Privacy Policy

Rizq — Islamic personal finance for Android · Package com.vynci.rizq
Published by Vynci Softworks, Kolkata, India
Effective date: 27 August 2026 · Last updated: 27 August 2026

Short version. Rizq stores your financial records — transactions, accounts, balances, budgets, debts, pensions and receipt photos — and your Islamic records — zakat assessments and payments, charity, riba markings, your madhhab and calendar settings — in a database on your device. We do not run a server that receives them, we do not sell or share them, and we do not use them for advertising. The only copy that ever leaves your phone is a backup you choose to create, encrypted in transit and stored in your own private Google Drive app folder that we cannot browse.

1. Who we are

Rizq ("the app", "we", "us") is an Android application published by Vynci Softworks ("the developer").

2. The core principle: your data stays on your device

Rizq is a local-first application. Everything you record is written to a private database file inside the app's own sandboxed storage, which other apps on your phone cannot read. This includes:

None of the above is transmitted to the developer. We operate no analytics service, no crash-reporting service, no advertising SDK and no user-profiling system. There is no account database on our side holding your balances, your zakat figures or your observance.

3. Religious and belief-related information

Some of what Rizq stores — your madhhab, your zakat and sadaqah records, your markings of what you wish to avoid — may reveal religious belief or practice. Under the GDPR this is a special category of personal data, and comparable laws elsewhere treat it as sensitive.

Please do not include religious or financial detail in feedback messages (section 4.5), which do reach us.

4. Data we do process, and why

4.1 Google account (sign-in) — required

Signing in with Google is required to use Rizq. We use Android's Credential Manager with Google Identity Services. From your Google profile the app receives, and stores on your device only:

This identifies you for Google Drive backup and detects when a different Google account signs in on the same device. Sign-in state is held in local preferences; the developer receives no copy of it except where you send feedback (section 4.5).

Account switching: because the database is a single device-local file with no per-account ownership, signing in with a different Google account wipes the local database and per-user preferences before continuing, so the previous user's records are not exposed to the new one. You are then offered a restore from the new account's own Drive backup. Back up before switching accounts.

4.2 Google Drive backup — optional, and yours alone

You may back up your data to Google Drive, manually or on a schedule you choose (off, daily, weekly or monthly). A backup is a ZIP archive of the app database plus your receipt images, uploaded over HTTPS to Google Drive.

The app requests only the drive.appdata scope. This is Drive's hidden, application-specific folder:

Rizq's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google Sign-In and Drive is used solely to provide the backup and restore features you request; it is never sold, never transferred to third parties except as needed to provide those features, never used for advertising, and never read by humans.

You can revoke the app's Drive access at any time at myaccount.google.com/permissions.

4.3 Local backup and export — entirely offline

You may export your data as a CSV or PDF file — including a zakat statement — or export the raw database to a location you pick with the Android file picker. These files are written where you choose and are never uploaded anywhere by the app. Once exported, the file is outside the app's sandbox and its security is your responsibility. A zakat statement contains religious and financial detail; store and share it accordingly.

Receipt images are deliberately excluded from CSV and PDF export.

4.4 Currency exchange rates — and no price feed at all for metals

If you use more than one currency, the app fetches daily reference rates from the public Frankfurter API (api.frankfurter.app). The request contains only currency codes — no amounts, no account details, no identifiers, and nothing about zakat. Rates are cached locally. Your device's IP address is necessarily visible to that service, as with any network request.

Gold and silver prices are not fetched. Rizq ships no metal price feed and queries no market data service. Nisab and zakat figures use the rates you enter, and the assessment records what they were. Nothing about your wealth or your nisab basis is sent anywhere to obtain a price.

Hijri dates are computed on your device from tabular data shipped inside the app, with a sighting offset you set yourself. No date, location or observance information is requested from any server, and the app does not ask for location permission at all.

4.5 In-app feedback — the one thing you send us

If you use "Send feedback" in Settings, the following is written to a Google Firebase Realtime Database controlled by the developer:

FieldPurpose
Star rating (optional) and topicTriage
Your messageThe feedback itself
Your signed-in email addressSo we can reply
App version and version codeReproducing bugs
Device model, Android SDK level, localeReproducing bugs

No financial or religious data crosses this boundary. No amounts, balances, accounts, categories, transactions, receipts, budgets, zakat assessments, giving records or madhhab settings are included — by design. Please do not type sensitive figures or personal religious detail into the message box; whatever you write there, we will read.

Feedback records are retained for as long as needed to act on them and are deleted on request. Firebase is operated by Google; see Firebase's privacy documentation.

4.6 Subscriptions and payments

Rizq Premium is sold as a subscription through Google Play Billing. Google processes the transaction end to end. We never see or receive your card number, bank details, billing address or any payment credential. The app only asks Google whether an active entitlement exists, and caches that yes/no answer locally so paid features do not flicker while Play is contacted. Purchases are governed by Google Play's Terms of Service.

4.7 Voice entry (microphone)

The app can create a transaction from speech. This uses the RECORD_AUDIO permission and Android's on-device speech-recognition framework. Audio is handed to the recogniser your device provides — usually Google's, which may process it on Google's servers under Google's own privacy terms. Rizq does not record, store, or transmit audio itself; it receives only the resulting text and parses it locally. The permission is optional; deny it and every other feature works normally.

4.8 Receipt photographs (no camera permission)

Attaching a receipt uses Android's system photo picker, so the app never requests broad photo-library or camera permissions and can only see the single image you select. The chosen image is copied into the app's private storage. It is deleted when you delete the transaction (after the undo window expires). Receipts are included in Google Drive backups and excluded from CSV/PDF exports.

4.9 Notifications

The app can post local notifications for budget thresholds, credit-card utilisation and bill dates, recurring transactions, pension contribution reminders, and Islamic reminders such as the zakat anniversary, a nisab crossing and Zakat al-Fitr during Ramadan. These are generated entirely on your device from your own data and your own calendar settings. No push service is used and nothing is sent to a server to produce them. The POST_NOTIFICATIONS permission is optional, and the Islamic reminders can be switched off individually.

4.10 Biometric app lock

If you enable the app lock, authentication is performed by Android's BiometricPrompt against credentials already enrolled on your device. Rizq never receives, stores or transmits your fingerprint, face data or device PIN — it receives only a success or failure result.

5. What we never do

6. Third-party services summary

ServiceWhat it receivesWhen
Google Sign-In / Identity ServicesStandard authentication dataAt sign-in (required)
Google Drive (appdata scope)Your encrypted-in-transit backup archive, stored in your own accountOnly if you enable backup
Google Play BillingPayment details, handled by GoogleOnly if you subscribe
Google Firebase Realtime DatabaseFeedback message, email, app/device version dataOnly if you send feedback
Frankfurter APICurrency codes onlyDaily, if multi-currency is used
Device speech recogniserSpoken audio (handled by the OS provider)Only when you use voice entry
Any metal price or Islamic calendar serviceNothing — none is usedNever

7. Data retention and deletion

To request deletion of anything we hold, contact vyncisoftworks@gmail.com. Since we hold almost nothing, such requests are usually limited to feedback records.

8. Your rights

Depending on where you live (GDPR in the EU/UK, CCPA/CPRA in California, DPDP Act in India, and comparable laws elsewhere) you may have the right to access, correct, delete, port or restrict processing of your personal data, and to object to it or withdraw consent.

In practice, most of these you can exercise yourself without asking us: your data is on your device, exportable to CSV or PDF at any time, and deletable at any time. For anything we hold — feedback records — write to vyncisoftworks@gmail.com and we will respond within 30 days. Under the CCPA we do not sell or share personal information, so there is nothing to opt out of.

Our lawful bases under GDPR are: contract (sign-in and delivering the app's function), consent (Drive backup, microphone, notifications, feedback), and legitimate interests (fixing bugs from feedback you send). Religious-belief data described in section 3 is neither collected nor processed by us, so no Article 9 condition is engaged on our side; it stays under your control on your device.

9. Security

Data is stored in the app's private sandbox, inaccessible to other apps on a non-rooted device. Network traffic uses HTTPS. Optional biometric/device-credential locking is available. Drive backups sit inside Google's infrastructure under your account's own protections.

No system is perfectly secure. A rooted or compromised device, or a backup or zakat statement you export to shared storage, sits outside these protections. Keep your device locked and your Google account protected.

10. Children

Rizq is not directed at children under 13 (or under 16 where local law sets that threshold) and we do not knowingly collect their data. If you believe a child has provided us with information, contact us and we will delete it.

11. International transfers

The Google services described above operate globally and may process data outside your country, under Google's own safeguards and standard contractual clauses. Your financial and religious records themselves are not transferred anywhere, because they do not leave your device.

12. Changes to this policy

We may update this policy as the app changes. The "Last updated" date at the top will change and material changes will be highlighted in the app or on the Play Store listing. Continuing to use Rizq after an update means you accept the revised policy.

13. Contact

Questions, requests or complaints: vyncisoftworks@gmail.com
EU/UK users may also lodge a complaint with their local data protection authority.