Permission Usage
Why PocketPaisa asks for permissions.
PocketPaisa is a personal ledger that keeps your records on your device by default. Signing in and cloud backup/sync are optional and only happen when you start them. Optional transaction location always remains local and is excluded from backup, sync, CSV export, and data reporting. This page explains each permission the app declares and how it is used.
Effective dateJuly 10, 2026
Data handlingTransaction location always stays local
Your Records Stay On Your Device
PocketPaisa stores your transactions, SMS drafts, receipts, and any optional transaction location in local app storage. You can use the app for manual expense and income tracking without signing in. Creating an account and backing up or syncing eligible ledger fields to our cloud are optional and only happen when you choose to start them. Transaction location is always excluded from cloud backup and sync, CSV export, and data reporting.
PocketPaisa's connections to its gateway server are encrypted in transit. See the Internet permission below for exactly when and why the network is used. Sensitive permissions are requested only when you open a feature that needs them, and you can deny any of them and keep using manual tracking.
Declared Permissions
S
Read SMS
Sensitive optional access
Android permission: android.permission.READ_SMS
Used for: reading recent bank, UPI, wallet, and card transaction messages on your device so PocketPaisa can create pending income or expense drafts for your review.
When used: only after you choose "Import SMS Transactions" and grant permission. The app scans recent inbox messages from the last 90 days, skips OTP and verification-code messages, and shows matching transaction drafts you can confirm, edit, or ignore.
What is not done: PocketPaisa does not send SMS messages, does not read call logs, and does not use SMS data for advertising. Parsed drafts are stored only in local app storage, and the raw SMS text is not uploaded.
I
Internet
Network access
Android permission: android.permission.INTERNET
Used for: the optional account sign-in (phone number and one-time code), the optional cloud backup and sync of eligible ledger fields that you start yourself, install measurement, and loading in-app web content.
When used: account sign-in and cloud backup/sync run only when you choose to sign in or start a backup or sync; eligible ledger fields are sent to our gateway only in that case. PocketPaisa also uses a measurement service (Adjust) to understand how the app was installed, which may involve a device advertising identifier. Network access is also used to load web content shown inside the app. If you choose Add location, Android's system Geocoder may process approximate coordinates over a network through the geocoding provider configured by your device.
What is not done: PocketPaisa's connections to its gateway are encrypted in transit. Signing in and cloud backup/sync are optional. Transaction location, raw SMS text, and receipt photos are never uploaded to the PocketPaisa gateway.
N
Network State
Normal permission
Android permission: android.permission.ACCESS_NETWORK_STATE
Used for: checking locally whether a network connection is available so PocketPaisa can handle offline states before using a network-dependent feature.
When used: as needed before or while a network-dependent feature is used. This is an Android normal permission that is granted automatically at installation and does not display a runtime permission prompt.
What is not done: this permission does not itself provide internet access and does not let PocketPaisa read the contents of network traffic. Network availability status is not retained or uploaded.
L
Approximate Location
Sensitive optional access
Android permission: android.permission.ACCESS_COARSE_LOCATION
Used for: adding optional approximate location information, such as a city or area label, to a transaction at your request.
When used: only after you choose Add location while adding or editing a transaction and grant permission. PocketPaisa accesses an approximate foreground location for that action. Android's system Geocoder may resolve the approximate coordinates on the device or may send them over a network to the geocoding provider configured by your device to return a readable city or area label.
What is not done: transaction location is stored only in local app storage and is excluded from PocketPaisa cloud backup and sync, CSV export, and data reporting. PocketPaisa does not request precise location, does not request background location, and does not continuously track you. PocketPaisa does not send transaction location to its own gateway server.
C
Camera
Optional receipt feature
Android permission: android.permission.CAMERA
Used for: taking a receipt photo that can be attached to a transaction.
When used: only after you tap the receipt action while adding or editing a transaction and grant permission. You may also pick existing images from your gallery instead, which does not require this permission. Receipt photos are saved in app storage on your device and are not uploaded.
Managing Permissions
You can change the optional runtime permissions for SMS, Camera, and Approximate location from Android Settings at any time. If one is turned off, the related optional feature may be unavailable until you grant permission again. Internet and Network State are Android normal permissions: they are granted automatically at installation and do not display runtime permission prompts.
For privacy questions about permissions, contact [email protected].