01

Scope

This policy describes the Niqdah Android application, its Firebase backend, optional automated email import, AI Chat, and this public website. Niqdah is an independent personal-finance project and is not a bank.

Effective and last reviewed: July 21, 2026.

02

Data we process

Niqdah processes information you enter or approve, including account labels and masked identity, balances and confidence, income and planning inputs, transactions, categories, savings goals and contributions, debt and repayments, reminders, notifications, profile settings, and pending import evidence.

Authentication identifiers and operational metadata support access control, synchronization, retries, deduplication, abuse protection, diagnostics, and deletion workflows.

03

Bank-message and email imports

Manual paste is parsed for an editable draft. The private build can optionally receive new SMS messages from allowed senders; it does not request historical READ_SMS access. The public build contains no SMS receiver.

When automated email import is enabled, you configure your own forwarding rule to an opaque, revocable address. Resend receives that forwarded message and calls a signed Firebase webhook. Niqdah sanitizes and parses the content, ignores attachments by default, does not fetch external HTML resources, and does not store raw email HTML in Firestore. Structured evidence and processing metadata may be retained for pending review, history, security, and deduplication.

04

AI Chat

AI Chat sends an authenticated request through Firebase Functions to OpenAI. The request can contain the question and selected finance summaries required to answer it. The provider key stays in Firebase Secret Manager.

Raw bank-message text is not sent to OpenAI by default. AI responses may be wrong and cannot autonomously save finance data. Review any suggested action.

05

Service providers

Firebase provides authentication, Firestore storage, Cloud Functions, secrets, and related backend infrastructure. Resend is the selected provider for forwarded email receiving. OpenAI processes explicit AI Chat requests. Each provider may process operational data under its own terms and retention controls.

Niqdah does not use Gmail or Outlook inbox APIs and does not sell personal financial data.

06

Retention and control

App data remains until you delete records, reset app data, request account deletion, or retention is required temporarily for security, backup, legal, or operational integrity. Provider-side backups and logs may take time to expire.

You can revoke an email import address, disable a forwarding rule, revoke private-build SMS permission, dismiss or save pending imports, and request account/data deletion.

07

Security

Niqdah uses Firebase authentication and rules, backend-only route mappings, signed webhook verification, secret stores, rate limits, input limits, deduplication, and redacted logging. No system can guarantee absolute security.

Do not send secrets or real bank messages through public support channels.

08

Questions

For privacy questions, start with the support guidance. Public bug reports can use GitHub Issues only when the content is fully sanitized.