Pavora AI — Privacy Policy
Last updated: June 19, 2026
- Introduction
- Data We Collect
- How We Use Your Data
- Firebase Services
- Analytics
- AdMob and Advertising
- In-App Purchases and Billing
- AI APIs and Processing
- Receipt Scanner (OCR)
- SMS Auto-Capture (Android only)
- UPI Payment Integration
- App Lock, PIN, and Biometrics
- Cookies and Local Storage
- Third-Party Services
- Account Deletion
- Your Rights
- Child Safety
- Data Retention
- Security
- International Transfers
- Changes to This Policy
- Contact Us
1. Introduction
This Privacy Policy explains how NIKKS CREATIONS ("we", "our", "us") collects, uses, stores, and protects information when you use Pavora AI, our AI-powered personal finance application distributed via Google Play and the Samsung Galaxy Store, and our related website (nikkscreations.in) (collectively, the "Service").
We are committed to protecting your privacy. By using Pavora AI, you agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the Service.
2. Data We Collect
We collect data in the following categories:
Account Information
- Email address, display name, and profile information you choose to provide
- Authentication credentials managed through Firebase Authentication (including Google sign-in)
Financial & Application Data
- Content you create within the app — transactions (income and expenses), budgets, savings goals, debts, bills, and subscriptions you track
- Receipt images and the data extracted from them, when you use the receipt scanner
- Chat messages you send to the AI finance coach
- App preferences, settings, selected currency, and configuration
- Subscription and purchase history (handled by Google Play or Samsung)
Technical Data
- Device model, operating system version, and language settings
- App version, crash logs, and diagnostic information
- Anonymized usage analytics
- IP address and approximate location (country level) for fraud prevention
3. How We Use Your Data
We use collected data to:
- Provide, maintain, and improve the Service
- Authenticate users and manage accounts
- Sync your financial data securely across your sessions and devices
- Process in-app purchases through Google Play billing or Samsung billing
- Deliver AI-powered features, insights, and personalized recommendations
- Send service-related communications, reminders, and respond to inquiries
- Detect, prevent, and address fraud, abuse, or security threats
- Comply with legal obligations
We do not sell your personal data to third parties.
4. Firebase Services
We use Google Firebase to power core backend functionality, which may include:
- Firebase Authentication for secure sign-in and user identity management
- Cloud Firestore for storing your user-generated content and app data
- Firebase Cloud Storage for storing receipt images you upload
- Firebase Cloud Functions for backend logic, purchase verification, and integrations
- Firebase Crashlytics for crash reporting and stability improvements
- Firebase Cloud Messaging for push notifications
- Firebase Remote Config for feature configuration
Firebase processes data in accordance with Google's Privacy Policy, available at policies.google.com/privacy.
5. Analytics
We use Firebase Analytics and similar analytics tools to understand aggregate usage patterns, identify performance issues, and improve the Service. Analytics data is processed in an anonymized and aggregated manner where feasible. You may be able to opt out of analytics within the app's settings.
6. AdMob and Advertising
Pavora AI may display advertisements served by Google AdMob to users on the free tier. AdMob may collect device identifiers, IP addresses, and limited interaction data to serve relevant ads and measure performance. AdMob's data practices are governed by Google's Privacy & Terms. Premium subscribers do not see ads.
Users can reset or limit ad personalization through their device's privacy settings:
- Galaxy / Android device: Settings → Google → Ads
- Or by visiting adssettings.google.com
7. In-App Purchases and Billing
All in-app purchases and subscriptions in Pavora AI are processed through Google Play Billing or the Samsung In-App Purchase (Samsung IAP) system, depending on the store from which you installed the app. We do not directly store your payment card details. Billing data — including purchase tokens, subscription status, and receipts — is provided by Google or Samsung and used to verify and maintain your premium entitlement. Refund requests, cancellations, and billing disputes are handled through the respective store. Please review the Google Play Terms of Service or Samsung Galaxy Store policies for specific terms.
8. AI APIs and Processing
The AI finance coach and certain insight features rely on third-party large language model providers (such as Google Gemini, OpenAI, or similar). When you use AI features, your input — for example, a question to the coach or a summary of relevant financial figures — may be transmitted to these providers for processing. We take reasonable steps to minimize the data shared and apply prompt-engineering practices to avoid unnecessary disclosure of personal information.
Important: AI-generated outputs are provided for informational and convenience purposes only and may contain inaccuracies. They do not constitute professional financial, investment, tax, legal, or other advice.
9. Receipt Scanner (OCR)
Pavora AI offers an optional receipt scanner that lets you capture a photo of a receipt (via camera or gallery) and extract details such as the merchant, total amount, taxes, date, and a suggested category, to help you log a transaction.
- Text recognition (OCR) is performed using on-device machine learning (Google ML Kit). The raw text recognition runs locally on your device.
- If you choose to attach a receipt image to a transaction, that image may be uploaded to Firebase Cloud Storage and associated with your account so it syncs with the transaction record. You can delete attachments at any time.
- Extracted values may be sent to an AI provider (see Section 8) for parsing and category suggestions. You review and confirm the parsed details before a transaction is saved.
- Camera and photo-library access is requested only when you use this feature, and you are prompted by the operating system before granting it.
10. SMS Auto-Capture (Android only)
Pavora AI offers an optional "Capture bank SMS" feature that can read transaction-related SMS messages on your Android device to help you log expenses automatically. This feature is off by default and must be explicitly enabled by you in the app's Settings.
What we read: When enabled, the feature scans incoming SMS messages from financial senders such as banks, card issuers, and UPI applications to identify transaction details (amount, type of transaction, merchant or counterparty, and date).
How the data is handled:
- SMS content is processed entirely on your device. The message text is never uploaded to NIKKS CREATIONS servers, never transmitted to any third party, and never used for analytics or advertising.
- Parsed transaction drafts are stored locally on your device until you review and confirm them. Once confirmed, the resulting transaction record is saved to your Pavora AI account using the same cloud sync mechanism as any other transaction you create manually.
- If parsing fails, the original SMS text remains on your device and is not exfiltrated. Anonymous parser failure counts may be recorded in Firebase Crashlytics, but the SMS body itself is never logged.
- Required Android permissions:
READ_SMSandRECEIVE_SMS. These are restricted permissions; you are prompted by the Android system before granting them.
Your controls: You can disable the feature at any time from Pavora AI's Settings screen, which immediately stops the SMS listener. You can also revoke the Android SMS permission from your device's system Settings. Disabling the feature does not delete transaction drafts that were already created — you can clear those from the in-app "SMS captures" review screen.
Platform availability: SMS reading is technically possible only on Android. On iOS, third-party applications cannot access SMS messages, so this feature is not offered. On Galaxy Store builds, the feature is available immediately. On Google Play Store builds, availability may depend on Play Store's restricted-permission review process.
11. UPI Payment Integration
Pavora AI offers a "Pay via UPI" feature that lets you initiate a UPI payment to a payee directly from within the app. Pavora AI is not a payment processor or financial institution and does not handle, hold, or transmit funds. Payments are processed entirely by your chosen UPI application (such as Google Pay, PhonePe, Paytm, BHIM, or any other installed UPI app), your bank, and the UPI network (NPCI).
What we pass to the UPI app: When you tap "Pay now", Pavora AI constructs a standard upi:// deep link containing only the information you entered: the payee's UPI ID (VPA), payee name, amount, and an optional note. Pavora AI then hands this deep link off to the Android system, which lets you choose which UPI application to open. Pavora AI does not see your UPI PIN, bank credentials, account number, or any authentication data.
What we do not receive back: The UPI protocol does not return payment confirmation or failure status to the originating app. Pavora AI therefore does not know whether your payment succeeded, failed, was declined, or is pending. When you return to Pavora AI after attempting a payment, you are shown a confirmation screen to manually record the transaction — you decide whether to save it as an expense based on what actually happened in your UPI app and bank.
Data we store related to UPI payments: If you choose to save a UPI-initiated transaction, the saved record includes the payee VPA, payee name, amount, note, and timestamp — the same data you would record manually. Bank-side payment details (success codes, settlement times, your account balance, and so on) are not visible to us and are not stored.
12. App Lock, PIN, and Biometric Authentication
Pavora AI offers an optional App Lock feature that requires a PIN or biometric authentication (fingerprint or face unlock) to open the app. This feature is off by default and must be enabled by you in Settings.
- PIN storage: Your chosen PIN (4 or 6 digits) is stored locally on your device using the operating system's secure storage facilities. The PIN is never transmitted to NIKKS CREATIONS servers and is not part of cloud backups associated with your account.
- Biometric authentication: When you enable biometric unlock, Pavora AI uses the Android
BiometricPromptsystem API to request authentication. The actual biometric data (fingerprint template, face geometry) never leaves your device and is managed exclusively by the operating system and your device hardware. NIKKS CREATIONS has no access to your biometric templates, scans, or images. - Lock state: Whether the app is locked at a given moment is tracked locally on your device. Locking does not affect cloud-stored data.
- Forgotten PIN: Because the PIN is stored only on your device, NIKKS CREATIONS cannot recover or reset it for you. If you forget your PIN, you may need to reinstall the app or sign back in with your account credentials, which may make locally-cached data inaccessible until re-sync.
Disabling App Lock from Settings removes the stored PIN and disables biometric unlock immediately.
13. Cookies and Local Storage
Our website may use cookies or browser local storage to remember preferences, support analytics, and improve performance. The Pavora AI mobile app may use local device storage to cache user data and configuration. You can control cookie behavior through your browser settings.
14. Third-Party Services
We rely on the following categories of third-party services:
- Cloud infrastructure: Google Firebase, Google Cloud
- App distribution and billing: Google Play (Google Play Billing) and Samsung Galaxy Store (Samsung IAP)
- Advertising: Google AdMob (free tier)
- AI processing: Google Gemini API, OpenAI API, and similar providers
- On-device text recognition: Google ML Kit
- Analytics and crash reporting: Firebase Analytics, Firebase Crashlytics
Each provider operates under its own privacy practices. We encourage you to review their policies.
15. Account Deletion
You may request deletion of your account and associated personal data at any time:
- In-app: Pavora AI includes a "Delete Account" option in Settings
- Email: Send a deletion request to support@nikkscreations.in from the email associated with your account
We will process deletion requests within a reasonable timeframe. Certain data may be retained for legal, accounting, or fraud-prevention purposes as required by law.
16. Your Rights
Depending on your jurisdiction, you may have rights including:
- The right to access the personal data we hold about you
- The right to request correction of inaccurate data
- The right to request deletion of your data
- The right to object to or restrict certain processing
- The right to data portability
- The right to withdraw consent
- The right to lodge a complaint with a supervisory authority
To exercise these rights, contact us at support@nikkscreations.in.
17. Child Safety
Pavora AI is intended for adults and is not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided personal information to us, please contact support@nikkscreations.in and we will take prompt steps to delete the information.
Parents and guardians who allow minors to use their devices are responsible for supervising the use of the Service.
18. Data Retention
We retain personal data only as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. When data is no longer required, we delete or anonymize it using secure procedures.
19. Security
We implement administrative, technical, and physical safeguards designed to protect your information. These include encryption in transit (TLS), secure authentication via Firebase, server-side validation of purchases and entitlements, access controls, and regular security reviews. However, no system can guarantee absolute security.
20. International Data Transfers
Our infrastructure relies on globally distributed cloud providers. Your data may be processed in countries other than your own, where data protection laws may differ. By using the Service, you consent to such transfers in accordance with applicable law.
21. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the app or via the registered email address. The "Last updated" date at the top of this policy reflects the most recent revision.
22. Contact Us
For privacy-related questions, requests, or concerns, contact us at:
- Email: support@nikkscreations.in
- Website: nikkscreations.in
- Studio: NIKKS CREATIONS
We respond to legitimate inquiries within a reasonable timeframe and will work with you to resolve any concerns.