Privacy Policy
Last updated 12 September 2026
The short version. Without an account, everything stays on your phone and we receive nothing at all. If you sign in, so that your ledger survives a lost phone and can be shared with family, your transactions and the categories you invented are synced to our servers alongside your name and an email address or phone number, and shown to the other members of any book you share. Your app-lock PIN never leaves the device, receipt photos are read and discarded, and voice entries are transcribed on the phone — no audio is uploaded.
- 1. Who we are
- 2. Data on your device
- 3. Data we receive
- 4. Why we use it
- 5. Who else sees it
- 6. How long we keep it
- 7. Your rights
- 8. Deleting your account
- 9. Security
- 10. Children
- 11. Changes
- 12. Contact
1. Who we are
Tijaorii ("Tijaorii", "we", "us") is a personal expense and income tracking app for iOS and Android, operated by Geeks of Kolachi. This policy explains what we do with personal data when you use the app or this website (tijaorii.com).
2. Data on your device
Tijaorii is built local-first. The following is written to a private database inside the app's own storage on your phone, which is why the app works without a connection. Without an account it is never transmitted to us. With an account, transactions and categories are also synced to our servers (section 3) so that they survive a lost phone and can be shared:
- Every transaction: amount, whether it was income or expense, date, and note
- Your categories, including any you create, with their icons and colours
- Your app appearance preference (light or dark)
Your app-lock PIN, if you set one, is stored in the operating system's secure credential store — the iOS Keychain or the Android Keystore — not in the app's database and not on our servers. We cannot read it and we cannot recover it for you.
Voice entries use the speech recognition built into your phone, set to work on-device. What you say is turned into text on the phone; the audio is not recorded, stored, or sent to us. The text becomes an ordinary transaction, which is then handled like any other. If your phone cannot recognise Urdu on-device, the app tells you and uses English instead of sending your voice anywhere.
Without an account, uninstalling the app deletes this data and we have no copy to restore. With an account, signing in again on a new phone restores your books from our servers.
3. Data we receive
Creating an account sends the following to our servers:
| Data | When | Why |
|---|---|---|
| Your name | Sign-up, profile edit | To address you in the app |
| Email address and/or phone number | Sign-up, sign-in, profile edit | Identifies your account and receives password-reset codes |
| Password | Sign-up, sign-in, reset | Stored only as a salted hash. We cannot read your password or recover it — only reset it. |
| Transactions and categories | Whenever the app syncs while signed in | So your books survive a lost phone and can be shared. Each entry is visible to the members of the book it belongs to, and to no other user. |
| Book memberships and invite codes | Creating, sharing or joining a book | Decides who may see which book |
| One-time reset codes | Password reset | Verifies it is you. Expires shortly after being issued. |
| Technical request logs | Every API call | IP address, timestamp and endpoint, kept briefly to diagnose faults and block abuse |
We do not use advertising identifiers, analytics SDKs, or third-party trackers in the app, and this website sets no cookies.
4. Why we use it
We process the data in section 3 in order to:
- create and authenticate your account (performance of our agreement with you);
- send password-reset codes you have requested (performance of our agreement);
- keep the service secure and available, including rate-limiting abuse (our legitimate interest in a working, non-abused service);
- meet legal obligations where they apply.
We do not sell personal data, and we do not use it for advertising or profiling.
5. Who else sees it
We share the minimum necessary with service providers who act on our instructions, and only for the purposes above:
- Our email delivery provider — sends password-reset emails. Receives your email address and the reset code.
- Our SMS delivery providers — send password-reset codes by text. Receive your phone number and the code.
- Our hosting and database providers — store the account records described in section 3.
Each is bound by contract to process your data only on our instructions, and none of them may use it for their own purposes. We will tell you which companies these are, and where they are based, on request — write to hello@tijaorii.com.
None of these providers receive your transactions, because we do not have them. We may disclose account data if legally required to do so.
6. How long we keep it
- Account records: until you delete your account (see section 8).
- Password-reset codes: minutes — they expire and are invalidated once used.
- Technical request logs: a short rolling window for security and debugging.
- On-device data: until you delete it in the app, delete your account, or uninstall Tijaorii.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or erase the personal data we hold, to object to certain processing, and to complain to your data protection authority.
In practice, most of this is in your hands: your name, email and phone are editable in Profile, any book exports to CSV, and account deletion is a button in the app. For anything else, write to us and we will respond within 30 days.
8. Deleting your account
In the app, open Profile → Delete account and confirm. This:
- marks your account deleted on our servers, which immediately invalidates your sign-in;
- erases the local database — every transaction, category and setting — from the device;
- removes your app-lock PIN from the device's secure store.
Deleted account records are retained in backups for a limited period before being purged. You can also email us to request deletion.
9. Security
Traffic between the app and our servers is encrypted in transit. Passwords are stored only as salted hashes. Reset codes are single-use and short-lived, and repeated attempts are rate limited. Your PIN is held in the platform keystore.
No system is perfectly secure. Your device is part of the picture: because a copy of your ledger is stored locally, anyone with access to an unlocked phone can read it. We recommend turning on the app lock and using your device's own screen lock.
10. Children
Tijaorii is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
11. Changes
If we change this policy we will update the date at the top of this page, and give notice in the app for anything significant.
12. Contact
Questions, requests, or complaints: hello@tijaorii.com.