Legal
Privacy Policy
HisabX is a personal-finance app, so the records you keep in it are among the most sensitive things you will ever type into a phone. This policy sets out what we collect, what we deliberately do not, who else can see any of it, and what you can do about all three.
Last updated September 1, 2026Effective September 1, 2026
The short version
- Your financial records are yours. We do not sell them, rent them, or use them to choose an advertisement.
- Everything you enter is saved on your own device first. It syncs to your account so it survives a lost phone and reaches your other devices, and the database itself is what stops anyone else from reading it.
- Crash and usage diagnostics carry no identifier for you, and no amount, note, counterparty or search you have typed. An amount is reported as a size range, never as a figure.
- Free accounts see ads. You choose whether they are personalised, you can change your answer later, and any paid plan removes them.
- You can export everything at any time, and you can delete your account from inside the app. Deletion is immediate and permanent.
This summary is here because a policy nobody reads protects nobody. It is not part of the policy — the sections below are what govern.
Who we are, and what this covers
HisabX (HisabX, we, us) publishes the HisabX mobile app and the website at hisabx.app. This policy covers both of them, and the servers behind them.
It does not cover what somebody else does with information you give them directly. If you follow a link out of HisabX — to an app store, to a bank, to anywhere — that destination's own policy governs from the moment you arrive.
For readers in a jurisdiction that uses the term: for the personal data described here, HisabX is the data controller. Questions go to hisabx.app@gmail.com, and there is a person on the other end of that address.
Information you give us
- Account details
- The email address and password you register with — or, if you continue with Google, the name, email address and profile picture Google associates with the account you pick. Passwords are stored only as a hash by our authentication provider. Nobody at HisabX can read yours, and nobody can recover it for you.
- Your financial records
- Everything you enter to make the app useful: transactions (amount, type, date, note, category, account, and cost of goods on a sale), the accounts you keep money in and their balances, budgets, the categories and tags you create, recurring templates, businesses you set up, and shopping lists.
- People you record
- A debt or loan stores the other party's name and, if you add one, their phone number. A cash-on-delivery order stores a customer name and a courier. This is information about somebody else, entered by you — see the next section.
- Preferences
- Your currency, language, appearance, time zone, active business, and which notifications you want. These sync, so a new phone starts where the old one left off.
- What you send us
- The contents of an email you write to support, including anything attached to it.
Information about other people
A debt record names a person and sometimes carries their phone number. That person is not a HisabX user by virtue of being in your ledger. They have not agreed to this policy, and they cannot see or correct what you have written about them.
So enter the least that makes the record useful to you, and treat it the way you would want a record of yourself treated. Where the law where you live places obligations on you for holding somebody else's details, those obligations are yours rather than ours.
We use a name or a number only to draw your own screens and, where you have asked for a reminder about a due date, to write that reminder for you. We do not contact the people in your ledger, and we build no profile of them.
Information collected automatically
- Crash reports
- When the app fails we receive a report through Google Firebase Crashlytics: what went wrong, where in the code, and the device model, operating system and app version it happened on. The error text is redacted first — see the next section, which is the part of this policy worth reading twice.
- Performance
- Firebase Performance Monitoring times how long the app takes to start and how long some operations take, so a release that is slower than the last one can be found.
- Usage analytics
- Firebase Analytics records that a feature was reached — an entry sheet opened, a budget created, a locked feature shown — against a randomly generated app-instance identifier assigned by Google. It is not your account id: no user identifier is ever set.
- Notification registration
- If you allow notifications, the app registers a delivery token from Firebase Cloud Messaging, along with an identifier it generates for that installation, the platform and the app version. The installation identifier is a random value stored on the device — not a hardware id and not an advertising id — and it exists so that a refreshed token replaces the old row instead of leaving a stale one behind.
- Advertising
- Ads are served by Google AdMob. What AdMob receives depends on the consent choice described under Advertising below.
- On your device
- A copy of your records lives in a database on the phone itself — that is what makes the app work offline — alongside a few settings that are deliberately device-local and never sync: whether the app lock is on, whether balances are hidden, and the pre-formatted snapshot the home-screen widget draws. A file you choose to import is read on the device; we never receive the file. Signing out clears all of it.
- Website
- Our host keeps ordinary server logs for hisabx.app — the time, the page and the network address a request came from — for security and availability. The site sets one cookie, and only if you use the language switch: it remembers whether you read English or Bangla. It runs no analytics, advertising or social tracking scripts at all.
One thing the website does on the first visit deserves naming: our delivery network attaches a country hint to the request, and we read it once to decide whether to show you English or Bangla. It is used for that decision and is not stored, logged against you, or used for anything else.
What never leaves your device
Diagnostics in a finance app are a genuine hazard, and it is worth being specific about why. The ordinary way to report a crash is to send the error text; the error text from a failed save contains the values the database was given, which for a transaction means the amount and the note. HisabX redacts before reporting, and the rule is tested against a real database error rather than asserted in a document.
| Instead of | What is actually sent |
|---|---|
| The amount | A size range — under 100, 1k–10k, and so on |
| The note you typed | Whether there was a note at all |
| What you searched for | How many characters it was, and how many results came back |
| A category you named yourself | The word custom |
| Who you are | Nothing. No user identifier is attached to analytics or crash reports. |
Beyond that: HisabX never asks for your location, and nothing in the app or the backend records what country you are in. We ask for no access to your camera, microphone, photos, messages or call history, and we do not read your address book. We are not a bank: we hold no card numbers, no bank credentials and no account numbers beyond the names you choose to give the accounts you track.
Permissions the app asks for
Each is asked for at the moment it is needed. Refusing any of them leaves the rest of the app working.
| Permission | When it is asked | What it is used for |
|---|---|---|
| Notifications | The first time a reminder or alert would be shown | Budget alerts, reminders for recurring entries, the weekly summary, and product announcements. Each kind has its own switch in Settings. |
| Biometrics or device lock | When you switch on the app lock | Unlocking HisabX. Your operating system performs the check and hands back a yes or a no; HisabX never sees a fingerprint or a face. |
| Contacts | Only when you tap to pick a contact while recording a debt | HisabX opens your system's own contact picker. Only the person you choose is read, and only their name and phone number are saved onto that debt. Your address book is not scanned, uploaded or kept. |
| Tracking (iOS) | Once, before any ad is requested | Apple's App Tracking Transparency prompt. Declining is respected, and ads become non-personalised. |
How we use your information
- To run the app: to store your records, sync them to your other devices, and draw every screen, report and export you ask for.
- To keep your account yours: to sign you in, to keep a session alive, and to detect and stop abuse.
- To notify you, where you have asked to be: budget alerts, reminders for recurring entries, weekly summaries, and occasional product announcements.
- To sell and support paid plans: to know which plan you are on, to unlock what it includes, and to answer you when you write in.
- To show advertising to free accounts, on the terms set out below.
- To fix and improve the product: to find crashes, to see in aggregate which parts of the app are reached and where people get stuck, and to decide what to build next.
- To meet a legal obligation, or to establish, exercise or defend a legal claim.
We do not sell personal data, and we do not share your financial records with anyone for their own marketing. Nothing you enter is used to choose an advertisement — the ad network never receives it.
Legal bases, for readers in the EEA and the UK
- Performance of a contract
- Everything needed to give you the service you asked for: your account, your records, sync, and any plan you have paid for.
- Consent
- Notifications, personalised advertising, and the contact picker. Each is asked for separately, each can be withdrawn — in the app's settings, in your device's settings, or both — and withdrawing one does not affect the others or the lawfulness of what was done before.
- Legitimate interests
- Keeping the service secure and available, understanding in aggregate how features are used, and improving the product. We collect the least that answers the question, which is why diagnostics are redacted and carry no identifier.
- Legal obligation
- Where a law requires us to keep, produce or disclose something.
Automated processing and notifications
Some of what HisabX does happens on our servers rather than on your phone, and it reads your records to do it. About once an hour a scheduled job looks at recent activity in your account to decide whether anything is worth telling you about: a budget heading over, a category unusually far above its own average, a recurring entry falling due, a run of days with nothing logged. Separately, recurring entries you have set up are posted on their due date whether the app is open or not.
None of this makes a decision with a legal or similarly significant effect for you. It produces messages, and only messages.
You can switch off any category of notification in Settings, or all of them at your device level. Switching them off stops the messages. The recurring entries you asked for still post, because posting them is the feature rather than the notification.
Advertising
HisabX is free, and free accounts see advertising: a card inside some lists, and an occasional short video you may choose to watch. Ads are served by Google AdMob.
Before any ad is requested the app runs a consent flow — Google's consent form where a data-protection law requires one, and on iOS Apple's App Tracking Transparency prompt as well. If you decline, ads still appear but are non-personalised: chosen without an advertising identifier and without a profile.
You can change your answer later. On iOS, in system Settings under Privacy and Security, then Tracking. On Android, by resetting or deleting your advertising id in Google settings. Where a consent form applies, HisabX offers a way to reopen it.
No ad network receives your transactions, balances, budgets, notes, categories or the names of people in your ledger. What Google collects in order to serve an ad is governed by Google's own policies, and we have no access to it.
Every paid plan removes advertising entirely.
Payments and subscriptions
Paid plans are sold through the app store you installed from, and managed through RevenueCat, the service that tells the app what your account is entitled to.
We never see your card number, and no payment instrument reaches our servers. What we receive is the outcome: which plan is active, when it renews or expires, and whether a trial has been used. RevenueCat is given an identifier for your HisabX account, so that a purchase follows you to a new phone.
Where a plan is arranged directly with us — a bKash, cash or bank transfer that no app store can see — we record it against your account ourselves, with the same two facts: what it is, and when it ends.
Billing history, cancellation and refunds are handled by whoever took the payment, under their own policy.
Access by our own staff
It would read better to claim that nobody at HisabX can reach your data. It would also be untrue. We run an internal console with privileged access to the database, and it exists because somebody has to be able to answer questions like why a subscription did not unlock, or why an account is stuck.
The rules we hold ourselves to: access is limited to named operators, operator actions are recorded, and the console is used for support, billing and operations rather than for browsing. The figures we look at routinely — how many accounts there are, how many are active — are aggregates that never require opening an individual ledger.
If you would rather nobody could ever open yours, the app exports your records in full, and deleting your account removes them from our side entirely.
Where your data is held
HisabX is operated from Bangladesh, and the services listed above run in data centres outside it. Using HisabX means your information is transferred to and processed in countries whose data-protection laws may differ from those where you live.
Where the law requires a safeguard for that transfer — in the EEA and the UK in particular — we rely on the standard contractual clauses and transfer arrangements our providers publish.
How long we keep it
- Your records are kept for as long as your account exists. A ledger's usefulness is its history, so nothing is aged out or quietly trimmed.
- Deleting your account is immediate and permanent: the account and every row attached to it — transactions, accounts, budgets, debts, orders, lists, settings, notifications, registered devices — are removed together. There is no recovery and no grace period during which we could restore it for you.
- Signing out clears the copy held on that device.
- Encrypted backups of the database exist for disaster recovery and are cycled out on a short schedule; a deleted account disappears from them as they cycle.
- Diagnostics held by Google expire on Google's own schedule, which is measured in months rather than years, and carry no identifier that could lead back to you.
- Records of a purchase, and correspondence with support, are kept for as long as tax, accounting or legal requirements demand.
Export before you delete. Once the account is gone, so is the only copy we hold.
How it is protected
- Every row in the database is fenced to its owner by a rule the database enforces itself, rather than by the app: a query for somebody else's records returns nothing, even if the app asks for them.
- Traffic between your device and our servers is encrypted in transit, and your session is carried by a short-lived token that refreshes rather than a stored password.
- The app can be locked behind your device's biometric or PIN, and balances can be hidden on screen. Both are device settings, and neither syncs to the server or to another phone.
- Backend addresses and keys are compiled into a build rather than committed to source, and the key with unrestricted database access exists only on the server.
No system is perfectly secure, and a policy that claims otherwise is selling something. If you find a weakness, write to hisabx.app@gmail.com — we would rather hear it from you.
Your choices and rights
Most of these you can exercise yourself, from inside the app, without asking us.
- See and correct
- Every record is editable where it appears.
- Export
- The app produces a PDF report and a CSV of your transactions, on demand.
- Delete
- Any single record, or the whole account, from Settings.
- Switch things off
- Notifications by category, advertising consent, the app lock, and the contact picker.
Depending on where you live you may also have rights to a copy of your personal data, to have it corrected or erased, to restrict or object to certain processing, to receive it in a portable form, and to withdraw a consent you have given. Write to hisabx.app@gmail.com and we will act within the time your law allows. We may need to confirm who you are first, and confirming will never ask for more than is necessary to be sure.
If you believe we have handled your data wrongly, we would rather hear it directly. You are also entitled to complain to the data-protection authority where you live.
Children
HisabX is not directed at children. You must be at least 13 to hold an account, and if you are under the age of majority where you live you may use it only with the involvement of a parent or guardian, who must agree to the Terms of Service and authorise any purchase.
We do not knowingly collect personal data from a child under 13. If you believe a child has created an account, write to hisabx.app@gmail.com and we will remove it.
Changes to this policy
We will update this policy as the product changes. The date at the top says when it last changed, and the version you are reading is the version in force.
Where a change materially affects you — a new recipient of your data, a new purpose, a narrower right — we will say so in the app before it takes effect, rather than only here.
Contact us
Questions about this policy, a request about your data, or anything you think we have got wrong: hisabx.app@gmail.com. Everything sent there is read.