Lekka — Privacy Policy

Effective date: 23 September 2026

Applies to: Lekka for Android, in India.

Lekka is published by Der Jidan, an individual developer based in Karwar, Karnataka, India. Throughout this policy, “I” means that person and “Lekka” means the app.

The short version

Lekka reads your bank’s SMS alerts on your phone, works out what you spent, and keeps a ledger. Your messages never leave your device. There is no account, no login, and no server holding your spending.

I cannot see your transactions. Not because I promise not to look — because the app never sends them anywhere, and contains no code that could.

One thing changed in this version: Lekka now counts four anonymous events so I can see where people get stuck during setup. Your ledger is not part of that and never will be. Section 3 lists all four, in full.

1. What Lekka reads, and where it goes

Lekka needs SMS permission. Here is exactly what it does with it.

ReadMessages in your inbox from a list of known bank and payment senders
Ignored entirelyEverything from any other sender — never parsed, never stored
ExtractedAmount, date, payee name, last four digits of the account, reference number
StoredThe extracted fields above, on your phone only
Never storedThe text of the message itself
Never transmittedAll of the above

The message body is never written to storage. Lekka keeps a one-way SHA-256 fingerprint of each message so it can tell when the same alert arrives twice; a fingerprint cannot be turned back into the message.

Messages that are not transactions — one-time passwords, promotional messages, balance notices, card statements — are recognised and discarded before anything is stored.

2. What is on your phone

Your ledger is stored in an encrypted database on your device (SQLCipher). The encryption key is held in the Android Keystore, which is hardware-backed on most modern phones. Neither the key nor the database leaves your phone.

Uninstalling Lekka deletes it.

3. What leaves your device

Nothing from your ledger. Not an amount, not a payee, not a message, not a balance, not a category, not a goal. None of it, by any route, ever.

There is still no account to sign into, nothing to sync, and no server holding your spending, because there is no server. I have no database of your transactions and no way to build one.

What does leave, from this version onward, is a count of four events, sent to Google Analytics for Firebase. I use it to see where people abandon setup. This is why Lekka now holds Android’s internet permission, which earlier versions did not — and it is the only reason.

3.1 The four events, in full

This is not a summary. The app has exactly four analytics calls and these are all of them:

You allowed SMS accessnothing
You did not allow SMS accesswhether you declined at Android’s own dialog, or skipped before reaching it
Setup finishedwhether SMS reading ended up switched on or off
An expense was addedwhether you typed it, confirmed it from a bank message, or filed it from a notification — and whether it had a category

No amount. No payee. No merchant. No category name. No account number. No text from any message. Not in these events and not anywhere else.

That is enforced by how the code is written, not only by intent: there is no general-purpose “log this” call in the app. Each of the four is a separate method that cannot accept a sum of money, a name, or a piece of text, so there is no route by which one could be added by mistake. Adding a fifth event means writing a fifth method, which is a change anyone reading the code can see.

3.2 What Google records on its own

Any app using this tool also reports, without the app asking: a per-install identifier, your device model, your Android version, the app version, and an approximate country worked out from your IP address.

Lekka switches off the parts of that which follow a person between apps — the advertising ID, the Android ID (SSAID), and ad-personalisation signals — and the advertising-ID permission is removed from the app entirely, so it is not merely unused but absent.

There is no in-app switch to turn analytics off today. I would rather write that plainly than imply a control that does not exist.

3.3 Payments

There is no paid tier today, and Lekka takes no money. The app contains no billing code of any kind, which is why its Play listing declares no in-app purchases — another claim you can check rather than take on trust.

If a paid tier is ever added it will run through Google Play’s own billing flow: card details would go to Google and never to me, and I would have no way to receive them. This policy will be updated before that ships rather than after.

3.4 What may be added later, and what it would mean

When a bank changes the wording of its alerts, Lekka stops recognising them. Fixing that faster would be easier if I could see the shape of a message that failed to parse.

That feature is not built. If it ships, it will be opt-in and off by default, and this policy will be updated before it ships rather than after. What would be sent is a version of the message with every digit destroyed — no amounts, no account numbers, no names, no UPI IDs — and only for messages that failed. Messages Lekka understood teach me nothing and would never be eligible.

I describe it here because it is the honest shape of my intent, not because it is running. Today, nothing from a message leaves — only the four counts in §3.1.

4. What Lekka never does

  1. No advertising. No ad SDKs, no ad IDs, ever. This is a permanent commitment, not a current state.
  2. No data brokers. Your information is not sold, rented, or shared for anyone’s marketing.
  3. No analytics on your spending. The counts described in §3.1 measure what you did — allowed a permission, finished setup, added an expense. They never measure what you bought, where, or for how much. No amount or merchant name is sent, in any event, ever.
  4. No third-party SDK can read your messages. Google Analytics is the only third-party component in the app. It has no access to your messages, your ledger, or the database, and what it can send is the closed list in §3.1.
  5. Lekka never holds, routes, or moves money. It cannot make a payment. It reads alerts about payments you made yourself. When you record money moved into a savings goal, you moved it — in your own banking app — and told Lekka afterwards.

5. Your data, your control

Because there is no account and no server copy of your ledger, there is nothing of your spending for me to delete on your behalf — I never had it.

The one exception is the analytics counts in §3.1. Those sit on Google’s servers rather than mine, tied to a per-install identifier and not to you by name, phone number or email. Google deletes them on its own retention schedule; I can also erase the whole set from the Firebase console. If you want that done, write to the address in §8 — though be aware that without a name or an account attached, the honest thing I can offer is erasing everything rather than finding your rows specifically.

If a server-side account is ever introduced, this policy will be updated before it ships, not after.

6. Children

Lekka is not directed at children and is not intended for anyone under 18.

7. Changes to this policy

The effective date at the top always reflects the current version. If this policy changes in a way that affects what Lekka does with your data, the change will be made here before the behaviour changes in the app, not after.

8. Contact and grievances

Under the Digital Personal Data Protection Act, 2023, you may contact me about how your data is handled, and you may escalate to the Data Protection Board of India if you are not satisfied with the response.