1. Introduction
LekhaVault is a personal finance management application developed and published by Japrinix Labs. It helps users organize financial records such as accounts, transactions, categories, budgets, recurring dues, savings plans, credit-card records, loan records, and reports.
This Privacy Policy describes the types of information handled by LekhaVault, how that information is used, how the production LekhaVault service API is involved, and how users can contact us with privacy questions.
2. Information We Collect
Depending on the features used, LekhaVault may process the following categories of information:
- Account and profile information, such as email address, display name, selected currency, locale, app settings, password verifiers, and reminder preferences.
- Financial records entered or imported by users, including account names, account types, balances, transactions, income, expenses, transfers, categories, payees, tags, notes, budgets, subscriptions, recurring rules, credit-card tracking records, loans, EMIs, savings plans, and contribution records.
- Documents you choose to upload to the Financial Vault, together with file information, notes, and links to the financial records they support.
- Import, export, backup, restore, duplicate-detection, integrity-check, and audit-related metadata created when those workflows are used.
- Support communications, including any information a user chooses to send when contacting Japrinix Labs.
- Technical and application information needed to operate, protect, troubleshoot, and improve the LekhaVault service, including minimized security-event, session, installation, and administrator-audit metadata.
- Notification information, including your preferences, notification history, app installation identifiers, and device messaging tokens used to deliver phone notifications. Preview delivery also uses per-phone public encryption keys and identifiers that bind delivery to your signed-in account and app installation. The notification service also processes technical information as described below.
3. Financial Information
LekhaVault is designed to handle user-entered financial tracking records. These records may be sensitive because they can describe income, spending, balances, debts, budgets, savings goals, payees, and other personal finance activity.
LekhaVault organizes records you enter or import; it does not connect to your bank to retrieve transactions or move money. Do not enter online banking passwords, ATM PINs, card PINs, or complete payment-card credentials into LekhaVault, including in notes or uploaded documents.
4. How We Use Information
We use information to provide and maintain LekhaVault, including to:
- Create, save, display, update, search, and organize financial records.
- Show dashboards, reports, balances, budgets, due dates, and summaries.
- Support reminders, recurring rules, import/export, backup, restore, and integrity workflows.
- Operate user account and application data services through the LekhaVault service infrastructure.
- Respond to support or privacy requests sent by users.
- Protect, troubleshoot, maintain, and improve the reliability of LekhaVault services.
Activity check-ins use the timing and number of transactions you add to remind you when your records may need updating. They can appear after 12 hours without a new transaction or when recent activity is lower than your usual pattern. Check-ins are enabled by default, limited to one per 24 hours, and can be turned off in notification preferences. This comparison is for reminders, not advertising or external AI analysis.
5. Service API Processing and Storage
The production LekhaVault architecture uses the LekhaVault API at https://app.lekhavault.com/api/v1 for applicable application data processing and storage. This API is part of the LekhaVault service and is not described here as a third-party API.
Account credentials, sessions, user-entered finance records, notification preferences, and applicable attachment content are processed by the service API. Passwords are stored as salted password verifiers, and session credentials are stored as one-way hashes rather than plaintext tokens.
Our public website and application use hosting and backup services. Account and financial records are stored in a database, and encrypted attachment files in a protected persistent directory separate from public website files. Hosting backups support service recovery. The mobile app also keeps local information needed to display and synchronize your records.
6. Data Security
We use reasonable administrative, technical, and organizational measures intended to protect information handled by LekhaVault. These include HTTPS connections, password verification, PIN or optional biometric app unlock, access controls, and encryption of stored attachment content and server-held push tokens. These protections do not mean that all service data is end-to-end encrypted or accessible only with keys you hold.
No electronic storage, software, network, or service can be guaranteed to be completely secure. Users should protect their devices, credentials, exported files, and backup files.
8. Third-Party Services
Hosting and email
Hostinger provides website and application hosting and backups. Our email delivery provider processes your email address and transactional messages, such as registration, recovery and account-deletion verification codes and completion notices. Automated messages may come from no-reply@lekhavault.com; contact us using the support addresses below.
Phone notifications
Google Firebase Cloud Messaging provides phone notifications for the Android app. This service initializes when the app starts and may create installation identifiers and messaging tokens before you enable phone notifications. The provider may also process technical information such as IP addresses, app identifiers, and service operation information.
When phone notifications are enabled, we associate a messaging token with your signed-in account and app installation. Delivery includes a random notification identifier, an event category, an app navigation route, and preview setting and binding identifiers. Phone delivery remains off until you enable it and grant the relevant Android permission.
Updated Android apps select Detailed notifications by default, while preserving a saved Protected choice. You can change this setting for each phone. Detailed titles and messages may contain amounts, payees, account names or due dates. Our API encrypts the financial title and message for that phone before sending it through the notification service. The provider receives encrypted preview content, not readable financial text. The private decryption key stays in the phone's protected key storage, and the app decrypts the preview on that phone for Android to display. Our API still processes your financial records; this delivery protection does not make all service data end-to-end encrypted.
Detailed notifications may appear outside LekhaVault, including on the lock screen, in notification history or on connected devices, according to Android and device settings. Your app PIN protects the app, not notification previews. Choosing Protected notifications shows generic notification text and clears current app alerts on that phone. It cannot recall notification-history copies or information already seen on connected devices. Older apps without preview support keep generic alerts. Opening a notification still requires the applicable sign-in or app unlock; a preview never unlocks your financial workspace.
Turning off Phone notifications stops our server from sending notifications to that app installation. It does not itself delete installation information held by the provider or stop the notification service from initializing. See notification service privacy and security information and the provider's privacy policy for how the provider handles information, including retention.
App distribution, Android, and your device manufacturer may provide their own platform services under their privacy terms. LekhaVault does not use the notification service for advertising.
9. Data Retention
We retain information for as long as needed to provide LekhaVault, comply with legal obligations, resolve disputes, enforce terms, maintain security, and support legitimate operational needs.
When account deletion completes, LekhaVault removes the account identity, raw email address, display name, credentials, recovery material, sessions, device registrations, financial records, notifications, and stored attachment content from the active service. Limited pseudonymous deletion-security evidence and operational logs have a default retention period of 120 days. Configured periods and documented legal or security needs may affect how long these limited records are kept.
Deletion-security evidence may include verification-factor results, failed-code count, keyed pseudonyms for the session, installation, network, and normalized email, minimal client and timing information, the accepted Privacy Notice version, and confirmation-delivery status. It does not contain the raw email address, name, user identifier, credentials, verification code, or financial data. Authorized administrators can locate it only by providing a deletion reference or an email address that is transformed with a separate secret key; the supplied email is not stored or logged by that lookup.
An authorized administrator may place an expiring legal hold on this limited record when required for a documented security incident, legal claim, regulatory request, or law-enforcement request. Every lookup, hold, and release is audited. The record is removed when its retention period expires unless an active legal hold requires it to be kept longer.
A separate minimal completion receipt may remain after that evidence expires. It contains a random receipt reference, account creation and deletion dates, policy and completion status, and email-delivery status, but not your email address, name, account identifier, or financial content. These receipts do not currently have an automatic expiry period.
Removal from active records does not guarantee immediate physical erasure from every storage copy. Recovery backups may retain earlier data until those backups expire under the hosting provider's retention arrangements. Files you exported or copied outside LekhaVault remain under your control.
10. Data Deletion and User Choices
You can manage records, archive accounts, export information, and request account deletion in the app. Archiving a record or deleting finance data is different from deleting your account: some finance-only deletions retain archived or deletion-marked records to preserve history and synchronization rules, while your account remains active.
Self-service account deletion requires the current account password, an exact typed confirmation, and a purpose-bound, single-use email verification code. After verification, a completed deletion revokes sessions, removes your account and associated data from active service records, and clears the mobile app's synchronized view. We attempt to send a final completion email. Account deletion cannot be undone through the app; the limited records and backup limitations described in the retention section still apply. If you cannot access the app, contact support@lekhavault.com for help with a deletion or privacy request. We may need to verify your identity.
In notification preferences, you can turn off Activity check-ins or Phone notifications independently. Phone notifications also require the relevant Android permission. You can choose Detailed or Protected notifications separately for each phone without changing which reminder categories are enabled. Signing out revokes that installation's registration with our notification service and clears current app alerts on that phone; in-app notification history is a separate feature. Changing the preview choice or signing out cannot recall copies in notification history or information already seen on connected devices.
11. Permissions
LekhaVault may request permissions needed for selected mobile features, including phone notifications and biometric unlock. An internet connection is used to communicate with the service. Document and import/export workflows use files you select through the system file picker; they do not require access to all files on your device. Biometric verification is performed through Android; LekhaVault does not receive your fingerprint or facial biometric template.
Permission prompts and controls can vary by Android version and distribution channel. Users can review or change permissions in device settings.
12. Children's Privacy
LekhaVault is a general personal finance application and is not directed to children. We do not knowingly seek personal information from children. A parent or guardian who believes a child has provided information through LekhaVault may contact us.
13. International Users
Users may access LekhaVault from different regions. Information may be processed in locations where LekhaVault, its service infrastructure, or hosting, notification and email providers maintain systems, including outside your country. The notification service uses global infrastructure. We do not promise that all processing or storage is confined to a particular country.
14. Changes to This Privacy Policy
We may update this Privacy Policy as LekhaVault features, service architecture, legal requirements, or operational practices change. Updates will be posted on this page with a new Last Updated date.
15. Contact Us
For privacy questions, support requests, or data-related inquiries, contact:
Japrinix LabsProduct: LekhaVault
Contact: contact@lekhavault.com
Support: support@lekhavault.com
Website: https://japrinixlabs.com
Return to the LekhaVault home page.