Privacy Policy
This Privacy Policy explains how Darayi ("the Application", "the App", "we", "us", or "our"), developed and maintained by Nayab Sayed, handles, stores, and protects your information.
1 Local-First Architecture & Financial Records
Unlike traditional financial services, Darayi operates on a local-first architectural paradigm:
- On-Device Database: All expenses, custom categories, investment portfolios, stock & mutual fund holdings, gold/silver quantities, liabilities, and manual notes are stored directly within your device's sandboxed local storage (IndexedDB via Dexie.js).
- No Central Application Servers: We do not operate remote user account servers, centralized proprietary databases, or telemetry tracking backends. We have zero access to your transaction amounts, bank records, or net worth values.
- Zero Forced Registration: You do not need an account, password, phone number, or email address to track your finances with Darayi.
2 Optional Google Drive Cloud Backup & OAuth 2.0
Darayi provides an optional cloud sync and backup feature using Google Drive. This feature is entirely voluntary and disabled by default.
-
Restricted Scope (
drive.appdata): When you connect your Google Account, Darayi requests authorization strictly for thehttps://www.googleapis.com/auth/drive.appdataOAuth 2.0 scope. -
Hidden Application Folder Isolation: Google restricts this scope exclusively to Darayi's dedicated, hidden
appDataFolder. Darayi cannot view, read, modify, or delete any of your personal files, Google Docs, photos, folders, or other Drive contents. -
Client-Side Backup Files: Backup archives (named
darayi-backup-*.json) are generated client-side on your device and uploaded directly to your own Google Drive. - Zero Server-Side Token Storage: Temporary OAuth tokens are held in your device's memory/storage. Where a Cloudflare Pages function is utilized for web OAuth token exchange, requests are stateless pass-through relays; tokens and credentials are never logged, recorded, or retained on our infrastructure.
- Revocation at Any Time: You can disconnect Google Drive at any time inside Darayi's Settings, or revoke permissions globally in your Google Account Security settings.
3 Advertising & Google AdMob (Android Native App)
To support ongoing maintenance and development, the Android version of Darayi incorporates the Google Mobile Ads SDK (AdMob) to display banner ads and app-open ads.
- Information Processed by Google AdMob: Google AdMob may automatically collect and process certain device information, including your device's Advertising ID (GAID), IP address (used for approximate coarse location and fraud prevention), device make/model, operating system version, and ad interaction metrics.
- Privacy Governance: The collection and processing of ad-related telemetry are governed by Google's Privacy Policy. For detailed information, please review the Google Privacy Policy and How Google uses information from sites or apps that use our services.
- Opt-Out & Ad-Free Option: You can reset or personalize your Advertising ID via Android Settings (`Settings > Google > Ads`). Furthermore, Darayi offers a permanent "Remove Ads" Lifetime In-App Purchase that completely deactivates the AdMob SDK and removes all advertising banners.
4 In-App Purchases & Google Play Billing
Darayi offers optional digital purchases (such as the "Remove Ads" lifetime license) through Google Play Billing:
- Payment Processing by Google Play: All transactions are executed securely by Google Play. Darayi never receives, stores, or processes your credit card numbers, debit cards, bank account details, UPI credentials, or billing addresses.
- Purchase Verification: Darayi receives a cryptographically signed purchase token and order state from Google Play to unlock ad-free features and enable restore-purchase functionality across your devices.
5 Biometric Security (Fingerprint & Face Unlock)
The Android version of Darayi includes an optional Biometric App Lock to protect your financial confidentiality:
-
Hardware Enclave Security: Biometric verification uses Android's native
BiometricPromptAPI. Authentication is performed entirely by your device operating system inside the hardware-isolated Trusted Execution Environment (TEE) or StrongBox. - Zero Biometric Data Access: Darayi never accesses, captures, scans, stores, or transmits your fingerprint, face scan, or biometric templates. The operating system only returns a simple boolean result (success or failure) to unlock the app UI.
6 Public Financial Market Feeds (Read-Only)
To present real-time portfolio valuations, Darayi performs anonymous, read-only HTTP GET requests to public market feeds:
- MFAPI.in: Fetches published daily Net Asset Values (NAVs) for Indian Mutual Funds.
- Yahoo Finance & IBJA: Fetches publicly available stock, ETF, and bullion reference prices.
- CoinGecko & Binance: Fetches public cryptocurrency spot exchange rates.
No Personal Data Transmission: Queries sent to these external endpoints consist exclusively of public asset identifiers
(e.g., fund scheme codes, ticker symbols like INF209K01164 or BTC-INR). Darayi never transmits your name, balances,
holdings quantities, or financial net worth to any market feed provider.
7 Device Permissions Utilized
Darayi requests only the minimum set of permissions necessary to deliver its functionality on Android:
| Permission | Technical Name | Purpose & Justification |
|---|---|---|
| Internet Access | android.permission.INTERNET |
Required to fetch public market price feeds, perform Google Drive cloud backup sync, and serve AdMob advertisements. |
| Network State | android.permission.ACCESS_NETWORK_STATE |
Enables the app to monitor online/offline connectivity and defer cloud synchronization when offline. |
| Biometrics | android.permission.USE_BIOMETRIC |
Allows users to secure the app with device fingerprint or face unlock via Android's native BiometricPrompt. |
| Google Play Billing | com.android.vending.BILLING |
Facilitates the optional "Remove Ads" lifetime in-app purchase through Google Play. |
| Notifications | android.permission.POST_NOTIFICATIONS |
Optional; triggers user-consented local alerts when mutual fund NAV updates occur. |
Permissions Not Requested: Darayi never requests access to your GPS location, Contacts, Microphone, Camera, SMS, or Phone State.
8 Data Retention & Deletion Policy
Darayi operates on a local-first philosophy. You maintain complete, unconditional control over your data at all times.
How to Delete Your Data
- Option 1 — Instant 1-Tap On-Device Wipe: Inside the Darayi application, open Settings (gear icon), scroll to the bottom, and tap "Reset App & Delete All Data". This immediately, permanently, and irreversibly wipes all IndexedDB records, portfolio entries, preferences, and local cache from your device.
-
Option 2 — Google Drive Cloud Backup Deletion: If you enabled optional Google Drive cloud sync:
- Inside Darayi Settings, tap "Disconnect Google Drive" to revoke cloud authorization.
- In your web browser or Google Drive app, navigate to Settings > Manage Apps > Darayi.
- Click Options > Delete hidden app data to permanently purge all
darayi-backup-*.jsonsnapshots.
- Option 3 — Assisted Deletion / Inquiry: Because Darayi does not maintain central user accounts or proprietary databases, we do not hold your financial records on remote servers. However, if you need any assistance verifying that your data is deleted, contact developer Nayab Sayed directly at basha@nayab.dev.
Data Scope & Retention Period
- Types of Data Deleted: All financial entries, expense logs, mutual fund/stock quantities, liability records, custom categories, and cloud backup files.
- Types of Data Retained: None. Darayi maintains zero retention of your financial records once wiped.
- Retention Period: Deletion occurs instantaneously (0 days retention) upon executing the reset.
- Data Portability Before Deletion: You can export an unencrypted JSON snapshot or formatted Microsoft Excel / CSV spreadsheet via Settings before initiating deletion.
9 Children's Privacy (16+)
Darayi is designed for personal expense logging, budgeting, and investment tracking for individuals who are at least 16 years of age (or the legal age of digital consent in your jurisdiction). The Application is not directed at young children. We do not knowingly solicit, collect, or maintain personal information from children under the age of 13 (or under 16 in jurisdictions requiring parental authorization). If you become aware that a child under these age thresholds has provided information or connected an account, please contact us immediately at basha@nayab.dev, and we will promptly take steps to assist with complete data removal.
10 Data Security Safeguards
We employ robust industry-standard technical measures to safeguard your information:
- End-to-End Transport Security: All network transmissions (market feeds, Google Drive sync, and billing) utilize secure HTTPS/TLS 1.3 encryption.
- Sandboxed Operating System Isolation: On Android and mobile browsers, local databases are isolated within Darayi's private application sandbox.
- Hardware-Backed Authentication: Biometric authentication relies strictly on Android hardware security modules (TEE / StrongBox).
11 Your Rights (GDPR, CCPA / CPRA & Global Frameworks)
Depending on your geographical jurisdiction, you may hold statutory rights under data protection laws such as the General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA/CPRA), including:
- The right to access and inspect your personal data.
- The right to rectify inaccurate records.
- The right to erasure ("Right to be Forgotten").
- The right to data portability.
- The right to opt out of the sale or sharing of personal data (Darayi does not sell your personal data).
Because your financial data resides solely on your physical device, you can exercise your rights directly at any moment without needing to submit a formal request: simply use the in-app export tools or execute the 1-tap reset action.
12 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect modifications in our features, changes in relevant legal standards, or updates to Google Play requirements. When modifications are made, the revised policy will be posted on this page with an updated "Last Updated" timestamp. We encourage you to review this policy periodically.
13 Developer & Data Controller Contact
If you have any questions, feedback, or inquiries regarding this Privacy Policy or Darayi's privacy practices, please contact:
dev.nayab.darayi)