Privacy Policy

This policy explains how Trakven ("Trakven", "we", "us" or "our") handles information when you use the Trakven website, mobile application and related services (the "Services"). If you do not agree with this policy, please do not use the Services.

Who is responsible for your data

Trakven is built and operated by Madhavan Ramesh, an independent software developer based in India. He is the data controller (and, under India's Digital Personal Data Protection Act, the data fiduciary) for the information described in this policy.

Contact and grievance redressal. All privacy questions, data-subject requests and complaints go to Madhavan Ramesh at hello@trakven.app. This mailbox is monitored personally and we aim to respond within 30 days. Trakven is a solo project and is not a Significant Data Fiduciary, so it has no separate Data Protection Officer; Madhavan handles these requests himself. If you are in the EU/UK and are not satisfied with our response, you may complain to your local data-protection authority.

Information we collect

Some app features may request access to notifications, the microphone (for voice input), photos, media, files or the device calendar. We use these permissions only to provide the feature you choose, and you can change them in your device settings.

Finance recovery from an already-unlocked device may ask Android or iOS to verify you with your device screen lock, fingerprint or face unlock. Biometric matching is handled by your device operating system. Trakven receives only whether verification succeeded or failed; we do not receive, store or transmit biometric templates, fingerprints, face scans or your device unlock code.

How we use information

We use information to provide and synchronize the Services; authenticate accounts; schedule notifications and emails; generate user-requested AI assistance; maintain security; diagnose failures; respond to support; comply with law; and improve reliability and usability. We do not sell your personal information or use the contents of your tasks, habits or finance records for third-party advertising.

Finance encryption and recovery

Finance encryption is optional. When enabled, Trakven encrypts your finance vault on your device before cloud synchronization. The finance vault includes salary, spending, savings, tags, asset types, templates and finance attachment metadata. The server stores only the encrypted payload, encryption metadata and wrapped vault keys needed for passphrase and recovery-key unlock. Your finance passphrase and recovery key are never sent to Trakven.

After you unlock Finance on a device, that device may store the unlocked finance vault key in secure local storage so you do not need to enter the passphrase every time. New devices or reinstalls require the passphrase or recovery key. If you lose the passphrase, recovery key and all already-unlocked devices, Trakven cannot decrypt or recover the encrypted finance vault. If you turn finance encryption off, the finance vault is decrypted on your device and future finance saves are stored as plaintext vault data in Trakven sync.

AI features

When you use the AI assistant, the prompt and relevant context you choose to submit are sent to OpenAI to generate a response. If you use voice input, your recording is sent to OpenAI for transcription and is not stored by us. Do not submit information you do not want processed for that purpose. AI output can be inaccurate and should be reviewed before you rely on it. Your finance vault is never included in AI context.

What we keep, and for how long. Your AI messages and the assistant's replies are stored so you can read back your conversations. They are encrypted at rest on our servers and are automatically deleted after 90 days. We keep a count of how many prompts you have used (without the text) so that daily limits keep working. You can erase your AI history at any time from AI settings > Clear AI history.

Note that "encrypted at rest" protects your stored conversations against unauthorised access to our database. It is not end-to-end encryption: the assistant has to read your prompt in order to answer it, and it is processed by OpenAI. This is different from the finance vault, which is end-to-end encrypted and which we genuinely cannot read.

Limits. To keep storage bounded, each conversation holds a limited number of messages and only a limited number of recent conversations are kept. When you exceed them the app tells you and asks before removing your oldest conversation. There is also a daily cap on how many prompts you can send.

Children

Trakven is not directed to children under 13, or under the minimum age required in your country, and we do not knowingly collect their personal information. We do not currently ask for your date of birth. If you believe a child has given us personal information, contact us and we will delete the account.

Service providers

We use service providers to operate Trakven, including Google for sign-in and Firebase push messaging, Supabase for hosted database services, OpenAI for optional AI features (both the chat assistant and speech-to-text transcription of voice input), Resend for requested email delivery, and cloud hosting and logging providers. These providers process information for us under their own terms and privacy commitments. The public website also loads fonts from Google and icons from unpkg, which may receive network information such as your IP address and browser details.

Internal access

A small number of authorised Trakven administrators can use an internal dashboard to support the Services. It can look up an account by email address and see that account's registered devices, error reports and activity records, so that we can investigate faults and abuse. Administrator access requires a separate login with two-factor authentication and is recorded in an audit log. Administrators cannot read your encrypted finance vault.

Website cookies and similar technologies

The Trakven marketing website uses Cloudflare Web Analytics, a privacy-first service that measures basic visits and website performance without using cookies or local storage. It also loads fonts from Google and icons from unpkg; these providers may receive ordinary network information such as your IP address, browser details and the requested resource. The website does not use advertising trackers or non-essential cookies, so it does not currently display a cookie-consent banner.

Legal bases and choices

Where applicable, we process information to perform our contract with you, based on our legitimate interests in operating and securing the Services, with your consent where requested, and to meet legal obligations. You may withdraw permission for optional device access or stop using optional AI and email features at any time.

Retention and account deletion

We retain account information and the content you create for as long as your account is active, because that content is the product. Some categories expire sooner: AI conversations are deleted after 90 days (and only your most recent chats are kept at all), voice recordings are never stored, and diagnostic and activity records are kept only as long as needed to investigate faults and abuse. You can delete everything at any time.

We retain account information and user content while your account is active and as needed to provide the Services. A signed-in user can delete their account directly in the Trakven app under Settings > Account & Devices > Delete account. The app requires a renewed sign-in check, an irreversible-deletion warning and typed confirmation.

When confirmed, Trakven immediately deletes the account and associated data from active systems, including reminders, tasks, logs, habits, finance vault data, AI usage history, preferences, registered devices, diagnostic and activity records linked to the account, and uploaded files. The deletion cannot be undone and Trakven cannot recover the deleted account or content. Deleting Trakven does not delete the user's Google account.

Residual encrypted backup copies may persist only until overwritten under the hosting provider's normal backup cycle and are not restored to recreate a deleted account. We retain a one-way, peppered identity hash after deletion to prevent background sessions from silently recreating the deleted account, together with aggregate counts of removed device platforms and app versions. This record does not retain the email address, Google identifier, push token, installation identifier or device name. Diagnostic, AI-usage and email-delivery records are retained only as needed to operate, secure and troubleshoot the Services, and are removed with the associated active account unless law requires longer retention. We may retain other information only where and for as long as applicable law strictly requires it. If you cannot access the app, use our account deletion page to submit a verified deletion request.

Security

We use reasonable administrative, technical and organizational safeguards, including encrypted network transport, provider-managed encryption at rest, access controls and audited administrative access. Optional finance encryption encrypts the finance vault on the device before cloud synchronization. Other reminders, tasks, habits, logs and non-finance attachment metadata are not end-to-end encrypted and are processed by our backend to provide synchronization, search, notifications and optional AI features. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

International processing

Our providers may process information in countries other than yours. Where required, we use appropriate safeguards for international transfers.

Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, or complain to a data-protection authority.

Two of these are self-serve inside the app, with no need to contact anyone: Settings > Legal & Privacy > Download my data gives you a portable JSON copy of everything we hold, and Settings > Account & Devices > Delete account erases it. For anything else, email us and we will action it.

Children

The Services are not directed to children under 13, or a higher minimum age where local law requires it. We do not knowingly collect personal information from children below the applicable age.

Changes and contact

We may update this policy and will post the new effective date here. Questions, privacy requests and grievances can be sent to Madhavan Ramesh at hello@trakven.app.