Hisab Ki Kitab · Trust & information
Privacy Policy
This policy describes data handling verified in the current Hisab Ki Kitab application and production configuration.
Last updated:
Information stored in your account
An account can contain your name and email address, a password hash for password sign-in, currency, finance mode, language and theme preferences, monthly income, university or hostel details, and custom categories. Passwords are stored as bcrypt hashes; the application does not store the original password.
Records you enter can include income and expenses (amounts, dates, categories and notes), budgets, goals, lending and borrowing details, shared-living groups and contributions, and messages exchanged with the AI Advisor. The application uses these records to provide its financial-management features, summaries, reports, reminders, and Advisor responses.
Authentication and browser storage
The browser uses first-party HTTP-only session cookies named hw_access and hw_refresh for signed-in requests. In production the cookies are Secure; the default SameSite policy is Lax. The access token is also held in memory while the page is open, not in localStorage. The application uses localStorage for theme and language preferences and for the selected Shared Living space and month. No sessionStorage use was found in the application code.
Google Analytics
Google Analytics 4 is configured in the current production build to understand how the application is used. It receives page views and allow-listed interaction metadata such as content category, calculator type, or feature type. Google documents that its default web collection can use a first-party _ga cookie to distinguish users and sessions and can collect browser/device details and approximate location. The integration disables Google Signals and advertising-personalization signals.
The analytics event code filters parameters through fixed allow-lists. It does not send entered income, expense, debt, balance, roommate-name, note, or other calculator values as analytics event parameters. There is no in-app analytics preference switch; browser controls can clear or block cookies, though blocking session cookies can prevent sign-in.
Other services and integrations
The website and API are deployed through Vercel and use a PostgreSQL database. The code does not identify the database hosting provider or its backup-retention schedule; those details are not stated here.
The AI Advisor is operating in rule-based fallback mode in the current production API health status. The code supports optional Gemini and Anthropic providers, but neither is active in the checked production deployment. Google sign-in is also disabled in the current production API configuration. If an external AI provider or sign-in integration is enabled later, this notice should be reviewed before that change.
The project includes an authenticated feedback feature. Feedback type, optional rating, message, and page are stored in the application database and are associated with the signed-in account. Production mail delivery is not configured. There is no public contact form or newsletter signup in the current application.
Operational logs
The API writes access-log entries that can include IP address, time, request method, sanitized URL, response status, referrer, and browser user-agent. Password-reset tokens are removed from logged URLs. The application code does not define a log-retention period; Vercel’s service-level log retention should be confirmed by the owner.
Retention and your choices
You can export your account data or delete your account from Settings. Account deletion removes the user row and its dependent application records through database cascades. The code does not establish how long infrastructure backups retain deleted records, so deletion from backups cannot be promised here. No other fixed retention schedule was found in the application code.
You can edit supported profile fields, sign out to clear the active session cookies, and clear browser storage through your browser settings. Blocking cookies may affect sign-in and other application behavior.
Security
The application hashes passwords with bcrypt, stores hashes rather than usable refresh tokens, and uses HTTP-only, Secure production session cookies. The live site uses HTTPS. These measures reduce risk but cannot guarantee that every system or transmission is completely secure.
Contact and updates
For privacy questions, contact Hisab Ki Kitab using the address on the Contact page. This policy may be updated when data handling changes; the displayed date identifies the latest content review.