Legal

Privacy Policy

Rakama holds a detailed picture of your money. This page explains exactly what that means — what is stored, why, who else can see it, and how to take it back.

Effective 8 August 2026Last updated 13 August 2026

The short version

Rakama stores the financial records you enter or import, plus the minimum needed to run an account — your name, email address and a hashed password. We do not sell your data, we do not show advertising, and we run no analytics or tracking software in the app or on this website. You can export everything, erase your financial records, or delete your account outright from inside the app, at any time, without asking us.

The short version

This summary is written for reading, not for lawyers, and it is accurate — but the sections below are the binding version. Where the two appear to differ, the detail wins.

  • We collect what you type into Rakama, and almost nothing else.
  • We do not sell or rent your data to anyone, for any purpose.
  • We show no advertising and embed no advertising or analytics SDKs.
  • Four companies process data on our behalf: our hosting provider, our database provider, our email provider, and — only if you switch on AI categorisation, and then only during a statement import — Google's text-embedding service. Each is described in Who else sees your data.
  • You can export, erase, and delete everything yourself, from the app.

Who we are

Rakama is a personal finance application for tracking expenses, budgeting, splitting bills and setting savings goals, available on the web, Android and iOS. For the purposes of data-protection law, the controller of your personal data is Rana Aazan Mujahid, trading as Rakama, DHA Phase 7, Lahore, Pakistan 54930.

You can reach us about anything on this page at privacy@rakama.app.

What we collect and why

Everything in this section is either something you typed, something you imported, or something technically unavoidable in running the service. There is no category of data we collect quietly in the background.

Account details

Your name, your email address, your chosen display currency (Rakama defaults to PKR), your app settings, and the date you created the account. Your password is never stored. What we store is a bcrypt hash of it, which cannot be reversed back into your password.

We also record whether your email address has been verified, and when a verification code was sent, so that codes expire and cannot be replayed.

Why: Necessary to perform our contract with you — without an account there is nothing to sign in to, and nowhere to keep your records.

Google Sign-In details, if you choose to use it

If you sign in with Google, we receive your Google account identifier, your email address, your name and your profile picture URL. We request only the openid email profile scope. We cannot see your Google password, your Gmail, your contacts, your Drive, or anything else in your Google account.

Why: Necessary to perform our contract, and only where you actively choose Google as your sign-in method. Signing in with an email address and password instead avoids this entirely.

Your financial records

This is the substance of what Rakama holds, and all of it is entered or imported by you:

  • Accounts — the names you give them, their type, their balance, their currency and their opening date. Rakama does not connect to your bank, so these are labels you create, not live bank connections.
  • Transactions — description, amount, date and time, category, type, currency, any note you add, and any file you attach to a transaction (for example a photograph of a receipt), along with its filename.
  • Categories — their names, colours and icons, including any you create.
  • Budgets — limits, periods, scope, alert thresholds and status.
  • Goals — name, description, target amount, amount saved and target date.
  • Bills — name, amount, issue and due dates.
  • Bill splits — the title of the split, the names you enter for the people in it, the expenses, who was excluded from what, and who has paid. See Bill splitting and other people.

Why: Necessary to perform our contract — this is the service. We do not analyse it for any purpose other than showing it back to you.

Categorisation corrections you make

When you correct the category Rakama guessed for a merchant, we store that correction so the same merchant is filled in correctly next time. We store the merchant text pattern and the category you chose, against your account only. Your corrections are never pooled with other users' or used to train anything shared.

Why: Legitimate interest in making the product work as expected — a categoriser that forgets your corrections is a categoriser you have to fight every month. This data never leaves your own account.

Session and security data

When you sign in, we set a session cookie named rakama_token containing a signed token that identifies your account. It is httpOnly, which means scripts cannot read it, and it expires after seven days. Changing your password invalidates every outstanding session immediately.

We use your IP address to rate-limit sensitive actions such as sign-up, sign-in, password changes and account deletion. To make that work across our hosting provider's multiple server instances, each counter is stored in our database as a single row holding the IP address, a count, and the moment the count expires. The row is deleted once that moment passes, typically within minutes. It is never joined to your account and is not used for any other purpose. We also keep a count of failed sign-in attempts against an email address, so repeated guessing can be slowed down; that count is deleted as soon as a sign-in succeeds, and in any case within an hour of the last attempt. Our hosting provider keeps its own short-lived request logs, which include IP addresses, as described in the next section.

We also keep a security log of events on your own account: sign-ins and failed sign-ins, password changes and resets, identity re-confirmations, signing out of all devices, exports and backups, imports and restores, erasing your data, and deleting your account. Each entry records what happened, when, the IP address it came from, and the browser or app that made the request. We keep these for as long as your account exists, because their purpose is to let you answer “did someone else get into my account?” — a log that expired would not answer it. You can read your own log at any time under Settings → Security → Security activity. Nobody can edit or erase individual entries, including us and including anyone who has taken over your account; the whole log is deleted when you delete your account. The log never contains a password, a token, or anything about your transactions.

Why: Necessary to perform our contract (keeping you signed in) and legitimate interest in security (stopping brute-force and abuse).

Sync bookkeeping

Rakama works offline, so we record when each record was last changed, and an identifier for each change your device has already sent us. This lets your devices agree on the current state without duplicating anything. It contains no financial detail of its own.

Why: Necessary to perform our contract — without it, a change you make offline would be applied twice or lost when your phone reconnects.

What we deliberately do not collect

These are absences we have verified in our own code, not aspirations. If any of them change, this policy changes first.

  • No analytics or tracking. There is no Google Analytics, no Firebase, no Meta pixel, no Crashlytics, no session-recording tool, and no product-analytics SDK in the website, the Android app or the iOS app.
  • No advertising, no ad identifiers, and no advertising SDKs.
  • No location data. The apps do not request location permission.
  • No access to your contacts, photos library, camera roll, call logs or SMS.
  • No bank credentials. Rakama has no bank connection feature. We never ask for, and cannot receive, your online banking login, card numbers, or account numbers. If anything claiming to be Rakama asks you for these, it is not us.
  • No biometric data. If you unlock the Android app with a fingerprint or face, that check happens entirely on your device through the operating system. Your biometrics never reach us and cannot.

The Android app requests three permissions in total: internet access, network-state access, and biometric unlock. That is the complete list.

Our lawful basis for using your data

Where data-protection law such as the UK or EU GDPR applies to you, we rely on the following bases, which are also noted against each item above:

  • Performance of a contract — for your account, your financial records, your sessions and synchronisation. These are the service itself.
  • Legitimate interests — for security, abuse prevention, and remembering your categorisation corrections. We have considered your interests and consider these uses to be ones you would reasonably expect.
  • Consent — for optional Google Sign-In, for AI categorisation (which is off until you switch it on; see Automatic categorisation and AI), and for any marketing email. Any of these can be withdrawn at any time, and withdrawing one does not affect the others or your account.
  • Legal obligation — where we are required to retain or disclose information by law.

Who else sees your data

We do not sell your personal data, and we never have. We do not share it with advertisers, data brokers, or credit reference agencies. The only third parties involved are the service providers we need to run Rakama, each of which processes data on our instructions and for no purpose of their own:

  • Our hosting provider (Vercel) — serves the website and the API. It necessarily handles requests in transit and keeps short-lived operational logs containing IP addresses and requested URLs.
  • Our database provider — stores your records at rest, encrypted by the provider.
  • Brevo — delivers transactional email. It receives your name, your email address and the contents of the message we are sending you, such as a verification code. It is used for nothing else.
  • Google — for optional Sign-In, and for the limited text-embedding use described in the next section, which happens only if you have turned AI categorisation on.

We may also disclose information where we are legally required to, or where it is necessary to establish or defend legal claims, or to protect the safety of a person. If we are ever compelled to disclose your data, we will tell you unless we are legally prohibited from doing so.

If Rakama is ever sold or merges with another company, your data may transfer as part of that transaction. We would tell you before it happened, and the new owner would be bound by this policy until you were given notice of any change.

Automatic categorisation and AI

Rakama guesses categories for your transactions. It is worth being precise about how, because "AI" is usually where financial apps are vaguest.

Most guessing happens on our own servers using a fixed keyword list and your own past corrections. No third party is involved in that, it is how every account works by default, and it needs no permission from you.

This is off until you turn it on

The part of this section that involves Google is opt-in. A new account has it switched off, and nothing about your transactions reaches Google unless you turn it on yourself in Settings → Privacy → AI categorisation. You can turn it back off in the same place at any time, without asking us and without giving a reason. Turning it off stops all sending immediately and deletes the merchant categories your own imports taught us.

When it is on and you import a statement or file containing merchant descriptions we do not recognise, we send those description strings — and only those strings — to Google's text-embedding service to work out what kind of merchant they are.

What is sent in that request:

  • The merchant description text, normalised — for example careem ride.

What is not sent:

  • Amounts, dates, balances, notes or attachments.
  • Your name, email address, account identifier or any other identifier.
  • Anything at all from transactions you entered by hand rather than imported.

The result is a mathematical representation of the text which we cache so the same merchant never needs sending twice. Your financial data is not used to train any AI model, by us or by anyone else.

One thing that cache does is worth stating plainly. A merchant mapping — the fact that the words careem ride mean transport — is stored against your account. Once three separate accounts have independently produced the same mapping for the same normalised text, and agree on the category, that one pair of words is promoted to a shared list so nobody has to send it again. What is shared is only the text and the category. It is not linked to you, it does not say who saw it, and it contains no amount, date or anything you wrote. But it does mean a description that appeared on your statement can contribute to a category another Rakama user is shown, which is why we would rather you read it here than not know.

Because a promoted mapping is agreed by several unrelated accounts and attributable to none of them, turning off AI categorisation deletes the mappings held against your account but cannot single out a promoted one. If you delete your account, the same applies: your own mappings go with it.

Bill splitting and other people

When you create a bill split, you type in the names of the people you are splitting with. Those names are personal data about someone else, and you are the one choosing to enter them. We store them so the split works, and we do nothing else with them — we do not contact those people, and we cannot, because Rakama does not ask for their contact details.

Please only enter what you need. A first name is usually enough. Anything you type about another person is deleted when you delete the split, or when you delete your account.

How long we keep it

We keep your data for as long as your account exists, because the whole point of the service is a financial history you can look back through. We do not expire your records after a period of time.

  • If you erase your financial data from within the app, those records are deleted from our database immediately and your account remains, empty.
  • If you delete your account, every financial record and the account itself are permanently deleted from our live database immediately. This is a hard delete, not a flag — the rows are gone, and we cannot restore them for you afterwards. Your security log goes with it.
  • Encrypted backups held by our database provider may retain a copy for up to 35 days before rolling off, after which no copy remains. Backups exist so we can recover the service from a failure; they are not searched, and we do not restore an individual account from them after a deletion.

Your rights and controls

Most privacy policies ask you to email someone and wait. In Rakama, the important controls are built into the app and you can use them yourself, immediately:

  • Get a copy of your data — export your records to a file from the app's settings, at any time, as often as you like.
  • Correct your data — edit or delete any record directly.
  • Erase your financial data — wipe every transaction, budget, goal, bill and split while keeping your login.
  • Withdraw consent to AI categorisation — Settings → Privacy, one switch, effective immediately, and it deletes the merchant mappings your imports created.
  • Delete your account entirely — permanently, from the app's settings.

Depending on where you live, you may also have the right to object to or restrict processing, the right to data portability, and the right to lodge a complaint with your local data-protection authority. To exercise anything not covered by the in-app controls, email privacy@rakama.app. We will respond within 30 days.

We will never charge you for a request, and we will never make you close your account in order to exercise a right.

How we protect it

  • All traffic is encrypted in transit over HTTPS, with strict transport security enforced.
  • Passwords are hashed with bcrypt and are never stored, logged, or recoverable.
  • Session tokens are signed, expire after seven days, are inaccessible to scripts, and are all invalidated at once when you change your password.
  • Sensitive endpoints are rate-limited against brute-force attempts.
  • Every request for data is scoped to the signed-in account, so one user's records cannot be returned to another.
  • Data is encrypted at rest by our database provider.
  • The website sends a strict content-security policy to limit what can run in your browser.

No system is perfectly secure, and we will not pretend otherwise. If we ever discover a breach affecting your personal data, we will notify you and the relevant authority without undue delay, and tell you plainly what happened and what to do.

Cookies and local storage

Rakama uses one cookie: the rakama_token session cookie described above, which exists only to keep you signed in. It is strictly necessary for the service to function, so there is no consent banner to click — there is nothing optional to consent to.

We use no tracking cookies, no third-party cookies, and no cross-site identifiers. Our blog stores one preference in your browser's local storage — whether you want to see phone or desktop screenshots — which never leaves your device and identifies nobody.

Where your data is stored

Our servers and database are hosted in the Asia-Pacific region. Our email and sign-in providers operate globally, which means that if you are in the EU, the UK, or another region with transfer restrictions, your data may be processed outside your country. Where that happens, we rely on the safeguards those providers offer, such as standard contractual clauses.

Children

Rakama is not directed at children and is not intended for anyone under 13. We do not knowingly collect personal data from children under 13. If you believe a child has given us personal data, contact us and we will delete it.

Changes to this policy

We will update this page when what we do changes. The date at the top always reflects the current version. If a change materially affects how we use your data, we will tell you by email or in the app before it takes effect, rather than relying on you to re-read this page.

Contact us

Questions, requests, or concerns about anything on this page go to privacy@rakama.app, or by post to Rana Aazan Mujahid, trading as Rakama, DHA Phase 7, Lahore, Pakistan 54930. We read every message.