1. Scope and controller
This Privacy Policy explains how RollingCash handles information when you use the RollingCash mobile application, website, APIs, support forms, and related services (together, the “Service”).
RollingCash is an independent personal project operated by its individual developer in India. For privacy questions or requests, contact rollingcashadmin@gmail.com.
RollingCash is a record-keeping and planning tool. It is not a bank, broker, payment account, financial adviser, or credit provider.
2. Information we collect
| Category | Examples | Why it is needed |
|---|---|---|
| Account and profile | Name, email, username, optional mobile number, verification status, country, time zone, currency, language, and preferences. | Create and secure your account, personalize the Service, and communicate with you. |
| Financial records you enter | Accounts, balances, transactions, dates, narrations, categories, budgets, goals, loans, cards, deposits, investments, demat holdings, reminders, and planning data. | Provide the tracking, ledger, chart, planning, and reporting features you request. |
| Authentication and security | Password hash, verification codes, signed session/token records, device description, IP address, user agent, login and session timestamps. | Authenticate you, maintain sessions, detect abuse, and protect accounts. |
| App activity | App install or unlock events, screens viewed, navigation path, action started/completed/abandoned, session duration, app version, and installation identifier. | Understand reliability and feature usage. These records describe actions, not the financial values or text entered in them. |
| Diagnostics | Error type, redacted error message and stack trace, route, app/build version, device and operating-system context, and diagnostic breadcrumbs. | Find crashes and technical failures. Diagnostic reporting is designed to exclude passwords, tokens, transaction bodies, and screenshots. |
| Support and deletion requests | Your account email, message, selected reason, request status, IP address, and browser/device information. | Answer support enquiries and process privacy or deletion requests. |
| Website usage | Page path, referring page/domain, browser user agent, IP address, anonymous visitor identifier, status code, and timing information. | Operate, secure, and improve the public website. |
RollingCash does not ask for or store full payment-card numbers. Card features use descriptive account information and may store limited details such as the last four digits when you provide them.
3. Where information comes from
- Directly from you, when you register, enter financial records, configure the app, or contact support.
- Automatically from your device or browser, for authentication, security, app activity, website analytics, and diagnostics.
- Public market-data sources, such as exchange-published data and supported quote providers, when investment-price features are used. RollingCash sends an instrument identifier needed to request public pricing data, not your complete portfolio.
- Payment providers, if paid checkout is enabled later, to confirm payment and subscription status.
4. How we use information
We use information only where reasonably necessary to:
- provide account, transaction, ledger, budget, planning, investment, and report features;
- create, authenticate, and maintain your account and app sessions;
- send verification, security, service, support, and deletion-confirmation messages;
- provide subscriptions and confirm payments if paid checkout is enabled;
- diagnose errors, prevent abuse, secure the Service, and enforce usage limits;
- measure app and website reliability and improve feature usability; and
- comply with applicable law and respond to valid legal requests.
Depending on the context and applicable law, processing is based on providing the Service you requested, your consent, our legitimate interest in operating and securing the Service, or a legal obligation.
6. Android permissions and device storage
Microphone
Microphone access is optional and requested only for voice Quick Entry. You may deny or revoke it and continue using text entry. RollingCash does not continuously listen in the background.
Local security storage
On supported mobile devices, authentication tokens and the local MPIN verifier are stored using the operating system's secure storage. MPIN is a local unlock control and is not sent to the RollingCash server. Diagnostic queues are encrypted on the device before upload. Android backup is disabled for the app.
Permissions not requested
The current Android app does not request contacts, precise location, SMS, call log, or broad external-storage access.
7. Retention and deletion
Account and financial records are retained while your account remains active so the Service can provide historical ledgers, reports, and planning features. Support and payment records may be retained as needed to resolve requests, prevent fraud, meet accounting requirements, or establish legal claims.
Security activity logs are normally configured for 90 days, and inactive session records for 365 days. App crash reports are normally retained for 30 days. Some security, payment, backup, or legal records may be retained longer where reasonably necessary or legally required.
You may request deletion through the account-deletion page or by emailing rollingcashadmin@gmail.com. We review requests to protect against unauthorised deletion. Once verified and completed, the account and associated application data are permanently erased using the administrative deletion process, except information that must be retained for legal, security, fraud-prevention, or backup-cycle purposes. A confirmation email is sent after completion.
Deleting the mobile app does not by itself delete server-side account data.
8. How information is protected
RollingCash uses safeguards appropriate to the current Service, including HTTPS for production API traffic, hashed passwords and refresh tokens, short-lived signed access tokens, secure mobile token storage, access controls, ownership checks on account data, restricted administrative functions, audit and security logs, rate controls, and encrypted diagnostic queues.
No system can guarantee absolute security. Keep your credentials private, use a secure device lock, and contact us promptly if you suspect unauthorised access.
9. Your choices and rights
Subject to applicable law, you may ask to access, correct, export, or delete your personal information; withdraw consent where processing relies on consent; or raise a concern about how information is handled.
- Profile and financial records can be corrected through available edit controls.
- Microphone permission can be managed in Android settings.
- Marketing email preference can be changed in your account preferences where available.
- Active app sessions can be reviewed or signed out through session settings.
- Deletion can be requested without reinstalling the app using our public deletion page.
We may need to verify that a requester controls the relevant account before fulfilling a request.
10. Children and younger users
RollingCash is a general personal-finance record-keeping tool and is not specifically directed to children. The Service does not intentionally request school, contact-list, precise-location, or advertising-profile data from children. Where local law requires parent or guardian permission for a younger user to create an online account, that permission should be obtained before use. A parent or guardian who believes a child provided personal information without appropriate permission may contact us to request review and deletion.
11. Data location and international processing
Primary application hosting is located in India through HOST.CO.IN. Some optional providers, such as speech recognition, email delivery, diagnostics, analytics, market-data, or future payment services, may process limited information in other countries. Where applicable, we rely on the provider's contractual and security safeguards and limit the information sent to what is needed for that function.
12. Changes to this policy
We may update this policy as RollingCash changes or legal requirements evolve. The effective date at the top will be revised when changes are published. Material changes may also be communicated in the app, on the website, or by email where appropriate.
13. Contact and grievances
RollingCash privacy contact
Individual developer and data controller, India
Email: rollingcashadmin@gmail.com
You may also use the contact form and select “Privacy or security.” Please do not include passwords, authentication codes, or unnecessary financial details.