1. Who runs Kharcha
Kharcha is built and operated by a small team in Karachi, Pakistan. The service runs at expense.iukhan.tech and through the Kharcha Android app. We are the data controller for everything described below.
2. What we collect
You give us
- Account basics: your name, email, household name, hashed password.
- Expenses: every entry you record, with its amount, date, list, and optional notes.
- Receipt photos: only when you choose to scan one. See section 4.
- Fuel logs: odometer, litres, rate, full-tank flag.
We collect automatically
- Sign-in tokens: a Sanctum API token per device for the app to stay signed in.
- Server logs: IP address, timestamp, and the URL you requested. Used for debugging and abuse-prevention, rotated every 14 days.
- Plan and scan usage: which plan your household is on, and how many AI scans you have used this month.
That is the full list. We do not run third-party analytics or advertising trackers.
3. Why we collect it
So Kharcha can do what you signed up for: keep your household ledger, parse the receipts you scan, calculate your fuel economy, and let you sign in across devices. Server logs exist so a real human can diagnose problems when something breaks.
We do not use your expense data to profile you, score you for credit, or train any model.
4. Receipts and the AI
When you scan a receipt, the photo is sent to Google Gemini through Google's API to extract the text, line items and total. Google's API terms for paid usage state that requests are not used to train Google's foundation models. We forward the photo, receive the parsed result, and immediately discard the photo from memory.
What stays in your account afterwards: the parsed text, the per-line items, the total, and a thumbnail you can review later. The original photo is not stored on Kharcha's server.
If you do not want any data leaving Kharcha's server, do not use the scan feature; everything works without it through manual entry.
6. Where it lives
Kharcha runs on a single VPS in Frankfurt, Germany, operated by Hostinger. The database is SQLite, stored on the same machine, backed up daily to encrypted off-site storage. Cross-border transfer happens because the server is outside Pakistan; by signing up you consent to this transfer for the purpose of running the service.
7. How long we keep it
- While your account is active: as long as you keep using Kharcha.
- After you delete your account: account, entries, receipts and fuel logs are removed within 30 days. Backups age out within another 60 days, after which nothing is recoverable.
- Server logs: 14 days, then deleted.
- Receipt photos: not stored at all. See section 4.
8. Your rights
You can, at any time:
- Export every entry, fuel log, and household setting as CSV from settings.
- Correct anything in your ledger by editing it.
- Delete your account, which deletes everything tied to it within 30 days.
- Ask what we have on you and we will tell you, in plain language, within seven days.
9. Children
Kharcha is not designed for children under 13. We do not knowingly collect their data; if you believe a child has created an account, email us and we will delete it.
10. Changes
We will post any material change here with a new effective date, and email anyone with a Pro plan at least 14 days in advance. The history of changes is kept publicly so you can see what changed and when.
11. Contact
Email privacy@iukhan.tech for any privacy question, a data request, or to flag a concern. A real human reads every email and replies within seven days.