Privacy Policy
Our Privacy Pledge
Chit was built from day one on a zero-cloud, privacy-by-design architecture. We do not collect, transmit, store, sell, or share your personal financial data, receipt images, or expense records. All information stays strictly inside your device's local memory.
1. Information We Do NOT Collect
We do not collect any personal data. When you use Chit:
- No Account Required: You do not need to register with an email address, phone number, password, or username.
- No Cloud Sync: We do not operate cloud databases that store your receipts or financial information.
- No Analytics or Tracking: We do not embed behavioral analytics, tracking beacons, advertising identifiers, or user profiling SDKs.
- No Financial Data Transmission: Your receipt images, merchant names, expenditure amounts, dates, and category tags are never sent over the internet.
2. Device Permissions & How They Are Used
To deliver core functionality, Chit requests the following device permissions:
- Camera (
android.permission.CAMERA): This permission is required exclusively to enable you to photograph paper receipts and invoices using your device camera. Photos captured by the camera are processed on-device using local optical character recognition (OCR) and saved only in your private application storage sandbox. Camera captures are never uploaded to any remote server. - Biometrics (
android.permission.USE_BIOMETRIC): Used only if you turn on the optional app lock in Settings. Unlocking is handled by Android's own fingerprint / face unlock / screen-lock prompt; Chit never receives or stores any biometric data. - Photo import (no permission required): "Import photo" uses Android's system photo picker, which gives Chit access only to the single image you choose. Chit does not request storage or media-library permissions, and photos taken inside Chit are not added to your gallery.
- Internet (
android.permission.INTERNET): Declared by the underlying app framework and on-device libraries. Chit never sends your receipts, images, amounts, or other financial data over the internet (see Section 5 for the limited diagnostics sent by Google ML Kit). - Vibration (
android.permission.VIBRATE) and screen-capture detection (android.permission.DETECT_SCREEN_CAPTURE): Declared by bundled libraries. Chit does not use vibration; screenshots and screen recordings of the app are blocked to protect your financial data.
3. Local Storage & Data Security
All receipt records, line items, settings, and custom categories are saved locally on your device using an embedded SQLite database (expo-sqlite). Data is protected by the native security mechanisms and application sandboxing of the Android operating system.
4. User Data Control & Deletion
Because all data resides exclusively on your device, you maintain 100% control over your data at all times:
- Delete Individual Receipts: Tap any receipt in the app and select "Delete" to permanently remove it and its associated image from your device.
- Delete All Receipts: Settings > Data > "Delete all receipts" permanently removes every receipt, its photo, and your custom categories. To also reset your preferences, use Android system settings (Settings > Apps > Chit > Storage > Clear storage).
- Backups Stay With You: Chit is excluded from Android's automatic Google Drive backup. If you want a copy, Settings > Data > "Backup (JSON)" creates a file that you choose where to save or send; "Restore Backup" imports it again.
- Uninstalling the App: Uninstalling Chit immediately and irreversibly deletes all receipts and database files stored within the application sandbox.
5. Third-Party Libraries & Services
Chit utilizes Google ML Kit for on-device text recognition. The OCR model is bundled with the app and runs entirely on your device hardware, so scanning works offline. Your receipt images and the recognized text are never transmitted to Google or any third party.
As described in Google's ML Kit data disclosure, the ML Kit library itself may send Google limited diagnostic information when a network connection is available — such as device model and OS version, app package name and version, a per-installation identifier, and performance metrics like recognition latency. This information does not include your receipts, images, or recognized text, and is used by Google to maintain and improve ML Kit.
6. Children's Privacy (COPPA Compliance)
Chit is not directed toward children under the age of 13. Because the application collects no personal information whatsoever, it inherently complies with the Children's Online Privacy Protection Act (COPPA) and international child privacy regulations.
7. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any revisions will be reflected on this page with an updated "Last Updated" date.
8. Contact Us
If you have any questions, suggestions, or concerns regarding this Privacy Policy or your privacy rights, please contact us at:
Email: support@rapidops.io
Project Website: https://apps.rapidops.io/chit/