Privacy Policy
Last updated: 24 August 2026 · Qwalet is built by Qariha. Questions: contact@qariha.com
Qwalet is a personal finance app. Almost everything in it is information you type in yourself. This page explains what we hold, why we hold it, where it is processed, and what you can ask us to do with it.
What Qwalet does not do
These are worth stating first, because they are the questions people usually have:
- No location tracking. The app requests no location permission at all. When it suggests a default currency during setup, it derives that from your device's time zone.
- No access to your contacts. The app requests no contacts permission and contains no code to read your address book.
- No advertising, no analytics, no tracking SDKs. Qwalet contains no advertising network, no analytics product, and no attribution or marketing SDK. Nothing about you is sold or shared for advertising.
What we collect
Account and identity
- Your email address, and a password that is stored only as a cryptographic hash — we never store or see the password itself.
- Your display name and username.
- Your preferred language and default currency.
- Two-factor authentication settings, if you enable them, and a linked Google account if you choose to sign in that way.
Crash diagnostics
- When something goes wrong, the app sends a diagnostic report to Google Crashlytics so we can find and fix it. A report contains the name of the operation that failed, a stack trace, and basic device information such as your Android version and model.
- It does not contain your financial records. The report is built from a fixed list of technical fields, never from the data on your screen — no amounts, no notes, no names, no sign-in codes and no tokens. This is enforced in the app's code, not by policy alone.
Device and session
- A cryptographic key pair created on your device, used to prove that requests come from a device you actually signed in on.
- A device identifier, device name and model, so you can see and revoke your own sessions.
- A push notification token, if notifications are enabled.
- Your device's time zone and interface language, sent with requests so amounts and dates are shown correctly. The time zone is used to handle the request and is not stored on your account.
Your financial records
Wallets, transactions, categories, budgets, scheduled transactions, shared bills, debts and groups. These are records you create; Qwalet is not connected to any bank and does not move money.
Receipt images
If you photograph a receipt, the image is uploaded so its details can be read and filled into a draft transaction for you to review. Both the image and the extracted details are stored against your account until you delete them.
This website
Everything above describes the app. The pages on qwalet.com are static: they set no
cookies, load no fonts, scripts or images from anywhere else, and carry no analytics or tracking of
any kind.
The account deletion page is the one exception, because it has to be interactive. When you use the form there, the email address you type is sent to us over an encrypted connection and used only to find the matching account, to email you a confirmation code, and to count recent requests from that address so the form cannot be abused. Requests are also rate-limited by IP address. The only other thing the page adds to the request is the language it is being displayed in, so that the email reaches you in that language.
The form answers the same way whether or not an account exists for the address entered, so it cannot be used to find out who has a Qwalet account.
Where your data is processed
All Qwalet data is processed in the European Union, on Google Cloud infrastructure in Paris, France. This includes the application, the database, caching and encryption keys.
Receipt images are processed by Google Cloud's Vertex AI on its EU endpoint, which reads the text of the receipt so the app can pre-fill a draft for you. Google acts as a processor for us in that role.
Two other services are involved: email (one-time codes and account notices) is delivered
through Google Workspace, sent from contact@qariha.com; and push notifications are
delivered through Firebase Cloud Messaging. You may notice our email arrives from
qariha.com rather than qwalet.com — Qariha is the company behind Qwalet,
and that is expected, not a phishing attempt.
What stays on your device
- Your fingerprint or face is never sent to us and never leaves your device. When you unlock Qwalet biometrically, your device's operating system performs the check and tells the app only whether it succeeded.
- If you set an app PIN, it is verified on your device.
- The app's local cache is stored in an encrypted database, with the key held in your device's secure storage.
Why we hold it
To provide the app: to sign you in and keep your account secure, to store and show the records you create, to read receipts you choose to scan, to send one-time codes and security notices, and to send notifications you have enabled. We do not profile you and we do not make automated decisions about you.
Sharing
We do not sell your data. Data is shared only with the infrastructure providers named above, acting on our instructions, and where we are legally required to disclose it.
One thing to be aware of: Qwalet has shared features. If you split a bill, record a debt or join a group with someone, that person sees your name and the details of the record you share with them, because it is their record too. If you later delete your account, they keep that record, carrying the name you had when you left.
Your rights
You can ask us for a copy of your data, correct anything inaccurate, or delete your account. You can also object to how we use your data or ask us to restrict it.
Two of those you can do yourself, without asking us, and both live in the app under Profile → Privacy. Export my data saves a full copy straight to your device. Delete account is in the same place, and also on the account deletion page of this site. For anything else, email contact@qariha.com from the address on your account.
How long we keep it
We keep your data while your account exists. Deleting your account starts a 30-day grace period: the account is deactivated immediately and permanently deleted at the end of it, unless you sign in during those 30 days, which cancels the deletion. The account deletion page explains the process and lists exactly what is removed.
Five things outlive the deletion. We would rather name them here than let you find out later:
- The accounting entries themselves, pseudonymized. Qwalet's books are double-entry and have to stay balanced, so the entries remain — with everything that pointed to you stripped out of them.
- Your display name, frozen on other people's records. A debt or a shared bill you had with someone is their record too, and it keeps the name you had when you left. Their own record of what they owe, or are owed, would be meaningless with no name on it.
- A record that the erasure happened, under a bare identifier with nothing else attached, so we can prove we did it if we are asked to.
- Your released @handle, held unusable for 30 days, so nobody can claim it straight away and pass themselves off as you.
- Anything other people wrote themselves. A note someone else typed about a bill you shared is their writing, not ours to delete.
Two residual effects are worth stating as well: other people's devices may still show a name you shared with them until they next sync, and a sign-in already in progress can stay valid for up to 15 minutes after you request deletion.
Children
Qwalet is not intended for children, and we do not knowingly collect data from them.
Changes
If this policy changes materially we will update the date at the top of this page and, where the change affects you, tell you in the app.