Privacy Policy
Last updated: 31 July 2026
Hisab AI is a Google-login-first accounting application for small businesses. This policy explains the categories of information the product handles, why they are used and the safeguards expected across Android, iOS and Web.
Account and business records
Google sign-in through Supabase Auth identifies the account owner and maintains the session. Hisab AI can store business profiles, customers, ledger entries, sales, expenses, invoices, inventory, imported bank rows, reconciliation decisions, settings and subscription status. Cloud rows use owner-based access controls so one authenticated user should not access another user’s records.
The app also uses a local Drift database for responsive operation and caching. On shared devices, local records are scoped to their authenticated account. Backup export, restore and deletion are designed to affect the current account only. Legacy records whose ownership cannot be established are not silently assigned to a newly signed-in user.
Payments and subscriptions
Supported purchases use Razorpay. The client can receive a public key ID and order information, while secret keys remain on the backend. Premium is activated only after server verification or trusted webhook processing. Hisab AI may retain payment references, plan details and verification status needed for support, reconciliation and entitlement checks. It does not need card credentials, UPI PINs or bank passwords.
AI and receipt processing
AI features may process the minimum text or receipt content needed for the action. Output is presented for review before an accounting record is saved. Hisab AI should not send Aadhaar or ID-proof images, bank credentials, passwords, UPI PINs or an unnecessary private customer dataset to an AI provider. Provider configuration and availability can vary by platform and environment.
Optional ID proof
Customer ID proof is optional and consent-based. ID-proof images are stored in app-private encrypted local storage where supported and are excluded from normal cloud sync. They are not included in default exports and are not sent to AI. The associated encrypted file and key metadata should be deleted when the owning customer or account is deleted.
Advertising
The signed-in Flutter web application contains no AdSense units. Public educational guide articles under /guides/ may display up to two clearly labelled Google AdSense units after substantial publisher content. Google and its partners may use cookies or similar technologies according to consent, browser settings and regional requirements.
Free users of supported Android or iOS builds may see Google AdMob banners or limited interstitial ads on eligible non-sensitive screens. Rewarded ads are optional and user initiated. Ads are not intended for sensitive flows such as adding udhar, receiving payment, creating an invoice, payment checkout, ID proof, privacy controls or AI review. Paid users should not see eligible in-app ads. If subscription status cannot be verified, ads are hidden rather than assuming the user is Free.
Bank data and notifications
Bank statement import is a manual file workflow. Hisab AI does not ask for net-banking passwords, OTPs or UPI PINs and does not scrape a bank account. Imported rows are reviewed before they become records. Notifications should avoid exposing private names, amounts, notes, ID details or bank information on a lock screen.
Sharing and service providers
Information is shared only with service providers needed to operate selected features, such as Supabase for authentication and cloud records, Google for sign-in and approved advertising, Razorpay for payments, and configured AI infrastructure for an initiated AI action. Each provider handles data under its own terms and legal obligations. Hisab AI does not sell customer ledger data.
Retention, access and deletion
Records are retained while needed to provide the account, meet legitimate operational or legal obligations, resolve payment disputes and support requested backups. A user can access account controls in the app and request assistance at hisabai03@gmail.com. Account deletion separates local data deletion, cloud application-data deletion and authentication-account deletion. The interface must not claim a cloud or Auth deletion succeeded until the backend confirms it.
Security and responsibility
Hisab AI uses authenticated sessions, owner-only access rules, encrypted local handling for especially sensitive images and server-side payment verification. No system is completely risk free. Users should secure their Google account, device lock and recovery methods, and should report suspected unauthorised access promptly.
Children and changes
Hisab AI is a business accounting product and is not directed to children. This policy may change when features, providers or legal requirements change. Material updates will change the visible last-updated date.
Contact
For privacy questions, corrections, grievances or deletion support, email hisabai03@gmail.com. Do not include passwords, OTPs, UPI PINs or full ID-proof images.