Qurbill

Privacy Policy

Last updated: 8/9/2026

This Privacy Policy explains how Qurbill ("we," "us," or "our"), operated as an individual developer in India, collects, uses, retains, and deletes your personal information when you use the Qurbill mobile application and related services (collectively, the "Service").

By accessing or using the Service, you signify that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described in this Privacy Policy. If you do not agree with this policy, please do not use the Service.

1. Definitions

  • "Personal Data" means any information that relates to an identified or identifiable living individual.
  • "Service" refers to the Qurbill mobile application, backend APIs, and any associated web landing pages.
  • "Third-Party Services" refers to external APIs and providers (e.g., Google, Cloudinary) that process data on our behalf.

2. Information We Collect

A. Information You Provide to Us

  • Account Information: When you register, we collect your phone number (verified via OTP), display name, profile picture (optional), and gender (optional).
  • Financial Information: We collect your UPI ID and preferred UPI app (e.g., Google Pay, PhonePe) to generate payment links. We do not collect or store credit card numbers, CVVs, or bank account passwords.
  • Transaction & Ledger Data: We collect information about your shared expenses, personal spends, incomes, budgets, and stock portfolios to provide the core tracking features.
  • Receipts & Images: We collect photos of receipts that you capture using your camera or upload from your gallery.

B. Information We Collect Automatically

  • Device and Usage Data: When you use the app, we automatically collect certain telemetry data, such as your IP address, device model, operating system version, app usage patterns, and crash reports. This is strictly used for debugging and improving the app.
  • AI Interaction Data: When you use our AI financial assistant, we log the text of your queries.

C. Information from Third Parties

  • Social Login: If you choose to log in via Google, we receive your Google ID, email address, and basic profile information from Google.
  • Contacts Integration: If you choose to add friends from your device's address book, we collect the phone numbers and contact names to facilitate expense sharing. By doing this, you confirm you have permission to share this information with us.

3. How We Use Your Information & AI Integration

We use the collected information primarily to provide, maintain, and improve the Service. Qurbill leverages third-party Generative AI models (specifically Google Gemini) to power core features.

A. AI Processing (Google Gemini)

  • Receipt Parsing: When you upload a receipt, the image is sent to the AI to extract line items, prices, merchant names, dates, and taxes. Please ensure you do not capture sensitive personal information (such as full credit cards, health information, or government IDs) in these images.
  • Financial Chat Assistant & Insights: The AI receives aggregated metrics (e.g., "Total spent on Food: ₹5000") to formulate natural language responses and budgeting advice. We do not send your raw, identifiable personal data (such as your full name, phone number, or UPI ID) to the AI models.
  • AI Audit Logs: For quality assurance and cost monitoring, we log interactions with the AI assistant. Upon account deletion, these logs are completely anonymized.

B. General Usage

  • To calculate and track shared expenses and personal budgets.
  • To generate UPI deep-links to facilitate peer-to-peer external payments.
  • To communicate with you, including sending payment reminders and system notifications.
  • To prevent fraud, abuse, and enforce our Terms and Conditions.

4. How We Share Your Information

We do not sell, rent, or lease your Personal Data to third parties. We share your information only in the following circumstances:

  • With Other Users: When you split an expense, the involved users will see your display name, phone number, UPI ID, and the details of the shared receipt to ensure transparency.
  • With Service Providers: We share information with trusted third-party vendors who assist us in operating the Service:
    • Google (Gemini AI): We securely send your receipt images and aggregated financial data to Google's Gemini API for processing.
    • Cloudinary: We store uploaded receipt images and profile pictures on Cloudinary's servers.
    • Firebase (Google): We use Firebase for user authentication, crash reporting (Crashlytics), analytics, and push notifications (FCM).
  • For Legal Compliance: We may disclose your information if legally required to do so by a court order, subpoena, or to protect the rights, property, or safety of Qurbill, our users, or the public.

5. Data Retention

We retain your Personal Data only for as long as is necessary to provide our Service:

  • Active Accounts: We retain your profile information, financial history, and receipt images as long as your account remains open.
  • Shared Receipts: Receipts attached to a shared group expense are retained indefinitely. Even if you delete your account, your friends require continuous access to these shared receipts for their own financial records and to audit past debts.
  • AI Audit Logs: Retained permanently for system improvement, but completely anonymized (stripped of any user identifiers) upon account deletion.

6. Account Deletion and Data Purging

You have the right to delete your account at any time directly within the mobile application's Settings > Delete Account menu.

The 3-Day Grace Period

When you request account deletion, your account enters a 3-day scheduled deletion grace period.

  • During this window, your account is marked for deletion, but the data is preserved.
  • If you change your mind, you can cancel the deletion simply by logging back into the app within those 3 days.
  • Once the 3 days have passed, the deletion becomes permanent and irreversible.

Deletion Protocol

When the grace period expires:

  • Profile Data: Your phone number, display name, UPI ID, and authentication records are permanently destroyed.
  • Private Receipts: Any receipt images hosted on Cloudinary that are associated only with your private expenses (PersonalSpends) are immediately and permanently hard-deleted.
  • Anonymization: Your personal identifier is permanently removed from all AI interaction logs.

(Note: We cannot delete data that has already been shared with third-party UPI apps during your payment transactions).

7. Your Data Subject Rights

Depending on your jurisdiction (including the Indian Digital Personal Data Protection Act, 2023), you may have the following rights:

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Correction: You can correct inaccurate data directly in your profile settings.
  • Right to Erasure: You can delete your account as outlined in Section 6.
  • Right to Withdraw Consent: You can revoke permissions (e.g., Camera, Contacts) via your device settings at any time, though this will limit app functionality.

To exercise data export rights, please contact our Grievance Officer.

8. Children's Privacy

Under the Digital Personal Data Protection (DPDP) Act, 2023, individuals under the age of 18 are considered children. Qurbill requires that any user under the age of 18 must have the explicit and verifiable consent of a parent or legal guardian to use the Service. By creating an account, you represent that you are either 18 years of age or older, or that you are a parent/guardian agreeing to these terms on behalf of a minor.

By using the payment facilitation features (UPI deep-links), you and your parent/guardian warrant that you meet the age requirements of your respective bank and UPI provider. Parents or guardians may contact us to review or delete their child's account.

9. Data Storage, Security, and International Transfers

We operate in India. Your data is securely stored in cloud databases and protected using industry-standard security measures (including Firebase token-based authentication and HTTPS encryption in transit).

Payment Data Localization (RBI Guidelines): Qurbill does not process, route, or store fiat banking payment transactions. We only store the UPI ID string and expense ledger metadata, which is not subject to RBI data localization mandates regarding core payment data.

However, no method of transmission over the internet is 100% secure. You are responsible for maintaining the security of your device and authentication credentials. If you access the Service from outside India, your information may be transferred to, stored, and processed in India and other jurisdictions where our service providers (like Google and Cloudinary) operate.

10. Grievance Redressal

In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act, 2023, the name and contact details of the Grievance Officer are provided below:

Grievance Officer: Sheelendra

Email: sheelusingh1904@gmail.com

Address: Mathura, Uttar Pradesh, India

The Grievance Officer will acknowledge your complaint within 24 hours and resolve it within 15 days from the date of receipt.