YekanYekan← Back to home
Yekan guide

Privacy policy

Clear, practical information about how Yekan works, your data, and app permissions.

Information we collect

We collect only what is needed to operate Yekan, with the user’s consent: account information such as name, email, mobile number, and optional profile image; login information for password, OTP, or Google sign-in; financial data including accounts, wallets, transactions, categories, and tags; device and session information such as IP address, device name, and last active time; and uploaded files such as receipts or financial documents.

How we use it

We use this information to provide and synchronize financial data, manage shared accounts and permissions, improve performance and user experience, secure sessions, prevent unauthorized access, and provide backups or exports. We never sell financial information or use it for advertising or marketing.

Yekan security architecture

Yekan protects financial, personal, and accounting data using layered safeguards and explicit access controls.

Authentication and secure login

User identifiers are generated as UUIDs. Passwords are never stored in plain text; only password hashes are retained. Yekan supports secure login methods including passwords, one-time passwords, and Google sign-in.

Sessions and app lock

Each login is recorded as an independent session with device information, IP address, and last-active time. Users can review active sessions and remotely terminate unwanted sessions. An optional app lock using a password, pattern, or device biometrics helps protect local financial data.

Access control and sharing

Account owners control collaborators and can grant or revoke limited view and edit permissions. Shared access is explicit, transparent, and auditable.

Files and attachments

Receipts and financial documents are stored in protected cloud storage. The database stores file identifiers and metadata rather than exposing public storage paths.

Secure communication and synchronization

Data is exchanged over HTTPS with secure authentication, and communication tokens are rotated periodically. Reference data such as banks, currencies, and categories is versioned so devices request only required changes. Data events are controlled and recorded for synchronization between authorized devices.

Security monitoring

Important events such as logins, data changes, account sharing, and unusual requests are recorded internally for review and to help identify suspicious activity.

User control and deletion

You can edit or delete your information, terminate sessions on other devices, export your data, or request deletion of your account and associated data.

Policy changes

We may update this policy in the future. The current version will always be published on this page.