JamaBook

Effective 27 September 2026 · Version 1.0

Privacy policy

What JamaBook collects, what it never collects, and what you can do about it. Written to India's Digital Personal Data Protection Act, 2023.

§1 Roles

Two kinds of data, and why the difference matters

JamaBook holds data about you, the lender, and data you enter about your customers. These are not the same thing in law.

For your own account details, Bytexus Software Solutions Pvt. Ltd. is the Data Fiduciary. For the customer records you enter, you are the Data Fiduciary and we act as your Data Processor — we store and sync that information on your instruction and never use it for our own purposes. Obtaining your customers' consent to record their details is your responsibility, not ours.

§2 Collection

What the app stores

Collected

  • Your mobile number, for the OTP that signs you in
  • Your name, business name, business phone and receipt footer
  • Customer records you enter: name, phone, address, area, code
  • Loans, instalments, receipts and their amounts
  • A device identifier, so your phones sync to one book

Never collected

  • Your SMS messages
  • Your phone contacts
  • Your location, at any precision
  • Photos, camera or microphone
  • Your call log or device phone state

The right-hand column is enforced, not promised. Those permissions are stripped from the app at build time, so the operating system refuses the request even if the code asks. Predatory loan apps in India are known for harvesting exactly these; JamaBook cannot, by construction.

Where it is stored

On your phone, in an app-private database only JamaBook can read, and on our servers at api.jamabook.in, hosted in India. Your PIN is held in the Android keystore, never in the database — so a copied backup file does not carry it. All transfers use HTTPS.

§3 Analytics

Analytics

If you leave analytics on, JamaBook sends anonymous usage events through Google Firebase Analytics — which screens are opened, whether a collection was saved offline, how a receipt was shared, and your book's size as a bucket such as "11–50 customers".

No customer name, phone number, address or rupee amount is ever included in an analytics event. This is enforced in the app's code, not merely in policy: an event may carry only numbers, true/false values and a fixed list of words, so free text — where a name could hide — cannot be attached to one.

Firebase processes this data on Google servers outside India. You can switch analytics off at any time under Settings → Security. Turning it off stops collection, not merely sending, and discards anything queued on the phone.

§4 Advertising

Advertising

The free plan shows banner ads from Google AdMob. To serve them, the Google Mobile Ads SDK accesses your device's advertising ID — a resettable identifier that is not your name and not your phone number. You can reset or delete it in Android Settings → Privacy → Ads.

Your customer records and loan amounts are never shared with advertisers. The paid plan shows no ads at all.

Ads never appear on the Collect screen or on a receipt — the two places where a mis-tap costs real money, or where an advert would make proof of payment look like marketing.

§5 Your rights

Your rights under the DPDP Act

  • Access — request a copy of what we hold about you
  • Correction and erasure — have it corrected or deleted
  • Withdraw consent — turn analytics off, or close your account
  • Grievance redressal — raise a complaint with the officer named on our contact page, and escalate to the Data Protection Board of India if it is not resolved

To exercise any of these, write to nitin@bytexus.com. We respond within 30 days.

Deleting your data

Logging out removes the book and the PIN from that phone. To erase your account and its server records permanently, email nitin@bytexus.com from your registered number's address. Deletion is permanent — export your CSVs first if you need them.

Retention

Records are kept while your account is open, because a lending ledger is a running account that must reconcile over years. After account closure we delete or anonymise within 90 days, except where law requires us to keep records longer.

Children

JamaBook is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

Changes to this policy

Material changes will be announced in the app before they take effect. The date at the top of this page always reflects the current version.

§6 Data safety

Data safety summary

This mirrors the declarations made in the Google Play Data Safety form.

Data types and handling
Data typeCollectedSharedPurpose
Phone numberYesNoSign-in by OTP
Name, business detailsYesNoPrinted on receipts
Customer records you enterYesNoApp function; sync across your devices
Financial records (loans, receipts)YesNoApp function
App interactionsOptionalGoogle FirebaseAnalytics — anonymous, opt-out in Settings
Advertising IDYesGoogle AdMobAdvertising on the free plan
Crash and diagnosticsOptionalGoogle FirebaseFixing faults
LocationNoNo—
ContactsNoNo—
SMS messagesNoNo—
Photos, camera, microphoneNoNo—

Data is encrypted in transit. You can request deletion of your account and its records at any time.

§7 Permissions

Every permission the app requests

The complete list, as declared in the installed app. None of these prompts you, and none reads your personal content.

Android permissions — com.jamabook.app 1.0.0
PermissionWhy
INTERNETSync your book to the server
ACCESS_NETWORK_STATEDetect when you are offline, so saves queue instead of failing
ACCESS_WIFI_STATEThe same, for Wi-Fi
VIBRATEThe short buzz confirming a collection saved
USE_BIOMETRIC, USE_FINGERPRINTUnlock with a fingerprint instead of the PIN
FOREGROUND_SERVICEFinish a sync that is already running
ACCESS_ADSERVICES_AD_IDThe advertising ID, for ads on the free plan
ACCESS_ADSERVICES_TOPICS, ACCESS_ADSERVICES_ATTRIBUTIONGoogle's Privacy Sandbox ad delivery
BIND_GET_INSTALL_REFERRER_SERVICEWhich campaign led to an install — not who you are