Vibexio Private Limited (“we”, “us”, “our”) operates the Kubyn mobile application. This Privacy Policy explains what personal data we collect, why we collect it, how we protect it, who we share it with, and the rights you have over it.
It is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (“DPDP Act”).
By using Kubyn, you agree to the practices described below. Where the law requires specific consent — for example, for financial data accessed through an Account Aggregator, or for voice processing — we request it separately and explicitly within the App.
1. Data we collect
1.1 Data you provide
- Identity and contact data: name, email address, mobile number, date of birth, gender, and optional demographic details such as occupation or income range, used to personalise insights.
- Account security data: your Security PIN (stored only as a cryptographic hash, never in plain text) and OTP verification status.
- Financial data you enter: transactions (amount, category, description, date), income and expense records, financial goals and contributions, bill payment details, and calculator inputs.
- Voice input: voice commands you speak to record transactions or query your finances, and logs of those interactions.
- Chat data: messages you exchange with the in-app assistant.
- Support data: queries, complaints, and correspondence you send us.
1.2 Data collected with your explicit consent
- Bank and financial account data via Account Aggregator: account details, balances, and bank transactions fetched through the RBI-regulated AA framework via our RBI-licensed Account Aggregator partner, strictly within the scope, frequency, and duration you approve on the consent screen. We never collect your bank login credentials.
- Payment data: UPI transaction references, payee and VPA details, amounts, and transaction status for payments you initiate. Card and UPI credentials are handled by the payment partner and are not stored by us.
1.3 Data collected automatically
- Device and technical data: device model, operating system and version, unique device identifiers, app version, IP address, language, and time zone.
- Usage and security data: login timestamps and activity, active sessions, feature usage patterns, crash logs, and diagnostic data.
- Notification token: Firebase Cloud Messaging (FCM) token, used to deliver push notifications.
We do not knowingly collect data from persons under 18 years of age.
2. How we use your data
| Purpose | Data used |
|---|---|
| Create and manage your account; authenticate you via OTP, PIN, and sessions | Identity, contact, security, and device data |
| Provide core features: transaction tracking, goals, calculators, statements, insights | Financial data you enter; Account Aggregator data where consented |
| Process and track payments you initiate | Payment data |
| Respond to voice commands and chat queries | Voice input, chat data, your financial records |
| Personalise insights and content | Demographic and usage data |
| Send transactional and security alerts, and promotional notifications where consented | Contact data, FCM token |
| Detect and prevent fraud, unauthorised access, and abuse | Login activity, device and session data |
| Provide customer support and resolve grievances | Support data, account data |
| Comply with legal, tax, and regulatory obligations | As required by law |
| Improve app performance and fix defects | Crash logs, diagnostics, aggregated usage data |
We do not sell your personal data, and we do not use your financial data for third-party advertising.
3. Legal basis and consent
- We process your data on the basis of your consent, the performance of the Services you have requested, and our legal obligations.
- Consent for financial data accessed through an Account Aggregator is obtained separately through the AA consent flow and may be paused or revoked at any time.
- Consent for promotional communications is optional and may be withdrawn in Settings.
- You may withdraw any consent at any time. Withdrawal does not affect processing already carried out lawfully, and some features may cease to function without the related data.
4. Who we share data with
We share data only with parties necessary to operate the Services:
- Payment partners — our authorised payment partner, the NPCI ecosystem, and your bank, to execute payments you initiate.
- Account Aggregator — our RBI-licensed Account Aggregator partner, to fetch financial data in accordance with your consent.
- Cloud hosting and infrastructure providers — to store and process data securely.
- Communication providers — SMS and OTP gateways, email service providers, and Firebase Cloud Messaging (Google) for push notifications.
- Analytics and crash-reporting providers — using aggregated or pseudonymised data wherever possible.
- Law enforcement, courts, and regulators — where required by applicable law or valid legal process.
- Successor entities — in the event of a merger, acquisition, or restructuring, subject to the protections in this Policy.
All vendors are bound by contractual confidentiality and data-protection obligations. We do not share your data with unauthorised third parties and do not sell it to advertisers or data brokers.
5. Storage, security, and international transfers
- Data is stored on secure servers located in India. Where any data is processed outside India, we ensure protections consistent with this Policy and applicable law.
- Security measures include encryption in transit (TLS/HTTPS), hashing or encryption of sensitive fields (your Security PIN is stored only as a cryptographic hash), role-based access controls, session management with device tracking, audit logging of login activity, and periodic security reviews.
- No system is completely secure. You also play a role: keep your device secure, use a strong device lock, never share your PIN or OTP, and log out of shared devices.
6. Data retention
- Account data: retained while your account is active.
- Financial and transaction records: retained while your account is active and thereafter only as long as required by applicable law, including tax, audit, and payment regulations.
- AA-fetched data: retained only for the duration specified in your consent, and deleted or rendered unusable when consent is revoked, subject to legal retention duties.
- Voice and chat logs: retained for 12 months for service quality and dispute resolution, then deleted or anonymised.
- Following account deletion: personal data is deleted or irreversibly anonymised within 30 days, except records we are legally required to retain.
7. Your rights
Subject to applicable law, including the DPDP Act, 2023, you have the right to:
- Access — obtain a summary of the personal data we hold about you and how it is processed.
- Correction — update or correct inaccurate, incomplete, or outdated data. Most of this is available directly in Settings.
- Erasure — request deletion of your personal data.
- Withdraw consent — including Account Aggregator consents and promotional communications, at any time.
- Grievance redressal — raise a complaint with our Grievance Officer and, if unresolved, escalate to the Data Protection Board of India.
- Nominate — nominate another person to exercise your rights in the event of your death or incapacity.
To exercise any right, use the in-app options or write to grievance@kubyn.org. We verify your identity before acting on a request and respond within the timelines prescribed by law.
8. Account deletion
You may delete your Kubyn account at any time:
- In the App: Settings → Account → Delete Account; or
- By email: write to support@kubyn.org from your registered email address with the subject line “Account Deletion”.
On deletion we immediately deactivate your account, revoke active sessions and Account Aggregator consents, and delete or anonymise your personal data in accordance with section 6. We confirm completion by email. Full details are on the Account Deletion page.
9. Cookies and similar technologies
The App does not use browser cookies. It uses device identifiers, local storage, and SDK-level identifiers — including the FCM token and analytics identifiers — for the purposes described in this Policy. This website’s use of cookies is described in the Cookie Policy.
10. Children’s privacy
Kubyn is intended for users aged 18 and above. We do not knowingly collect personal data from children. If you believe a minor has provided us with personal data, contact grievance@kubyn.org and we will delete it.
11. Data breach notification
In the event of a personal data breach, we will notify affected users and the relevant authorities — including CERT-In and the Data Protection Board of India — as required by applicable law, and will take prompt steps to contain and remediate the breach.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through the App or by email before they take effect. The “Last updated” date reflects the current version. Continued use of the App after the effective date constitutes acceptance.
13. Grievance Officer and contact
- Grievance Officer: Grievance Officer
- Email: grievance@kubyn.org
- Address: Chennai, Tamil Nadu, India
- Acknowledgment: within 48 hours. Resolution: within 30 days.
General queries: support@kubyn.org
