Hisab Dost

Privacy Policy

Hisab Dost · Document version: 19 August 2026

Contents

  1. Overview
  2. What Data We Collect
  3. Notification Access (Companion App)
  4. How Data is Processed
  5. Data Usage
  6. Data Sharing
  7. Data Security
  8. Your Rights (DPDP Compliance)
  9. Data Retention & Deletion
  10. Your Control
  11. Audit Trail & Service Integrity
  12. Security Incidents
  13. Compliance
  14. Children’s Privacy and Age Eligibility
  15. Updates to This Policy
  16. Related Pages
  17. Privacy & Grievance Contact

1 Overview

Hisab Dost is a bookkeeping companion that helps users track daily income, expenses, and financial activities through a Telegram/WhatsApp-based ledger and a companion Android app for automatic UPI transaction capture.

Our goal is simple - make financial tracking effortless, private, and secure.

2 What Data We Collect

We collect only the data required to provide our services.

Profile Information (provided during onboarding)
  • Phone number
Financial & Transaction Data
  • Transaction amount (₹)
  • Transaction type (credit / debit)
  • Timestamp
  • UPI reference (hashed, never stored in raw form)
  • Party name (if available from transaction or user input)
  • Notes or descriptions entered by the user
Account & App Technical Data (minimal)
  • Telegram ID or WhatsApp identifier, where applicable, used for account linking, service delivery, report access, and account management
  • App-generated device token or install identifier used for authentication, account security, service integrity, and abuse prevention
  • Subscription and purchase records used for service delivery, plan management, and support
We do NOT collect
  • Your name, city, or profession
  • Bank account numbers or card details
  • OTPs or passwords
  • Your bank account balance
  • Personal messages or chat notifications
  • Hardware or OS-level identifiers such as IMEI, Android ID, Advertising ID, or device serial number
  • Location data or GPS coordinates
  • Photos or files stored on your device

3 Notification Access (Companion App)

The companion app uses Android's Notification Listener Service to detect UPI payment confirmations. Strict on-device filters ensure only UPI-related notifications are processed. All other notifications are immediately discarded.

Raw notification text is never transmitted to our servers. Only minimal structured data - the amount, whether money was received or paid, a hashed transaction reference, merchant or party information if available, and the transaction time - is sent securely.

4 How Data is Processed

We follow a privacy-first architecture where filtering and extraction happen entirely on your device.

StepWhat HappensWhere
1Notification receivedYour device
2Filtered - is it UPI?Your device
3Non-UPI notifications discardedYour device
4Amount, type, hashed reference & party hint extractedYour device
5Structured data sent via HTTPSIn transit
6Stored in your personal ledgerServer (encrypted)

5 Data Usage

Your data is used only for Hisab Dost service purposes. We do not use your personal or financial data for advertising or unrelated profiling.

  • Maintaining your personal financial ledger
  • Generating financial summaries and reports
  • Detecting missed transactions, duplicate transactions, or mismatches
  • Managing consent, account status, subscription status, and deletion requests
  • Maintaining security, audit trail, and service integrity
  • Improving product functionality in a privacy-respecting way

6 Data Sharing

We do not sell, rent, or trade your personal or financial data. We do not display advertisements and we do not share data with advertisers or data brokers.

We may use trusted service providers only to operate Hisab Dost, such as secure hosting, database infrastructure, Telegram/WhatsApp messaging, app distribution, and payment processing where applicable.

Data may also be disclosed where required by applicable law, legal process, security investigation, fraud prevention, or compliance obligations.

7 Data Security

Protections we apply
  • HTTPS (TLS) encryption for all data in transit
  • AES-256 encryption at rest for sensitive personal data
  • SHA-256 hashed transaction references (raw UTR never stored)
  • Unique app-generated device/security token authentication
  • Restricted database access and least-privilege access controls
  • API rate limiting to prevent unauthorized access
  • Database hosted on infrastructure with disk-level encryption
  • Production Android app logs do not contain user financial data, raw notification text, OTPs, or full payment messages.

8 Your Rights (DPDP Compliance)

Under India's Digital Personal Data Protection Act (DPDP), 2023, you have control over your personal data processed by Hisab Dost.

You can
  • Access your data
  • Correct inaccurate profile data
  • Request complete deletion of your account data
  • Withdraw consent and stop future processing
In-app deletion controls
  • Use /deletedata to start account deletion
  • Type DELETE to confirm the request
  • Use /canceldelete within the pending window to cancel the request

Data requests can also be made by contacting us at the email address listed below.

9 Data Retention & Deletion

Account and ledger data is stored while your Hisab Dost account continues to exist, unless a shorter operational or legally required retention period applies. Moving between the Free Limited Plan and Paid Plan, expiry of paid access, or uninstalling the companion app does not by itself delete your server-side account or ledger data. You may request deletion at any time.

Deletion Process
Request started - when you use /deletedata and confirm with DELETE, your account is immediately disabled and new processing stops.
Pending deletion window (up to 8 hours) - during this period you may cancel the request using /canceldelete.
Permanently erased - after the pending window, eligible account data is irrecoverably deleted from our active systems.
Important clarification
  • Deletion applies to data processed and stored by Hisab Dost.
  • It does not delete messages already stored by Telegram, WhatsApp, banks, or other third-party platforms outside our control.
  • If deletion is cancelled during the pending window, the account is restored and normal processing resumes.

Where backups are used, residual copies of deleted account data may remain in encrypted backups for up to 30 days before removal through backup rotation. Separately, limited records may be retained longer only where required for legal, accounting, fraud prevention, security, audit, tax, billing, or compliance purposes, and only for the applicable purpose and period.

10 Your Control

You remain in control of your data and service access:

  • Disable notification access anytime from within the app or Android Settings
  • Stop using the service at any time
  • Uninstalling the companion app immediately stops notification access from that device
  • Use your phone’s screen lock, app lock, PIN, or biometric protection to help keep your Hisab Dost access private.
  • Use /deletedata to request account deletion
  • Use /canceldelete during the pending window to restore the account

11 Audit Trail & Service Integrity

We maintain limited internal audit records for security, consent, deletion, subscription, and service integrity purposes.

Audit records are intended to avoid raw notification text, raw SMS text, OTPs, full payment messages, and unnecessary sensitive data.

12 Security Incidents

If we become aware of a security incident affecting user data, we will take appropriate steps as required by applicable law.

13 Compliance

Hisab Dost is designed to comply with:

• India's Digital Personal Data Protection Act, 2023 (DPDP)
• Applicable Android app store developer policies and platform requirements for the distribution channels where Hisab Dost is published
• Android Notification Listener Service usage guidelines

Notification-based UPI processing is optional. We obtain the relevant user consent before using this feature, and Android Notification Access is granted separately by the user through Android system settings.

14 Children’s Privacy and Age Eligibility

Hisab Dost is intended only for individuals who are 18 years of age or older. By using the service, you confirm that you are 18 years of age or older.

We do not knowingly collect personal data from individuals who are under 18 years of age. If you believe that a person under 18 has provided personal data to Hisab Dost, please contact us so that we can review the request and take appropriate action, including deletion where applicable.

15 Updates to This Policy

We may update this privacy policy periodically. Changes will be reflected on this page with a revised date. Where a material change affects how personal data is processed or requires fresh consent, we will provide appropriate notice and obtain consent where required.

16 Related Pages

Terms & Conditions: michio.in/terms.html

Data Deletion Policy: michio.in/data-deletion.html

17 Privacy & Grievance Contact

For privacy-related questions, grievance requests, data access/correction requests, consent withdrawal, or data deletion requests, you may contact us at:

📧 Email: support@michio.in
🌐 Website: michio.in

For in-service deletion requests, the deletion flow follows the product process, including a pending deletion window of up to 8 hours. For email-based privacy, grievance, or deletion-related requests, we aim to acknowledge and respond within a reasonable time, typically within 7 working days.

To protect user data, we may ask for limited information necessary to verify that the request belongs to the correct account holder before processing certain requests.