Privacy Policy
Last updated: July 13, 2026
Kharcha Pani ("we", "our", or "us") is a personal finance tracking application developed and operated by Rahul Jangir. We are committed to protecting your personal data in compliance with India's Digital Personal Data Protection Act, 2023 (DPDPA).
This policy explains what data we collect, why we collect it, how we store and protect it, and the rights you have over your data.
Encrypted
All data encrypted at rest & in transit
No Selling
We never sell your personal data
You Own It
Your data, your rights, always
DPDPA 2023
Compliant with Indian data law
1. Who We Are
Kharcha Pani is a personal finance management application built and maintained by Rahul Jangir, an independent developer based in India. This is not a company, bank, NBFC, or regulated financial entity. We are a software tool to help you track and understand your own finances.
2. Data We Collect
2.1 Account Information
- Name: For account identification and personalization.
- Email address: For authentication, notifications, and account recovery.
- Profile picture (optional): Sourced from your Google or GitHub profile if you use OAuth.
2.2 Financial Data (Entered by You)
All financial data is entered manually by you. We do not connect to your bank, read your SMS, or access any external account. The data you enter includes:
- Expenses, income, and investment records
- Budget configurations and savings goals
- Subscription and insurance details
- Tax-related inputs (salary, deductions, regime preference)
- Net worth entries (assets and liabilities you choose to record)
2.3 AI Interaction Data
- Chat history: Conversations with the AI Copilot, stored for context-aware responses.
- Financial context sent to AI: When you use AI features, relevant summaries of your financial data are sent to Google Gemini AI. This is subject to Google's privacy policy.
2.4 Technical Data
- IP address: Collected for security and fraud prevention.
- Device and browser info: For session management.
- Usage patterns: Only with your explicit consent via the cookie banner.
3. How We Use Your Data
- Account management: Authentication, session handling, and account recovery.
- Finance tracking: Recording, categorizing, and analysing your entries.
- AI insights: Personalized financial recommendations via Google Gemini AI.
- Notifications: Budget alerts, subscription reminders, and tax deadline alerts via email.
- Security: Detecting unauthorized access and preventing abuse.
- Legal compliance: Meeting obligations under DPDPA 2023 and applicable Indian law.
4. Data Storage & Retention
- Database: PostgreSQL hosted on Neon (Vercel Postgres). Data is encrypted at rest (AES-256) and in transit (TLS 1.3).
- File storage: Receipt images stored via UploadThing (AWS S3).
- Session data: Managed by Better Auth, stored in the database.
- Retention: Data is retained while your account is active. On deletion, all data is permanently removed after a 30-day grace period.
- Backups: Automated daily backups retained for 30 days.
5. Third-Party Services
We use the following third-party services. We only share the minimum data necessary.
| Service | Purpose | Data Shared |
|---|---|---|
| Google Gemini AI | AI insights & copilot | Financial summaries, chat messages |
| Better Auth | Authentication | Session tokens, OAuth credentials |
| Vercel | App hosting | Hosting logs, IP addresses |
| Neon (Postgres) | Database | All user data (encrypted) |
| UploadThing / AWS S3 | File storage | Receipt images |
| Resend | Transactional emails | Email address, notification content |
We do not sell, rent, or share your data with advertisers or marketing companies.
6. Your Rights Under DPDPA 2023
Right to Access
View all your data within the app. Download a full export via Settings → Privacy → “Download My Data”.
Right to Correction
Edit or correct any financial entry directly within the app.
Right to Erasure
Delete your account via Settings → Danger Zone → “Delete My Account”. All data is permanently erased after a 30-day grace period.
Right to Data Portability
Export all data in CSV/JSON format at any time from Settings → Privacy.
Right to Withdraw Consent
Withdraw consent for AI data processing or analytics at any time via Settings → Privacy.
Right to Grievance Redressal
Contact our grievance officer (see Section 8) for any data-related concerns.
7. Security
- All data encrypted in transit (TLS 1.3) and at rest (AES-256).
- Authentication uses secure, HTTP-only session cookies.
- Database access is restricted via connection pooling and role-based access control.
- Automated daily backups with 30-day retention.
- Regular dependency audits to patch known vulnerabilities.
8. Children's Privacy
Kharcha Pani is not intended for users under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has created an account, please contact us and we will delete the data promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email and an in-app notice at least 14 days before they take effect. The "Last updated" date at the top of this page will always reflect the most recent revision.
10. Governing Law
This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023. Any disputes shall be subject to the exclusive jurisdiction of courts in Rajasthan, India.
11. Contact & Grievance Officer
Rahul Jangir — Grievance Officer
Email: hello@rahuljangir.work
Website: https://rahuljangir.work
We respond to all privacy-related inquiries within 72 hours.