Riqo is built on a local-only architecture. In ordinary use, the app does not communicate with any server operated by Vibhutix or any third party. Below is a precise record of what data exists, where it lives, and who can access it.
| Data type | Collected? | Notes |
|---|---|---|
| Financial records (expenses, balances, dues) | Never | Stored encrypted on your device only; never transmitted to us in readable form |
| Device address book / contacts | Never | People in Riqo exist only because you typed them in; no contacts permission is requested |
| Bank or UPI account access | Never | No account linking, no automatic import, no SMS reading |
| Location | Never | Not accessed |
| Device or advertising identifiers | Never | Backup files contain no device, user, or install identifier |
| Usage analytics | Never | No analytics SDK is included in the app |
| Crash reports or diagnostics | Never | No crash-reporting SDK is included |
| Name, email, or account details | Never | No account registration is required or offered |
Riqo cannot misuse your data because it never receives it. Everything you enter stays encrypted on your phone, and there is no Riqo server it could be sent to.
All processing happens on your device, only for the features you use. The purposes are narrow and user-directed:
Your data is not used for advertising, profiling, or training of any kind — and since it never reaches us, it could not be.
Riqo stores the following data locally on your phone only, inside a database encrypted with AES-256 (SQLCipher) and in your device's secure storage:
| Data | Storage location | Purpose |
|---|---|---|
| Financial ledger — expenses, recurring commitments (rent, SIP, EMI, subscriptions), shared splits, spaces, accounts, income schedule, lending records, and categories | Encrypted database | Powering the app: your Safe-to-Spend number and financial history |
| People you add (name, optional UPI hint, optional phone, notes) | Encrypted database | Splitting expenses and tracking dues with people you choose to record |
| App preferences (currency, theme, app-lock settings) | Device key-value storage | Remembering your setup |
| Database encryption key | Android Keystore / iOS Keychain | Decrypting your own data on your own device |
| App-lock PIN | Secure storage, as a salted hash | Verifying unlock; the PIN itself is never stored |
| Cloud sign-in token (only if you connect Google Drive) | Secure storage | Uploading your encrypted backup; never included in any backup or export |
You can erase all Riqo data at any time from Settings, or by uninstalling the app. No data persists on any server and no action with Vibhutix is required.
Default state: no network activity. With cloud backup off (the default), Riqo makes no network connections — no analytics, no update checks, no exchange-rate fetches, nothing. Settings shows a network status indicator that reflects the app's actual state.
If you choose to turn on cloud backup:
iCloud.com.vibhutix.riqo).If you lose your recovery key or passphrase, your cloud backup cannot be decrypted by anyone, including us. Please store your key safely. A backup we could recover for you would be a backup we could read — and we can't.
| Platform | Permission | Why | When it's used |
|---|---|---|---|
| Android | Internet | Uploading/downloading your encrypted cloud backup — nothing else | Only if you enable a cloud destination |
| Android | Biometric | Optional fingerprint/face unlock shortcut | Only if you enable biometric unlock |
| iOS | Face ID | Optional Face ID unlock shortcut | Prompted on first Face ID use |
Not requested: location, contacts, camera, microphone, SMS, phone, or calendar. Biometric data is handled entirely by your operating system — Riqo never sees or stores it.
The current version of Riqo contains no in-app purchases. The features that protect your data — encryption, app lock, export, encrypted local backup, and restore — are free.
If a paid feature is introduced in a future version, purchases will be processed exclusively by Google Play on Android and the Apple App Store on iOS. This means:
Riqo is a personal-finance app intended for general audiences. It does not contain features targeted at children and does not knowingly collect any personal data from anyone, including persons under the age of 13 (or the equivalent minimum age in your jurisdiction).
Because the app collects no personal data at all — from any user — there is no special risk to minors beyond standard device data-handling practices. If you are a parent or guardian and have concerns, you may contact us at the address in Section 14.
Because Riqo holds no personal data on any server, your data rights are exercised directly on your device — instantly, with no request to us required:
Export your complete data to CSV or JSON at any time, free. Export files are unencrypted plain data in your hands — be careful before sharing them.
Every record you enter can be edited or deleted directly in the app.
Settings offers a full erase that clears all data and resets the app. Uninstalling the app also removes its data. No server-side deletion request is needed because no server-side data exists.
If you used cloud backup, the encrypted file sits in your own Google Drive or iCloud account. You can delete it there at any time — it is under your control, not ours.
All processing is initiated by you on your own device. Simply not using a feature prevents its associated processing.
If your jurisdiction grants you additional statutory data rights, you may contact us at any time and we will respond within the timeframe required by applicable law.
Vibhutix retains no data about you on any server. All data retention decisions are therefore yours to make:
Vibhutix does not retain logs, usage records, or any derivative of your activity — there is nothing on our side to retain.
No analytics library, advertising network, tracking SDK, or data broker is included in the app. The only third parties involved are the cloud storage providers you may choose to connect:
| Service | Provider | Purpose | Data shared with provider |
|---|---|---|---|
| Google Drive (app-data scope) | Google LLC | Storing your backup, if you enable it | An encrypted file that neither Google nor Vibhutix can read; your Google sign-in is governed by Google's Privacy Policy |
| iCloud (Riqo's container) | Apple Inc. | Storing your backup, if you enable it | An encrypted file that neither Apple nor Vibhutix can read; governed by Apple's Privacy Policy |
Google's and Apple's handling of your accounts is governed by their own privacy policies, over which we have no control. We have deliberately limited integration to the narrowest storage scope each platform offers.
Riqo is built in India, for India first. Because of its local-only architecture, personal data is not transferred to Vibhutix in ordinary use — processing happens on your device, under your control. You retain all rights available under the DPDP Act, including grievance redressal. For any grievance, contact our Grievance Officer:
Grievance Officer: Happy Mishra · info@vibhutix.com
For users in jurisdictions with data-protection legislation — such as the EU/UK GDPR, California CCPA/CPRA, Brazil LGPD, and similar frameworks — Riqo does not sell or share personal information, does not use it for advertising, and does not transfer it to Vibhutix infrastructure. Rights of access, correction, deletion, and portability are available directly in the app as described in Section 08. For any request under applicable law, contact us via Section 14 and we will respond within the legally required timeframe.
Riqo employs the following technical and architectural safeguards:
No software can be guaranteed absolutely secure, but Riqo's architecture means that even in a worst case there is no server-side copy of your data to be exposed. If we become aware of a security issue affecting your data, we will make reasonable efforts to inform affected users and provide guidance.
We will update this Privacy Policy when Riqo's features change in ways that affect how data is handled, when applicable laws change, or when we need to clarify our practices.
When we make a material change — for example, if a future version introduces a paid cloud feature — we will:
Continued use of Riqo after an update constitutes acceptance of the revised policy.
Questions, requests, or concerns about this Privacy Policy or Riqo's data practices should be directed to:
Vibhutix
Developer of Riqo · App ID: com.vibhutix.riqo
Email: info@vibhutix.com
We respond to privacy-related enquiries as promptly as we can. Responses to legally mandated data subject requests will be provided within the timeframe required by applicable law in your jurisdiction.