Smart Hisab logoSmart Hisab

Data Deletion Policy

Last updated: 22 July 2026

This policy describes, at a technical level, what happens to each category of data Smart Hisab holds when it is deleted — whether through routine use (e.g., removing a contact) or a full account-deletion request (see the Delete Account Policy for how to make that request, since no in-app self-service deletion currently exists).

1. Data Deleted Through Normal App Use

ActionWhat actually happens
Delete a customer contactThe saved contact name/number mapping is removed. Transaction history with that phone number is retained — deleting a contact does not delete your ledger records.
Delete a transactionThe transaction is soft-deleted, not immediately purged from the database. It is excluded from balances and lists but the underlying record and its edit history are retained for audit/dispute purposes.
Delete a bill imageThe image is permanently removed from cloud storage (or local disk fallback) once ownership is verified; this cannot be undone.
Log outYour session is ended on that device. Your local encrypted ledger database on the device is wiped as part of the logout flow. This is different from an involuntary session expiry (e.g., token expiring or an admin disabling your account), which clears only your login session and preserves local data so unsynced entries are not lost.
Delete a reminderPermanently removed.

2. Full Account Deletion (Manual Request Process)

As documented in the Delete Account Policy, there is currently no in-app or automated API for a user to delete their own account — this is handled as a manual request to our support contact. Once actioned by us, the following categories are removed:

Data categoryAction taken
Account record (phone number, name, PIN hash, device ID, push token)Deleted
Transaction records tied to your accountDeleted or anonymized
Contacts you savedDeleted
RemindersDeleted
Edit-history / audit-trail entriesDeleted
Bill photos in cloud storageDeleted
Crash/diagnostic logs (Firebase Crashlytics)These are associated only with a one-way hashed identifier, not your phone number directly, and are subject to Google Firebase's own retention policy — they cannot be selectively purged by us on a per-user basis. [NEEDS INPUT: confirm Firebase Crashlytics' own data-retention window if this needs to be stated precisely.]

3. Data We Cannot Delete on Your Behalf

  • Any copy of your data on a device that is offline at the time of deletion and never reconnects.
  • Backups or snapshots of our database taken for disaster-recovery purposes, if any exist. [NEEDS INPUT: confirm whether the production MongoDB deployment takes backups/snapshots and their retention window.]

4. Timeframe

[NEEDS INPUT: define a concrete SLA (e.g., “processed within 30 days”) — this is a business/legal decision.]