AICA Passbook

Privacy policy

Last updated 11 July 2026

1. What we collect, and why

AICA Passbook collects the minimum a bank-statement verification and BSA report product needs: the statement file you upload (to parse it), your email (to run an account and issue reports), and payment details that never actually reach us: Razorpay handles those directly. Files are held in temporary memory only, never written to disk, and hard-deleted 60 minutes after upload, whether or not you download a result.

2. The data map

What we hold, where it lives, and how long
DataWhereRetention
PDFs, parsed rows, classified rowstmpfs (memory only)≤60 min, hard-deleted
Job receipts: ticket number, bank, row count, verdict (never the transaction rows themselves)DatabaseAccount lifetime (anonymous receipts: 24 h)
Email, report ledger, invoicesDatabaseAccount lifetime; self-serve delete any time
Card and UPI detailsRazorpay onlyWe never see or store them
IP counters (daily free-tier cap)Database24 h
Server logs, scrubbed of narrations and account numbersLog storage30 days

A technical honesty note on that IP-counter row: our cleanup job keeps yesterday’s counter alongside today’s as a clock-boundary safety margin, so on disk a given counter can persist for slightly under two days even though it only ever counts a single calendar day of parses toward the free-tier cap, and is never used for anything else.

3. Who else touches your data

  • Razorpay: processes payments (cards, UPI, netbanking) and holds your payment details directly; we never do.
  • An email delivery provider: sends the one-time sign-in codes and receipt emails you trigger.
  • Hosting: the site itself is served from a CDN; the API and database run on an India-region host.
  • Google: only if you choose to sign in with Google; we don’t require it, and we share nothing with Google if you don’t.

4. Cookies and tracking

AICA Passbook sets only functional cookies: the ones that keep you signed in and let us enforce the daily free-tier cap. No advertising pixels and no cross-site tracking. There is nothing here beyond what the product itself needs, which is why there’s no cookie banner.

We do measure usage — which pages are visited and how quickly they load — through our hosting provider’s built-in analytics. It sets no cookies, assigns you no identifier that persists between visits, and never sees a file you upload or anything read out of one. Because it stores nothing on your device, there is nothing here for you to opt out of.

5. Your rights under India’s DPDP Act, 2023

AICA Passbook is a Data Fiduciary for the personal data described above. We process it for one purpose (running the verification and classification product you asked for) and nothing else: we don’t train models on it, and we don’t resell it. We can’t train on what we don’t have, and most of what we handle is gone within the hour. If a breach occurs, we notify affected users and the relevant authority within the Act’s required timelines. Data is hosted in India, and the outside parties we share it with (above) are chosen to keep it there.

Grievance officer, for complaints under the DPDP Act: grievance@__DOMAIN_TBD__ [owner: replace before launch]

6. Your rights if GDPR applies to you

If you’re in a jurisdiction where the GDPR applies, the same architecture that protects everyone protects you. Erasure means deleting your account from the account page: every record we hold about you is removed, and any file still inside its 60-minute window is already gone before you even ask. Access means the account page itself: your ledger, receipts, and profile are visible there any time, with no separate request process, because the page already shows you everything we have.

7. Changes to this policy

We’ll update this page as the product changes and post a new date at the top when we do. Material changes that affect how we handle your data will also be reflected here before they take effect.