. Identifiers - name, phone number, email address, account identifier, device identifier, IP address in website and API server logsYes
B. Customer records - name, contact details, financial informationYes
C. Protected classifications - age, gender, race, and similarNo
D. Commercial information - the expense and payment records you enterYes
E. Biometric informationNo
F. Internet or network activity - browsing history, search history, interactions with adsNo
G. Geolocation dataNo
H. Audio, visual or similar - your profile photo, if you upload oneYes
I. Professional or employment informationNo
J. Education informationNo
K. Inferences drawn to create a profileNo
L. Sensitive personal information - log-in credentials, financial account or card numbers, precise geolocation, race, religion, message contents, genetic, biometric or health data, sex lifeNo

On category L: sign-in is handled by Firebase Authentication and we never receive a password. We hold no bank account number, card number or security code. The contents of bank messages are processed on your device and never reach us (section 8). Because we collect no sensitive personal information, the right to limit its use and disclosure does not arise, and there is no notice of financial incentive to give.

We retain each category for as long as your account exists and then delete it as described in section 13. We disclose the categories above to the service providers in section 11 for the business purposes described there, under contracts that forbid them any other use. The two exchange-rate services in that same section are not service providers and are not under such a contract; what reaches them is a currency pair, a date and an IP address, which is disclosed there in full. We have sold or shared no category of personal information in the preceding twelve months, and receiving a currency rate is not an exchange for anything of value.

California residents also have the "Shine the Light" right to ask what personal information we disclosed to third parties for their direct marketing purposes. The answer is none, and will stay none.

21. Deleting your account

In short

Settings, Profile, Delete Account. It is permanent.

You can delete your account and its data from inside the app, without emailing anyone and without waiting for us. The account deletion page lists every step, exactly what is removed, the one thing that is kept and why, and what to do if you cannot sign in.

Deletion is final. We do not keep a dormant copy of your account against the chance that you come back, and an account cannot be restored once confirmed.

22. Changes and contact

We will update this notice when the app changes. The date at the top always reflects the current version, and the updated version takes effect as soon as it is posted. If a change materially affects how your data is handled, we will tell you in the app rather than quietly editing this page.

For any question, request or complaint about your data, email support@koshac.com. That address reaches the Grievance Officer named in section 18 and is the right place for a request under any of the laws above.

Koshac is operated by an individual rather than a company, so there is no registered office to publish. Email is the contact route for every request and complaint described above. The developer's postal address is held by Apple and Google as part of the developer account and appears on the App Store and Google Play listings; if a law or an authority requires it in writing from us, ask at the address above and we will provide it.

If our answer does not satisfy you, escalate to the Data Protection Board of India, to your national supervisory authority in the EEA, the UK or Switzerland, or to your state Attorney General in the United States.