Privacy Policy
DigiExpense — by NextGen Star Technologies
Last Updated: June 21, 2026
1. Introduction
This Privacy Policy explains how NextGen Star Technologies ("we", "us", "our") collects, uses, stores, and protects your personal information when you use the DigiExpense mobile application ("App"). By using the App, you agree to the collection and use of information in accordance with this policy, in compliance with applicable Indian data protection laws and Google Play Developer Program Policies. If you do not agree, please do not use the App.
2. Information We Collect
2.1 Account Information
- Mobile phone number (required for OTP-based authentication)
- Name (optional, for personalisation)
- Occupation / profession type (optional, for dashboard customisation)
- Profile preferences and settings
2.2 Financial Transaction Data
- Transaction amounts (income and expenses)
- Transaction dates, categories, tags and descriptions
- Merchant / payee names
- Bank account identifiers (last 4 digits only — fully masked)
- Budget limits and financial goals
2.3 Notification Access (Android only)
⚠️ Important:
- We use Android Notification Access (NOT the READ_SMS permission) to detect bank/UPI transaction notifications.
- We ONLY process notifications matching known bank/UPI transaction patterns.
- We NEVER read OTP codes, verification messages, or personal messages.
- We NEVER access your SMS inbox — only notification content is captured.
- This is completely optional — the App works fully without it, and you can revoke it anytime in Android Settings.
2.4 Device Information
- Device model (manufacturer and model name) for app compatibility
- Operating system name and version (for crash reporting and compatibility)
- App version (to manage updates and show which devices are active on your account)
- Approximate last-active time of each logged-in device on your account
- We do NOT collect any hardware identifiers such as IMEI, MAC address, Android ID, serial number, or advertising ID.
- Anonymous usage analytics (no personally identifiable data)
2.5 Optional Feature Permissions
- Contacts (optional): only when you tap to add a customer/supplier from your phonebook, a single selected contact's name and number is imported. We do NOT read or upload your full contact list.
- Camera (optional): to scan or capture bills, receipts and QR codes. Images are used only for the feature you invoked.
- Microphone / Voice (optional): for Voice Entry, your speech is converted to text to create a transaction. Audio is not stored after transcription.
- Photos & Documents (optional): selected via the Android System Picker to attach a bill, logo or signature. We access ONLY the specific file you pick — never your entire gallery.
- Signature (optional): the signature you draw is saved as an image to print on invoices you generate.
3. How We Use Your Information
- Provide core expense tracking and budgeting features
- Auto-detect bank transactions from notifications (with explicit permission)
- Generate financial reports, insights and analytics
- Sync your data securely across your devices
- Send optional bill payment and budget reminders
- Process in-app subscription payments via Google Play Billing
- Display advertisements to free-tier users via Google AdMob
- Identify and manage the devices signed in to your account
- Improve app functionality, fix bugs and provide support
4. Data Storage and Security
- All data is transmitted over HTTPS/TLS encrypted connections
- Financial data is encrypted in transit and at rest on our servers
- HMAC-SHA256 request signing is used on native builds to prevent tampering
- Biometric authentication (fingerprint/face) is available for app lock
- Document vault files are encrypted before upload
- Session tokens are stored in device secure storage (Keychain/Keystore)
5. Data Sharing
We DO NOT sell, rent, or trade your personal or financial data to any third party. We may share data only in these limited circumstances:
- With your explicit prior consent
- To comply with applicable law, legal process, or government request
- To protect our rights, property or safety and that of our users
- With Google Play for subscription management (purchase tokens only)
- With Google AdMob to serve advertisements to free-tier users (device and usage signals only — never your financial data)
- With cloud service providers who host our infrastructure (under strict confidentiality agreements)
6. Your Rights
- Access and view all your stored personal data
- Correct or update inaccurate information
- Delete your account and all associated data permanently
- Export your financial data in standard formats
- Revoke notification access permission at any time
- Cancel subscriptions via Google Play Store
7. Data Retention
- We retain your data only as long as your account is active
- Upon account deletion, all personal data is permanently removed within 30 days
- Backup data is purged within 90 days of account deletion
- Payment records are retained as required by law (typically 7 years in India)
8. Third-Party Services
- Google Play Billing (subscription payments)
- Google AdMob (advertising — used to display ads to free-tier users)
- Google Firebase (crash analytics and push notifications)
- Secure cloud hosting provider (data storage)
9. International Data Transfers
Your data is primarily stored on servers located in India. If data is transferred outside India for backup or processing, we ensure adequate data protection safeguards are in place in compliance with applicable Indian data protection laws.
10. Children's Privacy
DigiExpense is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover such data, we will delete it immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via in-app notification or email at least 7 days before they take effect. Continued use after the effective date constitutes acceptance of the updated policy.
12. Contact Us