Rojgar — Privacy Policy
Effective date: 19 September 2026
App: Rojgar (Android package com.rojgar.app)
Developer: Shoeb Adnan
Contact: shoeb.adnan.cse@gmail.com
Rojgar is a personal money manager. It is built so that your financial records stay with you. This policy explains exactly what the app does with your data.
The short version
- Rojgar has no account, no server, no analytics, no advertising and no tracking.
- Everything you enter is stored only on your device.
- The developer never receives, sees, sells or shares your data.
- Optional backup and Google Drive sync are end-to-end encrypted with a passphrase only you know.
1. Data the app stores on your device
When you use Rojgar, the following is stored in a local database on your phone:
- Money sources you create (name, type, colour, icon, balance history).
- Entries: amounts, dates, notes, reasons, tags, transfers, loans.
- Templates, recurring rules, alerts and in-app notifications.
- Zakat calculations and the rates you enter.
- App settings (language, theme, hidden-amount preference, app-lock setting).
This data never leaves your device unless you choose one of the options in sections 3 and 4.
2. Data we collect
None. Rojgar does not collect personal information, usage statistics, crash reports, device identifiers, location, contacts or advertising IDs. It contains no third-party analytics or advertising SDKs.
3. Encrypted backup (optional)
If you turn on Backup, or export a backup file:
- The app writes a
.momofile containing your records, encrypted with a key derived from your passphrase (Argon2id key derivation, AES-256-GCM encryption). - The file is saved to a folder you choose on your device, or shared to a place you choose via your phone's share sheet.
- Without your passphrase the file cannot be read — not by us, and not by anyone else. If you forget the passphrase, the backup cannot be recovered.
The app's encrypted backup replaces Android's automatic cloud backup, which is turned off for Rojgar.
CSV export. Settings → Export CSV creates a plain spreadsheet file of your entries and hands it to your phone's share sheet. This file is not encrypted — the app warns you before creating it. Where it goes is your choice; the app sends it nowhere by itself.
4. Google Drive sync (optional)
If you connect Google Drive:
- You sign in with Google. The app requests only the
https://www.googleapis.com/auth/drive.appdatapermission. This gives the app access to a hidden, app-specific folder in your own Drive. It cannot see, read or change any of your other Drive files. - The app stores only encrypted files in that folder: one encrypted file per device, plus a small file holding the encryption salt and a passphrase check value (not the passphrase and not the key).
- Your records are encrypted on your phone before upload. Google stores ciphertext and cannot read it. The developer has no access to your Drive.
- Your Google account ID is used on your device only, to link your records to your Drive folder. It is not sent anywhere else.
Google API Services User Data Policy. Rojgar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from Google APIs is used only to provide the sync feature you turned on; it is not used for advertising, not transferred to others, and not read by any human.
5. Device permissions
| Permission | Why |
|---|---|
| Notifications | Local reminders for recurring entries and alerts. Created on your phone; nothing is sent to a server. |
| Run at startup | Re-schedules those reminders after your phone restarts. |
| Biometric | Optional app lock. Handled by your phone's operating system; the app never receives your fingerprint or face data. |
| Internet | Used only for Google Drive sync (if enabled) and to open the BAJUS gold-price website in your browser when you tap that link. |
6. Links to other websites
The zakat feature can open the BAJUS website in your browser. That site has its own privacy policy; Rojgar sends it no data.
7. Deleting your data
- In the app: Settings → Delete all data erases everything stored on the device.
- Uninstalling the app deletes all its on-device data. Backup files you saved to a folder of your choice remain until you delete them.
- Google Drive: Settings → Delete all data → tick Also delete Rojgar's encrypted data from Google Drive. Or go to Google Drive → Settings → Manage apps → Rojgar → Delete hidden app data. You can also revoke access at myaccount.google.com/permissions.
8. Security
Records are protected on the device by the optional app lock and Android's app-sandboxing. The encryption key for backup/sync is held in the Android Keystore. Backup and sync data that leaves the device is end-to-end encrypted; the only exception is a CSV file you explicitly choose to export.
9. Children
Rojgar is not directed at children under 13 and does not knowingly collect any data from anyone, including children.
10. Changes to this policy
If this policy changes, the new version will be posted at this address with a new effective date. Because the app collects no data, changes will not affect data we hold — we hold none.
11. Contact
Questions about this policy: shoeb.adnan.cse@gmail.com