Privacy policy
What we hold, why we hold it, and what we will never do with it.
Last updated: 23 August 2026
What we collect
From committee members: the name, email address and profile picture on the Google account you sign in with. We never see or store your Google password.
What you record: the entries your mandal enters — amounts, heads, payment modes, dates, receipt numbers, notes, and any bill photos you attach.
About donors: only what a collector types on an entry — a name, and a mobile number when one is given so the receipt can be sent. Nothing else about a donor is collected, and donors never have an account.
Your mandal: its name, address, registration number, established year, logo and the WhatsApp number we use to reach the committee.
Why we hold it
To run the app: to show your books, produce receipts, and keep every member's view in step.
To deliver receipts: a donor's mobile number is passed to WhatsApp solely to send that one receipt. Donors are never messaged about anything else, and we do not build any profile of them.
To take payment: when you buy a plan or receipts, the payment is handled by Razorpay. We record what was bought and when. We never see or store your card or UPI details.
Who can see your entries
Only members of your own mandal whom an admin has approved. Roles narrow this further — a volunteer sees only the entries they recorded themselves.
No other mandal can read your books. This is enforced by the database itself, not only by the app.
Our support team can access a mandal's records when we need to resolve a problem you have raised. Every such access is logged with who looked, when, and why.
We do not sell your data, we do not share it with advertisers, and we do not use it to train anything.
Where it lives
In Google Firebase, on servers operated by Google Cloud. Traffic is encrypted in transit.
Receipt images are generated on your phone and stored so they can be delivered on WhatsApp.
How long we keep it
For as long as your mandal uses the service, because a mandal's accounts are meant to be looked back at years later.
If you close your mandal or ask for deletion, see the data deletion page.
Your choices
You can correct or delete any entry from the app, subject to your role.
You can ask for a copy of your mandal's data, or ask us to delete it, at the address on the contact page.
Receipt numbers are never reused after an entry is deleted — a gap in a receipt book is what an auditor questions.
Children
The service is meant for committee members managing a mandal's accounts, and is not directed at children.
Changes
If this policy changes in a way that matters, we will say so in the app rather than quietly editing this page.