← Back to Taraka

Privacy Policy

Last updated: 28 July 2026

Taraka is developed and operated by Zenith7 (the developer named on the Google Play listing). Privacy contact: andrian.wu.7@gmail.com.

Taraka was previously called Moneta. Only the name changed — it is the same app from the same developer, and nothing in this policy changed with the rename.

The short version

Taraka is local-first: your data lives on your device and the app works fully without an account. A few optional features connect to outside services only when you use them — Google Sign-In, encrypted Google Drive backup, emailed PIN-recovery codes, and voice entry (all detailed below). Signing in also asks Google for permission to Taraka's private app-data folder in your Drive and performs a one-time, read-only check for an existing backup so we can offer to restore it — nothing is uploaded unless you enable Drive sync or explicitly replace the backup. There are no ads, no analytics, no tracking, and no Taraka server — ever.

What we collect

Signed out, Taraka collects nothing. The optional features collect only what they need:

Your financial records (wallets, transactions, amounts, notes, receipt photos) are entered by you and stay on your device unless you enable Drive backup.

Where your data lives

On your device: all wallets, transactions, budgets, goals, recurring schedules, templates, categories, receipt photos, and preferences live in your phone's local storage.

In your own Google Drive (only if you enable Drive sync or explicitly upload a backup): an encrypted backup of that data, kept in a private app-only folder that is hidden from your normal Drive view. It is encrypted on your device before upload. The encryption key is derived from your Google account identity, so treat your Google account's security as the backup's security boundary — anyone with full control of your Google account (and, in principle, Google itself) could access it. The backup file is labeled with your account email in its unencrypted file metadata so the restore prompt can show which account it belongs to; the financial data itself is always encrypted. We recommend also exporting a JSON/Excel backup periodically.

How long we keep it

Because there is no Taraka server, we don't hold your data on a schedule of our own — you control how long it lives. Your on-device records stay until you delete them in the app or uninstall Taraka. An encrypted Drive backup, if you turn sync on, stays in your Google Drive until you delete it (see "Deleting your data"). A PIN-recovery code sent through EmailJS is single-use and short-lived, and we store only a one-way hash of it on your device, never the code itself.

Where processing happens

Taraka itself runs on your device. The optional providers it can call — Google (Sign-In & Drive), EmailJS, and ExchangeRate-API — are operated by third parties that may process the request on servers outside your country, under their own privacy policies. Using an optional feature is your consent for that request to be made; if you don't use it, no such transfer happens.

Who we share data with

Taraka has no server or backend and never sells or shares your data for advertising. Optional features use these providers:

If you never sign in or turn these features on, none of them are contacted.

Phone permissions

Taraka requests these Android permissions, and only when you actively use the corresponding feature:

Network usage

All network calls use HTTPS. They are: Google Sign-In, Google's token-validation endpoint, and Google Drive (only if you sign in / enable sync); the EmailJS API (only when you request a PIN-recovery code); and currency rates from open.er-api.com (only if auto-update is on — no account or financial data is sent, though the service sees your device's IP address like any web request). Receipt photos and their text recognition are processed entirely on your device (the on-device recognition model is downloaded once by Google Play services).

Voice entry (optional). When you tap the microphone in voice entry, your speech is transcribed by your device's speech-recognition service. Where your device supports on-device recognition for the chosen language, the audio never leaves your phone; otherwise the audio may be sent to your device's speech service (for example, Google's) to transcribe it, under that provider's privacy policy — the same service your device uses for other voice input. Taraka never records, stores, or sends your voice audio to a Taraka server, and only the resulting text is used, on your device, to pre-fill the transaction for you to review.

Deleting your data

Taraka has no account of its own — you sign in with your existing Google account, and no separate Taraka profile is created on any server. To remove the data tied to your use of Taraka, follow these steps:

On-device: Settings → Reset → "Delete all data" wipes everything stored on this device (and uninstalling removes the app's local storage).

Cloud backup: if you turned on Drive sync, your encrypted backup stays in your Google Drive even after a reset or uninstall. To delete it, use Settings → Account & Security → Drive sync → "Delete cloud backup & sign out", which removes the backup and signs you out.

Without the app installed: you can delete the backup yourself at any time — open Google Drive → Settings → Manage apps → Taraka (it may still be listed under the app's former name, Moneta) → "Delete hidden app data". Revoking Taraka's access from your Google Account (Security → Third-party access) stops future access but does not delete the stored backup — use the Drive step above for that.

Children

Taraka is not directed at children under 13 and does not knowingly collect personal information from children under 13. The optional sign-in features described above are the only personal information Taraka handles.

Changes to this policy

Material changes will show up in the in-app "What's new" modal on the version that introduces them, and the date at the top of this page will update. Past versions are visible in the in-app Notifications log.

Your rights

Because your data lives on your device, you can exercise most rights directly in the app: access / export it any time (Settings → Data Management → Export JSON or Excel), correct it by editing records in the app, and delete it using the steps in "Deleting your data" above. For anything else — including questions, complaints, or requests you can't complete in-app — email andrian.wu.7@gmail.com and we'll respond as soon as we can.

We do not sell or "share" your personal information as those terms are used under laws such as the California Consumer Privacy Act (CCPA/CPRA), and there is no advertising or cross-context behavioural tracking to opt out of. Where a law such as the GDPR applies, our legal basis for the limited processing above is your consent, given by choosing to use each optional feature, which you can withdraw at any time by turning the feature off. These rights apply regardless of where you live; residents of regions with specific data-protection laws (EEA/UK, California, and others) may also contact us using the email above to exercise them.

Questions

Email andrian.wu.7@gmail.com, or file a GitHub issue at github.com/Zen1th7/moneta (note that GitHub issues are public — use email for anything private).