Privacy policy
In plain words: what we collect, where it goes, and why.
Last updated:
Who we are
haeifin is a debt and account book app. This policy explains what data the app and the haeifin.com website handle, why, and where it goes. The data controller is the haeifin team, based in Syria. Contact: info@haeifin.com.
In short
- Your book (accounts, entries and photos) is stored on your phone only, and we can’t see it.
- An account is optional. If you create one, we keep what is needed to sign you in and manage your plan.
- The Mudir sends your question to an AI provider to answer it, and saved chats are encrypted.
- No ads, we don’t sell data, and there are no analytics or tracking tools inside the app.
Your book is on your phone
Accounts, entries, debts, currencies, exchange rates, notes and entry photos are stored in a database on your device. The app works fully offline and without an account, and this data does not reach our server.
A backup is a file created on your phone, and you decide where to keep it. If you set a password, it is encrypted (AES-256-GCM); we cannot open it or recover the password.
If you create an account
An account is needed for a plan and for online features. Depending on how you sign in, we keep:
- Google: your Google account ID, your email and whether it is verified, your name and photo.
- Mobile number: your number. The verification code reaches you by SMS or WhatsApp through a messaging provider, and we keep the code only as a short-lived hash.
- Email: your email, and your password as a hash we cannot read.
- Devices and sessions: device type, model and app version, and the IP address and browser or app details of each sign-in session, so you can see your devices and sign out of them.
- Your photo: if you upload one, we resize it and keep it on our server.
The Mudir (AI)
When you ask the Mudir something, your question (text or voice) goes from our server to an AI provider to be answered: Google Gemini or OpenAI. With the question we send the last few messages of the chat, your account names and types, the book’s currencies, and today’s date and language, so it understands whom you mean. We do not send balances, except in a live call when you ask about a specific figure; then only the figure you asked about is sent.
We record the number and cost of requests to count credits, not your words or voice. If your plan keeps chats, they are stored encrypted (AES-256-GCM) with a key of your own. A chat you delete goes to the bin, and the bin empties itself after 30 days. You can export your chats.
We use the providers’ paid programming interfaces (APIs), not their consumer apps. With OpenAI we explicitly ask for requests not to be stored, and under both providers’ API terms, request data is not used to train their models.
Notifications
To send you a reminder or news, the app registers a Firebase Cloud Messaging token, together with the app language, your country, the app version, your time zone, and your account if you are signed in. You can turn notifications off in your phone’s settings.
Plans and payment
You subscribe on WhatsApp: you pick the plan, we send the payment options, and we activate the plan on your account. We keep the plan, price, date and a note. We do not keep any card or bank account details. The app checks the licence on your phone, even offline.
Phone permissions
- Contacts: to import names and numbers; read on your phone only, and never written to.
- Calendar: optional, to put due dates in your calendar. On your phone only.
- Camera and photos: for entry and account photos and for scanning QR codes. Photos stay on your phone (except your profile photo if you upload it).
- Microphone: to talk to the Mudir. The audio is sent to be understood and is not stored.
- Fingerprint or face: to lock the app; checked by your phone itself.
What we never do
- We don’t sell or rent your data.
- There are no ads in the app.
- There are no third-party analytics, tracking or crash-reporting tools inside the app.
- We never lock your book when your plan ends: reading, export and backup always stay open.
Where it is kept, and for how long
Account data is kept on our own server at netcup in Germany, and the database is backed up every night and kept for 14 days.
- Account data: until you delete your account.
- Verification codes: minutes.
- Saved chats: until you delete them (the bin, 30 days).
- Server backups: 14 days.
Your rights
You can see and correct your data in the app, export your book and your chats, unlink sign-in methods, sign out of any device, and delete your photo or any chat. To delete your whole account: Delete account. The app is not directed at children under 13.
This website
haeifin.com uses no tracking cookies and no ads, and its fonts and files are served from our own server, so your browser makes no requests to third parties. We count visits with Umami, installed on our own server: no cookies, no personal data, and your IP address is not kept.
Changes and contact
If this policy changes, we update it here with the date, and if the change is significant we let you know in the app. Questions? info@haeifin.com or WhatsApp.