Privacy Policy
Challan is developed and operated by Sankit Acharya as an independent developer ("we", "I"). This policy explains what data the Challan app collects, why, and what happens to it. The short version: your data is used to run the app for you — it is never sold, never used for advertising, and never shared beyond the service providers needed to operate the app.
What we collect
| Category | Data | Why |
|---|---|---|
| Account | Email address, name, and profile picture (if you sign in with Google), or phone number (if you sign in with phone verification) | To create and secure your account |
| Fleet & finance | Assets you register (vehicles and equipment), challan records (job / receipt details), expenses, and related notes you enter | This is the core function of the app: tracking income and costs per asset |
| Documents & photos | Images you upload (for example challan scans or vehicle documents such as an RC) and structured fields extracted from them | To store your records and help fill in details via OCR |
| Device | A push-notification token for your device | To deliver notifications you enable |
Document photos and OCR
When you photograph or upload a challan or vehicle document:
1. The image is stored privately in Google Cloud Storage, linked to your account, and served back to you through short-lived access links.
2. The image may be sent to Google's Gemini API to extract structured fields (for example vehicle or challan details). Google processes this data as a service provider to deliver the analysis result; it is governed by the Google Cloud terms, under which customer data is not used to train Google's models.
Service providers
Challan's backend runs on Google Cloud Platform. The providers that process your data on our behalf are:
| Provider | Purpose |
|---|---|
| Firebase Authentication | Sign-in (Google or phone number) |
| Google Cloud Run | Hosting the app's backend |
| Managed PostgreSQL | Hosting account, fleet, and finance data |
| Google Cloud Storage | Storing document and challan photos |
| Google Gemini API | OCR / document field extraction |
| Firebase Cloud Messaging | Push notifications |
No other third party receives your personal data.
Retention and deletion
Your data is kept for as long as your account exists. When your account is deleted, account details, fleet and finance records, and stored photos associated with your account are permanently deleted. See how to delete your account. Routine operational logs (used for debugging and service health) are not a substitute for your records and expire automatically.
Security
All data is transmitted over encrypted connections (TLS) and stored with encryption at rest by the hosting providers above. Access to your data requires your authenticated session; there is no public access to any of it.
Your rights
You can access your logged data in the app at any time. You can delete individual records in the app where that action is available, or delete your entire account and associated data. Depending on where you live, you may have additional legal rights (such as access, correction, portability, or erasure under GDPR or similar laws) — to exercise any of them, contact us at the address below.
Children
Challan is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and it will be deleted.
Changes
If this policy changes materially, the effective date above will be updated and the app will point to the current version at this address.
Contact
Questions or requests about your data: challan.app@sankit.dev