Darayi

Portfolio & Expense Tracker

Official Privacy Policy

Privacy Policy

This Privacy Policy explains how Darayi ("the Application", "the App", "we", "us", or "our"), developed and maintained by Nayab Sayed, handles, stores, and protects your information.

Privacy by Design & Local-First Philosophy: Darayi is built from the ground up as a private, local-first application. Your personal financial records, expenses, asset allocations, and net worth calculations remain strictly on your physical device unless you explicitly opt to use Google Drive backup.
Effective Date: October 2, 2026 • Last Updated: October 2, 2026 • Package ID: dev.nayab.darayi • Developer Contact: basha@nayab.dev

1 Local-First Architecture & Financial Records

Unlike traditional financial services, Darayi operates on a local-first architectural paradigm:

2 Optional Google Drive Cloud Backup & OAuth 2.0

Darayi provides an optional cloud sync and backup feature using Google Drive. This feature is entirely voluntary and disabled by default.

3 Advertising & Google AdMob (Android Native App)

To support ongoing maintenance and development, the Android version of Darayi incorporates the Google Mobile Ads SDK (AdMob) to display banner ads and app-open ads.

4 In-App Purchases & Google Play Billing

Darayi offers optional digital purchases (such as the "Remove Ads" lifetime license) through Google Play Billing:

5 Biometric Security (Fingerprint & Face Unlock)

The Android version of Darayi includes an optional Biometric App Lock to protect your financial confidentiality:

6 Public Financial Market Feeds (Read-Only)

To present real-time portfolio valuations, Darayi performs anonymous, read-only HTTP GET requests to public market feeds:

No Personal Data Transmission: Queries sent to these external endpoints consist exclusively of public asset identifiers (e.g., fund scheme codes, ticker symbols like INF209K01164 or BTC-INR). Darayi never transmits your name, balances, holdings quantities, or financial net worth to any market feed provider.

7 Device Permissions Utilized

Darayi requests only the minimum set of permissions necessary to deliver its functionality on Android:

Permission Technical Name Purpose & Justification
Internet Access android.permission.INTERNET Required to fetch public market price feeds, perform Google Drive cloud backup sync, and serve AdMob advertisements.
Network State android.permission.ACCESS_NETWORK_STATE Enables the app to monitor online/offline connectivity and defer cloud synchronization when offline.
Biometrics android.permission.USE_BIOMETRIC Allows users to secure the app with device fingerprint or face unlock via Android's native BiometricPrompt.
Google Play Billing com.android.vending.BILLING Facilitates the optional "Remove Ads" lifetime in-app purchase through Google Play.
Notifications android.permission.POST_NOTIFICATIONS Optional; triggers user-consented local alerts when mutual fund NAV updates occur.

Permissions Not Requested: Darayi never requests access to your GPS location, Contacts, Microphone, Camera, SMS, or Phone State.

8 Data Retention & Deletion Policy

Darayi operates on a local-first philosophy. You maintain complete, unconditional control over your data at all times.

Data Deletion Instructions: You can purge all your financial records, transactions, custom categories, and cloud backup snapshots at any time using the steps outlined below. No financial records are retained on developer servers.

How to Delete Your Data

Data Scope & Retention Period

9 Children's Privacy (16+)

Darayi is designed for personal expense logging, budgeting, and investment tracking for individuals who are at least 16 years of age (or the legal age of digital consent in your jurisdiction). The Application is not directed at young children. We do not knowingly solicit, collect, or maintain personal information from children under the age of 13 (or under 16 in jurisdictions requiring parental authorization). If you become aware that a child under these age thresholds has provided information or connected an account, please contact us immediately at basha@nayab.dev, and we will promptly take steps to assist with complete data removal.

10 Data Security Safeguards

We employ robust industry-standard technical measures to safeguard your information:

11 Your Rights (GDPR, CCPA / CPRA & Global Frameworks)

Depending on your geographical jurisdiction, you may hold statutory rights under data protection laws such as the General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA/CPRA), including:

Because your financial data resides solely on your physical device, you can exercise your rights directly at any moment without needing to submit a formal request: simply use the in-app export tools or execute the 1-tap reset action.

12 Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect modifications in our features, changes in relevant legal standards, or updates to Google Play requirements. When modifications are made, the revised policy will be posted on this page with an updated "Last Updated" timestamp. We encourage you to review this policy periodically.

13 Developer & Data Controller Contact

If you have any questions, feedback, or inquiries regarding this Privacy Policy or Darayi's privacy practices, please contact:

Developer: Nayab Sayed
Developer Website: https://nayab.dev
Contact Email: basha@nayab.dev
Application: Darayi (dev.nayab.darayi)