Kharcha

Privacy Policy

Last updated 20 September 2026

Kharcha is an expense tracker for your own money. This policy describes exactly what it does with your information. Every claim below is a description of how the app is built, and each one can be checked against the source code, which is public.

The short version

What Kharcha stores, and where

On your phone. Everything. Your spends, categories, occasions, cards, and the people you have lent to are stored in a database on the device. This is the primary copy — Kharcha is built to work fully offline, and the phone is the source of truth.

In the cloud — only if you sign in. If you create an account, a copy of that same data is saved to a private area of Google Firebase that only your account can read. This exists so you do not lose your records if you lose your phone. If you never sign in, no copy is made and no data leaves the device.

Bank SMS

Kharcha's distinctive feature is turning bank and UPI messages into expense entries. How that works matters, so it is spelled out:

If you sign in, the *expense* created from a message is backed up like any other expense — the amount, date, merchant name and category. The raw message text is not.

Optional encryption of the cloud copy

You can set a password of your own choosing — letters, numbers, a phrase, whatever you like — and Kharcha will then encrypt the identifying parts of each spend, the merchant name and your note, on the phone before they are uploaded. The backup is unreadable without that password, including to whoever operates the storage. It is not your account password and is never sent anywhere.

This is off unless you switch it on, and nothing changes for anyone who never opens the setting.

What Kharcha does not do

If Kharcha is ever acquired, this policy travels with your data: a buyer would be bound by it, and any change would be announced in the app before it took effect.

Permissions, and why each is needed

PermissionWhy
Read SMSTo find transaction alerts from banks and UPI apps and turn them into entries, on the device. Optional.
NotificationsTo send the one daily reminder you can turn on, and nothing else.
Exact alarm / boot completedSo that daily reminder fires at the time you chose, and survives a restart.
VibrateFeedback on that notification.

Kharcha requests no other permissions.

Third parties

Kharcha uses Google Firebase (Authentication and Cloud Firestore) for accounts and cloud backup, and only when you have signed in. Firebase is a data processor here: it stores your data on Kharcha's behalf and is not permitted to use it for its own purposes. Google's handling of that data is covered by its own terms.

Kharcha uses Expo to deliver app updates. Update delivery involves your device requesting a bundle; it does not carry your financial data.

There are no other third parties. No advertising networks, no analytics providers, no data brokers.

Your control

Children

Kharcha is not directed at children under 13 and does not knowingly collect their information.

Security

Cloud data is protected by per-account rules that permit each account to read and write only its own records, and is transmitted over TLS. Local data is held in the app's private storage, which other apps cannot read on a non-rooted device, and device backup of the app's data is disabled.

For the cloud copy you can go further and encrypt the identifying fields with a password of your own, described above.

No system is perfect. If you find a security issue, please report it (see below) rather than disclosing it publicly, and it will be addressed.

Cost

Kharcha is free. There is no paid tier today. Were one ever introduced, the existing free functionality would not be taken away and made paid, and no part of the app would ever be funded by advertising or by selling data.

Changes

Material changes to this policy will be shown in the app before they take effect, not quietly published. The date at the top reflects the current version.

Contact

Questions, data requests or security reports: contact@shubhamjangid.in