Hisab
Home Features Privacy العربية

Privacy Policy

Last updated: July 2026

Introduction

Hisab ("we", "our", or "the app") is an open-source group expense splitting application. This Privacy Policy explains how we collect, use, and protect your information when you use our app. We are committed to transparency and respecting your privacy.

App Permissions

The app may request the following permissions. All are optional and requested only when you use the related feature. • Camera — To scan receipts when you choose the scan flow while adding an expense (tap the camera button). We do not record or store video; images are used only for this scan flow and are processed on your device or via optional AI services you configure. • Photos / Photo library — To let you choose expense images from your gallery when adding an expense (tap the gallery option). We only access images you explicitly select. • Notifications — To send you push notifications when group members add or edit expenses (Online mode only). You can disable this at any time in Settings > Privacy > Push Notifications. If you deny or disable notifications, the app works fully; you simply won't receive push alerts. • Notification access (Android, Transaction Scanner) — Only if you enable Transaction Scanner in Settings. The app may read notification text from apps you allow to detect bank or payment transactions, process them on your device, keep a local history of added and ignored messages, and show drafts for your approval before they become expenses. After setup, an empty app list captures nothing. You can turn the scanner off or revoke Notification access in Android system settings at any time. Draft and history text stays on your device and is not synced. Optional cloud AI, if you turn it on, sends that text to the AI provider you configured.

Data We Collect

In Offline mode, all data stays on your device. No data is sent to any server. In Online mode, we collect: - Email address (for authentication) - Display name and avatar (optional, set by you) - Group names, participant names, and expense data you create - Anonymous usage telemetry (if enabled in Settings)

How Data Is Stored

Offline mode: Data is stored locally on your device using SQLite. Nothing leaves your device. Online mode: Data is stored in clear text on cloud servers powered by Supabase (PostgreSQL). Data is NOT end-to-end encrypted. Do not store sensitive personal, financial, or confidential information. We recommend backing up your data regularly using the Export feature in Settings.

How We Use Your Data

Your data is used solely to provide app functionality: - Syncing expenses across your devices - Managing group memberships and invites - Calculating balances and settlements We do not sell, rent, or trade your personal data to any third party. We do not use your data for advertising or profiling.

Third-Party Services

The app may use the following third-party services: - Supabase: Cloud database and authentication (when using Online mode) - Google OAuth / GitHub OAuth: Sign-in authentication (optional) - Gemini / OpenAI: Cloud receipt scanning AI (optional, requires your own API key) - Gemini Nano (Android AI Core): Optional on-device receipt AI when you enable it and your device supports it These services have their own privacy policies. We encourage you to review them.

Data Sharing

We do not share your data with third parties except as required to operate the services listed above. Group data is shared only with members of the same group. We may disclose data if required by law.

Data Security

We implement row-level security policies on our database to ensure users can only access their own data. However, data in Online mode is stored in clear text and is not end-to-end encrypted. We cannot guarantee absolute security. We accept no liability for data loss, breaches, or unauthorized access.

Your Rights

You have the right to: - Export all your data at any time (Settings > Data & Backup > Export) - Delete local data from this device (Settings > Advanced > Delete local data) - Delete your data from the server (Settings > Advanced > Delete cloud data) - Request full account deletion (account deletion page, or open an issue on our GitHub repository or contact the developer via the app's About section) - Disable telemetry at any time (Settings > Privacy) - Use the app entirely offline with no data collection

Data Retention

Your data is retained until you delete it. When you delete your data through the app, it is removed from our servers. We do not retain backups of deleted user data.

Children's Privacy

This app is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us so we can delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected in app updates. We encourage you to review this policy periodically. Continued use of the app after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions or concerns about this Privacy Policy, please open an issue on our GitHub repository or contact the developer through the app's About section.

Hisab — حساب
Home Features