01
Zero Data Selling
We never sell, rent, or trade your personal financial data to advertisers, brokers, or data analytics firms.
02
Strict Account Isolation
Every transaction, salary record, loan, and goal is server-scoped exclusively to your authenticated account ID.
03
Complete Deletion Rights
Delete individual entries anytime or erase your entire account and all records permanently with one action.
1 Our Privacy Philosophy
My Expenses Diary 360 is built to serve as your personal, confidential financial notebook. We believe your daily expenses, monthly salary details, loan payments, and savings goals are strictly confidential personal matters. We do not use your financial entries for profiling, automated decision-making, or third-party behavioral targeting.
2 Information We Collect
We only collect information that you explicitly provide when creating an account and logging your entries:
- Account Credentials: Your name, email address, and an encrypted password (hashed using industry-standard bcrypt algorithms).
- Financial Records: Income entries, daily expense items, amounts, categories, and payment dates that you choose to record.
- Duty & Attendance: Check-in and check-out logs, working status (Present, Half-day, Absent), and shift notes for your personal estimation.
- Salary Configurations: Monthly salary amount and working day settings used solely to compute your personal estimated earnings.
- Liabilities & Goals: EMI/loan balances, recorded loan repayments, savings goals, and contribution milestones.
- Bills & Reminders: Upcoming recurring and one-time bills, due dates, and paid flags.
3 How We Protect Your Data
Your records are safeguarded through multi-layer application security controls:
- Server-Enforced Scope: Every database query for transactions, attendance, loans, and bills is rigidly filtered by the authenticated user's ID. No user can view or mutate records belonging to another account.
- Secure Session & Tokens: Web sessions use encrypted, HTTP-only cookies protected against cross-site scripting (XSS) and cross-site request forgery (CSRF). Mobile API connections require revocable Sanctum Bearer tokens.
- Encryption in Transit: All communications between your browser, mobile app, and our server are designed to occur over secure HTTPS connections.
4 Cookies & Local Storage
We only utilize essential first-party cookies necessary for authentication and session integrity:
- Session Cookie (
laravel_session): Identifies your active session so you remain securely logged in across pages.
- CSRF Token (
XSRF-TOKEN): Protects your forms from unauthorized cross-site submissions.
We do not employ third-party tracking cookies, Google Analytics trackers, or advertising beacons.
5 Your Rights & Account Deletion
You have full autonomy over your records:
- Edit & Delete: You can edit or delete individual transactions, attendance days, loans, and bills directly from each module.
- Full Account Deletion: You can permanently delete your entire account at any time from your Profile Settings. Selecting account deletion permanently purges your account credentials and all related transaction, attendance, salary, loan, bill, and savings history from the active database.
6 Administrative Oversight & Audit Logging
To ensure system integrity and security, super-administrators have restricted oversight access for system administration. Any inspection of account statistics or administrative role update is automatically timestamped and permanently logged in the internal audit trail.
7 Contact Us
If you have any questions or concerns regarding this Privacy Policy or your personal data handling, please contact our support team at: