Skip to content
NiyamPay

Privacy Policy

Effective and last updated: 19 September 2026

1. About NiyamPay and this policy

NiyamPay (“NiyamPay”, “we”, “us”) is a personal financial planning and decision-support tool for individuals in India. It performs calculations and projections — repayment plans, credit card behaviour, budgets, net worth, emergency reserve, goals and retirement projections — using only the figures a user chooses to enter. NiyamPay is not a bank, lender, broker, collection agency, investment adviser or account aggregator, and it does not arrange credit.

This policy explains what information the NiyamPay web application collects, why, who processes it on our behalf, how long it is kept, and the controls available to you. It applies to the website and application at niyampay.com.

2. Information you provide directly

Account and sign-in information. When you create an account we collect your email address and a password (stored only as a hash by our authentication provider), or, if you choose Google Sign-In, the basic Google account information described in section 10. You may optionally add a display name. We also keep the time when you confirm that you are at least 18 and the version of the Terms and Privacy Policy shown with that confirmation.

Financial information you enter. Everything financial in NiyamPay is typed in by you. Depending on the features you use, this can include:

  • income sources and amounts, including recurring extra income;
  • budget categories, planned amounts and the expenses you record against them;
  • assets and savings balances you choose to track;
  • debts — lender or account name you type, outstanding balance, interest rate, EMI, tenure, due dates and debt type;
  • credit card details you enter manually — credit limit, statement and minimum amounts, EMI and purchase balances, and your chosen payment strategy;
  • payments you record, including amounts, dates and notes you add;
  • goals and target amounts and dates;
  • planning and profile facts — date of birth, number of dependents, retirement age, month start date, payday, currency, language and timezone;
  • saved plan versions and monthly review snapshots you create;
  • app preferences such as theme and display settings.

NiyamPay never asks for and does not want bank login credentials, OTPs, card numbers, CVVs, PAN or Aadhaar. Please do not enter them. Use a nickname rather than a full account number when naming a debt or card.

3. Information collected automatically

  • Authentication/session data. A session token issued by our authentication provider is stored in your browser so you stay signed in.
  • Browser storage. Besides that session token, NiyamPay stores interface preferences locally, including your theme and dismissed prompts. Older versions stored financial records in your browser. The legacy import flow retains a local backup, which can remain after import or cloud-data deletion. On a shared device, export any copy you need and clear this site's browser data to remove that local copy.
  • Technical and diagnostic data. Our hosting and database providers process standard request data (such as IP address, timestamp, and user-agent) to serve and secure requests. Application errors may be logged for troubleshooting. Avoid including passwords, tokens or unnecessary financial details in error reports or support messages.
  • Analytics. NiyamPay does not run advertising or third-party behavioural analytics trackers in the application.

4. How we use information

  • authenticate you and keep your session secure;
  • save, sync and display your own records across your devices, and generate the calculations, projections, plans and review comparisons the product exists to provide;
  • operate, maintain and improve the reliability of the service;
  • detect, investigate and prevent abuse, security incidents and technical faults;
  • respond to you when you contact us;
  • comply with applicable legal obligations.

Your figures are used to compute results for you. They are not used for advertising, profiling or scoring, and no automated decision is made about you.

5. What NiyamPay does not do

  • no bank or card account connection, and no Account Aggregator integration;
  • no automatic ingestion of your financial data from SMS, email, statement OCR or file/CSV import;
  • no advertising, ad networks or ad profiling;
  • no sale or rental of your personal or financial information;
  • no sharing of your data with lenders, brokers, insurers or marketers;
  • no credit scoring and no personalised investment advice.

6. Third-party services we rely on

NiyamPay uses a small number of service providers that process data strictly to run the product:

  • Supabase — provides the managed authentication service and the PostgreSQL database in which your account and records are stored.
  • Google — only if you choose Google Sign-In, to authenticate you (see section 10).
  • Application hosting and delivery — serves the website and application code and processes standard request data.

These providers act as processors for the purposes above and are subject to their own privacy terms. We do not claim any guarantee on their behalf.

7. Sharing and disclosure

We share information only: (a) with the service providers named above, to the extent needed to operate NiyamPay; (b) when you ask us to or export it yourself; and (c) where required by law or valid legal process, or to protect the rights, safety and security of users and the service. We do not sell personal or financial information, and we do not disclose it for advertising.

8. Storage, isolation and security

Your records are stored in a managed PostgreSQL database. Every financial table is protected by row-level security so that a row can only be read by the signed-in account that owns it. Debt, card and payment ledger changes pass through database functions that derive ownership from the signed-in session and commit related rows together. Additional database rules reject records that reference another user's data. The application's server-side handlers derive your identity from a verified session token rather than from the request body, and traffic is encrypted in transit. Private screens are rendered only after sign-in and are not cached by shared caches.

These are reasonable safeguards, not a guarantee. No online service can promise absolute security. Please use a strong, unique password and keep your email account secure.

9. Data retention

Your account and the financial records you enter are retained for as long as your account is active, or until you delete them. “Delete all my data” removes your financial records while keeping your login; “Delete my account” requests removal of the login and linked records. Export first if you want a copy. Financial-data deletion runs as one database transaction, so a failed request is rolled back rather than partly deleting the current database records. Provider backups and operational or security logs can remain subject to provider retention settings and applicable legal requirements. Cloud deletion does not remove copies you downloaded or legacy browser backups.

10. Google Sign-In

If you choose “Continue with Google”, Google authenticates you and returns basic account information — your email address, and the name and profile picture URL associated with your Google account where available. We use it solely to create and identify your NiyamPay account and to display your name. NiyamPay requests no additional Google scopes: it does not read your Gmail, Drive, Contacts, Calendar or any other Google data, and it writes nothing back to your Google account. Your NiyamPay financial data is never sent to Google.

11. Your controls

  • Access and correct — every figure is visible and editable in the app.
  • Download — Profile → Download full data gives a complete structured JSON export of your records.
  • Delete financial data — Profile → Delete all my data.
  • Delete account — Profile → Delete my account.
  • Ask us — email the address in section 14 with any privacy question or request.

12. Age eligibility

NiyamPay is intended only for people aged 18 or older managing their own finances. Account creation and first use require that confirmation. We do not knowingly provide accounts to children. If you believe a child has created an account, contact us so we can investigate and remove it where appropriate.

13. Changes to this policy

We may update this policy as the product changes. The revised version will be posted on this page with a new “last updated” date; material changes will also be signalled in the app. An update to this notice does not by itself authorize a new use of your personal data.

14. Contact

For any privacy question, data request or grievance-related complaint, email support@niyampay.com.