Privacy Policy
Your data. Your choices.
A clear account of what KharchaBill collects, why it is needed, where optional services are involved, and the controls available to you.
Overview and scope
This policy applies when you use KharchaBill websites, account workspace, support forms and connected features. KharchaBill is a product of ManchLabs. It explains our handling of personal data; it does not replace the terms of a third-party service you choose to connect.
Data we collect
Depending on the features you use, we process:
- Account data: name, email address, mobile number, password hash, verification state, currency, timezone and preferences.
- Financial records you enter or import: accounts, transactions, categories, budgets, loans, cards, recurring items, goals, assets, liabilities and investments.
- Service and security data: session, device, browser, IP address, login history, audit events and error information.
- Support and community data: messages, enquiries, feedback or stories you submit.
- Plan and payment records: plan, amount, currency, status and payment-provider references. KharchaBill does not ask you to store card PINs, CVVs or online-banking passwords.
How we use data
We use data to create and secure your account, maintain your ledger, calculate reports, provide budgets and reminders, process verified plan payments, answer support requests, prevent abuse, diagnose faults and meet applicable obligations. Core totals and financial calculations are produced by application logic, not generated by an AI model.
Email finance sync
Email sync is optional. If you connect a supported Google or Microsoft mailbox, KharchaBill uses the permission you grant to retrieve relevant financial messages for review and import. Connection details, sync status, message metadata and parsed transaction candidates may be stored. Review imported entries before relying on them, and disconnect the mailbox from Settings when you no longer want syncing.
The standard retention setting for reviewed email-sync material is configurable; operational records may be retained where needed to prevent duplicate imports, investigate errors or meet legal requirements.
Optional AI processing
AI-assisted features are disabled unless configured and, where required, you provide explicit consent. Financial insight requests are designed to send limited aggregates such as period totals and savings rate. Optional generic email parsing masks common sensitive patterns before sending a limited extract to the configured provider. Requests are configured not to be stored by the model provider where the provider supports that control.
Do not treat AI output as financial, tax, legal or investment advice. You can withhold or withdraw optional consent without losing the core ledger features.
Cookies and local storage
KharchaBill uses essential session and security cookies to keep you signed in, protect forms and remember necessary preferences. We do not describe optional advertising cookies as essential. If analytics or marketing technologies are introduced, this notice and the relevant consent controls will be updated first.
When data is shared
We share only what is needed with service providers that help operate the product—for example hosting, transactional email, payment verification, connected mailbox providers and an AI provider when you enable an applicable feature. We may also disclose information when legally required, to protect users or the service, or during a business reorganisation subject to appropriate safeguards. Providers may process information outside India under their own infrastructure and contractual terms.
Retention and security
We retain information while your account is active and for as long as reasonably needed for the feature, security, dispute resolution and legal obligations. Account deactivation removes access and anonymises key identity fields; some financial, payment, audit or backup records may remain for a limited period where technically or legally necessary.
We use access controls, password hashing, CSRF protection, user-isolated queries, session controls and audit logging. No internet service can promise absolute security, so protect your password and report unexpected activity promptly.
Your choices and requests
You can correct profile details, change preferences, disconnect integrations, export supported account data and request account deactivation from the application. You may also ask about access, correction, erasure, consent withdrawal or a grievance through the contact page. We may verify your identity before acting on a request and may retain data where an applicable obligation requires it.
Updates and contact
We may update this policy when the product, providers or legal requirements change. Material changes will be communicated through the service or your registered email when appropriate. For a privacy question or grievance, use our secure contact form and select the privacy-related subject where available.