Last updated 20 September 2026
There are two Mero Paisa products and they handle your information in completely different ways. The Android app keeps everything on your phone and cannot send it anywhere. The web app uses an account and stores your records on a server. This page covers both, separately. Nothing below applies to the other product unless it says so.
In short
Nothing. The app does not collect, transmit or share any personal information. There are no user accounts and no sign-up. Everything it reads — including SMS and notifications, if you switch those on — stays on your device.
This is not only a policy commitment. The app's release build does not declare the INTERNET permission, so it has no way to open a network connection at all. It contains no analytics, no crash reporting, no advertising and no third-party tracking code.
These five, and nothing else. Several permissions that the app's libraries would otherwise add — access to your photos, videos, audio and external storage — are explicitly removed from the released app, because it has no use for them.
| Permission | What it is for |
|---|---|
| USE_BIOMETRIC | The optional app lock. |
| USE_FINGERPRINT | The same lock on Android 9 and older. Capped at API 28 so newer devices are never asked for it. |
| READ_SMS | Reading bank transaction alerts, from the senders you link to an account yourself. Not RECEIVE_SMS — nothing wakes the app when a message arrives. |
| POST_NOTIFICATIONS | Delivering the two reminders, if you switch them on. |
| RECEIVE_BOOT_COMPLETED | Restoring those two reminder alarms after a restart or an app update, which Android otherwise drops. |
The app can read your bank's transaction alerts so you do not have to type them in. This is off until you set it up, and setting it up means picking the sender for each account yourself from the list of senders on your phone — only their names are listed, and no message is read to build that list.
eSewa, Khalti, IME Pay and most mobile-banking apps confirm a payment with a push notification and nothing else — there is no SMS to re-read later. So the app can also read notifications, from the apps you link to an account.
The app can post two local reminders: one in the evening, and one on Sunday morning at the start of the budget week. Both are optional and are scheduled by your phone, on your phone. No reminder contains or transmits any of your figures, and nothing about them leaves the device.
Everything you enter — transactions, money sources, savings goals, spending limits, debts and family member tags — is stored in a single database file in the app's private storage on your device. It never leaves that device and is never sent to us or to anyone else.
To be precise about what protects it: that file is not separately encrypted by the app. It is protected by Android's app sandbox, which keeps other apps out, and by your device's own encryption. If you want a lock on top of that, switch on the app lock described below.
Any backup or export you create — a .bak backup file or an .xlsx workbook — is written to a location you choose, or handed to the app you choose through your phone's share sheet. Those files are entirely under your control. We never receive them, see them, or know they exist.
If you turn on the app lock, authentication is handled entirely by your device's operating system. The app never sees, stores or transmits your fingerprint, face or PIN — it is only told whether the check passed.
The one place a Google service is involved. The app can ask whether a newer version is available and hand you over to the Play Store to install it. That check runs inside the Play Store app's own process, not ours — Mero Paisa opens no connection and, having no INTERNET permission, could not. Nothing about you or your finances is part of it. If you installed the app some other way, you will never be offered an update this way at all.
The app does not knowingly collect data from anyone, including children, because it does not collect data at all.
The web app is a different product from the Android app and gives you different guarantees. It has accounts, so it necessarily has a server, and what you enter is stored there rather than on your device. It is still being built: signing up and signing in work, but the ledger behind them is not finished.
We do not collect anything else. There is no analytics code, no advertising, no third-party tracker and no third-party cookie on this site.
Exactly two, both strictly necessary to keep you signed in, and both set when you log in:
Both use SameSite=Lax and are deleted when you log out. They last as long as the sign-in the API grants, and at most seven days, after which you are signed out and have to log in again. Your access token is never exposed to the browser: pages call this site, and this site calls the MeroPaisa API on your behalf.
On the MeroPaisa API, which runs on Microsoft Azure App Service with a managed SQL Server database. Microsoft acts as our hosting provider and processes the data on our instructions.
Signing in here does not give you your phone's records, and entering something here does not put it on your phone. This is not a missing feature — the Android app has no internet permission, so it cannot send or receive anything. The two keep entirely separate records. To move data yourself, use the app's backup and export files.
There is no self-service delete button yet. Email us at nepcoder.me@gmail.com from the address you registered with and we will delete the account and everything stored against it.
If this policy changes, the updated version is posted on this page with a new “last updated” date.
Questions about any of this go to nepcoder.me@gmail.com.