Legal

Mobile privacy policy

Effective
18 August 2026
Applies to
The Krediit app for iOS and Android
Sections
15
Website privacy policy

The short version

Your cards, spends and plans live in a database on your phone, backed up to your Krediit account so they can follow you to a new phone — readable by your account alone. We show no ads and no advertising or tracking SDKs, and never sell or share your data. We count anonymous screen views to see which parts of the app get used — never tied to you or to what is in your wallet.

Who we are

Krediit (“we”, “us”) is a credit-card rewards optimizer for India-issued cards, available on Android and iOS. For anything in this policy, contact support@krediit.online.

Data stored on your device

The cards you add to your wallet, spend amounts you enter or import, planned purchases, reward-point balances, Pro status and app settings are stored in a local database on your device. This data never leaves your device unless you sign in (see Backup & sync). Deleting the app deletes it.

Account

Using Krediit requires an account — it keys the backup that lets your wallet follow you to a new phone. If you sign in with Google or Apple, we receive your name and email address from that provider; if you sign up with email, you give them to us directly. Our authentication provider (Supabase) assigns your account an identifier. We use these only to show you're signed in and to key your backup.

Krediit's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Backup & sync (only when signed in)

When you're signed in, your wallet, spends, planned purchases and Pro status are backed up to our database (hosted by Supabase) so they can follow you to a new phone. Row-level security ensures this data can be read and written only by your own account. Syncing can be turned off in Settings, and signing out stops it; to have your backed-up data deleted, email support@krediit.online.

Statement import (optional, Pro)

If you import a statement PDF, it is read entirely on your device: the app extracts only the results — card name, last 4 digits, transaction amount, merchant, date and reward-point balances. The file itself is not uploaded, stored or shared, and no human reads it.

One narrow exception, off by default: if a statement can't be read by the on-device rules or on-device AI model and smart extraction is enabled, the relevant text excerpt is sent over an encrypted connection to our server function, which uses Anthropic's Claude API to return only the structured fields above. The excerpt is processed transiently, never stored, and used for nothing else.

Card catalog & news

The app periodically downloads its card database, themes and the Pulse news feed from our servers. These requests carry standard network metadata (such as your IP address) but no account identifiers, and we don't log or profile them.

Anonymous usage statistics

To learn which screens are worth improving, the app records that a screen was opened — the screen's name only, such as “wallet” or “card detail”. It never records which card, goal, offer or amount you were looking at, what you tapped, or anything you typed.

These counts are processed by Aptabase, a privacy-focused analytics service, and carry no account id, device id, advertising id or any other identifier that persists. Each event includes only your app version, OS version, device model and language, plus a random session id that is discarded after an hour of inactivity — so sessions cannot be joined together into a profile of you, by us or by anyone else. Nothing here is used for advertising.

Purchases

The Krediit Pro subscription is processed by Google Play or the Apple App Store. We never see your payment details; we only record that Pro is unlocked.

What we never collect

No full card numbers, CVVs, PINs, OTPs or banking credentials — Krediit never asks for them and cannot access them. No location, contacts or advertising identifiers. No ad or cross-app tracking SDKs of any kind, and nothing that profiles you across other apps or websites. We do not sell, rent or share your personal data with anyone.

Security

Local data is protected by your device's storage sandbox. Anything synced travels over TLS and is protected by per-user row-level security in our database. Statement passwords you save for encrypted PDFs stay on the device and are never synced.

Deleting your data

On-device data: uninstall the app or clear its storage. Backed-up data: sign out to stop syncing, and email support@krediit.online from your account address to have your backup and account deleted — we complete deletion within 30 days.

Children

Krediit is a credit-card tool and is not directed at anyone under 18.

Your rights & grievances

Under India's Digital Personal Data Protection Act, 2023 you may request access to, correction of, or deletion of your personal data, and withdraw consent at any time. Write to our grievance contact at support@krediit.online; we respond within 30 days.

Changes to this policy

If we change what data is handled or how, we'll update this policy in the app and revise the effective date above before the change takes effect.

Contact us

Questions about this policy, or a request about your data? Reach us directly — there is no ticket system and no form to fill in.

Support hours
Mon–Fri, 10:00–18:00 IST
Response time
Within 48 hours