Genesis

Privacy Policy

What we hold,
and what we don't.

Genesis is a personal finance organizer. Your records are stored encrypted on your own device. Three things leave it, each only in a specific circumstance, and they are all listed below.

Last updated 28 July 2026 StableVersion Apps Data Fiduciary under India's DPDP Act, 2023

Stays on your device
Transactions, balances, net worth
Budgets, goals, categories
Documents and receipts
Notes
Your encryption keysiOS Keychain / Android Keystore
Leaves your device
Email, name, photoOnly if you sign in — the app works without an account
Receipt textOnly when you scan. Never the image.
Anonymous usage dataOnly with your consent. Off by default.
Balance Nothing on the left is readable by us. We never receive it.
01

Who we are

Genesis is operated by StableVersion Apps. For the purposes of India's Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for the personal data described here.

Privacy and grievance contact: stableversionapps@gmail.com

02

What stays on your device

Your accounts, transactions, balances, budgets, goals, categories, assets, liabilities, savings, notes, reminders and attached documents are stored only on your device, in a database encrypted with SQLCipher using AES-256. The key is generated on your device and held in the iOS Keychain or the Android Keystore.

Documents and receipt images you attach are encrypted individually with AES-256-GCM under per-document keys in the same secure storage.

03

What we collect, and why

DataWhyWhen
Email, display name, profile photo To create and identify your account Only if you sign in with Google or Apple. Genesis works fully without an account.
Receipt text — not the image To read the merchant, amount and date so you do not type them Only when you scan a receipt. See section 05.
Anonymous product analytics — screens opened, features used, app and device version, crash information To see which features are used and to fix faults Only if you turn on “Share usage data” in Settings. It is off by default.
Backup archive To let you restore your data Only if you enable Google Drive backup. Stored in your own Drive, in a private folder we cannot browse, encrypted with a passphrase you choose. We never receive it.
04

What we never collect

  • Bank credentials. Genesis connects to no bank. Every figure in the app is one you entered.
  • Your transactions or balances. They stay on your device. There is no sync path that sends them to us.
  • Receipt or document images. Text recognition runs entirely on your device.
  • Screen recordings. Session replay is disabled in the app and cannot be switched on remotely.
  • Advertising identifiers. We do not track you across other apps or sites, do not sell personal data, and do not use it for advertising.
  • Location, contacts, calendar, microphone or SMS. The app does not request these permissions.
05

Receipt scanning, and the AI involved

When you scan a receipt, text recognition runs on your device using Google ML Kit. The photograph never leaves your phone.

The recognised text is then sent to our server, which forwards it to a third-party AI provider that extracts the merchant, amount, date and a suggested category. Receipt text can contain a merchant name and address, the items you bought, and occasionally the last four digits of a card. It is used only to return those fields to you, is not used to train any model, and is not retained after the request completes.

If you would rather that did not happen, do not use receipt scanning. Every field can be entered by hand, and nothing else in the app sends anything to an AI provider.

06

Who else is involved

ProcessorWhat they handleWhere
SupabaseAccounts and sign-in; relaying receipt text per section 05Cloud hosting
Google — Sign-In, Drive, ML KitAuthentication; your own backups; on-device text recognitionYour Google account / your device
AppleSign in with Apple
AI extraction providerReceipt text only, per section 05
PostHogAnonymous analytics, only if you opt inUnited States

Each is bound by contract to handle data only on our instructions. Data may be processed outside India; where that happens, it is because the service you are using is hosted there.

07

How long we keep things

  • On your device: until you delete it or uninstall the app.
  • Account data: until you delete your account.
  • Receipt text: not retained after extraction completes.

Minimal processing logs are kept for one year, including after account deletion. Rule 8(3) of India's DPDP Rules, 2025 requires this and states it applies even where the person has deleted their account. We keep the minimum the rule requires, use it for nothing else, and erase it when the year is up.

08

Your rights

  • Access — everything is visible in the app, and Settings → Export produces a full CSV.
  • Correct or update — directly in the app.
  • Erase — Settings → Delete Account, or the web deletion page.
  • Withdraw consent — analytics can be switched off in Settings, as easily as it was switched on.
  • Nominate someone to exercise these rights on your behalf on death or incapacity — write to us.
  • Complain — to us, and afterwards to the Data Protection Board of India if you are not satisfied.

Write to stableversionapps@gmail.com. We respond within 90 days, and usually far sooner. Please include the email address on your account so we can identify you.

09

Deleting your account

Deletion removes your account and the data we hold, from the app or from the web. Full details and the request route are on the account deletion page.

Because your records live on your device rather than with us, deleting the account removes the sign-in details we hold; deleting from inside the app removes the records on the device as well. The one exception is the processing logs described in section 07.

10

Children

Genesis is not intended for anyone under 18. We do not knowingly collect data from children, and we do not carry out behavioural monitoring or targeted advertising in any case. If you believe a child has given us personal data, contact us and we will delete it.

11

Security

The database is encrypted at rest with SQLCipher. Documents are encrypted individually. Keys are held in platform secure storage. All network traffic uses HTTPS. Screenshots and app-switcher previews are blocked on both platforms. Server-side access is restricted per user by database row-level security.

No system is perfect. If you find a security issue, please write to us — we would rather hear from you than not.

12

Changes

If we change how we handle your data, we will update this page and, where the change is significant, ask for your consent again rather than assume it.