This page describes what Nivora actually collects and why, in plain language. It isn't a substitute for legal advice — if you're relying on it for a specific regulatory requirement (GDPR, CCPA, or similar), have it reviewed for your own situation.
When you register: your name, email address, a securely hashed password, your chosen currency/language, and (for the mobile app) a hashed 4-digit PIN used only for quick device unlock. If you sign in with Google instead, we verify your Google ID token and store your Google account ID, name, and email — we never see or store your Google password.
Everything you enter to use the app: transactions, accounts, budgets, savings goals, planner tasks, notes, and — for the khata/People-ledger feature — the name, phone number, and any other contact details you choose to add for people you lend to or borrow from. This data is yours; we don't read it for any purpose other than showing it back to you and computing the totals/reports the app displays.
Transaction and ledger-entry forms have an optional "use current location" action. Nothing is captured unless you tap it, and each tap triggers your device's own permission prompt first. We never track location in the background.
Photos or files you attach to a transaction are stored in a private bucket that nothing outside this deployment can reach — attachments are only ever served back to you after we confirm you're the owner. Receipt images are processed by open-source OCR software (Tesseract) running on our own server to pull out text, then simple pattern-matching extracts a merchant/amount/date guess for you to review — no receipt image or its contents are ever sent to a third-party AI or OCR service.
Each time you sign in (password, PIN, or Google), we record the IP address, device/browser info from your browser's or app's own identification string, and the time — kept as a security log so you (and an administrator, if something looks wrong) can see your own recent login history. This is separate from the anonymous analytics below and is tied to your account.
Loading a public page (like this one, or the login/register screens) records the page path, a referrer if any, and a random identifier your browser generates and stores itself — used only to avoid double-counting a repeat visit. This is not tied to your identity and no IP address is stored for this. It exists purely so we can see whether the product is being used at all.
A short, complete list — nothing beyond this:
Nobody else. Your financial data, attachments, and login history stay on infrastructure we run ourselves.
You can export a full backup of a book's data (transactions, accounts, categories, recurring rules, attachments, and more) at any time from Settings → Export data — nothing is withheld or requires asking us first.
There's no self-service "delete my account" button yet. If you want your account and data removed, reach out through the Contact page and we'll handle it manually.
Passwords and PINs are stored as salted hashes, never in plain text. Attachments live in a private storage bucket not reachable from outside our own infrastructure. A production deployment of this app runs entirely over HTTPS.
This app isn't directed at children, and we don't knowingly collect data from anyone under 13.
If what we collect or how we use it changes meaningfully, we'll update the date at the top of this page.
For anything about your data — including a deletion request — use the Contact page.