Pesa Traq Follow Your Money

Privacy Policy

This Privacy Policy describes, in full, how the Pesa Traq Android application collects, uses, stores, and safeguards information in connection with your use of the Application. Please read it carefully before installing or using Pesa Traq.

On‑device only No ads or trackers No account required Effective 8 September 2026 Applies to version 1.6.0 and later
01

Overview

Pesa Traq is an Android application that reads M‑Pesa and Airtel Money transaction confirmation messages already present on the user's device and converts them into a structured, categorized record of personal spending. The Application performs this processing entirely on the User's device. It does not operate a backend server, does not require the creation of an account, and does not transmit Transaction Data, SMS Data, or any other information collected by the Application to the Developer or to any third party.

This Policy is published to satisfy the disclosure obligations that apply to an application requesting access to SMS content under the Google Play Developer Program Policies, and to give Users a complete and accurate account of the Application's data practices before they grant any permission.

If any statement in this Policy is inconsistent with the Application's actual behavior in a released version, the Developer will correct either the Application or this Policy promptly upon becoming aware of the inconsistency.

02

Definitions

The following terms, capitalized throughout this Policy, have the meanings given below.

"Application" or "Pesa Traq"
The Android application distributed under the package identifier com.mpesatracker.mpesa_tracker and marketed under the name "Pesa Traq."
"Developer," "we," "us"
The individual developer who builds, publishes, and maintains Pesa Traq.
"User," "you," "your"
The natural person who installs, accesses, or otherwise uses the Application.
"Device"
The Android smartphone or tablet on which the Application is installed.
"SMS Data"
The content of SMS messages present on the Device that the Application reads for the purpose of identifying money-provider transaction confirmations.
"Transaction Data"
The structured information the Application extracts from SMS Data, together with any category, note, or manual entry a User adds, as described in Section 3.
"Personal Data"
Any information relating to an identified or identifiable natural person. Within the Application, Transaction Data may constitute Personal Data because it can reveal a User's counterparties and spending habits, even though it does not include a User's name, national identification number, or contact details.
"Money Provider"
Safaricom's M‑Pesa service and Airtel Money, the two mobile money services whose confirmation messages the Application is built to parse.
03

Information we collect

The Application inspects incoming and, on request, previously received SMS messages solely to identify those originating from a recognized Money Provider sender identifier. Messages from any other sender, including personal correspondence, one-time passcodes, delivery notifications, and promotional messages, are not read, parsed, stored, or otherwise processed by the Application.

Data extracted from a qualifying message

When an SMS message is identified as a Money Provider transaction confirmation, the Application's on-device parser extracts the following fields where present in the message text: the transaction reference code; the transaction amount; the direction of the transaction, that is, whether funds were sent or received; the name or identifier of the counterparty, such as a person, till number, or paybill; the timestamp printed within the message itself; the resulting M‑Pesa account balance; any transaction fee charged; and, for bank transfer messages, the destination bank account number. A message that reports a failed transaction, for example a declined Fuliza overdraft draw due to insufficient funds, is recognized and discarded without being recorded as a transaction.

Data you provide directly

The Application also stores information you enter yourself: the category, subcategory, and any notes you assign to a transaction; categorization rules and keyword lists you define; counterparty patterns the Application learns from your corrections; and manually entered transactions for cash payments or messages that were never received.

Data the Application does not collect

Collected

  • M‑Pesa and Airtel Money confirmation SMS content
  • Transaction Data parsed from those messages
  • Categories, notes, and rules you configure
  • Transactions you enter manually

Never collected

  • Personal messages, OTP codes, or any other SMS content
  • Contacts, call logs, photos, or files
  • Precise or approximate location
  • Camera or microphone input
  • Device identifiers, advertising IDs, or analytics identifiers
  • Browsing activity or data from other applications
  • Name, email address, phone number, or account credentials

Because the Application has no registration or sign-in flow, it has no mechanism by which to associate the Transaction Data it stores with a User's real-world identity, and it does not attempt to do so by any other means, such as device fingerprinting.

04

How we use information

Information described in Section 3 is used exclusively to operate the features of the Application on the Device on which it was collected. Specifically:

None of the foregoing processing occurs on a server operated by the Developer or by any third party. All computation described in this section is performed by the Application on the Device's own processor.

The Developer does not use any information collected by the Application for advertising, marketing, profiling for purposes unrelated to the Application's core function, research unrelated to the Application, or any purpose other than those stated in this section.

05

Legal basis for processing

Pesa Traq is designed primarily for Users transacting through M‑Pesa and Airtel Money in Kenya, and this Policy is drafted with reference to the Kenya Data Protection Act, 2019, and the regulations issued under it. Where the Application processes Personal Data, it does so on the following bases:

Because all processing occurs on-device under your direct control, the Developer does not act as a data controller or data processor with respect to Transaction Data in the ordinary sense contemplated by data protection law, as the Developer at no point receives, stores, or has access to that data.

06

Where your data lives

All Transaction Data, categories, rules, and settings are stored in a local SQLite database located within the Application's private storage area on your Device, an area that the Android operating system isolates from other applications by default. The Application maintains no backend infrastructure, database, or server of any kind, so there is no remote location to which this data could be copied, synchronized, or transmitted, whether inside or outside Kenya.

Android's built-in device backup service, which is controlled by the User's own Google account rather than by the Developer, may include the Application's local storage in an encrypted backup to the User's personal Google Drive storage, in the same manner it would for most other installed applications that do not explicitly opt out. The Developer has no access to, and receives no copy of, any such backup. A User may disable this behavior for the Application, or for the Device generally, from Android Settings under System, then Backup.

07

Permissions we request

The Application requests a fixed, minimal set of Android permissions. Each permission maps to exactly one feature described in this Policy, and none is used for any purpose beyond what is stated below.

PermissionPurpose
READ_SMS
RECEIVE_SMS
Allows the Application to detect new Money Provider messages as they arrive, and, at your request, to import Money Provider messages already present in your SMS inbox. A native Android component filters incoming broadcasts to known Money Provider sender identifiers before any parsing occurs, and the Application never composes or sends an SMS message.
POST_NOTIFICATIONS Displays the review-inbox alert and the daily spending summary as standard Android notifications generated locally by the Application.
RECEIVE_BOOT_COMPLETED Re-registers the scheduled daily summary alarm after the Device restarts, since Android clears previously scheduled alarms on every reboot.

READ_SMS and RECEIVE_SMS are classified by Google Play as restricted, sensitive permissions. The Developer requests them because automatic capture of Money Provider transaction messages is the Application's core, user-facing function, disclosed prominently at first launch and in the Application's Play Store listing, and the Application is submitted for review, where applicable, under the Google Play Permissions Declaration process governing SMS access for personal financial management applications.

You may revoke SMS access at any time from Android Settings, under Apps, then Pesa Traq, then Permissions. The Application will continue to operate for manual transaction entry, reporting, and review of previously imported data; it will simply stop capturing new messages automatically until the permission is restored.
08

Third-party services

The Application does not integrate any third-party software development kit for analytics, crash reporting, advertising, attribution, or any other purpose. It does not embed a third-party SMS retrieval library or a third-party notification service; SMS capture and notifications are implemented using native Android APIs written and maintained by the Developer.

The only external parties with any relationship to your use of the Application are the following, whose own data practices are outside the Developer's control and are governed by their own privacy policies:

The Developer receives no information from, and shares no information with, either of the parties listed above beyond what is inherent in the ordinary operation of the Google Play distribution platform and the Android operating system itself.

09

Sharing and disclosure

The Developer does not sell, rent, trade, or otherwise disclose Transaction Data, SMS Data, or any other information collected by the Application to any third party, for monetary consideration or otherwise, because the Developer does not receive or possess a copy of that data in the first place. The Application makes no network requests of its own; this can be independently verified by reviewing the Application's data usage in Android's own network settings, which will show no traffic attributable to Pesa Traq.

Because the Developer never holds Transaction Data, the Developer has no ability to comply with a request from a government authority, law enforcement body, or civil litigant for that data, as no such data exists outside the User's own Device.

10

Retention and deletion

Transaction Data is retained locally for as long as the Application remains installed on your Device, or until you delete it yourself; the Application does not impose an automatic expiry or purge on any record. You control retention directly, through the following mechanisms:

11

Security measures

Because Transaction Data never leaves your Device, its practical security depends substantially on the security of the Device itself. The Application relies on the following safeguards:

The Application's local database is not separately encrypted beyond the protection Android's own storage sandbox and, where enabled, full-device encryption already provide. The Developer recommends that Users protect the Transaction Data stored on their Device by enabling a screen lock, keeping the Device's operating system and security patches up to date, and enabling full-device encryption where it is not already the Android default.

No method of storage is completely free of risk, and the Developer cannot guarantee absolute security. However, because Transaction Data is never transmitted over a network by the Application, it is not exposed to the risks associated with data in transit or with a centralized server breach.

12

Automated categorization

The Application applies an automated, on-device categorization engine to classify each debit transaction, using, in order of priority, counterparty patterns you have previously confirmed, category keywords you have configured, known Kenyan merchant recognition, user-defined time and amount rules, and an amount-bucket fallback. Credit transactions are filed automatically as "Money In" without categorization, since they require no spending review.

This categorization exists solely to reduce the manual effort of reviewing your own transactions and has no legal or similarly significant effect on you: it does not determine your eligibility for any product or service, does not influence any decision made by the Developer or a third party about you, and every categorization it produces can be reviewed, corrected, or reverted by you at any time from within the Application. No categorization decision, correction, or pattern learned by the engine is transmitted to the Developer or to any third party.

13

Your rights

Under the Kenya Data Protection Act, 2019, and comparable data protection frameworks, individuals generally hold rights to access, correct, delete, restrict, and port their Personal Data, and to object to certain processing of it. Because the Application stores Transaction Data exclusively on your own Device, with no copy held by the Developer, you already hold and directly control the only existing copy of that data at all times, and you may exercise the substance of each of these rights without needing to submit a request to the Developer:

If you believe the Application is not honoring any statement in this Policy, you may contact the Developer using the details in Section 18, or lodge a complaint with the Office of the Data Protection Commissioner of Kenya, or with the data protection authority of your own jurisdiction where applicable.

14

Children's privacy

Pesa Traq is a personal finance application built around M‑Pesa and Airtel Money, mobile money services that under Kenyan regulation require an account holder to be at least eighteen years of age. Accordingly, the Application is not directed to, marketed to, or knowingly used by children, and the Developer does not knowingly collect information from any individual under the age of thirteen, or under the applicable age of digital consent in the User's jurisdiction, whichever is higher. If the Developer becomes aware that the Application has collected information from a child in violation of this section, the Developer will take reasonable steps to ensure that information is deleted, recognizing that, in the ordinary case, such data already exists only on the child's own Device and is deleted by the remedies described in Section 10.

15

International users

The Application's SMS parser is tuned specifically against message formats used by Safaricom's M‑Pesa and Airtel Money in Kenya. Users located outside Kenya, or using a Money Provider other than those two services, should expect the Application's automatic parsing to recognize few or no messages, though manual transaction entry remains fully available regardless of location.

Because the Application transmits no data over any network, no cross-border transfer of Transaction Data occurs as a result of using the Application, regardless of where the User or their Device is physically located.

16

Changes to this policy

The Developer may revise this Policy from time to time to reflect changes in the Application's functionality, applicable law, or Google Play policy requirements. Any revision will be published at this same address with an updated effective date at the top of the page. Because the Application has no mechanism to contact Users directly, Users are encouraged to review this page periodically; material changes affecting the collection or use of information will additionally be noted in the release notes accompanying the Application version in which they take effect.

17

Governing law

This Policy is governed by and construed in accordance with the laws of the Republic of Kenya, including the Data Protection Act, 2019, without regard to conflict-of-law principles. Nothing in this Policy limits any statutory right a User may hold under the law of their own jurisdiction that cannot lawfully be waived by agreement.

18

Contact us

Questions, concerns, or requests relating to this Policy or to the Application's data practices may be directed to the Developer at the address below. The Developer aims to respond to legitimate inquiries within a reasonable time.

mkimanimburu@gmail.com