Privacy Policy
Last updated: 14 August 2026
Jibiyar is about your money, and financial data is among the most private data anyone has. This document explains in plain language what we collect, why, how long we keep it, and what rights you have. The Persian text is the governing version.
1. Scope
This policy governs all data processed when you use the Jibiyar apps (mobile and desktop) and the jibiyar.com website. It forms an integral part of the Terms of Use.
2. Who is responsible for your data
Khared Hoosh Yar (private joint-stock company), registration number -, national ID -, the provider of Jibiyar, is responsible for collecting and processing your data. Contact details are in the final section of this document.
3. What we collect
We collect only what the service needs in order to work:
- Account information: your mobile number or email address (for sign-in and authentication) and your display name, if you have entered one.
- Transaction data: the amount, currency, description, category, date and, where recorded, the beneficiary of each expense or income entry.
- Speech and its transcript: when you use voice entry, your audio is sent to our servers to be turned into text.
- Chat messages: the text you write in the chat assistant and the replies you receive.
- Technical information: device model, OS version, app version, language, and a random device identifier that is not tied to your identity.
- Crash reports: when an error occurs, the technical stack trace is sent to our self-hosted system for debugging.
4. What we do not collect
As an explicit commitment, we do not collect any of the following — not for ourselves and not for anyone else:
- Your location. The app requests no location permission.
- Your contacts, SMS messages, photos or device files.
- Banking details: card numbers, account numbers, PINs, or any data from your bank account. Jibiyar does not connect to your bank.
- Advertising identifiers or tracking cookies. There is no third-party advertising or behavioural analytics in the app.
- Crash reports never carry financial content, speech transcripts, phone numbers, email addresses or sign-in tokens.
5. Legal basis for processing
We process your personal data on the following bases:
- Your explicit consent — as required by Articles 58 and 59 of the Iranian E-Commerce Act of 1382 (2003), which make any use of personal data messages conditional on the data subject's express consent. You give that consent by accepting this document on first launch.
- Performance of the contract — processing without which the service you signed up for cannot be provided.
- Legal obligation — where the law or an order from a competent judicial authority requires it.
- Breach of Articles 58 and 59 is a criminal offence under Article 71 of the same Act, and we hold ourselves to it.
6. Purposes of processing
Your data is processed only to: provide and maintain the service; synchronise transactions across your own devices; build reports and spending analysis for you; authenticate and secure your account; handle your support requests; and fix technical faults.
We do not sell your data. We never sell, rent or otherwise make your personal or financial data available to any third party for advertising.
7. Speech processing and AI
When you use voice entry, the recording is sent to our servers to be converted to text and to have its meaning (amount, category, date) extracted.
This processing runs on our own self-hosted infrastructure. Your audio and text are not sent to any external AI service or third party.
Once the audio has been transcribed the recording is deleted; only the extracted text and the resulting transaction remain.
8. How long we keep data
Nothing is kept longer than necessary:
- Audio recordings: deleted immediately after transcription.
- Transactions and chat messages: until you delete your account.
- Server logs: at most 30 days.
- Crash reports: at most 90 days, and with nothing that identifies you.
- Deleting your account permanently and irreversibly erases your transactions, transcripts and messages.
9. Sharing with third parties
We share your data with no one, except in these limited and necessary cases:
- The SMS provider: your phone number only, and only to send the one-time sign-in code.
- The hosting provider: on whose infrastructure our servers run, with no access to data content.
- Competent judicial authorities: only under a lawful order and within the framework of the Computer Crimes Act of 1388 (2009) and other applicable law.
- Our error-reporting system (Bugsink) is self-hosted on our own infrastructure; no data goes to a third-party service.
10. Where data is stored
All your data is held on servers located inside Iran. Your personal data is not transferred abroad.
11. Security
Traffic between the app and our servers is always encrypted (TLS). Your sign-in tokens are held in the operating system's secure storage on your device — Keychain on iOS, EncryptedSharedPreferences on Android — and are never stored in plain text. Staff access to user data is restricted and granted on a need-to-know basis.
That said, as is true of any system, no method of transmitting or storing information is completely secure. We cannot guarantee absolute security, but we undertake to notify you at the earliest opportunity if a breach puts your data at risk.
12. Your rights
You have the following rights over your data:
- Access: view all your transactions and account information at any time, inside the app.
- Correction: edit or delete any transaction, and change your display name.
- Portability: export all your data as CSV or JSON from Settings → Data. This is free and does not require a subscription.
- Erasure: delete your account and all associated data, from Settings.
- Opting out of notifications: turn the daily reminder off at any time, in the app or in your OS settings.
- Complaint: raise a question or complaint through the contact channels in the final section.
13. Children
The service is not designed for people under 18. We do not knowingly collect data from children. If we learn that an account belongs to a minor without guardian consent, we will delete it.
14. Device permissions
The app asks for only these permissions, each solely for its stated purpose:
- Microphone: only for recording expenses by voice, and only while you are holding the mic button. The app does not listen in the background.
- Notifications: only for the daily reminder. Your operating system asks you for this permission once; it is optional, and declining it affects nothing else in the app.
- Internet: to synchronise with the server.
15. Notifications
The daily reminder is on by default: one silent notification a day, and only on days when you have not recorded anything. You can turn it off whenever you like, in the app's settings or in your OS settings. Its scheduling happens on your own device and sends nothing to the server.
16. Changes to this policy
We may update this document. The current version is always available in the app and at jibiyar.com/privacy. For a material change — particularly to what we collect or how long we keep it — we will notify you in the app before it takes effect and ask for your consent again.
17. Contact and complaints
For any privacy question or complaint, reach us through these channels. We aim to answer data-related requests within seven working days:
- Email: info@jibiyar.com
- WhatsApp: +98 915 348 7312
- Telegram: @Jibiyar_support_bot
- Support page: jibiyar.com/support
- If you are not satisfied with our response you may take the matter to the competent regulatory bodies, including the Consumer and Producer Protection Organisation.