01
Scope
This policy describes the Niqdah Android application, its Firebase backend, optional automated email import, AI Chat, and this public website. Niqdah is an independent personal-finance project and is not a bank.
Effective and last reviewed: July 21, 2026.
02
Data we process
Niqdah processes information you enter or approve, including account labels and masked identity, balances and confidence, income and planning inputs, transactions, categories, savings goals and contributions, debt and repayments, reminders, notifications, profile settings, and pending import evidence.
Authentication identifiers and operational metadata support access control, synchronization, retries, deduplication, abuse protection, diagnostics, and deletion workflows.
03
Bank-message and email imports
Manual paste is parsed for an editable draft. The private build can optionally receive new SMS messages from allowed senders; it does not request historical READ_SMS access. The public build contains no SMS receiver.
When automated email import is enabled, you configure your own forwarding rule to an opaque, revocable address. Resend receives that forwarded message and calls a signed Firebase webhook. Niqdah sanitizes and parses the content, ignores attachments by default, does not fetch external HTML resources, and does not store raw email HTML in Firestore. Structured evidence and processing metadata may be retained for pending review, history, security, and deduplication.
04
AI Chat
AI Chat sends an authenticated request through Firebase Functions to OpenAI. The request can contain the question and selected finance summaries required to answer it. The provider key stays in Firebase Secret Manager.
Raw bank-message text is not sent to OpenAI by default. AI responses may be wrong and cannot autonomously save finance data. Review any suggested action.
06
Retention and control
App data remains until you delete records, reset app data, request account deletion, or retention is required temporarily for security, backup, legal, or operational integrity. Provider-side backups and logs may take time to expire.
You can revoke an email import address, disable a forwarding rule, revoke private-build SMS permission, dismiss or save pending imports, and request account/data deletion.
07
Security
Niqdah uses Firebase authentication and rules, backend-only route mappings, signed webhook verification, secret stores, rate limits, input limits, deduplication, and redacted logging. No system can guarantee absolute security.
Do not send secrets or real bank messages through public support channels.
08
Questions
For privacy questions, start with the support guidance. Public bug reports can use GitHub Issues only when the content is fully sanitized.