Privacy policy
Last updated [date]
What we never ask for
Milekha reads statements you already have. It does not connect to your bank, so there is a whole category of secret it has no reason to hold, and does not:
- your net-banking username or password;
- your UPI PIN, card PIN, CVV, or any one-time password;
- your full account or card number — only the last four digits are kept, so you can tell your accounts apart.
Nobody from [Registered entity name] will ever ask you for these. Treat any such request as fraudulent.
What we collect
- Account details — your name, email address and, if you provide one, mobile number, so we can identify you and send service notices.
- Statements you upload and the transactions read from them.
- What you record — accounts, budgets, goals, categories, notes and tags.
- Technical records — sign-in times, device and browser details, and IP address, kept to secure the account and investigate abuse.
- Payment records — the plan, its status and invoice references. Card details are handled entirely by Razorpay and never reach our servers.
Why we use it
To provide the service you asked for: reading your statements, keeping your ledger, showing your budgets and insights, taking payment for a paid plan, and keeping the account secure. We do not sell your data, and we do not use your financial data for advertising.
Who else sees it
- Razorpay, for payments.
- Our hosting provider, which stores the data on our behalf.
- Nobody else, unless the law requires it, or you ask us to.
Support staff cannot browse your transactions. Reaching identifiable financial data requires a recorded reason tied to a support ticket, and the record is written before the data is shown.
How long we keep it
- Uploaded statement files: 90 days by default, and you can delete the original at any time without losing the imported transactions.
- Your transactions and account: until you delete them.
- Audit and security records: retained longer, because they exist to show what happened to your account.
Your rights
You can see, correct, export or erase your data from Privacy & data in the app, without asking us. Export is a full CSV archive. Erasure removes your ledger and closes the account; records we must keep by law are retained and nothing else.
Security
Data is encrypted in transit. Sensitive fields are encrypted at rest, passwords are stored only as salted hashes, and every session can be reviewed and revoked from your settings.
Contact
Write to [privacy@yourdomain]. If you are not satisfied with our response you may complain to the Data Protection Board of India.