Nivora

Privacy Notice

Last updated 31 July 2026

This page describes what Nivora actually collects and why, in plain language. It isn't a substitute for legal advice — if you're relying on it for a specific regulatory requirement (GDPR, CCPA, or similar), have it reviewed for your own situation.

What we collect

Account information

When you register: your name, email address, a securely hashed password, your chosen currency/language, and (for the mobile app) a hashed 4-digit PIN used only for quick device unlock. If you sign in with Google instead, we verify your Google ID token and store your Google account ID, name, and email — we never see or store your Google password.

Your financial data

Everything you enter to use the app: transactions, accounts, budgets, savings goals, planner tasks, notes, and — for the khata/People-ledger feature — the name, phone number, and any other contact details you choose to add for people you lend to or borrow from. This data is yours; we don't read it for any purpose other than showing it back to you and computing the totals/reports the app displays.

Location (only if you use it)

Transaction and ledger-entry forms have an optional "use current location" action. Nothing is captured unless you tap it, and each tap triggers your device's own permission prompt first. We never track location in the background.

Receipts and attachments

Photos or files you attach to a transaction are stored in a private bucket that nothing outside this deployment can reach — attachments are only ever served back to you after we confirm you're the owner. Receipt images are processed by open-source OCR software (Tesseract) running on our own server to pull out text, then simple pattern-matching extracts a merchant/amount/date guess for you to review — no receipt image or its contents are ever sent to a third-party AI or OCR service.

Login activity

Each time you sign in (password, PIN, or Google), we record the IP address, device/browser info from your browser's or app's own identification string, and the time — kept as a security log so you (and an administrator, if something looks wrong) can see your own recent login history. This is separate from the anonymous analytics below and is tied to your account.

Anonymous visit analytics

Loading a public page (like this one, or the login/register screens) records the page path, a referrer if any, and a random identifier your browser generates and stores itself — used only to avoid double-counting a repeat visit. This is not tied to your identity and no IP address is stored for this. It exists purely so we can see whether the product is being used at all.

What we don't do

  • No advertising or ad-tracking scripts of any kind on this site.
  • No selling, renting, or sharing your data with data brokers.
  • No third-party analytics platforms (no Google Analytics, Meta Pixel, or similar) — the visit counter above is our own, self-hosted, and minimal.

Who else sees anything

A short, complete list — nothing beyond this:

  • Google, only if you choose "Continue with Google" — to verify your sign-in.
  • Cloudflare Turnstile, a bot-check widget shown on the registration and contact forms — it sees your interaction with the challenge, not your account data.
  • Our email provider, only to send you account emails you'd expect (password reset, email verification) — never marketing.

Nobody else. Your financial data, attachments, and login history stay on infrastructure we run ourselves.

Your data

You can export a full backup of a book's data (transactions, accounts, categories, recurring rules, attachments, and more) at any time from Settings → Export data — nothing is withheld or requires asking us first.

There's no self-service "delete my account" button yet. If you want your account and data removed, reach out through the Contact page and we'll handle it manually.

Security

Passwords and PINs are stored as salted hashes, never in plain text. Attachments live in a private storage bucket not reachable from outside our own infrastructure. A production deployment of this app runs entirely over HTTPS.

Children's privacy

This app isn't directed at children, and we don't knowingly collect data from anyone under 13.

Changes to this notice

If what we collect or how we use it changes meaningfully, we'll update the date at the top of this page.

Questions

For anything about your data — including a deletion request — use the Contact page.

Back to login