Privacy Policy

Last Updated: August 2, 2026

1. Introduction

Welcome to Pikash. We are committed to protecting your privacy and ensuring you have a secure experience when using our local-first personal finance tracker. This Privacy Policy explains how we collect, use, and safeguard your information.

2. Data Collection and Storage

Pikash is designed with a "local-first" architecture. This means that your financial data (including wallets, transactions, goals, and debts) is primarily stored locally on your device. We synchronize this data with our secure cloud servers (Supabase) solely for the purpose of backup and multi-device access, and only if you choose to create an account.

3. How We Use Your Information

The information collected is used to:

  • Provide, maintain, and improve our services.
  • Enable seamless synchronization across your devices.
  • Provide personalized AI-driven financial insights (only with your explicit consent).
  • Facilitate community sticker sharing and regional content discovery.

4. Device Permissions & Sensitive Data

Pikash only requests the permissions it needs for features you choose to use. Every permission below is optional and can be disabled at any time from your device settings.

Microphone & Voice Entry

When you use voice entry to log a transaction, Pikash uses your device's built-in speech recognition to convert your speech to text on your device. The microphone is only active while you are actively recording. We never store or upload the raw audio. Only the resulting text transcript is sent to our AI service so it can be parsed into a transaction.

Notification Access

If you enable the transaction detector, Pikash uses Android's notification access to read incoming notifications only from the finance, bank, and e-wallet apps you explicitly add to your whitelist. This is used to automatically detect and suggest transactions. Notifications are matched against on-device rules; when you enable AI parsing, the relevant notification text may be sent to our AI service to extract the transaction details. Notifications from non-whitelisted apps are ignored, and this feature is entirely opt-in.

Receipt Images & Photos

Any receipt or transaction images you attach are stored locally on your device only. These images are never uploaded to our servers or included in cloud sync.

Cloud Synchronization

Cloud sync is optional and only runs when you are signed in. When enabled, your financial records (wallets, transactions, goals, debts, and related metadata) are backed up to our secure cloud (Supabase) so you can restore them and access them across devices. Sync is user-initiated through the app, and all synced data can be permanently removed via the Account Management page.

IP Location & Regional Auto-Detection

To provide regional defaults such as your localized country scope and currency formatting during onboarding and within the Community gallery, Pikash performs lightweight, non-blocking IP geolocation lookups via third-party service providers (such as ipapi.co). Your public IP address is processed strictly in transit to infer your two-letter ISO country code and default currency code. We do not log, store, or link your IP address to your personal financial records, nor do we sell location data to third parties. You may manually select or override your country and currency preferences at any time.

Community Gallery & Public Sticker Bundles

Pikash includes a Community gallery where users can optionally share custom sticker bundles. When you publish a sticker bundle to Community, the bundle assets (sticker graphics, title, collection name, description, and target country scope) are stored on our secure cloud database (Supabase) and made publicly discoverable to other users. You can choose to publish under your Named Identity (displaying your profile name and avatar) or an Anonymous Identity (displaying a system-generated pseudonymous handle). You can delete your published sticker bundles at any time directly within the app, which immediately removes them from public discovery.

AI Processing

AI features run only when you explicitly trigger them (for example, voice entry, the chat assistant, or AI notification parsing). When triggered, we send the relevant text (such as your transcript or notification text) along with lightweight context about your wallets and categories so the assistant can respond accurately. We do not use your data to train third-party models.

Subscription Data

Pikash Pro is processed through RevenueCat and the Google Play Store or Apple App Store. Pikash receives only your subscription status and entitlements (whether you are on the free or Pro tier, and renewal or expiry dates). We never receive or store your full payment card details, which are handled entirely by the app store.

5. Data Deletion

You have full control over your data. You can request the complete deletion of your account and all associated data at any time via the Account Management page. Upon request, all synced records and account information on our servers will be permanently removed. You can also delete individual sticker bundles you have published to the Community gallery at any time.

6. Contact Us

If you have any questions about this Privacy Policy, please contact us through the support channels provided in the Pikash app.