Privacy Policy

Last Updated: September 1, 2026 • Effective Date: September 1, 2026

Summary for Users: Padchi Pe is built on zero-knowledge and end-to-end encryption. Your bills, Padchis, and digital signatures are encrypted directly on your device before transmission. We cannot read, decrypt, or share your private Padchi content.

1. Introduction

This Privacy Policy explains how Padchi Pe ("we", "our", or "the App") collects, uses, and protects your information when you use our mobile application and related web services. We are dedicated to ensuring user privacy, transparency, and compliance with Google Play Developer Policies and global data protection regulations.

2. End-to-End Encryption & Zero-Knowledge Architecture

Padchi Pe uses strong cryptographic protocols (including LibSignal / Signal Protocol primitives) to secure communication between users:

  • Client-Side Encryption: The text content of your Padchis, financial amounts, and digital signature strokes are encrypted on your local device before being sent to our backend servers.
  • Private Key Ownership: Cryptographic private keys never leave your physical device. Only the intended sender and receiver hold the keys needed to decrypt and view the Padchis.
  • Server Inability to Decrypt: Our cloud servers (Google Firebase/Firestore) only store scrambled, encrypted data. Neither Padchi Pe developers nor any third party can access or inspect the contents of your Padchis.

3. Information We Collect

To provide core application functionality, we collect minimal and necessary information:

A. Account & Profile Information

  • Username & Account Credentials: Used for account creation, secure authentication, and allowing other users to find and identify you when sending a digital Padchi.
  • Public Identity Keys: Cryptographic public keys uploaded to allow other users to encrypt messages intended for your device.

B. Encrypted Message Payloads

  • Encrypted Padchi Data: Stored securely in Google Cloud Firestore in an encrypted, unreadable format until retrieved and decrypted by recipient devices.
  • Status Metadata: Padchi status indicators (e.g., Paid, Unpaid, Timestamps) used to coordinate real-time UI state between participants.

C. Device & Push Notification Data

  • Firebase Cloud Messaging (FCM) Token: A device-specific token used solely to route instant push notifications (e.g., "You received a new Padchi" or "Status changed to Paid").

4. Device Permissions We Request

Padchi Pe requests minimal permissions strictly to support core functionality:

  • POST_NOTIFICATIONS: Required to alert you in real-time when new Padchis, signature confirmations, or status changes occur.

5. Third-Party Service Providers

We work with trusted industry standard cloud infrastructure providers:

  • Google Firebase (Authentication, Firestore, Cloud Messaging): Provides encrypted database hosting, secure user authentication, and notification routing. Google processes this data in accordance with Google's Privacy Policy and standard security certifications.

We do not sell, rent, or monetize your personal data or contact details to advertisers, data brokers, or marketing partners.

6. Data Retention & Automatic Deletion

  • Active Records: Encrypted Padchis remain available for you and your counterpart until settled or deleted.
  • Auto-Delete Option: Padchi Pe provides built-in auto-delete timers allowing users to automatically wipe settled Padchis from the database after a specified period.
  • Manual Deletion: You can delete individual Padchis directly from the app at any time.

7. Account & Data Deletion Rights

In accordance with Google Play's User Data & Account Deletion Policy, you have full control over your account and data:

  • You may delete your account directly inside the app under Settings → Account → Delete Account.
  • You can also submit an account deletion request via our public web portal without opening the app at: Padchi Pe Account Deletion Portal.
  • Upon account deletion, your user profile, cryptographic public keys, authentication records, and associated metadata are permanently erased from our databases.

8. Children's Privacy

Padchi Pe is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we discover that a child under 13 has provided personal information, we immediately remove such information from our servers.

9. Security Measures

We employ end-to-end encryption, strict Firestore security rules, secure HTTPS transport layer encryption (TLS 1.3), and token-based authentication to safeguard your information against unauthorized access, alteration, or disclosure.

10. Changes to This Privacy Policy

We may update our Privacy Policy periodically to reflect app updates or regulatory requirements. Any modifications will be posted on this page with an updated "Last Updated" timestamp.

11. Contact Us & Data Protection Inquiries

If you have any questions, feedback, or data requests regarding this Privacy Policy or your account, you can submit an inquiry or account removal request directly through our online portal: