Privacy Policy
Last updated: September 26, 2026
Hamyon AI (“we”, “our”, or “us”) respects your privacy and is committed to protecting your personal information. This Privacy Policy explains what information we collect, how we collect it, how it is used, and how your personal data is protected when you use the Hamyon AI mobile application and related services.
1. Information We Collect
We collect only the information necessary to provide personal finance tracking and related local tools:
A. Account Information
- Username: Required to identify your account and sync data.
- Password: Hashed securely using industry-standard bcrypt encryption on the client and server. We never store plain-text passwords.
- Full Name (Optional): Display name for personalizing your profile.
- Phone Number (Optional): Optional contact method; not required to register or use the app.
- Referral Code (Optional): Optional promotional code entered during registration.
B. Financial & Transaction Data
- Transactions: User-entered income, expense, and transfer records (amount, currency, category, date, and optional note).
- Debts & Loans: Contact names, amounts, due dates, and settlement status recorded by the user.
- Budgets & Goals: Target spending amounts and savings goals set by the user.
C. Voice, Audio & AI Interaction Data
- Voice Audio & Transcripts: When you choose to use the Voice AI entry feature, temporary voice audio is recorded and transcribed into transaction data.
- AI Assistant Prompts: Text questions and prompts submitted to the AI money assistant.
D. Geolocation (When In Use Only)
- Location Data: Foreground-only, approximate coordinates are requested only when you actively use map-based features (such as prayer times & Qibla direction, InBaraka local listings, or Xonadosh housing). We do not collect persistent or background location.
E. App Usage Statistics & Diagnostics
- First-party usage statistics: When you are signed in, the app sends basic usage events to our own server (hamyon-ai.uz): app opened, which section/screen was opened (the screen type, never its contents), foreground/background and session length, together with device platform, brand, model, OS version, app version and language. We use this only to understand which features are used and to fix problems. It is not used for advertising and is not sold or shared.
- Crash reports and analytics (Google Firebase): Crash logs, diagnostics and in-app screen events are processed by Firebase Crashlytics and Google Analytics for Firebase (see Section 4). No advertising identifier is used and no cross-app tracking takes place.
F. Push Notifications
- Push token: If you allow notifications, a push token issued by Firebase Cloud Messaging / Apple Push Notification service is stored on our server with your account and device type/app version so we can deliver messages, reminders and incoming support-call alerts. The token is deleted when you sign out or delete your account. You can turn notifications off at any time in your device settings.
G. Support Calls & Screen Sharing (only with your consent)
- Admin-initiated support calls: Our support team may call you inside the app to help with a problem. The app shows a clearly labelled incoming-call screen with Accept and Decline. Nothing is transmitted unless you tap Accept; the camera and microphone are used only after you accept (and after the normal system permission prompt). There is no silent, background or automatic answering. You can end the call at any time.
- Screen sharing: During an accepted call you may choose to share your screen to show the problem. It starts only after you tap Share and approve the operating system’s screen-recording consent dialog; a visible banner/notification (and the system indicator) is shown for as long as sharing is active, and you can stop it at any time.
- What is stored: Call audio, video and shared screen are sent directly and encrypted (WebRTC, DTLS-SRTP) between your device and the support agent and are not recorded. We keep only call metadata (time, duration, whether the call was accepted/declined and whether screen sharing was started/stopped) in an audit log for security and quality purposes.
2. How We Collect Information
We collect personal information through the following methods:
- Direct User Input: Data you manually enter into input forms (transactions, debts, budgets, account creation).
- User-Initiated Voice Input: When you explicitly tap the microphone button to record a transaction or query.
- Local Device Storage: The app stores financial records locally on your device in a secure SQLite database for offline-first availability.
- Automatically, while you use the app: usage events, device/app information, crash diagnostics and your push token, as described in Sections 1.E and 1.F.
- Secure Network Communication: When account synchronization or AI features are used, data is transmitted over encrypted HTTPS/TLS connections.
3. How We Use Information
Collected information is used strictly to provide and improve app functionality:
- To calculate account balances, category breakdowns, financial health summaries, and monthly reports.
- To parse voice input into structured expense/income records.
- To answer user questions regarding personal budgeting and financial literacy via the AI assistant.
- To synchronize your personal data securely across your devices when logged in.
- To send push notifications you have allowed (reminders, messages, incoming support calls).
- To provide consent-based in-app support calls and optional screen sharing.
- To measure feature usage and stability (usage statistics, crash reports) and fix problems.
- To protect against abuse, unauthorized access, and fraud.
We do not use advertising SDKs, ad trackers, or IDFA/ATT tracking. We do not sell user personal information to any third parties.
4. Third-Party Services & Third-Party AI Data Sharing
Hamyon AI integrates with third-party service providers solely to perform specific functions requested by the user:
- hamyon-ai.uz: Our backend server infrastructure for account management, encrypted backup synchronization, and community listings.
- Google Gemini (Google LLC): Primary AI model used for the AI money assistant and voice transaction extraction.
- Pollinations (pollinations.ai): Secondary fallback for AI text processing and illustrative chart generation.
- OpenStreetMap & Nominatim: Provides map tiles and reverse geocoding when you use map views.
- Central Bank of Uzbekistan: Public official currency exchange rates for informational reference.
- CoinGecko: Public cryptocurrency market pricing for informational reference (no trading, brokerage, or custodial services).
- Google Firebase (Google LLC): Push notifications (Cloud Messaging), crash reports (Crashlytics), usage analytics (Google Analytics for Firebase, without the advertising identifier), remote app configuration (Remote Config) and app integrity verification (App Check). Firebase processes device/app identifiers (installation ID, app instance ID, push token), app version, OS and device model, crash stack traces and in-app events such as screens opened. We set only a pseudonymous user ID (a one-way hash); names, phone numbers, financial amounts and message contents are never sent to Firebase.
Confirmation of Equal Protection
We explicitly confirm that any third party the app shares personal data with (including Google LLC and Pollinations) provides the same or equal protection of user personal data as stated in this Privacy Policy.
All third-party AI providers operate under strict data protection terms and confidentiality obligations. They process data solely to fulfill user-initiated requests, do not retain user personal data for advertising purposes, and do not use personal data to train public artificial intelligence models.
User Consent for AI Processing
Sending data to third-party AI services requires prior, explicit in-app consent from the user. Before any user prompt, voice recording, or financial context is transmitted to Google Gemini or Pollinations, an in-app consent dialog is presented detailing what data will be sent and who receives it. Users may decline or revoke AI consent at any time in Settings. If consent is declined, no data is shared with AI services, and manual financial tracking remains 100% operational.
5. Data Retention & Security
We implement industry-standard administrative, technical, and physical security measures to safeguard user data against unauthorized access, loss, or alteration. Passwords are cryptographically hashed using bcrypt with salt. All API communication occurs exclusively over HTTPS/TLS.
6. User Rights & Account Deletion
Users have full control over their personal data, including the right to access, export, or permanently delete their account and all associated data.
- In-App Deletion: You can delete your account and all stored data directly inside the app at any time by navigating to Settings → Delete account.
- Email Request: You may also request complete account and data deletion by contacting us at support@hamyon-ai.uz. Deletion requests are processed within 48 hours.
7. Children’s Privacy
Our application and services are not directed to children under the age of 13. We do not knowingly collect personal data from children under 13.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.
9. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
Email: support@hamyon-ai.uz
Website: https://hamyon-ai.uz