NRDDA
๐Ÿ“š Privacy policy

HisaabKiKitaab

HisaabKiKitaab holds your money records, so you are owed an unusually direct account of where those records live and who can reach them. This policy is written to match exactly what the app does.

Effective 19 August 2026 Package com.nrdda.hisaabkikitab Publisher NRDDA Tech Platform Android

01. Overview

HisaabKiKitaab (“the App”, “we”, “our”) is a personal expense tracker and daily ledger for Android, published by NRDDA Tech, Hyderabad, India. It is built for fast entry and honest month-end numbers.

Key takeaways

  • You sign in with an email address and password, managed by Google Firebase Authentication.
  • Your ledger is backed up to the cloud under your own private account key, so you can restore it on a new phone.
  • We never connect to your bank. The app has no bank login, no SMS reading, and no account aggregation. Every entry is one you typed.
  • We never see your card or bank credentials. Purchases go through Google Play Billing.
  • We do not sell your financial data. It is not shared with advertisers, lenders, credit bureaus, or data brokers โ€” ever.

02. Where your money data actually lives

HisaabKiKitaab keeps two copies of your ledger, and it is important that you know about both.

Copy 1

On your device

Every expense, budget, category, and note you enter is written first to a local database in the app’s private storage, protected by the Android sandbox so that other apps cannot read it. This is what makes the app fast and usable with no signal.

Copy 2

In your private cloud backup

When you are signed in, the app synchronises your ledger to Google Firebase Realtime Database, stored under a path keyed to your own account ID. This is what lets you reinstall the app or move to a new phone without losing your history.

What is synchronised:

  • Expense entries โ€” amount, category, date, payment mode, and any note or description you typed
  • Budgets and per-category budget limits
  • Expense edit history
  • Credit and balance figures
  • Your notification and reminder rules
  • Basic device information for the device holding your session
  • Security metadata used to sign you out everywhere if you change your password

Access is restricted to your authenticated account. Other users of the app cannot read your ledger, and there is no sharing, social, or public feed feature in HisaabKiKitaab.

Be aware: because your ledger is backed up to the cloud, deleting the app from your phone alone does not erase it. To remove the cloud copy as well, use the account deletion process in section 09.

03. What we collect and why

Account

Sign-up and sign-in

Collected: your email address and a password, handled by Google Firebase Authentication. Firebase stores your credential; we never store or see your plaintext password.

Purpose: identifying which ledger is yours, restoring your data on a new device, and signing you out of other devices when you change your password.

Financial

The entries you type

Collected: the expense amounts, categories, dates, payment modes, budgets, and free-text notes you enter yourself.

Purpose: being the ledger. This data exists to be shown back to you in totals, reports, and budget warnings. It is not analysed for advertising, not scored for creditworthiness, and not shared with any third party for their own purposes.

Not collected: your bank account number, card number, UPI ID, net-banking credentials, or SMS messages. The app has no permission to read any of these.

Diagnostics

Analytics, crashes, and configuration

Collected: anonymous Firebase app-instance ID, screen and feature usage events, session duration, app version, device model, OS version, and โ€” when the app crashes โ€” a stack trace with the device state at that moment.

Purpose: Firebase Analytics tells us which features get used, Crashlytics tells us what broke, and Remote Config lets us change settings without shipping an update. Crash reports contain technical diagnostics, not the contents of your ledger.

Advertising

Google AdMob

The free tier of the app displays banner advertisements served by Google AdMob. AdMob may collect your Advertising ID (GAID), IP address, device model, OS version, and ad interaction events for ad delivery, frequency capping, and fraud prevention.

Your ledger contents are never sent to AdMob or used to target ads at you. You can reset or delete your Advertising ID under Android Settings › Google › Ads, and users on a paid plan do not see ads.

Purchases

Google Play Billing

Collected: purchase tokens, order IDs, product identifiers, and your entitlement status (whether the account is on the paid plan).

Payment security: all payments are processed entirely by the Google Play Store. We never see, collect, or store your card number, UPI ID, or any banking credential.

04. Android permissions we declare

PermissionCategoryWhy the app needs it
INTERNETNetwork Signing in, backing up and restoring your ledger, loading ads, and reporting crashes.
POST_NOTIFICATIONSNotifications Daily entry reminders and budget-limit alerts on Android 13 and above. Generated locally on your device.
READ_EXTERNAL_STORAGE
(Android 12L and below only)
Storage Reading a file you pick when importing or restoring a report. Declared with maxSdkVersion="32", so it is not requested on newer Android versions.
WRITE_EXTERNAL_STORAGE
(Android 9 and below only)
Storage Saving an exported expense report to your device on older Android versions. Declared with maxSdkVersion="28".

HisaabKiKitaab does not request access to your SMS messages, call logs, contacts, camera, microphone, or location. An expense tracker that reads your SMS to auto-import bank alerts would need those permissions โ€” this one deliberately does not.

05. Third-party services

Every one of these is a Google service operating as our data processor under Google’s data protection terms. There are no other recipients. We do not sell your personal or financial information to anyone.

06. Google Play Data Safety mapping

Data categoryData type Collected / sharedRequired?Purpose
Personal infoEmail address, user ID Collected (Firebase Auth)Required Account management, app functionality
Financial infoUser-entered expense, budget and credit records Collected (Firebase Realtime Database). Not shared.Required App functionality โ€” the ledger and its backup
Financial infoPurchase history Collected (Google Play Billing)Optional Purchase fulfilment, entitlement checks
App activityApp interactions Collected (Firebase Analytics)Required Analytics, app improvement
App info & performanceCrash logs, diagnostics Collected (Crashlytics)Required Diagnostics, app stability
Device or other IDsAdvertising ID, Firebase instance ID Collected & shared (AdMob, Firebase)Optional Advertising, analytics, fraud prevention

Data is encrypted in transit using HTTPS/TLS, and you can request deletion of your data.

07. Children’s privacy

HisaabKiKitaab is a personal finance tool intended for adults and is not directed at children under 13. We do not knowingly collect personal information from children under 13 (or under 16 in the EU/UK). If a parent or guardian believes a child has created an account, contact us and we will delete the account and its data promptly.

08. Your rights and controls

  • Access: your entire ledger is visible inside the app, and you can export it as a report at any time.
  • Correction: edit or delete any individual entry directly in the app; edits are recorded in your own edit history.
  • Deletion: see section 09.
  • Ad controls: reset or delete your Advertising ID under Android Settings › Google › Ads, or remove ads by upgrading.
  • Notifications: turn reminders off in the app’s settings or in Android notification settings.
  • Complain: you may raise a complaint with your local data protection authority. Under India’s DPDP Act, EU/UK GDPR, and California’s CCPA/CPRA, we honour access, correction, and deletion requests for all users regardless of location.

We respond to rights requests within 30 days, free of charge.

09. Deleting your account and data

Two things to delete

  • Local copy: Android Settings › Apps › HisaabKiKitaab › Storage › Clear data, or simply uninstall the app.
  • Cloud copy and account: open Settings › Delete account in the app. You confirm once, then re-enter your password to prove it is you. This removes your authentication record and the ledger stored under your account key.

By email: write to nrdda.owner@gmail.com from your registered email address with the subject “HisaabKiKitaab account deletion”. We complete the deletion within 30 days and confirm when it is done.

What survives deletion: aggregated, de-identified analytics that can no longer be linked to you, and purchase records that Google Play retains for tax and refund purposes.

10. Security and retention

  • In transit: all traffic between the app and Firebase uses HTTPS/TLS.
  • At rest: cloud data is stored on Google Cloud infrastructure with Google’s encryption at rest; on-device data lives in private app storage protected by the Android sandbox.
  • Access rules: the cloud database is scoped so that a signed-in account can read and write only its own records.
  • Session control: changing your password invalidates sessions on other devices, and a remote wipe marker clears the local copy on a device that has been signed out.
  • Retention: your ledger is kept for as long as your account exists. Analytics follows Firebase’s standard retention (typically 14 months). Crash reports are retained around 90 days.
  • Breach handling: if a breach affects your personal data, we will notify affected users and the relevant authority as required by law.

No system is perfectly secure. We use industry-standard measures, but we cannot guarantee absolute security.

11. Changes to this policy

We update this policy when the app’s data practices change, and the effective date at the top always reflects the current version. For material changes we will notify you in the app before the change takes effect.

12. Contact

Publisher: NRDDA Tech, Hyderabad, India

App: HisaabKiKitaab (com.nrdda.hisaabkikitab)

Data protection contact: Dipak Chouhan

Email: nrdda.owner@gmail.com