Summary
SavingsJar is an offline expenses tracker. Everything you enter is stored in a private database on your own device. We collect nothing, we operate no servers that receive your data, and the app contains no analytics, advertising or tracking.
There is one optional feature that uses the network, and it stays off until you switch it on: automatic backup to your own Google Drive. If you enable it, you sign in with your Google account and the app uploads its encrypted backup file to your Drive. That file belongs to you and lives in your Google account — it never passes through, and is never stored on, any server of ours, and we cannot read it.
You can delete individual Drive backups from inside the app on the Restore screen, which lists every backup the app has created. To cut the app off from your Drive entirely, open your Google Account and remove SavingsJar's access under Data & privacy → Third-party apps & services. You can also delete the backup files directly in Google Drive.
| Data | Why it is handled | Leaves your device |
|---|---|---|
| Transactions and categories | To record and report the spending you enter. | No |
| Loan records | To track money you have lent or borrowed. | No |
| Display name and preferences | To greet you and remember your settings. | No |
| App-lock PIN and passphrase | To lock the app, held in the Android Keystore rather than the app database. | No |
| Google account name and email only with Drive backup | Used by Google's own APIs to sign you in and authorise the app to write backups to your Drive. | Handled by Google, not by us |
| Encrypted backup file only with Drive backup | So you can restore your records on a new device. Encrypted before it leaves the app. | Yes — to your own Google Drive |
| Identifiers and analytics | Not collected. The app contains no analytics SDK. | Not collected |
Contents
- Who we are and what this policy covers
- Information we collect
- How we use information
- Permissions
- Information you create, and where it lives
- Backups, exports and imports
- Google sign-in and Google Drive backup
- Third-party services and processors
- Information about other people
- Data retention and deletion
- Security
- Children's privacy
- Your rights
- Changes to this policy
- Contact
1. Who we are and what this policy covers
SavingsJar is published by Pragat Inc ("we", "us", "our"), an independent software studio. For the purposes of the GDPR we are the data controller for this app, and under India's Digital Personal Data Protection Act, 2023 we are the data fiduciary.
This policy covers the SavingsJar Android application distributed
through Google Play under the package identifier
inc.pragat.expenses_manager. It does not cover
Google Play itself, your Google account, Google Drive, or any
other service you may choose to copy your exported files into
— those are governed by Google's own terms and policies.
By installing and using the app you accept this policy. If you do not agree with it, please uninstall the app.
2. Information we collect
We collect nothing. The developer of SavingsJar receives no data about you or your use of the app — no personal information, no financial information, no device identifiers, no usage or crash analytics, no location, no contacts, and no advertising identifiers.
We operate no servers. Pragat Inc has no backend that your records are sent to, no database of users, and no copy of anything you enter. Your data lives in exactly two places, both of which you control: your device, and — only if you turn on the optional backup feature — your own Google Drive.
There is no sign-up and no account with us. If you enable Google Drive backup you sign in with a Google account that you already own, so that Google can authenticate you and give the app permission to write into your Drive. That sign-in is handled by Google; see section 7 for exactly what is involved.
3. How we use information
Because we receive no information, we do not use, profile, analyse, disclose, sell or share any information about you. We have never done so, and we have built no mechanism that would let us.
The information you enter is used only by the app, on your device, to show you your own records and the summaries calculated from them. If you enable Drive backup, it is additionally packaged into an encrypted file and uploaded to your Drive — and to nowhere else.
4. Permissions
The released app declares two Android permissions:
| Permission | Why it is needed |
|---|---|
USE_BIOMETRIC |
To let you unlock the app with your device fingerprint or face, if you enable that option. |
INTERNET |
Used solely by the optional Google Drive backup feature — signing you in and transferring your encrypted backup file to and from your Drive. If you never enable that feature, the app makes no network requests at all. |
The app does not request storage, contacts, location, camera, or phone permissions, and it does not read the list of accounts on your device — you pick the Google account yourself in a system-provided sign-in sheet.
About biometrics: your fingerprint or face data is handled entirely by Android and never reaches the app. SavingsJar only receives a success-or-failure result from the operating system. We never see, store or transmit biometric data.
5. Information you create, and where it lives
The app is a tool for recording your own information. The data you enter is stored locally on your device only, in an app-private SQLite database and app-private preference storage that other apps cannot read:
- Transactions — amounts, dates and times, income/expense type, notes.
- Categories and tags — names, colours and icons you create.
- Loan records — the direction (money lent or borrowed), the other person's name and phone number if you choose to enter them, the principal amount, the date, an optional due date, notes, and any repayments you log.
- Your display name — if you enter one during onboarding, used only to greet you on the home screen.
- Preferences — theme, currency symbol, financial-year start month, default categories, and the date and location of your most recent backup.
- App-lock settings — your PIN and your biometric-unlock preference are stored separately, in the operating system's encrypted keystore-backed storage (Android Keystore), not in the app database. They are deliberately excluded from backups.
- Backup passphrase — if you save one for convenience, it is stored in the same encrypted keystore and never written into a backup file.
None of this is sent to us. We cannot see it, we cannot recover it for you, and we have no copy of it. It leaves your device only in the ways described in the next two sections, and only when you ask for it.
6. Backups, exports and imports
You are in full control of your data leaving the app, and it only happens when you explicitly ask for it:
-
Encrypted backup — creates a single
passphrase-protected
.embakfile encrypted with AES-256-GCM, using Argon2id to derive the key from your passphrase. The file is saved to your device's Downloads folder or a location you pick. -
Backup to Google Drive — optional, off by
default. The same encrypted
.embakfile is uploaded to your own Google Drive, either when you tap Back up or automatically on the schedule you choose. See section 7. - Restore — reads a backup file you select — from your device, or from the list of your Drive backups — and requires your passphrase.
- CSV export — writes your transaction history to an unencrypted CSV file at a location you choose.
- CSV import — reads only the single file you pick, using the system file picker.
Once a backup or CSV file is saved to your device, it is outside the app's protection. If you then copy it to a cloud drive, email it, or move it to another device, that data is subject to the privacy practices of whichever service you use. CSV exports are not encrypted and are readable by anything that can open the file. Please store and share these files carefully.
Your passphrase cannot be recovered. We do not have it and there is no reset mechanism. If you lose it, the backup file cannot be decrypted by anyone, including us — and that applies to backups stored in Google Drive too.
7. Google sign-in and Google Drive backup
Automatic backup to Google Drive is an optional feature. It is switched off when you install the app, and nothing in this section happens unless you turn it on.
What happens when you enable it
- You sign in with a Google account of your choosing. The sign-in is performed by Google, using Firebase Authentication, and you are asked to grant the app permission to store files in your Drive.
- Google returns your name, email address and an account identifier to the app. These are used only to show you which account is connected and to authenticate subsequent Drive requests. They are not used for profiling, marketing or any other purpose.
-
The app builds the same passphrase-encrypted
.embakbackup described above and uploads it to your Drive. Encryption happens on your device before the upload, so what is stored in Drive is ciphertext.
What we receive
Nothing. There is no Pragat Inc server in this flow. The backup file travels from your device to your Google Drive; we never hold a copy, we cannot list your backups, and we could not decrypt one if we had it. Your Google account name and email are processed by Google's authentication service and remain on your device — they are not forwarded to us or to anyone else.
What the app can and cannot see in your Drive
The app requests the narrowest Drive access that will do the job: it can only see and manage the files it created itself. It cannot read, list, modify or delete any other document, photo or file in your Drive.
Turning it off and deleting your backups
- Delete individual backups — open the Restore screen in the app. It lists the backups held in your Drive and lets you delete any of them.
- Sign out — disconnect the account in the app's backup settings. Automatic backups stop immediately. Backups already in your Drive stay there until you delete them.
- Revoke access entirely — go to your Google Account and remove SavingsJar under Data & privacy → Third-party apps & services. The app loses all access to your Drive from that moment. You can also delete the backup files yourself from drive.google.com.
Deleting the app's data on your device (see section 10) does not delete backups already in your Drive, and deleting Drive backups does not delete the records on your device. They are two independent copies, and both are yours to remove.
SavingsJar's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this data to others except as necessary to provide the backup feature you asked for, and we never use it for advertising, profiling, credit assessment, lending, or to train generalised AI or machine-learning models.
8. Third-party services and processors
SavingsJar contains no analytics, advertising, crash reporting, tracking or social SDKs. We use no Google Analytics, no Firebase Analytics or Crashlytics, and no advertising network. Apart from Google Play distribution, the services below are involved only if you enable Google Drive backup:
| Service | What it does | Privacy policy |
|---|---|---|
| Firebase Authentication (Google) | Signs you in with your Google account and issues the token the app uses to reach your Drive. Google processes your name, email address, account identifier, IP address and sign-in timestamps for this purpose. | firebase.google.com |
| Google Drive API (Google) | Stores and retrieves your encrypted backup file inside your own Google Drive, under your own storage quota. | policies.google.com |
| Google Play | Distribution and installation of the app. | policies.google.com |
Your Google account and your Google Drive storage are your relationship with Google, governed by Google's Privacy Policy and Terms of Service, and are outside our control and visibility.
Apart from these, the app is built with open-source software libraries that run entirely on your device and perform no network communication of your data.
9. Information about other people
If you record a loan and enter another person's name or phone number, that information is typed by you and stored only on your device — the app never reads your contacts and never transmits these details. You are responsible for handling other people's information lawfully and respectfully, and for deleting it when you no longer need it. You can remove any loan record, along with its repayment history, from within the app at any time.
10. Data retention and deletion
Every copy of your data sits somewhere you control, so you control its entire lifetime:
- Delete individual records — remove any transaction, category, tag or loan from within the app.
- Delete everything on the device — uninstalling SavingsJar permanently removes its database, its preferences and its keystore entries from your device.
- Delete Google Drive backups — use the Restore screen in the app, or delete the files in Google Drive, or revoke the app's access to your Google account entirely. See section 7. Uninstalling the app does not remove backups already in your Drive.
- Backup and CSV files you created on the device are stored wherever you saved them and are not removed by uninstalling. Delete those files yourself if you want them gone.
We hold no data about you, so there is nothing for us to retain, and no deletion request you need to send us. Sign-in records held by Google's authentication service are removed when you revoke the app's access to your Google account.
11. Security
- Your data lives in app-private storage that other applications cannot access.
- Your PIN and backup passphrase are held in the operating system's encrypted keystore-backed storage, not in the app's database.
- Backups are encrypted with AES-256-GCM and Argon2id key derivation. This happens on your device, so a backup uploaded to Google Drive is encrypted in transit and at rest, with a key only you hold.
- Drive access is limited to files the app itself created; the app cannot reach the rest of your Drive.
- Optional PIN and biometric app lock protects the app if someone else has your unlocked phone.
No security measure is absolute. A rooted or compromised device, or malware with elevated privileges, can undermine these protections, and we recommend keeping your device's screen lock and system updates enabled.
12. Children's privacy
SavingsJar does not collect any data from anyone, including children under 13 (or the equivalent minimum age in your jurisdiction). We have no way to receive a child's personal information, and therefore nothing to delete. The Google Drive backup feature relies on a Google account, which Google requires its own minimum age to hold.
13. Your rights
Privacy laws including the EU and UK GDPR, the California CCPA/CPRA, and India's Digital Personal Data Protection Act, 2023 give you rights to access, correct, export and delete personal data that an organisation holds about you, and to know whether it is sold or shared.
We hold no personal data about you, and we do not sell or share personal information. In practice this means:
- Access and portability — all your data is already on your device, and you can export it yourself at any time via encrypted backup or CSV export.
- Correction and erasure — you can edit or delete any record in the app, or uninstall the app to erase everything on the device. Backups in your Google Drive are deleted from the app's Restore screen, from Drive itself, or by revoking the app's access to your Google account.
- Withdrawing consent — Google Drive backup is opt-in, and you can withdraw that consent at any time by signing out in the app or revoking access in your Google Account. Withdrawal does not affect anything you did before it.
- No sale or sharing — there is nothing to opt out of, because your data is never transmitted to us or to any third party for their own purposes.
- Complaints — you may raise a concern with us at any time, and you retain the right to complain to your local supervisory authority.
For the personal data Google processes as part of sign-in and Drive storage — your name, email address and the files in your own Drive — you exercise your rights directly through your Google Account.
14. Changes to this policy
If a future version of the app changes how data is handled, this policy will be updated and the "Last updated" date above will change. Any change that would involve collecting or transmitting data would be described here before it takes effect, and the Play Store listing's Data Safety section would be updated accordingly. Please review this page periodically.
15. Contact
Questions about this privacy policy or the app's data handling:
Pragat Inc — Privacy enquiries
pragat.apps@gmail.com
We aim to respond to privacy enquiries within 30 days.