Loading Cinematic Experience (0%)
SCROLL DOWN
↓

Privacy Policy

Your privacy and data security are our top priority. We use military-grade encryption and secure cloud infrastructure to protect your financial records.

App: Udhar Bahi Khata & Loan Manager
Developer: VIPRAGI
Updated: July 13, 2026
✦

Introduction

Welcome to Udhar Bahi Khata & Loan Manager ("the App", "we", "us", or "our"). This Privacy Policy explains how we collect, use, store, protect, and disclose your information when you use our mobile application. By downloading, installing, or using the App, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the App.

This App is a financial record-keeping tool designed for lenders, shopkeepers, and small business owners to manage their loans, EMI schedules, Khata (Udhar Book / Ledger), cashbook, staff, and customer records.
1

Information We Collect

1.1 Information You Provide Directly

When you create an account or use the App, we may collect the following information:

  • User Account Information: Full name, Email address, Password (managed securely by Firebase), Mobile number, Country, State, and Profile picture.
  • Customer / Borrower Data: Customer name, contact details, identity documents (Aadhaar, PAN, Voter's ID entered voluntarily by you for record-keeping), address, and notes.
  • Financial & Transaction Data: Loan details, EMI schedules, payment records, Khata entries, and cashbook transactions.
  • Staff Information: Staff names, phone numbers, roles, salaries, and attendance records.
  • Live Support Data: Chat messages, images, and documents uploaded during support interactions.

1.2 Information Collected Automatically

  • Crash & Error Reports (via Firebase Crashlytics): When the App encounters a crash or unexpected error, diagnostic data is sent to Crashlytics. This includes: device model, OS version, app version, stack traces, and timestamps. This data does NOT contain any personal financial records or identifiable information.
  • Device & Security Information: When a security threat is detected (e.g., rooted/tampered device), minimal OS info and threat type are collected to protect the App.
  • Last Login Timestamp: We record your last login time for account management.

1.3 Information We Do NOT Collect

  • We do NOT collect GPS location or precise location data.
  • We do NOT collect advertising IDs.
  • We do NOT use any advertising or behavioral tracking SDKs.
  • We do NOT collect browsing history or app usage patterns.
  • We do NOT collect or access your SMS, call logs, or camera in the background.
2

Permissions We Request

Permission Purpose
Internet To sync your data with secure cloud servers, authenticate your account, and provide Live Support chat.
Network State To detect internet connectivity and enable offline-first functionality.
Read Contacts To allow you to select customer names/numbers easily. We do NOT upload or store your entire contact list on our servers. Only the specific contact you select is used.
Notifications To send local EMI and loan payment reminders on your device (Android 13+).
3

How We Use Your Information

We use the information we collect exclusively to:

  • Provide, operate, and maintain the App's core services.
  • Generate PDF reports and loan statements.
  • Send local EMI reminder notifications on your device.
  • Enable manual WhatsApp sharing (initiated only by you).
  • Provide Live Customer Support via in-app chat.
  • Authenticate and secure your account.
  • Sync your data to the cloud for backup.
  • Detect and prevent fraud and security threats.
We DO NOT send automatic background messages to your customers, use your data for advertising, create profiles for targeted ads, or sell/rent your data to third parties.
4

Data Storage & Security

4.1 Local Storage

Your data is primarily stored on your device in an AES-256 encrypted SQLite database (using SQLCipher). The encryption key is securely stored in the Android Hardware Keystore, making it inaccessible to other apps.

4.2 Cloud Storage

When you use cloud sync, your data is securely stored on Supabase (PostgreSQL). All transmission occurs over HTTPS with SSL/TLS certificate pinning to prevent interception.

4.3 Security Measures

We implement industry-standard security including:

  • AES-256 database encryption
  • SSL/TLS Certificate Pinning
  • Firebase App Check (Play Integrity)
  • Runtime Application Self-Protection (RASP) against root/tampering
  • Row-Level Security (RLS) on cloud database
  • No Android backup (allowBackup=false)
5

Third-Party Services

The App uses the following third-party services:

6

Account Deletion & Data Retention

You have the right to request deletion of your account at any time through the App's Settings screen.

Grace Period: Your account enters a grace period where app access is restricted but data is retained safely. You may cancel the request during this period.

Permanent Deletion: If you do not cancel, your account and ALL associated data (cloud backups, profile info, locally stored data) will be permanently and irreversibly deleted from our servers and your device.

Web Data Deletion Request: If you no longer have access to the App, you can also request account and data deletion by sending an email to udharbahikhata.support@gmail.com from your registered email address.

7

Offline Functionality

The App is designed with an offline-first architecture. Core features work fully without an internet connection. Data is stored locally in an encrypted database on your device. Cloud sync occurs only when you have an active internet connection.

8

Contact & Community

If you have any questions, concerns, or requests regarding this Privacy Policy, or want to join our community, please connect with us: