Effective date: 29 September 2026 · Replaces the version of 15 August 2026
This Privacy Policy describes how the Ritikal Android application ("Ritikal", "we", "our", "the App") handles your information. Ritikal is a personal "Life OS" for Nepal: a Bikram Sambat calendar and panchanga, tasks and events, a journal, personal finance, and a document vault.
The short version: Ritikal works fully offline, and everything you create is stored encrypted on your device. Nothing leaves your device unless you use a feature that needs it: signing in for cloud sync, AI features (which also need you to be signed in), or sharing a file yourself. There are no ads, no analytics and no tracking SDKs, and we never sell your data.
Everything you enter is stored in the app's private storage on your device, in a database encrypted with SQLCipher (256-bit AES). Journal text is additionally encrypted with AES-256-GCM. Encryption keys are kept in Android's secure storage (Android Keystore); we have no access to them. This includes:
You can use Ritikal without an account. If you sign in, with an email link or with Google, we create an account so your records can sync between your devices and so you can use AI features.
When you are signed in, the following is sent over an encrypted (TLS) connection to our database, hosted by our cloud provider Supabase:
Row-level security rules in the database ensure that only your signed-in account can read or change your records. We do not look at your records, and we do not use them for any purpose other than syncing them back to you.
AI features are available only when you are signed in, and only while AI is switched on in Settings. When they are on, Ritikal reads what you capture and suggests a task, event, note or transaction from it. To do that, the content is sent through our server function to Google's Gemini API, which returns a structured result:
Documents in the Vault are never sent to AI; their text recognition runs on your device.
Our server function does not store the content. It passes it to Google and returns the answer. We keep only a monthly count of your AI requests, to enforce a fair-use limit.
Google receives the content under the Gemini API Additional Terms of Service and the Google Privacy Policy. Under those terms Google may keep content sent to the Gemini API and use it to provide, improve and develop its products, which can include review by human reviewers. For that reason, don't use AI features on anything you would not want Google to see. You can switch AI off at any time, and nothing is sent while it is off.
On Android, Ritikal can read your SMS inbox to find bank and mobile-wallet transaction alerts, so you don't have to type every transaction by hand. Before Android asks you for the SMS permission, Ritikal shows a screen explaining what will be read and why, and asks only if you choose Continue.
Every permission is optional and requested only when you use the feature that needs it:
| Permission | What it is used for |
|---|---|
| SMS (read) | Finding transaction alerts in your inbox, as described in Section 4. |
| Location | One reading, when you ask for panchanga at your own location, to compute sunrise, sunset and tithi there. It stays on your device and is not synced. Without it, Kathmandu is used. Ritikal never tracks your location in the background. |
| Contacts | Letting you pick one contact for a lend/borrow record. Only that contact's name and phone number are saved. Your contact list is not read or uploaded. |
| Camera | Scanning documents into the Vault, and photo capture. Text recognition (OCR) of scanned documents runs on your device. |
| Microphone | Voice capture. Speech-to-text uses your device's speech recognition service, provided by Android (usually Google), under its own terms. |
| Notifications, alarms and reminders | Showing the reminders you set, at the time you set them. |
| Biometrics | The optional app lock. Your fingerprint or face is checked by Android; Ritikal never receives it. |
Photos and files are chosen through Android's own photo and file pickers, so Ritikal has no access to the rest of your gallery or storage.
We do not sell, rent or trade your data, and we do not share it for advertising. Data leaves your device only to the following companies, and only for the features described above:
When you share or export something yourself (for example, a backup file sent by email), the app or service you choose handles it.
You can export a .ritikal backup file, optionally protected by a passphrase (AES-256-GCM, with the key derived from your passphrase using PBKDF2 at 120,000 iterations). The file is saved wherever you choose. We cannot read it or recover a forgotten passphrase.
On-device data is encrypted at rest (SQLCipher and AES-256-GCM, as above). All network traffic uses TLS. Cloud records are protected by per-account row-level security. No system is perfectly secure, but we design Ritikal so that as little as possible leaves your device in the first place.
Ritikal handles financial records, bank SMS messages and identity documents, and is intended for adults (18 and over). It is not directed at children, and we do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will delete it.
We update this policy when the app changes how it handles data. The effective date at the top shows the latest version, and material changes are noted in the app's release notes.
Questions about this policy or your data, including deletion requests: sunya.shuvashis@gmail.com. Website: ritikal.app.