Privacy Policy
This Privacy Policy explains how the Kash mobile application (“Kash”, “we”, “us”) handles information. Kash is designed as an offline-first expense tracker: your financial entries are stored on your device.
1. Who we are
Kash is published as an open-source / publicly distributed app under the package name
com.kash.app.kash. For privacy questions, contact us via
GitHub Issues.
2. Information you enter in the app
Depending on how you use Kash, the app may store on your device:
- Expense and income amounts, merchants, notes, timestamps, and categories
- Budget settings (for example monthly spending limit and income targets)
- App preferences (lock settings, reminder on/off, and similar options)
- Optional security question text and a hashed answer (not stored in plain text)
- PIN-related secrets stored with platform secure storage (hashed/salted; not recoverable by us)
This information stays on your phone unless you export a backup or spreadsheet and choose where to save or share that file.
3. What we do not collect as an account service
- Kash does not require creating an account to use the core expense tracker
- We do not operate a cloud ledger that syncs your spending history to our servers
- We do not sell your personal or financial data
4. Crash diagnostics (limited network use)
To improve stability, release builds may send crash and diagnostic reports using Google Firebase Crashlytics. Those reports can include device model, OS version, app version, and stack traces. They are used to fix bugs.
Crash reporting is not used to upload your expense list, notes, or backup files. Internet access in the app exists for this diagnostics purpose (and related connectivity checks).
5. Notifications
If you enable the daily reminder, Kash schedules a local notification (around 8:30 PM) to remind you to log expenses. You can disable this in Settings. Notification permission is requested so the reminder can appear.
6. Biometrics and app lock
If you enable app lock, Kash may use the device biometric hardware (fingerprint / face) or a PIN you set. Biometric data is processed by your device’s system; Kash does not receive or store your fingerprint or face template. PIN verification material is stored using platform secure storage on your device.
7. Backups and files
When you save a backup or CSV, you choose the destination (for example Downloads or a folder via the system file picker). Those files are under your control. On older Android versions, limited storage permission may be used only to write exports.
8. Permissions (Android)
- Internet / network state — crash diagnostics
- Notifications — optional daily reminder
- Boot completed — restore reminder schedule after reboot
- Vibrate — notification feedback
- Biometric / fingerprint — optional unlock
- Write external storage (Android 9 and below only) — saving exports on older devices
9. Children’s privacy
Kash is not directed at children under 13 (or the minimum age required in your country). Do not use the app if you are under that age.
10. Data retention and deletion
Because primary data is on-device, uninstalling Kash (or using in-app delete-all, if available) removes local app data subject to your device’s normal uninstall behavior. Crash reports retained by Google Firebase follow Google’s retention practices for that product.
11. Changes
We may update this policy. The effective date at the top will change when we do. Continued use after an update means you accept the revised policy.
12. Contact
Privacy requests: github.com/EtanaAlemu/kash/issues