Privacy Policy
Last Updated: January 6, 2026
1. Introduction
Rupiya ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our financial management application.
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our application.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Name, email address, phone number, and password when you create an account
- Financial Data: Investment details, portfolio information, transaction history, and financial goals
- Family Information: Information about family members if you use our family sharing features
- Communication: Messages, feedback, and support requests you send to us
2.2 Information Collected Automatically
- Device Information: Device type, operating system, browser type, and unique device identifiers
- Usage Data: Pages visited, features used, time spent on the application, and interaction patterns
- Location Data: General location information based on IP address (not precise GPS)
- Log Data: Server logs including access times, pages viewed, and error messages
2.3 Information from Third Parties
- Authentication providers (Google, Firebase) for account creation and login
- Financial data providers for live market prices and investment information
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, maintain, and improve our application and services
- To process your transactions and send related information
- To send administrative information and updates
- To respond to your inquiries and provide customer support
- To monitor and analyze trends, usage, and activities for security and improvement purposes
- To detect, prevent, and address fraud and security issues
- To comply with legal obligations and enforce our agreements
- To personalize your experience and deliver targeted content
4. Data Storage and Security
4.1 End-to-End Encryption
Your financial data is protected with military-grade encryption. We implement end-to-end encryption using AES-256 encryption, the same standard used by banks and government agencies. This means:
- Client-Side Encryption: Your data is encrypted on your device before being sent to our servers
- Zero-Knowledge Architecture: We cannot access your encrypted data even if we wanted to
- Your Keys, Your Data: Only you have the encryption keys to decrypt your information
- Automatic Encryption: All sensitive data including expenses, income, investments, and personal information is automatically encrypted
4.2 Data Storage
Your encrypted data is stored securely using Google Firebase, a leading cloud infrastructure provider with enterprise-grade security. All data is encrypted both in transit and at rest using industry-standard encryption protocols (TLS 1.3).
4.3 Security Measures
- AES-256 Encryption: Military-grade encryption for all sensitive financial data
- PBKDF2 Key Derivation: Secure key generation with 100,000+ iterations
- Secure Authentication: Password hashing with bcrypt and secure session management
- Regular Security Audits: Continuous vulnerability assessments and penetration testing
- Firewall Protection: Advanced DDoS mitigation and intrusion detection
- Access Controls: Role-based permissions and multi-factor authentication
- Automatic Backups: Encrypted backups with disaster recovery procedures
- Security Monitoring: 24/7 monitoring for suspicious activities and threats
4.4 What This Means for You
Complete Privacy: Even if our servers were compromised, your financial data would remain secure because it's encrypted with keys only you possess. We have designed our system so that we cannot access your sensitive information, ensuring your privacy is protected at all times.
4.5 Data Retention
We retain your personal data for as long as your account is active or as needed to provide our services. You can request deletion of your account and associated data at any time, subject to legal retention requirements. Upon deletion, your encrypted data is permanently removed from our systems.
5. Data Sharing and Disclosure
5.1 We Do NOT Share Your Data
We do not sell, trade, or rent your personal information to third parties. Your financial data is strictly confidential and used only for the purposes outlined in this policy.
5.2 Limited Disclosures
We may disclose your information only in the following circumstances:
- Legal Requirements: When required by law, court order, or government request
- Service Providers: To trusted third parties who assist us in operating our application (e.g., cloud providers, payment processors) under strict confidentiality agreements
- Family Sharing: With family members you explicitly authorize to view shared financial information
- Business Transfers: In case of merger, acquisition, or sale of assets (with notice to you)
- Protection of Rights: To protect our legal rights, privacy, safety, or property
6. Your Privacy Rights
6.1 Access and Portability
You have the right to access your personal data and receive a copy in a portable format.
6.2 Correction and Deletion
You can update, correct, or delete your personal information through your account settings or by contacting us.
6.3 Opt-Out
You can opt out of receiving promotional communications by adjusting your notification preferences.
6.4 Data Subject Rights
If you are in the EU, UK, or other jurisdictions with data protection laws, you have additional rights including the right to restrict processing and object to processing.
7. Cookies and Tracking
We use cookies and similar tracking technologies to enhance your experience. You can control cookie settings through your browser. Disabling cookies may affect some functionality of the application.
8. Third-Party Links
Our application may contain links to third-party websites. We are not responsible for their privacy practices. Please review their privacy policies before providing any information.
9. Children's Privacy
Our application is not intended for children under 13 years of age. We do not knowingly collect personal information from children. If we become aware of such collection, we will delete it immediately.
10. International Data Transfers
Your information may be transferred to, stored in, and processed in countries other than your country of residence. These countries may have data protection laws different from your home country. By using our application, you consent to such transfers.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last Updated" date. Your continued use of the application constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us at:
- Email: help.rupiya@gmail.com
- Address: 16, Maa Vihar Colony, Indore, MP