English
Effective date: 21 September 2026 · Contact: engiggilabs@gmail.com
1. Scope and summary
Money Leak & Rights Radar is a local-first organizer for records, payments, documents, evidence, reminders and related life-admin work. The app does not require an account. Engiggi Labs does not operate an account service, cloud business-data store or synchronization service. Billing-enabled releases use the separate purchase and access services described in Section 8a.
Core business records, document images, files, OCR content, searches and personal reminder intent are stored and processed on the device. This does not mean that all app-related data always stays on the device: user-directed backup, export, open and share actions, optional Firebase announcements and documented Google ML Kit diagnostics have the separate boundaries below.
The app is an organizational tool. It is not a bank, payment service or legal service, and it does not make payments, cancel subscriptions, submit claims or complete legal or other external actions for you.
2. Information stored on the device
Depending on the features you use, the app may store:
- records, dates, lifecycle state, payment occurrences, amounts and currencies;
- titles, notes, references and other information that you enter;
- documents, photos, PDFs, evidence metadata and app-owned file copies;
- OCR text, extracted suggestions, review state and local search terms;
- assets, timelines, maintenance plans and workflow or checklist state;
- personal reminder intent and device-local notification state;
- bounded recent searches, filters, smart-collection pins and app preferences; and
- content-free operational state used for local recovery, reconciliation and integrity checks.
Demo content is session-only and is kept separate from the real workspace. The app does not treat a record, reminder or exported dossier as proof that an external action occurred.
3. Backups, exports, opening and sharing
You can explicitly create a readable portable backup or a selected PDF, CSV or dossier export. You can also ask Android to open or share a selected file. In those cases, the selected copy leaves the app's private storage and is handled by the folder, document provider, viewer, share target or recipient that you choose. That destination may store or transmit the copy under its own terms.
Backups and exports are not encrypted by an additional app-layer encryption system. Sensitive export categories, including identifiers, notes and OCR text, follow the selection shown before generation; some are excluded by default. Engiggi Labs does not receive these copies. Clearing the workspace or uninstalling the app does not delete copies already handed to an external destination. You must delete those copies from that destination.
4. Optional product and tester announcements
On Android, the app offers two separate optional purposes: tester updates and product news. Both are Off by default. Core records, documents, OCR, search, reports, backups, exports and personal reminders continue to work without enabling either purpose.
If you explicitly enable at least one purpose, Google Firebase Cloud Messaging and Firebase Installations may process a Firebase Installation ID, registration state, non-personal topic membership and technical message-delivery metadata. The app stores applicable client registration state in Android private storage. The Firebase Installation ID and registration state are excluded from SQLite, portable backups, exports, navigation routes and normal logs.
FCM auto-initialization remains disabled until an announcement purpose is enabled. Firebase Analytics collection, BigQuery delivery export and Android notification delegation remain disabled under this version's configuration.
Announcement payloads are limited to generic product or test communication and a closed set of navigation metadata. They must not contain workspace record or document identifiers, amounts, notes, OCR text, filenames or other workspace content. An announcement cannot perform a payment, completion, OCR, file, backup, export or other business-data mutation.
You can turn either purpose Off in Settings. Turning the final purpose Off disables client auto-initialization and attempts the applicable topic unsubscribe, Messaging unregister and Firebase Installation deletion. The app can report only its client-visible result. Provider-side retention, deletion timing and completion are subject to Google's terms and policies and are not promised to be immediate.
5. On-device OCR and Google ML Kit
Android OCR and document scanning use Google ML Kit and Google Play services components. OCR starts only through an explicit feature action. Product code does not send your document images or recognized text to a cloud OCR service; recognition results are handled locally unless you later include them in a user-directed backup or export.
Google-documented performance or utilization diagnostics and component or model delivery may use Google services. Those vendor-controlled technical processes are not an Engiggi Labs business-data repository. There is no separate in-app switch for vendor diagnostics.
6. Biometrics and device security controls
Archive biometric protection is optional and Off unless you enable it. The app asks Android to authenticate you and receives a capability or success/failure result. It does not receive, store or export your fingerprint, face or other biometric template. Templates remain under the device operating system's control.
Biometric Archive protection and preview screen-capture controls restrict presentation surfaces; they are not file encryption and cannot guarantee that content is never captured.
7. Notifications and permissions
Personal reminders are scheduled locally and are separate from optional FCM announcements. Android and device settings control notification permission, channels, sound, vibration, lock-screen display and connected-surface presentation. A posted notification is not proof that it was seen.
The app does not guarantee reminder delivery, savings, or any financial, legal, contractual or other outcome.
Personal reminder content defaults to the privacy-preserving Private mode. The more descriptive Detailed mode is a separate user choice. Android or device-maker settings can further change how either mode appears.
The Android build may declare camera, internet, notification, reboot, biometric and vibration permissions for the features described here. Camera and notification permission are requested contextually. The frozen configuration does not request broad photo, video or audio-library access, microphone, location, contacts, SMS, Advertising ID, exact-alarm special access, full-screen intent or overlay permission.
8. Analytics, advertising and sale of data
The app has no Firebase Analytics, Google Analytics, Crashlytics, app-authored behavioral analytics, advertising SDK use or Advertising ID permission. Engiggi Labs does not sell personal data. These statements do not remove the separately disclosed Firebase Messaging and Installations processing or ML Kit diagnostics boundary.
8a. Pro purchases and invitation access
In billing-enabled Android releases, Google Play handles payment and RevenueCat verifies Pro access. Technical processing includes the SDK-generated anonymous customer identifier, purchase history, product/base-plan identifiers, purchase tokens or receipts, renewal and access status, app/SDK/device technical information, locale and currency. Purchase processing is encrypted in transit and is not ephemeral. RevenueCat uses purchase data for access functionality and subscription/revenue analytics; this is not behavioral tracking of your local workspace. We do not send your payment-card details to RevenueCat or collect advertising identifiers or marketing attributes.
We do not send record titles, notes, documents, images, OCR text, searches, files or the bill amounts you enter to RevenueCat. The store price paid for Pro is different from your personal bill data. Older releases without billing do not use this purchase integration.
Where invitation access is enabled, your explicit code submission sends the code and anonymous purchase identifier over HTTPS to our Cloudflare Workers verifier. Its private SQLite Durable Object keeps only a hash of the identifier, invitation reference, status, attempt and time information, plus aggregate rate-limit counters. Raw codes and identifiers are not stored in that ledger; request bodies and headers are not recorded in our Worker logs. Cloudflare may process IP addresses and technical request metadata. Codes are not saved in workspace backups. The verifier grants access through RevenueCat, not through a shared login. This service is separate from local business data and does not synchronize your workspace. It is called only when you submit an invitation code, not for normal purchases or local workspace use. A free-service quota outage does not replace or cancel your separately verified purchase rights.
For purchase/access data requests, email the contact below; optionally include the technical support identifier you choose to reveal in Pro. We review the request and can delete the RevenueCat customer record and applicable invitation records, subject to necessary legal, transaction and abuse-prevention retention. No fixed universal or immediate provider-erasure period is promised. Google Play keeps its own transaction records. Deletion does not cancel a subscription; restore or later store synchronization can recreate purchase records. See Pro purchase terms.
9. Retention and deletion
Local data remains until you edit, archive, delete or clear it using available app controls, or clear the app's data through Android. Ordinary Android uninstall behavior removes app-controlled private state, but device backup, restore or device-to-device transfer behavior may be controlled by Android or the device maker.
Documents and assets use a recoverable Trash flow and a 30-day purge boundary. Shared bytes may remain while another retained item or recovery operation still references them. Failed cleanup remains retryable rather than being reported as complete. Recent searches and smart-collection pins can be cleared through their controls.
External backups, exports and shared copies must be deleted at their destination. Optional announcement opt-out follows Section 4, but immediate provider-side erasure is not promised. Because the app does not require an account, there is no app account to close. Billing-enabled releases do create technical purchase/access records; see Section 8a and the Data Deletion page for requests concerning them.
Step-by-step deletion guidance and the privacy-request contact are available on the Data Deletion page.
10. Service providers and external destinations
Google provides Firebase Cloud Messaging and Installations for optional announcements, and ML Kit and Google Play services components for Android OCR and scanning. Android system components and destinations chosen by you may also handle camera, picker, viewer, document-provider, biometric, notification and share actions. Their processing is governed by their own terms and policies.
Engiggi Labs does not operate an automated production campaign sender, server token database, remote OCR or language-model service, bank integration, cloud synchronization or other business-data backend for this version.
11. Children and regional requirements
Money Leak & Rights Radar is not designed for children. This policy does not replace consent, disclosure or age-related obligations that may apply in a distribution region.
12. Changes and contact
If the app's data practices or this policy change, this page will be updated with a new effective date and any in-app or store disclosure required by law or platform policy.
Privacy questions: engiggilabs@gmail.com
Published policy: https://money-leak-rights-radar.web.app/privacy/