01. Overview
HisaabKiKitaab (“the App”, “we”, “our”) is a personal expense tracker and daily ledger for Android, published by NRDDA Tech, Hyderabad, India. It is built for fast entry and honest month-end numbers.
Key takeaways
- You sign in with an email address and password, managed by Google Firebase Authentication.
- Your ledger is backed up to the cloud under your own private account key, so you can restore it on a new phone.
- We never connect to your bank. The app has no bank login, no SMS reading, and no account aggregation. Every entry is one you typed.
- We never see your card or bank credentials. Purchases go through Google Play Billing.
- We do not sell your financial data. It is not shared with advertisers, lenders, credit bureaus, or data brokers โ ever.
02. Where your money data actually lives
HisaabKiKitaab keeps two copies of your ledger, and it is important that you know about both.
On your device
Every expense, budget, category, and note you enter is written first to a local database in the app’s private storage, protected by the Android sandbox so that other apps cannot read it. This is what makes the app fast and usable with no signal.
In your private cloud backup
When you are signed in, the app synchronises your ledger to Google Firebase Realtime Database, stored under a path keyed to your own account ID. This is what lets you reinstall the app or move to a new phone without losing your history.
What is synchronised:
- Expense entries โ amount, category, date, payment mode, and any note or description you typed
- Budgets and per-category budget limits
- Expense edit history
- Credit and balance figures
- Your notification and reminder rules
- Basic device information for the device holding your session
- Security metadata used to sign you out everywhere if you change your password
Access is restricted to your authenticated account. Other users of the app cannot read your ledger, and there is no sharing, social, or public feed feature in HisaabKiKitaab.
Be aware: because your ledger is backed up to the cloud, deleting the app from your phone alone does not erase it. To remove the cloud copy as well, use the account deletion process in section 09.
03. What we collect and why
Sign-up and sign-in
Collected: your email address and a password, handled by Google Firebase Authentication. Firebase stores your credential; we never store or see your plaintext password.
Purpose: identifying which ledger is yours, restoring your data on a new device, and signing you out of other devices when you change your password.
The entries you type
Collected: the expense amounts, categories, dates, payment modes, budgets, and free-text notes you enter yourself.
Purpose: being the ledger. This data exists to be shown back to you in totals, reports, and budget warnings. It is not analysed for advertising, not scored for creditworthiness, and not shared with any third party for their own purposes.
Not collected: your bank account number, card number, UPI ID, net-banking credentials, or SMS messages. The app has no permission to read any of these.
Analytics, crashes, and configuration
Collected: anonymous Firebase app-instance ID, screen and feature usage events, session duration, app version, device model, OS version, and โ when the app crashes โ a stack trace with the device state at that moment.
Purpose: Firebase Analytics tells us which features get used, Crashlytics tells us what broke, and Remote Config lets us change settings without shipping an update. Crash reports contain technical diagnostics, not the contents of your ledger.
Google AdMob
The free tier of the app displays banner advertisements served by Google AdMob. AdMob may collect your Advertising ID (GAID), IP address, device model, OS version, and ad interaction events for ad delivery, frequency capping, and fraud prevention.
Your ledger contents are never sent to AdMob or used to target ads at you. You can reset or delete your Advertising ID under Android Settings › Google › Ads, and users on a paid plan do not see ads.
Google Play Billing
Collected: purchase tokens, order IDs, product identifiers, and your entitlement status (whether the account is on the paid plan).
Payment security: all payments are processed entirely by the Google Play Store. We never see, collect, or store your card number, UPI ID, or any banking credential.
04. Android permissions we declare
| Permission | Category | Why the app needs it |
|---|---|---|
INTERNET | Network | Signing in, backing up and restoring your ledger, loading ads, and reporting crashes. |
POST_NOTIFICATIONS | Notifications | Daily entry reminders and budget-limit alerts on Android 13 and above. Generated locally on your device. |
READ_EXTERNAL_STORAGE(Android 12L and below only) | Storage | Reading a file you pick when importing or restoring a report. Declared with maxSdkVersion="32", so it is not requested on newer Android versions. |
WRITE_EXTERNAL_STORAGE(Android 9 and below only) | Storage | Saving an exported expense report to your device on older Android versions. Declared with maxSdkVersion="28". |
HisaabKiKitaab does not request access to your SMS messages, call logs, contacts, camera, microphone, or location. An expense tracker that reads your SMS to auto-import bank alerts would need those permissions โ this one deliberately does not.
05. Third-party services
- Google Firebase (Authentication, Realtime Database, Analytics, Crashlytics, Remote Config) โ firebase.google.com/support/privacy
- Google AdMob โ policies.google.com/technologies/ads
- Google Play Services & Play Billing โ policies.google.com/privacy
Every one of these is a Google service operating as our data processor under Google’s data protection terms. There are no other recipients. We do not sell your personal or financial information to anyone.
06. Google Play Data Safety mapping
| Data category | Data type | Collected / shared | Required? | Purpose |
|---|---|---|---|---|
| Personal info | Email address, user ID | Collected (Firebase Auth) | Required | Account management, app functionality |
| Financial info | User-entered expense, budget and credit records | Collected (Firebase Realtime Database). Not shared. | Required | App functionality โ the ledger and its backup |
| Financial info | Purchase history | Collected (Google Play Billing) | Optional | Purchase fulfilment, entitlement checks |
| App activity | App interactions | Collected (Firebase Analytics) | Required | Analytics, app improvement |
| App info & performance | Crash logs, diagnostics | Collected (Crashlytics) | Required | Diagnostics, app stability |
| Device or other IDs | Advertising ID, Firebase instance ID | Collected & shared (AdMob, Firebase) | Optional | Advertising, analytics, fraud prevention |
Data is encrypted in transit using HTTPS/TLS, and you can request deletion of your data.
07. Children’s privacy
HisaabKiKitaab is a personal finance tool intended for adults and is not directed at children under 13. We do not knowingly collect personal information from children under 13 (or under 16 in the EU/UK). If a parent or guardian believes a child has created an account, contact us and we will delete the account and its data promptly.
08. Your rights and controls
- Access: your entire ledger is visible inside the app, and you can export it as a report at any time.
- Correction: edit or delete any individual entry directly in the app; edits are recorded in your own edit history.
- Deletion: see section 09.
- Ad controls: reset or delete your Advertising ID under Android Settings › Google › Ads, or remove ads by upgrading.
- Notifications: turn reminders off in the app’s settings or in Android notification settings.
- Complain: you may raise a complaint with your local data protection authority. Under India’s DPDP Act, EU/UK GDPR, and California’s CCPA/CPRA, we honour access, correction, and deletion requests for all users regardless of location.
We respond to rights requests within 30 days, free of charge.
09. Deleting your account and data
Two things to delete
- Local copy: Android Settings › Apps › HisaabKiKitaab › Storage › Clear data, or simply uninstall the app.
- Cloud copy and account: open Settings › Delete account in the app. You confirm once, then re-enter your password to prove it is you. This removes your authentication record and the ledger stored under your account key.
By email: write to nrdda.owner@gmail.com from your registered email address with the subject “HisaabKiKitaab account deletion”. We complete the deletion within 30 days and confirm when it is done.
What survives deletion: aggregated, de-identified analytics that can no longer be linked to you, and purchase records that Google Play retains for tax and refund purposes.
10. Security and retention
- In transit: all traffic between the app and Firebase uses HTTPS/TLS.
- At rest: cloud data is stored on Google Cloud infrastructure with Google’s encryption at rest; on-device data lives in private app storage protected by the Android sandbox.
- Access rules: the cloud database is scoped so that a signed-in account can read and write only its own records.
- Session control: changing your password invalidates sessions on other devices, and a remote wipe marker clears the local copy on a device that has been signed out.
- Retention: your ledger is kept for as long as your account exists. Analytics follows Firebase’s standard retention (typically 14 months). Crash reports are retained around 90 days.
- Breach handling: if a breach affects your personal data, we will notify affected users and the relevant authority as required by law.
No system is perfectly secure. We use industry-standard measures, but we cannot guarantee absolute security.
11. Changes to this policy
We update this policy when the app’s data practices change, and the effective date at the top always reflects the current version. For material changes we will notify you in the app before the change takes effect.
12. Contact
Publisher: NRDDA Tech, Hyderabad, India
App: HisaabKiKitaab (com.nrdda.hisaabkikitab)
Data protection contact: Dipak Chouhan
Email: nrdda.owner@gmail.com