Privacy policy
Last updated:
The short version. Lipi is a personal finance app. We collect what you put into it and the minimum needed to run it safely. We don’t show ads, we don’t sell or share your personal data, and we don’t ask for your bank login. You can get a copy of your data or have it deleted at any time.
Who we are
Lipi is operated by Lipi Technology, based in Nepal (“Lipi”, “we”, “us”). We are the data controller (called a “data fiduciary” under India’s DPDP Act) for the personal data described here.
- General support: [email protected]
- Privacy questions, requests and complaints (our grievance officer inbox): [email protected]
We have not yet appointed a representative in the European Union or the United Kingdom. We will name one here if our use in those regions requires it. Until then, people in the EU and UK can reach us directly at the privacy address above, and we will answer in the same way.
This policy covers the Lipi app at app.lipi.com.np, the website at lipi.com.np, and the Lipi API that both use.
What we collect
Information you give us
- Account details: your name, email address and password. We never store your password itself, only a one-way hash of it.
- Google sign-in: if you sign in with Google, Google tells us your name, email address and Google account identifier. We do not get your Google password or access to anything else in your Google account.
- Your financial records: everything you enter into Lipi, including accounts and balances, transactions, categories, tags, notes, budgets, recurring items, loans, assets, and, on Premium, invoices and the client details you add to them.
- Attachments: receipts and other files you upload.
- Preferences: language, theme, currency, date format, notification settings and similar choices.
- Messages to us: anything you send to support or the privacy inbox.
When you add details about other people, such as a client’s name and email on an invoice, you are responsible for having a right to share them with us. We only use them to provide the feature you are using.
Information collected automatically
- Session and device information: for each signed-in session we record a device name, your browser’s user agent, IP address and when the session was last used, so you can see and sign out of your sessions.
- Account activity: when you sign in, and a log of changes made in your account, such as creating or editing a record. This lets us support you, investigate problems and keep an audit trail.
- Server logs: IP address, time, requested address, response status and similar technical details. We use them for security, abuse prevention (for example, limiting repeated sign-in attempts) and fixing errors.
What we don’t collect
We do not ask for or collect your bank or wallet login details. We do not collect your precise location, contacts, advertising identifiers or browsing activity on other sites. We do not use tracking or advertising cookies on the app or the website.
How we use your information
We use personal data only for the purposes below. For people in the EU and UK, the table also gives our legal basis under the GDPR.
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Create your account and sign you in | Account details, Google sign-in data, session information | Performing our contract with you |
| Store, sync and show your records, and run features such as budgets, reports and reminders | Financial records, attachments, preferences | Performing our contract with you |
| Send service emails, such as email verification, password reset and important notices | Name, email address | Performing our contract with you |
| Keep Lipi secure, prevent abuse and fraud, and enforce our terms | Session information, activity log, server logs | Our legitimate interest in protecting users and the service |
| Diagnose problems and improve reliability | Server logs, activity log | Our legitimate interest in running a working service |
| Answer your support and privacy requests | Messages, account details | Performing our contract, or our legal obligations |
| Manage Premium and record payments | Account details, plan and payment records | Performing our contract; legal obligations for accounting |
| Comply with the law and respond to lawful requests | Any data, as strictly required | Legal obligation |
| Optional features you choose to turn on, such as receipt scanning | The data that feature needs | Your consent, which you can withdraw at any time |
We do not use your data for advertising, we do not build marketing profiles, and we do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
The website at lipi.com.np
The marketing website is a set of static pages. It sets no cookies and runs no analytics or tracking. It stores one item in your browser: your light or dark theme choice, if you pick one. Our hosting provider processes your IP address and request details to deliver the pages and protect them from attacks.
Storage on your device
The Lipi app stores a few things in your browser so it can work:
- Sign-in tokens in local storage, so you stay signed in.
- A copy of your data in the browser’s database (IndexedDB), so the app is fast and can work offline. It is wiped when a different person signs in on the same device.
- Preferences such as theme and language.
These items are strictly necessary for the service you asked for, so they do not need consent, and there is no cookie banner. Signing out removes your sign-in tokens. Clearing your browser’s site data removes everything.
Who we share it with
We do not sell your personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined in California law. We share personal data only with the following:
Service providers (processors) that run parts of Lipi for us, under contracts that allow them to use the data only to provide their service to us:
| Provider | What they do | Data involved |
|---|---|---|
| Cloud hosting provider (servers in the United States) | Runs the Lipi API, database and search | All account data and records |
| Cloudflare, Inc. | Hosts the app and website, stores attachments (R2), protects against attacks | IP addresses, request data, attachments |
| Google LLC | Google sign-in, only if you choose it | Sign-in request, name, email, account identifier |
| Email delivery provider | Sends service emails | Name, email address, email content |
| Better Stack, Inc. | Server logs and uptime monitoring | Server logs, which may include IP addresses and account identifiers |
| OpenAI or Anthropic (optional, when available) | Reads text from receipt images you choose to scan | The receipt image you submit |
Our staff. A small number of authorised people can open account records when it is needed to give you support you asked for, to investigate abuse or security incidents, or to meet a legal obligation. Access is limited to what the task needs, and administrative actions are recorded in an audit log.
Legal and safety reasons. We may disclose data if the law requires it, to respond to a valid legal request, or to protect the rights, safety or property of our users, the public or Lipi. Where the law allows, we will tell you first.
Business changes. If Lipi is merged, acquired or sells its assets, your data may transfer to the new owner, who must keep honouring this policy. We will tell you before that happens.
With your permission. In any other case, only if you ask us to.
International transfers
Lipi is operated from Nepal, and our servers are in the United States. Cloudflare serves content from locations around the world. Using Lipi therefore means your data is transferred outside Nepal and outside the country you live in.
Where the GDPR or UK GDPR applies, we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum), or on the EU–US Data Privacy Framework where a provider is certified under it. For people in India, we transfer data only to countries the Indian government has not restricted. You can ask us for more detail about these safeguards.
How long we keep it
| Data | How long |
|---|---|
| Your account and records | While your account is open |
| Records you delete | Removed from your account at once, and permanently purged within 90 days |
| Everything, after you delete your account | Erased within 30 days |
| Backups | Encrypted, and rotated out within 35 days, so deleted data leaves them within 35 days of being erased |
| Server logs | 30 days |
| Account activity log | 24 months, then archived; entries about you are erased when your account is erased |
| Records of actions our staff took on your account | Kept for accountability, with your personal details removed after your account is erased |
| Payment and accounting records | As long as tax and accounting law requires |
How we protect it
- All traffic to Lipi is encrypted with HTTPS.
- Passwords are stored only as one-way hashes.
- Each person’s data is separated. Every request is checked against the signed-in account, so no one can see another person’s records.
- Staff access is restricted and administrative actions are logged.
- Backups are encrypted.
No system is perfectly secure. If a personal data breach puts your rights at risk, we will notify the relevant authorities within 72 hours of becoming aware of it where the law requires, and tell affected users without undue delay, including what happened and what you can do.
Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you and get a copy.
- Export your data in a portable format (JSON and CSV).
- Correct data that is wrong or incomplete. You can edit most of it yourself in the app.
- Delete your account and personal data.
- Object to or ask us to restrict certain uses.
- Withdraw consent for anything that relies on it, such as optional AI features, without affecting what happened before.
To use any of these rights, email [email protected] from the address on your account. We may ask you to confirm your identity. We will reply within 30 days, and tell you if we need longer where the law allows it. Using your rights is free, and we will not treat you differently for using them.
European Union and United Kingdom
You have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR and UK GDPR. You can object at any time to processing based on our legitimate interests. You also have the right to complain to the data protection authority where you live or work. In the UK, that is the Information Commissioner’s Office.
California
Under the CCPA as amended by the CPRA, you have the right to know what personal information we collect, use and disclose; to delete it; to correct it; and to opt out of its sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. We use sensitive personal information, such as your account password and the financial records you enter, only to provide the service, so the right to limit its use does not change anything. You can use an authorised agent to make a request for you. We will not discriminate against you for exercising these rights.
In the last 12 months we have collected these categories of personal information, for the purposes and from the sources described above: identifiers (name, email, IP address, account identifiers); financial information you enter; internet or network activity (session and log data); and account login credentials. We have disclosed them only to the service providers listed above, for business purposes.
India
Under the Digital Personal Data Protection Act, 2023, you have the right to access information about your personal data, to correct, complete, update and erase it, to grievance redressal, and to nominate someone to exercise your rights if you die or become incapacitated. Send grievances to [email protected]. If you are not satisfied with our response, you can complain to the Data Protection Board of India.
Nepal
Under the Individual Privacy Act, 2075 (2018), your personal information is collected with your consent, used only for the purpose it was collected for, and kept confidential. You can ask us to correct or remove it by writing to the privacy address above.
Children
Lipi is not meant for anyone under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has created an account, contact us and we will delete it.
Optional AI features
Receipt scanning is not available yet. When it is, it will be off by default. If you turn it on, the image you choose to scan is sent to an AI provider (OpenAI or Anthropic) to read the text on it:
- Lipi scanning: the image goes to our account with the provider. The provider may not use it to train its models, and we do not keep the image after processing, apart from the receipt you choose to attach.
- Your own API key: if you add your own key, the image goes to your account with that provider, under your agreement with them.
We will update this policy and tell you before the feature launches.
Changes to this policy
If we make a material change, we will tell you by email and in the app at least 30 days before it takes effect. For smaller changes, we will update the date at the top of this page. Earlier versions are available on request.
Contact
Lipi Technology, Nepal Privacy and grievances: [email protected] Support: [email protected]