This Privacy Policy describes, in full, how the Pesa Traq Android application collects, uses, stores, and safeguards information in connection with your use of the Application. Please read it carefully before installing or using Pesa Traq.
Pesa Traq is an Android application that reads M‑Pesa and Airtel Money transaction confirmation messages already present on the user's device and converts them into a structured, categorized record of personal spending. The Application performs this processing entirely on the User's device. It does not operate a backend server, does not require the creation of an account, and does not transmit Transaction Data, SMS Data, or any other information collected by the Application to the Developer or to any third party.
This Policy is published to satisfy the disclosure obligations that apply to an application requesting access to SMS content under the Google Play Developer Program Policies, and to give Users a complete and accurate account of the Application's data practices before they grant any permission.
If any statement in this Policy is inconsistent with the Application's actual behavior in a released version, the Developer will correct either the Application or this Policy promptly upon becoming aware of the inconsistency.
The following terms, capitalized throughout this Policy, have the meanings given below.
com.mpesatracker.mpesa_tracker and marketed under the name "Pesa Traq."The Application inspects incoming and, on request, previously received SMS messages solely to identify those originating from a recognized Money Provider sender identifier. Messages from any other sender, including personal correspondence, one-time passcodes, delivery notifications, and promotional messages, are not read, parsed, stored, or otherwise processed by the Application.
When an SMS message is identified as a Money Provider transaction confirmation, the Application's on-device parser extracts the following fields where present in the message text: the transaction reference code; the transaction amount; the direction of the transaction, that is, whether funds were sent or received; the name or identifier of the counterparty, such as a person, till number, or paybill; the timestamp printed within the message itself; the resulting M‑Pesa account balance; any transaction fee charged; and, for bank transfer messages, the destination bank account number. A message that reports a failed transaction, for example a declined Fuliza overdraft draw due to insufficient funds, is recognized and discarded without being recorded as a transaction.
The Application also stores information you enter yourself: the category, subcategory, and any notes you assign to a transaction; categorization rules and keyword lists you define; counterparty patterns the Application learns from your corrections; and manually entered transactions for cash payments or messages that were never received.
Because the Application has no registration or sign-in flow, it has no mechanism by which to associate the Transaction Data it stores with a User's real-world identity, and it does not attempt to do so by any other means, such as device fingerprinting.
Information described in Section 3 is used exclusively to operate the features of the Application on the Device on which it was collected. Specifically:
None of the foregoing processing occurs on a server operated by the Developer or by any third party. All computation described in this section is performed by the Application on the Device's own processor.
The Developer does not use any information collected by the Application for advertising, marketing, profiling for purposes unrelated to the Application's core function, research unrelated to the Application, or any purpose other than those stated in this section.
Pesa Traq is designed primarily for Users transacting through M‑Pesa and Airtel Money in Kenya, and this Policy is drafted with reference to the Kenya Data Protection Act, 2019, and the regulations issued under it. Where the Application processes Personal Data, it does so on the following bases:
Because all processing occurs on-device under your direct control, the Developer does not act as a data controller or data processor with respect to Transaction Data in the ordinary sense contemplated by data protection law, as the Developer at no point receives, stores, or has access to that data.
All Transaction Data, categories, rules, and settings are stored in a local SQLite database located within the Application's private storage area on your Device, an area that the Android operating system isolates from other applications by default. The Application maintains no backend infrastructure, database, or server of any kind, so there is no remote location to which this data could be copied, synchronized, or transmitted, whether inside or outside Kenya.
Android's built-in device backup service, which is controlled by the User's own Google account rather than by the Developer, may include the Application's local storage in an encrypted backup to the User's personal Google Drive storage, in the same manner it would for most other installed applications that do not explicitly opt out. The Developer has no access to, and receives no copy of, any such backup. A User may disable this behavior for the Application, or for the Device generally, from Android Settings under System, then Backup.
The Application requests a fixed, minimal set of Android permissions. Each permission maps to exactly one feature described in this Policy, and none is used for any purpose beyond what is stated below.
| Permission | Purpose |
|---|---|
| READ_SMS RECEIVE_SMS |
Allows the Application to detect new Money Provider messages as they arrive, and, at your request, to import Money Provider messages already present in your SMS inbox. A native Android component filters incoming broadcasts to known Money Provider sender identifiers before any parsing occurs, and the Application never composes or sends an SMS message. |
| POST_NOTIFICATIONS | Displays the review-inbox alert and the daily spending summary as standard Android notifications generated locally by the Application. |
| RECEIVE_BOOT_COMPLETED | Re-registers the scheduled daily summary alarm after the Device restarts, since Android clears previously scheduled alarms on every reboot. |
READ_SMS and RECEIVE_SMS are classified by Google Play as restricted, sensitive permissions. The Developer requests them because automatic capture of Money Provider transaction messages is the Application's core, user-facing function, disclosed prominently at first launch and in the Application's Play Store listing, and the Application is submitted for review, where applicable, under the Google Play Permissions Declaration process governing SMS access for personal financial management applications.
The Application does not integrate any third-party software development kit for analytics, crash reporting, advertising, attribution, or any other purpose. It does not embed a third-party SMS retrieval library or a third-party notification service; SMS capture and notifications are implemented using native Android APIs written and maintained by the Developer.
The only external parties with any relationship to your use of the Application are the following, whose own data practices are outside the Developer's control and are governed by their own privacy policies:
The Developer receives no information from, and shares no information with, either of the parties listed above beyond what is inherent in the ordinary operation of the Google Play distribution platform and the Android operating system itself.
Transaction Data is retained locally for as long as the Application remains installed on your Device, or until you delete it yourself; the Application does not impose an automatic expiry or purge on any record. You control retention directly, through the following mechanisms:
Because Transaction Data never leaves your Device, its practical security depends substantially on the security of the Device itself. The Application relies on the following safeguards:
The Application's local database is not separately encrypted beyond the protection Android's own storage sandbox and, where enabled, full-device encryption already provide. The Developer recommends that Users protect the Transaction Data stored on their Device by enabling a screen lock, keeping the Device's operating system and security patches up to date, and enabling full-device encryption where it is not already the Android default.
No method of storage is completely free of risk, and the Developer cannot guarantee absolute security. However, because Transaction Data is never transmitted over a network by the Application, it is not exposed to the risks associated with data in transit or with a centralized server breach.
The Application applies an automated, on-device categorization engine to classify each debit transaction, using, in order of priority, counterparty patterns you have previously confirmed, category keywords you have configured, known Kenyan merchant recognition, user-defined time and amount rules, and an amount-bucket fallback. Credit transactions are filed automatically as "Money In" without categorization, since they require no spending review.
This categorization exists solely to reduce the manual effort of reviewing your own transactions and has no legal or similarly significant effect on you: it does not determine your eligibility for any product or service, does not influence any decision made by the Developer or a third party about you, and every categorization it produces can be reviewed, corrected, or reverted by you at any time from within the Application. No categorization decision, correction, or pattern learned by the engine is transmitted to the Developer or to any third party.
Under the Kenya Data Protection Act, 2019, and comparable data protection frameworks, individuals generally hold rights to access, correct, delete, restrict, and port their Personal Data, and to object to certain processing of it. Because the Application stores Transaction Data exclusively on your own Device, with no copy held by the Developer, you already hold and directly control the only existing copy of that data at all times, and you may exercise the substance of each of these rights without needing to submit a request to the Developer:
If you believe the Application is not honoring any statement in this Policy, you may contact the Developer using the details in Section 18, or lodge a complaint with the Office of the Data Protection Commissioner of Kenya, or with the data protection authority of your own jurisdiction where applicable.
Pesa Traq is a personal finance application built around M‑Pesa and Airtel Money, mobile money services that under Kenyan regulation require an account holder to be at least eighteen years of age. Accordingly, the Application is not directed to, marketed to, or knowingly used by children, and the Developer does not knowingly collect information from any individual under the age of thirteen, or under the applicable age of digital consent in the User's jurisdiction, whichever is higher. If the Developer becomes aware that the Application has collected information from a child in violation of this section, the Developer will take reasonable steps to ensure that information is deleted, recognizing that, in the ordinary case, such data already exists only on the child's own Device and is deleted by the remedies described in Section 10.
The Application's SMS parser is tuned specifically against message formats used by Safaricom's M‑Pesa and Airtel Money in Kenya. Users located outside Kenya, or using a Money Provider other than those two services, should expect the Application's automatic parsing to recognize few or no messages, though manual transaction entry remains fully available regardless of location.
Because the Application transmits no data over any network, no cross-border transfer of Transaction Data occurs as a result of using the Application, regardless of where the User or their Device is physically located.
The Developer may revise this Policy from time to time to reflect changes in the Application's functionality, applicable law, or Google Play policy requirements. Any revision will be published at this same address with an updated effective date at the top of the page. Because the Application has no mechanism to contact Users directly, Users are encouraged to review this page periodically; material changes affecting the collection or use of information will additionally be noted in the release notes accompanying the Application version in which they take effect.
This Policy is governed by and construed in accordance with the laws of the Republic of Kenya, including the Data Protection Act, 2019, without regard to conflict-of-law principles. Nothing in this Policy limits any statutory right a User may hold under the law of their own jurisdiction that cannot lawfully be waived by agreement.
Questions, concerns, or requests relating to this Policy or to the Application's data practices may be directed to the Developer at the address below. The Developer aims to respond to legitimate inquiries within a reasonable time.