Privacy Policy
Last updated: August 8, 2026
This Privacy Policy explains how Fehm ("Fehm", "we", "us", or "our") collects, uses, stores, and protects information when you use the Fehm mobile application and this website (together, the "Service"). Fehm is a personal finance tracking app that helps you record expenses, income, loans, and voluntary charitable giving (Sadqa).
By creating an account or otherwise using the Service, you agree to the collection and use of information as described in this policy.
1. Information We Collect
Account information
- Username, email address, and a securely hashed password (we never store your password in plain text)
- Your full name, as provided during profile setup
- Language preference (English or Urdu)
Financial data you enter
Fehm does not connect to your real bank accounts, cards, or any third-party banking API. All wallet balances, expenses, income records, loans, and Sadqa entries are manually entered by you and stored so the app can display your totals and history. This data reflects what you choose to record, not a live feed from any financial institution.
Device and usage data
- A push notification token (via Firebase Cloud Messaging) so we can deliver reminders and alerts to your device
- Device name, platform (Android/iOS), and app version, for support and compatibility purposes
- IP address and basic activity logs (e.g. login times) for account security
Files you choose to upload
If you attach a receipt to a loan or utility bill entry, or attach a screenshot to feedback you submit through "Talk to Fehm", that image is uploaded to our secure cloud storage (Cloudflare R2). You control whether to attach anything — none of this is required to use the app.
Subscription information
If you subscribe to a paid tier, your purchase is processed by Google Play Billing and managed through RevenueCat. We receive your subscription tier, purchase/renewal dates, and transaction identifiers — we do not receive or store your card number or other raw payment details; those are handled entirely by Google Play and RevenueCat.
2. How We Use Your Information
- To provide the core functionality of the app — tracking your wallets, expenses, income, loans, and Sadqa
- To send you notifications you've opted into, such as loan reminders or maintenance alerts, via push notification, email, or in-app message
- To enforce the feature limits associated with your subscription tier
- To respond to feedback, bug reports, or support requests you submit
- To maintain the security of your account and detect misuse
- To show advertisements to users on the Free tier, via Google AdMob (see Section 3)
3. Third-Party Services We Use
We rely on a small number of trusted third-party services to operate Fehm. Each only receives the minimum data needed to perform its function:
- Firebase Cloud Messaging (Google) — delivers push notifications to your device.
- Resend — sends transactional emails, such as email verification codes and password reset codes.
- Cloudflare R2 — stores images you voluntarily upload (receipts, feedback screenshots).
- Google Play Billing & RevenueCat — process and manage paid subscriptions.
- Google AdMob — displays advertisements to Free tier users. AdMob may collect an advertising identifier and usage data to serve ads; you can review Google's own privacy practices for details.
These providers process data under their own privacy policies, and we choose providers that maintain industry-standard security practices.
4. Data Storage & Security
Your data is stored in a PostgreSQL database on infrastructure we control. Passwords are hashed using bcrypt and are never stored or transmitted in plain text. All communication between the app and our servers is encrypted using HTTPS/TLS. Access to production data is restricted to what's necessary to operate the Service.
While we take reasonable, industry-standard measures to protect your information, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
5. Data Retention & Account Deletion
You can request account deletion at any time from within the app (Settings → Delete Account). Here's exactly what happens:
- Your account is immediately deactivated and you're signed out.
- For 30 days, your account and data are retained but inaccessible for normal use — if you log back in during this window, you can restore your account and all of your data in full.
- If 30 days pass without restoration, your personal data is permanently and irreversibly deleted from our systems.
You may also email support@fehmapp.com to request deletion or ask questions about data we hold about you.
6. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data (most of this you can edit directly in the app)
- Request deletion of your account and associated data, as described above
- Request a copy of your data in a portable format
To exercise any of these rights, contact us at support@fehmapp.com.
7. Children's Privacy
Fehm is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If we become aware that we've collected data from a child under 13 without appropriate consent, we will delete it promptly.
8. International Data Processing
Fehm is operated from Pakistan, and our servers and service providers may process your data in Pakistan or other countries where our third-party providers operate. By using the Service, you consent to this processing.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we'll update the "Last updated" date above and, where appropriate, notify you through the app.
10. Contact Us
If you have questions about this Privacy Policy or how your data is handled, reach us at support@fehmapp.com.