Privacy policy
Your budget is yours.
Kharcha holds some of the most revealing data a person has — where their money goes. This page says exactly what is stored, who can see it, and how to take it all back.
Last updated 1 September 2026.
The short version
We store the budget you build and the account you sign in with. We do not sell it, we do not advertise against it, and we do not build a profile of you for anyone else. There are no advertising trackers in the apps or on this site, and nothing is shared with an ad network. The iOS app does send de-identified product analytics and crash reports to PostHog, our own analytics service, so we can see which features get used and fix what breaks — the detail is below.
The rest of this page is the detail behind that, in the order it usually gets asked about.
What we store
Your account. Your email address and display name. If you sign in with Apple or Google, we get whatever that sign-in hands over — with Apple’s “Hide My Email”, that is a relay address, and we never learn the real one. Passwords and sign-in codes are handled by Clerk, our authentication provider; they never reach our servers.
Your budget. Everything you put in: budgets, accounts and their balances, transactions with their payees and notes, categories, monthly assignments, loans, and reconciliations. This is the product — there is no version of Kharcha that works without storing it.
A record of emails we sent you. Which message, when, and whether it was delivered — so that a “we tell you once” email is told once, even across a retry.
Operational logs. Server logs and performance traces, which include request paths, timings, errors, and the account id a request belonged to. They exist to find and fix faults. They do not contain your transaction contents.
Product analytics and crash reports. From the iOS app only: which screens and features you use, category-free details of actions like adding a transaction or importing a statement, your app version, device model and OS, and crash diagnostics. No amounts, payees, notes, or category names are included. This goes to PostHog, tied to a pseudonymous id derived from your account — not your name or email — and that link is dropped when you sign out. The web app and this site send nothing to PostHog.
Statements you import
When you import a bank or wallet statement, the file is read in memory and turned into rows you review before anything is saved.
The original file is not kept. We store its name, its type, and a SHA-256 hash of its bytes — the hash is what lets us tell you “you already uploaded this exact file”. The file itself is never written to disk or object storage.
Between upload and commit we hold a PII-scrubbed grid of the extracted rows, so that you can re-map columns without uploading again. It is deleted the moment the batch is committed or discarded. After that, all that remains are the transactions you chose to import — the same as if you had typed them in.
Product analytics
The iOS app measures how it is used so we know what to build and what to fix. It is first-party — the data goes to our own PostHog project and nowhere else. It is not advertising, not tracking you across other apps, and never sold.
What is recorded is the shape of what you do: a screen was opened, a transaction was added and whether it had a category, a loan was created, an import saved a number of rows. The values in your budget — amounts, payees, notes, the names of your categories — are never part of it. Crash reports carry the error and where in the code it happened.
Events are attributed to a pseudonymous id derived from your account, so we can tell one person’s session from another’s without knowing who you are. Signing out resets it. PostHog processes this in the United States; it is in the table below.
What we never do
- Sell or rent your data to anyone.
- Show you advertising, or share data with ad networks.
- Connect to your bank. Kharcha has no bank credentials, no open banking link, and no ability to move money. It reads statements you hand it, nothing more.
- Use your budget to train machine-learning models, ours or anyone else’s.
- Show you ads, run advertising trackers, or track you across other apps.
- Use product analytics for anything beyond understanding and fixing the app — no profiling, no selling it on, no ad networks.
Who else touches it
A handful of services process data on our behalf, each for one job. They are bound to use it only to provide that service.
| Service | What it does | What it sees |
|---|---|---|
| Clerk | Sign-in and account security | Email, name, credentials, sign-in events |
| Supabase (PostgreSQL) | The database everything is stored in | All of your budget data |
| Fly.io | Runs the API (Singapore region) | Data in transit while a request is served |
| Vercel | Hosts this site and the web app | Requests to the site |
| Resend | Sends the few emails we send | Your email address and the message content |
| Grafana Cloud | Performance traces, to find faults | Request paths, timings, errors, account ids |
| PostHog (United States) | Product analytics and crash reports for the iOS app | Feature and screen events, action metadata, app version, device model and OS, crash diagnostics, IP address, and a pseudonymous account id |
Data is stored and processed in Asia — the database in ap-south-1 and the API in Singapore. Some of these providers are companies based elsewhere, so operating them involves transfers outside your country. The iOS app’s product analytics and crash reports are processed by PostHog in the United States.
The AI connector
Kharcha can be added to ChatGPT or Claude as a connector. This is off unless you set it up, and it is the one way the contents of your budget leave our systems on purpose.
When you connect one, you sign in and authorise it, and from then on that assistant can read the budget data you granted it — and write to it when you ask. What the assistant’s operator then does with what it reads is governed by their privacy policy, not ours. Disconnect it from their side at any time; the access ends immediately.
How long we keep it
- Budget data: until you delete it, or until you delete your account.
- The scrubbed import grid: until that import is committed or discarded.
- Email send records: kept, so we do not repeat ourselves.
- Operational logs and traces: a short rolling window.
- Product analytics and crash reports: kept in PostHog for a limited period, then deleted. What remains is keyed only to a pseudonymous id, which after account deletion points to nothing.
Getting it back, or deleting it
Delete your account. Settings → Delete account, in the app or on the web. This removes your budgets, accounts, transactions, categories, imports and entitlements. It is immediate and it cannot be undone. Backups age out on their own schedule.
Get a copy. Write to us and we will send you an export of your data.
Stop the emails. Every non-essential email has an unsubscribe link that works without signing in. Receipts and other messages about your account are sent regardless, because they are the record of something you did.
Depending on where you live you may also have rights to correct inaccurate data, restrict how it is used, or object to processing. Ask and we will do it.
Children
Kharcha is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has an account, tell us and we will remove it.
Changes
If this policy changes in a way that matters, we will say so here and move the date at the top. Continuing to use Kharcha after a change means the new version applies.
Contact
Questions, requests, or a privacy problem you have spotted: hello@merokharcha.com. A person reads it.