Privacy Policy
Last updated: June 2026 · Written in plain English, because a privacy policy you can't read protects no one.
What we collect
- Identity: mobile number, name, city, age — to run your account and personalise calculations.
- Financial data you enter: income, assets, loans, insurance, tax inputs — the entire product runs on this.
- Bank data via Account Aggregator: only with your explicit consent, only the scope you approve (balances, transactions, holdings — view only), fetched through the RBI-regulated AA framework. We never receive or store your bank credentials.
- Usage data: which features you use, anonymised — to improve the product.
What we never do
- We never sell your data. Our revenue is subscriptions (and any clearly disclosed referral commissions) — not your data.
- We never share your individual financial data with advertisers or employers.
- We never train shared/public AI models on your personal data. Your private personalisation memory is scoped to your account alone and is deleted with your account.
Service providers we use
To run PayWatch we rely on a small number of processors that handle data strictly on our instructions: our cloud hosting & database provider (Railway), our email provider (Resend, only if you add an email), push-notification delivery (Google Firebase Cloud Messaging, only on the mobile app), and our payment provider (Razorpay, for subscriptions). When you scan a statement, the file is parsed on your own device using libraries loaded from a public CDN (Cloudflare) — the file itself never leaves your device. We do not sell or rent your data to anyone.
Where your data lives
PayWatch runs on managed cloud infrastructure (Railway). Your data is encrypted in transit (HTTPS/TLS) and at rest by our hosting and database providers. Depending on the hosting region in use, some processing may occur on servers outside India; where that happens it is done under the safeguards permitted by the DPDP Act. We are working toward an India-region deployment for full data residency. Passwords are not used (mobile-OTP login); OTPs and session tokens are stored only in hashed form.
Children
PayWatch is intended for users aged 18 and above. If you are under 18, a parent or guardian must set up and consent to the account on your behalf; we record that consent at sign-up. We do not knowingly process a minor's data without verifiable parental consent.
Security incidents
If a personal-data breach occurs, we will notify the Data Protection Board of India and affected users without undue delay, describing the nature of the breach, its likely impact, and the steps we are taking.
Your rights (DPDP Act, 2023)
- Access & portability: download your complete data as JSON from Settings, any time.
- Correction: edit any data point in the app directly.
- Erasure: delete your account from Settings — all personal data is permanently removed within 7 days. GST invoice records are retained in anonymised form for the statutory period, as required by law.
- Consent withdrawal: revoke Account Aggregator consent in Settings; AA-sourced data is deleted within 24 hours.
- Grievance: our Grievance Officer (contactable at grievance@paywatch.in) acknowledges complaints within 48 hours and resolves them within 30 days, per the DPDP Act and IT Rules, 2021.
Retention
Active accounts: data retained while you use the service. Cancelled subscriptions: data retained 90 days so you can return, then queued for deletion. Deleted accounts: removed within 7 days of the request. Statement and Form-16 files are parsed entirely on your device and are never uploaded to our servers.
Cookies & tracking
The web app uses only functional storage (your session tokens) on your own device. No advertising trackers, no third-party analytics cookies.