HISAAB
Privacy Policy
Last updated: July 11, 2026
Developer: Arham, operating via Vawcom · Contact: arham@vawcom.com
1. Summary
- Your spending data stays on your phone.
- HISAAB has no backend server and does not upload your transaction history.
- SMS and notification access are used only to detect payment and transaction alerts.
- When enabled, a lightweight foreground service may run to keep payment capture reliable.
- HISAAB may show local notifications for capture or review prompts.
- “Report an issue” is user-initiated and opens your email app with optional debug details.
- You can delete data anytime by clearing app data or uninstalling HISAAB.
- Data is not sold, not used for ads, and not shared with third parties for marketing.
2. Introduction
HISAAB is a personal finance and expense tracking Android app developed by Arham, operating via Vawcom. It is not a bank, payment processor, lender, or investment service. It helps users track spending by automatically parsing payment alerts.
This policy explains what data HISAAB accesses, how it is used, and what control you have. Questions can be sent to arham@vawcom.com.
3. Data stored locally on your device
HISAAB stores information in a local SQLite database on your device. This may include:
- Parsed transactions (amount, merchant or payee, category, date)
- Optional raw alert text so you can review parsing in the app
- App preferences (for example budget settings and account holder name for self-transfer detection)
- Gmail message IDs already processed, to avoid duplicate imports
4. SMS access (Android)
Permissions: READ_SMS, RECEIVE_SMS
Declared Play use case: SMS-based money management
HISAAB reads SMS only to import payment transaction alerts from banks and mobile wallets (for example Easypaisa, JazzCash, Raast, UBL, and similar short-code senders).
What is read
- SMS from known wallet or bank short codes
- Messages that look like transaction alerts
What is not read or used
- Personal chat messages
- OTP or verification codes (ignored by parsing logic)
- Marketing texts
HISAAB is not your default SMS app and does not send SMS. SMS content is never uploaded to any server and is never used for advertising, analytics resale, or unrelated features. You can revoke SMS access anytime in Android Settings.
Android permissions may technically allow access to all SMS messages, but HISAAB filters for transaction alerts and ignores OTP and non-payment content in normal processing.
5. Notification access (Android)
HISAAB can use Android Notification Access (user-enabled in system Settings) to read payment notifications from banking and wallet apps (for example JazzCash, NayaPay, UBL, and Google Wallet) for automatic expense logging.
When notification access is enabled, HISAAB may run a lightweight foreground service while the app is in the background so payment alerts are not missed. This service is used only for transaction detection and does not upload your data.
- Only used for payment-related notifications
- Processed on-device
- Not uploaded to Vawcom or any HISAAB server
- HISAAB may request
POST_NOTIFICATIONSfor local app alerts - Local notifications are generated on-device and are not sent to us
- You enable and can revoke this in Android Settings → Notification access
- If permissions remain enabled, capture may resume after device restart
6. Optional Gmail connection
You may optionally connect your Google account to import payment emails.
- Uses Google Sign-In and the Gmail API
- Uses read-only Gmail access for payment-related import
- Reads payment-related emails from your mailbox
- Does not upload email content to HISAAB or Vawcom servers
- OAuth tokens are stored securely on your device
- Google's privacy policy also applies when you connect Gmail
- You can disconnect Gmail from within the app
- Only activated when you explicitly opt in
7. What is never uploaded
- SMS or notification content
- Full transaction history to a developer-operated cloud
- Contacts or personal chats
8. Network use and third parties
HISAAB has no developer backend. Limited network use includes:
- Gmail API — optional and user-initiated; reads payment emails
- Google Fonts — may download font files; no personal data sent
Not used
- Firebase, Sentry, or other analytics or crash SDKs that phone home spending data
- Advertising SDKs
- Cloud sync of spending history
9. Backup, export, and deletion
- Android auto-backup is disabled for app data — spending data is not backed up to Google Drive by default through the app
- You may export a backup file when you explicitly choose to share or export from Settings
- You may import a previously exported backup file; imported data stays on your device
- If you export or share a backup file, you control where it goes (for example email or cloud drive)
- Vawcom does not receive exported backup files unless you send them to us directly
- You can delete data by clearing app data, uninstalling, or revoking permissions
- Release builds avoid logging sensitive SMS or notification bodies
10. Security
- Processing is primarily on-device
- Gmail API traffic uses HTTPS
- Cleartext HTTP is blocked in release builds
11. Children's privacy
HISAAB is not directed at children under 13 (or under 16 where applicable). We do not knowingly collect children's data.
12. Changes to this policy
We may update this page. The “Last updated” date will change when we do. Continued use of HISAAB after changes constitutes acceptance of the updated policy.
13. Contact
Questions about privacy: arham@vawcom.com
If you choose “Report an issue” in the app, your email app may include app version, device type, and optional locally stored crash details in the draft sent to this address. Spending history and SMS content are not included unless you add them yourself.
14. Data retention and deletion
Transaction data is kept on your device until you delete it, clear app data, uninstall HISAAB, or restore from a backup. We do not retain copies on developer servers because HISAAB has no backend server for transaction storage.