Privacy Policy
Effective date: September 3, 2026
Lekhva is a local-first invoicing application. This policy describes information processed by the Lekhva Android application and related website. Lekhva is provided by the developer identified in its Google Play listing. Privacy and deletion requests can be sent to the contact address below.
Local-first business data
Business profiles, clients, invoices and line items, payments, receipts, estimates, credit notes, recurring-invoice schedules, settings, drafts, logos and generated documents are stored in Lekhva's encrypted application storage. Lekhva does not upload this workspace content to its backend during normal operation.
PDFs, CSV files and backups are written or shared only to destinations you choose. Copies outside Lekhva's app-managed storage remain under your control.
Accounts and Google Sign-In
Account use is optional because Lekhva supports Guest Workspace. Supabase processes account email, account UUID, authentication provider and session data for sign-in, recovery, security and account management. If you choose Google Sign-In, Google and Supabase may provide your email, display name, profile-image URL, provider identity and related provider metadata. Lekhva never receives your Google password.
Usage limits
Guest usage counters remain local. Authenticated lifetime invoice/client counters and invoice-quota claims are stored in Supabase and scoped to the authenticated account UUID.
Purchases and RevenueCat
Google Play handles checkout and payment credentials. Lekhva and RevenueCat do not receive full card, bank-account or UPI credentials. RevenueCat processes an anonymous App User ID before sign-in and the exact Supabase UUID after sign-in, together with product/package identifiers, transaction and purchase history, subscription status, entitlements, promotional access, restoration information and related store metadata. Only server-authoritative verification grants production Pro access.
Firebase Analytics
Firebase Analytics is enabled in production. It processes lifecycle and screen activity, app interactions, subscription-screen and purchase events, backup creation/restoration events, device and app information, app-instance or Firebase installation identifiers and related diagnostics. Granular location and device collection is enabled, so Analytics may process city-level location derived from IP address, device brand and model, operating-system and platform versions, and screen resolution. Depending on the Android device and its settings, Analytics may also process the Android Advertising ID.
The production Analytics property currently has Google Signals disabled, no Google Ads links, no BigQuery links, and Google products and services data sharing disabled. Ads personalization eligibility is enabled in Analytics. This means eligible Analytics events are not marked as excluded from ads personalization, although no Google Ads account is currently linked for audience or event export. These controls may be changed by the responsible developer and this policy must be updated if the production configuration changes.
Firebase Crashlytics
Firebase Crashlytics is enabled in production and may process crash reports, stack traces, non-fatal diagnostics, device/application state, Crashlytics or Firebase identifiers, session information and Analytics breadcrumbs. Lekhva does not intentionally attach invoice, client, payment or document content to crash reports.
Service providers and sharing
Lekhva uses Supabase for accounts, usage, quota and entitlement projections; RevenueCat for purchase and entitlement management; Firebase Analytics and Crashlytics for analytics and reliability; Google Play for distribution, checkout and store records; and storage/sharing providers selected by you for exports. Lekhva does not sell personal information. Firebase and Google Analytics process Analytics data as service providers under the currently configured controls described above; no Google Ads or BigQuery export link is configured and Google products and services data sharing is disabled.
Retention
Supabase account data and RevenueCat customer data are retained while needed to provide the account and are removed through account deletion, except where information must be retained for security, fraud prevention or legal compliance. Google Play independently retains transaction and billing records under Google's policies. Local app-managed workspace data remains until in-app account deletion, application-data clearing or uninstall; exported copies remain at their destinations. Firebase Analytics and Crashlytics information follows the configured Firebase and Google service retention controls. Lekhva does not state a fixed Firebase retention period because that period has not been independently verified for the production property.
Account and data deletion
In-app deletion removes the exact authenticated RevenueCat customer, Supabase account and account-scoped backend records, then removes that account's local encrypted workspace, settings, drafts, app-managed backups/documents, usage caches and scheduled invoice notifications. Guest Workspace and other device accounts remain untouched.
Deleting Lekhva does not cancel recurring Google Play billing. Cancel an active subscription in Google Play first. Google retains store transaction records. Eligible Play purchases may be restorable after account recreation; promotional RevenueCat access is not restored by Google Play. Exported copies must be deleted by you.
See Delete your Lekhva account and data for the in-app and external request process.
Children
Lekhva is intended for business users and is not directed to children.
Contact
Privacy and deletion questions can be sent to [email protected].