Privacy

Last updated 25 September 2026

This describes what the app actually stores, where it lives and who can reach it. It was written from the database schema and the app's permissions rather than from a template, so where it says "we do not collect" something, the code has no way to.

The short version

Who this is

Nirman Hisab is built and operated by Sourabh Dhaker, Indore, Madhya Pradesh, India. For anything on this page, including a request to delete data, write to sdhaker2@gmail.com. It reaches one person, and it is usually answered the same day.

Who controls what

Accounts belong to a business, not to individuals. The business — your employer, if you are a site manager — decides who is given a login, what is recorded and what happens to it. We hold and protect that data on their behalf and do not use it for anything of our own. If you are a manager and want your records changed or removed, ask your admin first; if that is not possible, write to us and we will help.

What we store, and why

WhatWhy it exists
Your name and phone number The phone number is the login. The name is what other people in your business see next to an entry you recorded.
Your password, stored only as a bcrypt hash To sign you in. It is not stored in a readable form and cannot be read back — not by us either. A forgotten password is replaced, never recovered.
Your business's details — its name, the owner's name, a contact number and city Given when the business is set up, so we know whose account it is and can reach somebody about it.
The records your business creates — sites, expenses, cash received, labour counts and worker names, materials, contractors and suppliers, and the amounts against them This is the app. It is your book, kept for you.
Photographs you attach — bills, delivery challans, site photos Attached to the entry they belong to. They are served only through a signed link that expires, never from a public address.
A contact you pick from your phone — the one name and number you tapped Only when an admin adds a manager and chooses to pick from contacts, instead of typing. The phone's own contact list opens outside the app, so the app has no contacts permission and never sees your address book — only the contact you chose. It fills in the form; it is stored only if you save, as that manager's name and login number.
A notification token for each phone, with the platform (Android or iOS) and the app version Only if you accept notifications. It is how a message reaches your phone and nobody else's. It is deleted when you sign out.
Sign-in sessions, including the IP address a browser sign-in was started from Signing in to a computer by scanning a code from your phone. The record exists so a code cannot be reused or stolen, and it expires within minutes.
Crash reports — the error, where in the app it happened, your phone's model and the app version So a fault can be fixed without asking you to reproduce it. No contents of your entries are included.
Problem reports you send us, with any photos you attach, plus the screen you were on and the app version Only when you choose to report a problem. Filled in automatically so you do not have to describe your phone.
Server access logs — the IP address, the time and the page requested Standard web-server records, kept briefly, used to keep the service running and to spot abuse. They are rotated and overwritten automatically.

What we deliberately do not collect

This is not a promise about intent — it is a statement about what the software is able to do:

The demo sends nothing

"Try it with sample data" runs entirely in your browser or on your phone, on figures we generated. Nothing you type into it is transmitted, and it is stored only on that device. You can wipe it with "Reset data" in the yellow bar at any time.

Where it lives, and who can reach it

The database and photographs are on a single server rented from Hetzner in Germany. Traffic to it is encrypted (HTTPS). A backup is taken every night. The server keeps its own copies for 14 days. A second copy is encrypted on the server before it leaves, and kept for 90 days with Cloudflare R2 and on the operator's own computer; the key that opens it is not on the server, and Cloudflare does not have it.

Between businesses: every record carries the business it belongs to, and the query layer refuses to return another business's rows. One client cannot see another's sites, money or people.

Inside a business: a manager sees the sites they are assigned to. An admin sees everything in their own business.

Us: as the operator, one person has technical access to the server and therefore, in principle, to what is on it — this is true of every hosted service and it would be dishonest to claim otherwise. What we have deliberately not built is a screen that shows it: the operator console reports how many sites and people a client has and never the amounts, because knowing a client runs four sites is running the platform and reading what they spent is reading their books.

The companies we pass anything to

Google (Firebase Cloud Messaging), and only if you turn notifications on. To deliver a notification to your phone, its token and the text of that notification pass through Google's service — for example "₹4,500 to approve" — and, on an iPhone, on to Apple's push service, which is the only way a notification reaches one. Nothing else is shared with them: no account, no records, no photographs. Turn notifications off in your phone's settings and nothing goes at all.

Cloudflare (R2 storage) holds the encrypted nightly backup described above. It is stored there, not read there: Cloudflare has no key to open it.

There is no other processor. No email service, no analytics company, no advertising network, no payment gateway.

How long we keep it

Your records are kept for as long as your business has an account, because a site book with the last two years missing is not a book. A deleted expense is kept briefly so it can be undone, then removed. Notification tokens are deleted when you sign out. Sign-in codes expire in minutes. Access logs rotate and are overwritten.

When a business leaves, tell us and we will delete its data — every record and every photograph — and confirm when it is done.

Deleting your account

In the app, open Account → Delete my account and enter your password — it takes effect at once. Or go to the Delete your account page. It says exactly what is removed, what stays in your business's books and why, and how long it takes.

Your rights

You can ask us to show you what we hold about you, correct it, export it, or delete it. Write to sdhaker2@gmail.com from the address or about the phone number concerned. We will not charge for it and we will not ask why.

Two honest notes. Your business's admin can already export the whole book as a spreadsheet from inside the app, which is usually faster than asking us. And where a record is part of your employer's accounts — an expense you recorded, for instance — we will act on their instruction rather than delete one entry out of somebody's books on request.

Security, plainly

Passwords are hashed and never stored readably. Traffic is encrypted. Photographs are only reachable through short-lived signed links. Repeated failed sign-ins are locked out. No system is perfect; if something goes wrong that affects your data we will tell you what happened rather than hope you do not notice.

Children

This is a tool for running a construction business. It is not intended for anyone under 18 and we do not knowingly create accounts for them.

Changes

If this changes, the date at the top changes with it. If a change materially affects what we do with your data, we will tell account holders directly rather than quietly editing this page.

Questions, or a request about your data: sdhaker2@gmail.com