We do not sell your data. We do not run ads. We do not build advertising profiles. Raqam works fully offline: your expenses live on your device unless you turn on an account and sync. Receipt images are processed to extract text and are not used to train general-purpose models. You can export everything and delete everything, permanently, from inside the app.
The rest of this page is the detail behind those sentences.
01What we collect
We collect as little as we can get away with while still running the product. Here is the whole list.
| Category | What it is and why |
|---|---|
| Account details | Your name, email address and a hashed password (or an Apple/Google sign-in identifier). Only collected if you choose to create an account. Used to authenticate you and sync across devices. |
| Financial entries | Amounts, categories, dates, notes, merchant names and tags you record. Used to display, chart and report on your own spending. |
| Receipt images | Photos you deliberately capture or upload for scanning. Used to extract merchant, total, date and line items. |
| Preferences | Currency, budgets, categories, theme, notification settings, language. |
| Subscription status | Whether you hold an active Premium plan, its term, and its renewal date. Payments themselves are handled by Apple or Google — we never see your card. |
| Diagnostics | Crash reports, app version, device model and OS version. Aggregated, not tied to your entries. You can switch this off in Settings. |
We do not collect your bank credentials, contacts, precise location, browsing history, advertising identifiers, or the contents of your camera roll beyond the images you explicitly select.
02What stays on your device
Raqam is offline-first by design. When you use it without an account:
- Every expense, budget, category and receipt image is stored in an encrypted database on your phone.
- Nothing is transmitted to us except anonymous crash diagnostics, if you have left those enabled.
- Deleting the app deletes the data. There is no server copy to recover, so please export first.
When you create an account and enable sync, an encrypted copy of your ledger is stored on our servers so it can reach your other devices. You can turn sync off at any time and choose whether to keep or wipe the server copy.
03AI processing
Three features involve machine processing of your input: natural-language expense entry, receipt scanning, and spending insights.
Receipt scanning
When you scan a receipt, the image is sent over an encrypted connection to our processing service, text is extracted, structured fields are returned to your device, and the image is deleted from our servers within 24 hours. The copy you keep lives on your device (or in your synced ledger, if sync is on).
Natural-language entry and insights
The sentence you type, and the aggregate figures needed to answer a question, are processed to produce a result. We send the minimum necessary — typically amounts, categories and dates, not your name or email.
Training
Your expenses, receipts and questions are not used to train general-purpose AI models, ours or anyone else's. We may use fully anonymised, aggregated statistics (for example, "3% of scanned receipts fail on faded thermal paper") to improve accuracy. Where we use third-party model providers, they are contractually bound to process data only on our instruction and not to train on it.
04How we use data
- To run the product — storing, categorising, charting and reporting on the expenses you record.
- To sync — delivering your ledger to your other signed-in devices.
- To generate insights and stories — your weekly recap, forecasts and budget alerts.
- To support you — answering your emails, reproducing bugs you report.
- To keep the service safe — detecting abuse, fraud and automated scraping.
- To meet legal obligations — tax, accounting, and lawful requests we cannot refuse.
We rely on performance of a contract for core functionality, legitimate interests for security and product improvement, consent for optional diagnostics and marketing email, and legal obligation where the law requires it.
06How long we keep it
- Receipt images on our servers — deleted within 24 hours of processing.
- Synced ledger data — kept while your account is open; deleted within 30 days of account deletion.
- Account records — deleted within 30 days of your request, except where tax law requires us to retain a billing record.
- Diagnostics — retained for 90 days, then discarded.
- Support emails — retained for 24 months.
07Your rights
Wherever you live, you can do all of the following — most of it without contacting us at all:
- Access and export — Settings → Export gives you a complete CSV or PDF of everything you have recorded.
- Correct — every field of every expense is editable.
- Delete — Settings → Delete account removes your server data permanently. This cannot be undone.
- Object or restrict — turn off diagnostics, sync, notifications and AI features individually.
- Withdraw consent — unsubscribe links are in every non-essential email.
- Complain — you may lodge a complaint with your local data protection authority. We would rather you told us first.
If you are in the EEA or UK, these are your GDPR rights. If you are in California, you additionally have the right to know, delete, correct and opt out of "sale" or "sharing" — we do neither, so there is nothing to opt out of. We will never discriminate against you for exercising a right.
08Security
- Data is encrypted in transit (TLS 1.3) and at rest (AES-256).
- The on-device database is encrypted and can be locked behind Face ID, Touch ID or your device passcode.
- Access to production systems is limited to a small number of staff, requires hardware keys, and is logged.
- We run third-party penetration tests annually and patch on a fixed schedule.
No system is perfect. If a breach ever affects your data, we will notify you and the relevant authority within 72 hours of becoming aware, and tell you plainly what happened.
09Children
Raqam is not directed at children under 13 (or under 16 in jurisdictions that set that threshold). We do not knowingly collect their data. If you believe a child has created an account, write to us and we will delete it.
10International transfers
Our servers and processors may be located outside your country. Where data leaves the EEA or UK, we rely on Standard Contractual Clauses or an adequacy decision, and we apply the same protections described here regardless of where the data sits.
11Changes to this policy
If we make a material change we will tell you in the app and by email at least 14 days before it takes effect, and the version number at the top of this page will increase. Minor clarifications are published with an updated date. Previous versions are available on request.
12Contact
Privacy questions, requests and complaints go to privacy@raqam.app and are answered by a person, usually within two working days. For formal data protection matters you can reach our Data Protection Officer at the same address, marked for their attention.
Still not sure about something?
Ask us directly. We would rather over-explain than have you guess.