Potnis — Privacy Policy
Last updated: 21 August 2026
Who we are
Potnis is an Android app published by Harsh Pandhe. For anything in this policy, contact harshpandhehome@gmail.com.
What Potnis reads, and why
With your permission, Potnis uses Android's notification access to read notifications posted by banking and payment apps. It looks for payment alerts and extracts the amount, the merchant or payee, the date, and where available the bank name, reference number and account balance.
This is the app's core function. Without it Potnis cannot record spending automatically, which is the only reason it exists. Notifications from apps that are not banking or payment apps are ignored, and anything that does not parse as a payment is discarded.
Reading and parsing happen entirely on your device. Notification content is never transmitted anywhere.
What Potnis stores
Everything is stored in a database inside the app's private storage on your phone, which other apps cannot read:
- Transactions — amount, merchant, category, date, bank, reference, balance, and the original alert text
- Anything you enter yourself — IOUs, bills, savings goals, notes
- Your category corrections, so they stick next time
- App settings
The original alert text is kept so the app can show you what a transaction was derived from, and correct its own mistakes. It stays on your device.
What Potnis does not do
- No account. There is nothing to sign up for and no password.
- No servers. Potnis does not upload your financial data anywhere.
- No bank login. Potnis never asks for banking credentials and could not use them.
- No SMS access. Potnis does not request permission to read your text messages.
- No advertising, no analytics, no tracking, no third-party SDKs collecting data about you.
- No selling or sharing of your data.
Permissions
- Notification access
- Reads bank and payment notifications to record transactions. You grant this in Android settings and can revoke it there at any time. If you revoke it, Potnis stops recording new transactions; everything already saved stays.
- Run at startup
- Lets capture resume after you restart your phone, so alerts that arrive before you next open the app are not missed.
- Internet
- Not used for your financial data. It is present because the app framework requires it and, where enabled, for crash reporting.
- Biometric / fingerprint
- Only used if you turn on App lock in Settings. Unlocking is handled entirely by Android's own biometric system — Potnis only receives a yes/no result and never sees or stores any fingerprint, face, or PIN data itself.
- Notifications
- Used to show a local reminder when a few transactions are waiting to be filed under a category, and nothing else. This is a notification Potnis posts to your own phone — it never involves a server, and the notification itself only ever says how many transactions are waiting, never a merchant name or amount.
Home-screen widget
If you add the Potnis widget to your home screen, it shows your total spend for the current month. That number is written to a small piece of storage the widget reads from directly — the same on-device-only rule applies: nothing is sent anywhere to produce it.
Crash reports
If crash reporting is enabled in the released build, a crash sends technical diagnostics — the error, the code path, the Android version and device model — to our error-tracking provider so the bug can be fixed. Crash reports never contain your transactions, merchant names, amounts, or notification text. This is reflected in the app's Data Safety listing on Google Play.
Your data, and getting rid of it
Because everything is on your device, you are in full control:
- Export — Settings › Export everything writes a CSV of all your data that you can save or send anywhere.
- Export a statement — Settings › Export statement (PDF) writes a password-protected PDF of your transactions, meant to be read or shared with someone else. The password is set by you, on your device, and Potnis never sees or stores it.
- Back up — Settings › Back up (encrypted) writes an encrypted, password-protected copy of everything to a file you choose where to save. It's encrypted with a password only you know; Potnis does not keep a copy of that password and cannot recover it for you. Restoring a backup replaces everything currently on the device with what's in the file.
- Delete — Settings › Delete everything permanently erases all transactions, IOUs, bills, goals and corrections.
- Uninstall — removing the app removes its database with it. Nothing is left behind, and nothing exists elsewhere.
There is no account to delete, because there is no account. We hold no copy of your data and therefore cannot access, restore, or delete it for you.
Children
Potnis is not directed at children under 13 and we do not knowingly collect data from them. Since the app sends nothing to a server, this is a statement of intent rather than a data-handling practice.
Changes
If a future version adds optional cloud sync, this policy will be updated before that version ships, and sync will be opt-in with a clear explanation of what leaves your device. The date at the top always reflects the current version.
Contact
Questions, or a privacy concern: harshpandhehome@gmail.com.