Privacy Policy
1. Introduction
Klera (“the App”, “we”, “our”) is a personal finance application built for India. This Privacy Policy explains what data the App collects, how it is used, and what rights you have over it under the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable laws.
Key principle: Klera is designed to be privacy-first and offline-first. Your financial data lives on your device. We do not sell, rent, or share your personal data with advertisers or third parties for marketing purposes.
What that does and does not mean. Every feature of the App works without a network. The App is not, however, a device that never talks to the internet, and we would rather list the exceptions than let you discover them: the App shows ads (§7a), can back up an encrypted copy of your data to your own Google Drive if you turn that on (§4a), fetches public market prices if you track investments (§7b), checks whether a newer version of the App exists (§7c), and sends crash reports if you opt in (§7d). None of these transmits your transactions, balances, categories, accounts, or contacts.
2. Data We Collect
2a. Data you provide (stored on-device only)
| Category | Examples | Purpose |
|---|---|---|
| Account details | Account name, type, opening balance | Core ledger functionality |
| Transactions | Amount, category, date, notes, merchant (optional) | Expense tracking |
| Contacts & IOUs | Name, borrow/lend amounts | Personal IOU ledger |
| Goals | Goal name, target amount, contributions | Savings tracking |
| Budgets | Monthly total and per-bucket limits (Needs / Wants / Investments / Learning) | Budget planning |
| Loan records | Loan name, principal, rate, tenure | Loan Tenure Planner |
| Calculator inputs | SIP/loan parameters (ephemeral) | Financial calculators |
| App settings | Currency preference, biometric lock toggle | App configuration |
All of the above is stored exclusively on your device in an encrypted SQLite database (AES-256 via SQLCipher). It is never sent to our servers unless you explicitly enable cloud sync (a future paid feature).
2b. Data collected automatically
The App runs no analytics and no usage telemetry. We do not track which screens you open, what you tap, or how often you use the App, and we do not collect crash reports unless you explicitly opt in (§7d).
The one automatic collection is by the advertising SDK: because the App is ad-funded, Google’s Mobile Ads SDK collects your device’s Advertising ID and standard device and network information in order to serve ads. It receives none of your financial data. See §7a for the full description and for how to set your ad-personalisation preference.
2c. Data we do NOT collect
- Aadhaar number, PAN, passport, or any government ID
- Full card numbers, CVV, or card PINs (only last-4 digits + network nickname, at your option)
- Call logs. Klera never requests call-log access, and does not build “after-call” spend prompts of any kind. This is a permanent design decision, not a current limitation.
- Biometric data (biometric authentication is handled entirely by your device OS — we never see the raw biometric)
- Location data
2c-i. Contacts (opt-in, read-only, one screen only)
Klera does use your device’s contacts, in one narrow place, and we would rather spell out the boundary than list it under “never”.
When you are adding an udhaar (IOU) entry and typing a person’s name, you may tap an explicit “suggest from phone contacts” control. Only then does the App request the Android/iOS contacts permission, and only then does it read your address book — live, in that moment, to show you matching names and phone numbers as you type. Specifically:
- The permission is never requested during onboarding, on app launch, or when a name field simply receives focus. It is requested only from that one deliberate tap.
- Contacts are read-only and used in the moment. Klera does not enumerate your address book into its own database, does not keep a copy after the field loses focus, and does not sync, upload, or transmit contacts anywhere — this code path makes no network call at all.
- Picking a suggestion does not by itself save anything. A person becomes a stored Klera contact only when you tap Save on the udhaar entry, exactly as if you had typed the name by hand.
- You can decline the permission and keep using the ledger normally — you just type the name yourself.
- There is no “import all my contacts” or contact-sync feature.
2d. Automatic transaction tracking from bank SMS (Android only, opt-in)
Reading your bank and UPI transaction messages to build your expense records for you is Klera’s primary way of recording transactions, and the reason the App requests SMS access. You are offered it when you first set the App up, from a card on the home screen, and from Settings → Privacy. It is off until you turn it on, and you can turn it off again at any time.
What is read. Only messages whose sender ID is on a fixed allowlist of known bank, UPI and card-issuer sender IDs built into the App (e.g. HDFCBK, SBIINB). Messages from anyone else — people, OTPs from other services, marketing — are never inspected. An explicit “Scan existing messages” action reads the messages already in your inbox the same way, so past spending can be recovered in one pass.
What is stored, and for how long. The text of a captured message is stored on your device only, inside the App’s encrypted database (AES-256, SQLCipher). Klera keeps it so that related messages can be joined together (a hold and its release, a mandate and the debit it authorises) and so a parsing mistake can be corrected later. A captured message that never becomes a transaction is deleted automatically after 30 days. One that did become a transaction is kept as that transaction’s record of where it came from, for as long as you keep the transaction.
Where it never goes. Message text is never transmitted anywhere, never logged, and never shared with us or any third party — the App has no server to send it to. It is deliberately excluded from data export and from encrypted backups (including Google Drive backup), and it is never synced. Deleting your data (Settings → Privacy → Delete All My Data) erases it, as does turning capture off and clearing captured data.
What Klera never does. It never becomes your device’s default SMS handler, never sends SMS, never reads your call log, and never uses message content for advertising, profiling, or any purpose other than building your own ledger on your own device.
2e. Notification-based auto-capture (not in the current release)
The App does not currently read your notifications. Notification-access capture is built but switched off in every released version, and the App does not ask for notification access or hold that permission. Nothing in this section applies to the App you have installed today.
We describe it here so the boundary is on record before it ever ships. If we enable it in a future version, it would be strictly opt-in and would work like §2d: the App would read the payment notifications your bank and UPI apps post to your notification shade, matched against a fixed allowlist of known bank and UPI senders, and turn them into a draft transaction for you to review and save. Notifications from any other app would be ignored, all parsing would happen entirely on your device, and no notification content or parsed data would ever be transmitted, logged, or shared with us or any third party. Turning it on would require granting notification access yourself in your device’s settings, and you could revoke it there at any time.
Note that this is unrelated to the App’s ordinary reminder notifications — the ones Klera posts to you for due dates, budgets and backup status. Those send nothing anywhere.
2f. Sharing a receipt into Klera
You can share a payment message or receipt image into Klera from another app (for example a UPI app or WhatsApp). Klera reads the amount, date and payee from what you shared, using on-device text recognition, and pre-fills a draft transaction. The image and text are processed on your device and are not uploaded. Nothing is captured unless you actively share it.
3. How We Use Your Data
Your data is used solely to provide the App’s features to you, on your device:
- Display your account balances, transaction history, and reports
- Calculate EMI, loan comparisons, SIP projections, and goal progress
- Enforce your app-lock preference (biometric / device PIN)
We do not use your financial data for advertising, profiling, or any purpose other than running the App for you.
4. Data Storage and Security
- Encryption at rest: The database is encrypted with AES-256 (SQLCipher). The encryption key is generated on first launch, stored in your device’s OS secure keystore (Android Keystore / iOS Secure Enclave), and never leaves your device.
- OS-level backup is switched off: Klera opts out of the operating system’s own automatic app-data backup for its encrypted database files, so your ledger is not swept into an OS backup as a side effect. This is separate from Klera’s own backup feature, described next.
- Screen security: Financial screens are protected with
FLAG_SECURE(Android) / screen-capture prevention (iOS) to prevent screenshots and screen recordings from leaking financial content. - App lock: You can require biometric authentication or a PIN before the App opens.
4a. Google Drive backup (opt-in — your Drive, your passphrase)
Klera does offer a cloud backup, and it is worth being precise about what that means, because “cloud” usually implies “our servers”. It does not here.
What it is. If you turn on Google Drive backup (Settings → Backup), Klera signs in to your own Google account and stores an encrypted backup file there. There is no Klera server in this path and we never receive a copy. Klera does not operate a backend that stores your financial data.
What Google can see. The file is encrypted before it leaves your device, with a key derived from a backup passphrase that you choose. Google stores an opaque encrypted blob. Neither Google nor Klera can read its contents. File names carry only a timestamp — never amounts, categories, or the names of people in your ledger.
Which part of your Drive. Klera requests only the drive.appdata scope — a hidden, application-private folder. Klera cannot see, list, open, or modify any other file in your Google Drive, including files created by other apps. This is the narrowest scope Google offers for this purpose, and we chose it deliberately over the more convenient alternative that would have made the backup visible in your Drive UI at the cost of broader access.
About the passphrase. You set it once, on your first backup. If you enable automatic backup, the passphrase is stored in your device’s OS keystore so that backups can run without prompting you every time; disconnecting Drive removes it from the device and revokes the access token. We cannot recover your passphrase. If you forget it, the backup cannot be decrypted by anyone, including us — that is the necessary consequence of us not holding a key, and you should store it somewhere safe.
When it runs. Automatic backup is opportunistic, not a background service: when you open the App, Klera checks whether the chosen interval (daily or weekly) has elapsed since the last backup and, if so, uploads one. Klera does not run background code to upload your data while the App is closed. You can also back up on demand at any time.
Restoring. On a new device, install Klera, connect the same Google account, and enter your passphrase. Restore always accepts a typed passphrase, so a backup made on another phone is recoverable.
Turning it off. Drive backup is off until you enable it. Disconnecting stops automatic backups and clears the stored passphrase and access token from the device. Backups already in your Drive remain yours and can be deleted through your Google account at any time.
Local backup. Independently of Drive, you can create an encrypted backup file and store or share it wherever you choose, and export your data as described in §5.
5. Your Rights (DPDP Act + Good Practice)
You have the following rights over your personal data:
| Right | How to exercise |
|---|---|
| Access / Portability | Settings → Privacy → Export My Data. Generates a JSON export of your on-device data — your ledger, accounts, contacts, budgets, goals and loans. The raw text of captured bank SMS is deliberately left out of the export (and out of backups), so message bodies cannot leave the device through a file you share; see §2d. |
| Erasure | Settings → Privacy → Delete All My Data. Permanently wipes all personal data from the device in one tap. |
| Correction | Edit any transaction, account, or contact directly in the App. |
| Withdraw consent | Settings → Privacy holds your consent choices: turn crash reporting off, change your ad-personalisation preference, disconnect Google Drive backup, or switch off live price lookups. You may also uninstall the App at any time; this removes all locally stored data. |
| Grievance | Email support@kleraapp.com within 30 days; we will acknowledge within 48 hours and resolve within 30 days. |
6. Children
The App is not directed at children under 18. We do not knowingly collect data from minors.
7. Third-party Services
These libraries run entirely on your device and transmit nothing:
| Library | Purpose | Data access |
|---|---|---|
| Drift (SQLite) / SQLCipher | Local encrypted database | On-device only |
| flutter_secure_storage | Key and passphrase storage | OS keystore only |
| local_auth | Biometric / PIN app lock | OS biometric API only |
| ML Kit text recognition | Reading a shared receipt image or a scanned statement | On-device only — images are never uploaded |
The services below do use the network. Each is listed with what it receives.
7a. Advertising (Google AdMob + UMP consent)
The App is free, and every feature is included. It is funded by advertising, and we would rather explain that trade than bury it. An optional ad-free subscription (₹30/month or ₹300/year) removes the ads — and nothing else; how that purchase is processed is described in §7f.
- What the ad network receives. Google’s Mobile Ads SDK receives the data it needs to serve an ad — including your device’s Advertising ID and standard device/network information. It does not receive your transactions, balances, categories, budgets, goals, accounts, loans, contacts, or udhaar entries. No financial content from your ledger is sent to any ad network, ever. We do not sell your data, and we do not use your financial data for advertising, profiling, or targeting.
- Where ads appear. A small number of native slots, styled to match the App and labelled “Ad” — currently on Home, Insights, Manage Loans, Net Worth, the parsed-results step of statement import, and the udhaar ledger.
- Where ads never appear. The add-expense / quick-add / add-IOU capture flow, onboarding, Settings, security and app-lock screens, and — importantly — the data export, data deletion, and backup/restore screens. Your rights under §5 are never placed behind, next to, or after an advertisement.
- Your choice. On first run you are shown Google’s standard UMP consent prompt and choose whether ads are personalised. You can change this later in Settings; your choice is also recorded in the App’s own consent record. Ads are not shown during your first several sessions, and each placement can be switched off remotely by us if it proves intrusive.
- Sensitive categories such as loans, gambling, dating and crypto are blocked in our AdMob configuration.
7b. Live market prices (on by default for investments; can be switched off)
If you track investments, the App fetches public market prices (for example fund NAVs, gold rates, and stock quotes) over the network so it can show current values and returns. This is controlled by a toggle in Settings that is on by default and can be switched off, in which case investments show only the cost values you entered and no price request is made.
What is sent is a request for public price data. No personal or financial data is transmitted — not your holdings’ quantities, not your cost, not your account details, and not any identifier tied to you. Note that for individual stock quotes, the price provider necessarily learns which symbols were requested; if that matters to you, switch the toggle off.
7c. App version check
On launch, the App fetches a small, public configuration file from our servers to determine whether a newer version is available and whether an update should be recommended or required. This request contains no personal data and no financial data; it is a plain download of a public file, and the App works on its built-in defaults if it fails.
7d. Crash reporting (opt-in, off by default)
If you choose to turn on “Crash reports” (offered once during setup, and always available in Settings → Privacy), the App uses Sentry to send us technical crash and error reports — stack traces, the type of error, your device model, OS version, and app version. This is off unless you explicitly turn it on, and you can turn it off again at any time. We do not send your financial data as part of this: every report is scanned and stripped of anything that looks like an amount, balance, account, category, contact, or note before it leaves your device, as a safeguard in addition to our engineering practice of never logging financial content in the first place. Crash reports are not linked to your identity — the App has no user accounts.
7e. Google Drive backup
Only if you enable it, and covered in detail in §4a above. Google stores an encrypted blob it cannot read, in an app-private folder Klera cannot see outside of.
7f. Ad-free subscription purchases (Google Play billing + RevenueCat)
If you buy the optional ad-free subscription (§7a), the purchase is made through Google Play billing and tied to your Google Play account — the App has no accounts of its own. The App uses RevenueCat to manage subscription state: whether your subscription is active, renewed, or expired. What RevenueCat receives is limited to an anonymous app-instance identifier and the store’s purchase and entitlement tokens — never your ledger, transactions, balances, or contacts. Your card details are handled entirely by Google Play and never touch Klera.
The resulting ad-free flag is stored locally on your device. It is not included in backups, and it survives Delete All My Data (§5) — so wiping your ledger does not take away a purchase you paid for; “Restore purchase” also re-applies it after a reinstall.
Future versions may add encrypted multi-device sync (opt-in). It will be disclosed in an updated Privacy Policy before it is enabled.
8. Changes to This Policy
We will notify you of material changes via an in-app notice before the effective date. Continued use after the effective date constitutes acceptance.
9. Contact Us
Grievance Officer: Manish Talreja Email: support@kleraapp.com Response time: within 48 hours (acknowledgement), 30 days (resolution)