Privacy
Last updated 11 September 2026
Dhyan Pay is a personal budgeting app run by an individual, not a company. This page says exactly what it collects and why, in the order the law asks for it. It is deliberately short enough to read.
Who is responsible
Hari K, an individual based in India, decides what data Dhyan Pay collects and why — which makes him the data fiduciary under the Digital Personal Data Protection Act, 2023. Contact: info@dhyanpay.in.
What is collected, and what it's for
| Data | Why |
|---|---|
| Your email address | To create your account, sign you in, and reset your password. And, only if you tick the optional box when you sign up or turn it on in Settings, to send you the occasional email about the app itself — a nudge if you set up wallets and then stop using it, and nothing else. That box is separate from the ones you must tick to sign up, it is off unless you turn it on, and turning it off again is one tap in Settings → Alerts. No newsletters, no marketing, and your address is never sold, rented or passed to anyone. |
| Your wallets | Names, icons and the monthly limits you set. This is the budget itself. |
| Your payments | Amount, date, the label you typed, an optional note, which wallet, and whether you confirmed it. This is what produces your balances and your monthly report. |
| Your recurring rules | The label, amount, wallet and day of the month for a payment you've asked the app to log for you every cycle. |
| Your household, if you create or join one | Its name, who is in it, each person's role, and which of your wallets you have shared into it. See when you share a wallet below. |
| A fingerprint of payee UPI IDs (historic) | A short code derived from the UPI ID, never the UPI ID itself, so a shop you had paid before could suggest the same wallet. The app stopped scanning QR codes in August 2026 and no longer creates these; the ones recorded before then are still attached to those payments and are deleted with them. It is a fingerprint for matching, not a secure hash, so it is treated here as your personal data rather than as anonymous. |
| Which payment app the habit gate saw (optional) | Only if you set up the gate's app-check step on your own phone: the moment the gate runs, your device sends which payment app it opened for — nothing else — keyed by a random token that names your device, not you. It is used once, to label the button and open the right screen, and is read once and deleted as the app picks it up; an unclaimed one is swept within minutes. |
| Your alert settings | Your chosen alert style, threshold and reminder timing, plus a browser push token if you turn on notifications, so alerts can reach you. |
What is never collected
- Your bank account, card details, account balance or UPI PIN. The app has no connection to your bank and never asks for one.
- The UPI IDs or phone numbers of people you pay, in readable form.
- Your SMS messages. Dhyan Pay does not read messages, ever.
- Your contacts, your location, or any advertising identifier.
- Aadhaar, PAN, or any KYC document.
What stays on your phone only
Which UPI apps you have, which one you prefer, your light or dark theme choice, and an offline copy of your own data so balances still show without a signal. These never leave the device and are not sent to any server — the gate’s optional app check above is the one exception, and only if you build it.
When you share a wallet
Wallets are private until you deliberately share one into a household. Once you do, everyone in that household can see every payment in that wallet — its amount, date, label, note, and who made it — and members can add payments to it. That is the point of the feature, but it is the one place where your data becomes visible to another person, so it is worth being exact: you share wallet by wallet, the wallets you don't share stay yours alone, and joining a household exposes nothing about your other wallets, your limits, or your balances.
A shared wallet is a shared counter, not a joint account. Dhyan Pay still holds no money and settles nothing between members.
If you delete your account, payments you added to a shared wallet stay in that ledger, detached from your account and no longer carrying your name. Everything else goes — see your rights below.
Analytics
This website counts its own page views, and measures how quickly its pages load, through Vercel, the service that already hosts it. The counter sets no cookie, stores no IP address, and tells one visit from another by a hash that is discarded within a day, so it cannot be tied back to you. The speed measurement records how long the page took to draw, along with the kind of device, browser and connection it was drawn on, and nothing about who you are. These are the only scripts this site loads that we did not write, and both are served from this same address — the site still loads no fonts, no beacons and nothing else from anyone.
There is still no Google Analytics, no Facebook pixel, and no third-party advertising or tracking on this site or in the app. Nothing about you is shared with an advertising company.
The app keeps no usage counts. Nothing about how you use it — which screens you open, which buttons you press — is counted, stored or sent, by us or by anyone else. It briefly did in August 2026; that was switched off, and everything it had recorded has been deleted.
If the app crashes on your phone it records the error message and which screen it happened on, in that same database, so it can be fixed. That carries none of your money data either.
Where it's stored, and who else touches it
In a Supabase database hosted in Mumbai, India, and served through Vercel. Both are processors acting on instructions; neither uses your data for their own purposes. Your account and everything in it is stored in India and is not moved out of it. That includes the crash reports above, and anything you send through Help & feedback — messages and attached files live in the same Mumbai project, visible only to you and to us. Apart from a wallet you have deliberately shared into a household, no other user of Dhyan Pay can see any of your data.
Two services sit outside India, and this is the whole of what each one gets:
- Brevo delivers email. To send you a confirmation link, a password code, or an app email you asked for, your address and the contents of that one message pass through Brevo's servers in the European Union. They are a processor under contract, they do not use your address for anything of their own, and they receive nothing else — not your wallets, not your payments, not your balances.
- Google's Gemini helps word the optional app emails, and is given nothing about you whatsoever. See the next section, because that sentence is worth being exact about.
How the optional emails are worded
If you turn those emails on, some of the wording is drafted by an AI model — Google's Gemini — so that an automated sequence doesn't arrive as the same form letter several times over.
It is given no personal data to do that. Not your email address, not a name, not an amount, not a wallet name, not a date, not an identifier of any kind. It is told only which of a small handful of situations applies — "set up wallets, never recorded a payment" is a whole example — and it writes one paragraph of encouragement around that. Your own figures are put into the email afterwards, here, on our own servers, and never reach the model. Anything it writes that contains a number is thrown away and replaced with wording written by hand, so it can never state a figure about your spending.
Your rights
You can do all of these yourself, inside the app, today:
- See your data — Settings → Export everything as CSV gives you every payment in a plain file.
- Correct it — any payment's amount, label, note, date and wallet can be edited or deleted.
- Erase it — Settings → Delete everything removes your account and your rows from the database for good. It is not a soft delete and it is not recoverable. One exception: payments you added to a wallet shared with a household stay in that shared ledger, detached from your account and no longer carrying your name, because deleting them would rewrite balances the other members still rely on. If you owned the household, it passes to whoever joined it first.
- Withdraw consent — the optional app emails go off in Settings → Alerts, one tap, with nothing else about your account affected. For the data the app needs in order to be the app at all, deleting your account is how that consent is withdrawn, and it takes the same number of taps as signing up did.
- Nominate someone — if you want another person to exercise these rights on your behalf, write to the address above.
How long it's kept
Until you delete it. If an account goes unused for twelve months, you'll get an email first, and then it is deleted. Server logs from Supabase and Vercel roll off on their own schedule, about a year, and are used only to investigate faults.
If something goes wrong
If there is ever a breach involving your data, you will be told directly and in plain language — what happened, what it means for you, and what is being done — and the Data Protection Board will be notified. There is no threshold below which you would not be told.
Children
Dhyan Pay is for adults. By creating an account you confirm you are 18 or older. Accounts found to belong to children will be deleted.
Complaints
Write to info@dhyanpay.in and you will get a reply within seven days — see the contact page. If you aren't satisfied, you can complain to the Data Protection Board of India.
Changes
If this page changes in a way that affects what is collected or why, the app asks you again rather than assuming. The next time you open it you will see what changed, with a box to tick for each document, and declining and signing out is offered in the same breath — carrying on without asking would mean relying on an agreement you never gave. The date at the top always reflects the current version.