Legal
Last updated: May 2025
Niaa FinOps ("Niaa", "we", "our") is a personal finance manager built for East Africa. This policy explains what data we collect, how we use it, and the choices you have. We keep it plain — if something is unclear, email us.
When you create an account: your name, email address, and a hashed password.
When you add transactions manually: the amount, date, category, and notes you enter.
When you enable SMS auto-parsing: parsed transaction data extracted from M-Pesa and bank SMS messages on your device. Raw SMS messages are never sent to our servers.
When you scan a receipt: the image you upload and the structured data we extract from it.
Usage data: device type, app version, screen views, and feature interactions — collected to improve the product.
To provide the service: displaying your accounts, transactions, budgets, reports, and loan tracker.
To improve the product: understanding which features are used and where friction exists.
To communicate with you: account-related notifications such as budget alerts or payment reminders you configure.
We do not sell your data to third parties. We do not use your financial data to serve advertising.
Niaa requests permission to read SMS messages from financial senders you choose (e.g. Safaricom, NCBA, KCB, Equity). This permission is entirely optional.
SMS parsing runs locally on your device. The raw message content is never transmitted to our servers.
Only the structured output — amount, merchant, date, and transaction type — is uploaded and stored.
You can disable SMS access at any time in Settings › SMS sources, or by revoking the permission in your device settings.
Your data is stored on servers hosted in the European Union (Supabase / AWS eu-west-1).
All data is encrypted in transit using TLS 1.2 or higher.
Passwords are hashed using bcrypt and are never stored in plain text.
We use row-level security (RLS) policies so that your data is accessible only to your account.
We retain your data for as long as your account is active. If you delete your account, all personal data is permanently removed within 30 days.
Supabase — database and authentication infrastructure.
Firebase Cloud Messaging — push notifications (device token only; no message content is shared).
Google ML Kit — on-device OCR for receipt scanning. Images are not sent to Google.
Sentry — crash reporting (anonymised stack traces; no financial data is included).
Access: you can export all your data to Excel from Settings › Export at any time.
Correction: you can edit or delete any transaction, account, or category directly in the app.
Deletion: you can permanently delete your account from Settings › Account › Delete account.
Portability: exported Excel files are in a standard format readable by any spreadsheet app.
To make a formal data request or report a concern, email us at privacy@niaa.app.
Niaa is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it promptly.
We may update this policy as the product evolves. When we make material changes, we will notify you in the app and update the "Last updated" date below. Continued use of Niaa after the effective date constitutes acceptance of the updated policy.
For privacy questions or requests, contact us at privacy@niaa.app.
Niaa FinOps — Nairobi, Kenya.