Privacy policy
Sampati is a personal ledger. It holds what you put in it, and it does not go looking for anything else.
Last updated 6 August 2026
The short version
Sampati holds the money entries you type in, and the account you sign in with. It has no connection to any bank. It does not sell data, does not carry advertising, and has no analytics SDK following you around the app. You can export everything or delete everything from inside the app, without asking anyone.
The rest of this page is the detail behind that, including every outside company involved and exactly what each one receives.
What Sampati holds
Your account
Signing in is your email address and a six-digit code sent to it — there is no password, and no Google, Apple or Facebook login. Sampati receives an account identifier and your email address. The sign-in itself is handled by Clerk.
What you enter
Everything you record: transactions, income, transfers, the accounts and institutions you name, balances, budgets, bills, goals, share and gold holdings, IPO applications, money lent and borrowed and the names you file it under, payslip figures, remittance details, notes and rationales you write, and the derived monthly summaries built from all of it.
How you use the app
Language, calendar and numeral preferences, notification settings, which days you logged an entry and your streak, the amounts you repeat often (so the app can offer them again), and a record of AI credits granted and spent.
Device
A push notification token, if you allow notifications, so reminders can reach your phone. Sampati does not collect an advertising identifier, and does not track you across other apps or websites.
What it never collects
- Bank credentials. No logins, no card numbers, no OTPs, no account numbers held for connection purposes. There is no bank integration in Sampati and none is planned.
- Your location. Sampati does not request or receive location data.
- Your contacts. People you lend to are names you type, not contacts read from your phone.
- Advertising identifiers. There is no advertising in Sampati and no ad network in it.
- Health, biometric templates or anything similar. Face ID and fingerprint unlock are handled entirely by your phone; Sampati is told only whether the check passed.
AI capture
AI capture is optional and never runs on its own. When you ask Sampati to read something, that specific item is sent to a model provider so it can be turned into a draft entry:
- the sentence you typed or pasted;
- the recording you made while holding the record button;
- the photo or screenshot you picked;
- the statement PDF you chose;
- a payment alert you approved, if you enabled alert reading on Android.
Your name, email address and the rest of your ledger are not attached to that request. The reply comes back as a draft you can correct, and nothing is written to your ledger until you press save.
A recording, photo or PDF you hand to AI capture is held in Sampati's own storage while the draft is open, because the read may take a moment and you may want to look at it again. It is deleted when you save the draft, when you discard it, and by a scheduled clean-up if you do neither. Sampati keeps the draft itself and a record of what the read cost in credits.
Model providers are named in the table below. Sampati uses their standard API endpoints, under terms which do not permit training on data submitted through them.
Reading payment alerts on Android
This feature is off until you turn it on, Android only, and it needs a permission you grant in your phone's own settings — notification access. Here is exactly what it does:
- You choose which apps Sampati may look at — your bank, eSewa, Khalti and the like.
- Filtering happens on your phone. Notifications that are not about a payment, and anything that looks like a one-time password or verification code, are discarded on the device and never leave it.
- What survives the filter is shown to you in Sampati's inbox. A message becomes an entry only when you open it, read it and save it.
- Turning the feature off in Settings, or revoking notification access in Android settings, stops it immediately.
Notification data is used only to help you record your own transactions. It is never sold, never used for advertising, and never shared with anyone beyond the processing described here.
Who processes it
| Company | What it does | What it receives |
|---|---|---|
| Convex | Database and backend hosting | Everything described under “What Sampati holds” |
| Clerk | Sign-in and account management | Email address, and the sign-in codes it sends you |
| Expo | Push notification delivery | Push token and the text of the reminder |
| Google (Firebase Cloud Messaging) | Push delivery on Android | Push token and the text of the reminder |
| Google (Gemini API) | Reads voice notes, photos and statement PDFs | Only the item you asked it to read |
| Cerebras, Groq, DeepInfra | Read typed and pasted text | Only the text you asked them to read |
These providers process data on Sampati's instructions. Sampati does not share your data with anyone else — not with banks, insurers, employers, credit bureaus, data brokers or advertisers. The only other case is a lawful order from a competent authority, which is answered narrowly.
Convex and Clerk host outside Nepal. Using Sampati means your entries are stored on their infrastructure.
How it is used
- To show you your own ledger, budgets, balances and charts.
- To send the reminders and reviews you turned on.
- To turn something you gave it into a draft entry, when you ask.
- To keep the app working — fixing faults, preventing abuse, and keeping AI usage within the credits on your account.
That is the complete list. Your entries are not used to build a profile of you, are not used to train any model, and are not used to advertise anything.
How long it is kept
Your ledger is kept while your account exists, because a ledger with holes in it is not a ledger. Delete an individual entry and it is gone. Delete your account and everything is removed.
Capture drafts you never saved, and payment alerts you never turned into entries, are cleared automatically after a short period.
Export and deletion
Export. Settings has a one-tap export of every entry as CSV or JSON. No request, no waiting.
Deletion. Settings, then Delete account. It removes your entries, accounts, budgets, goals, holdings, drafts, credits and your sign-in — everywhere, permanently, with no recovery. If you have already removed the app, see the account deletion page.
Correction. Everything in Sampati is editable by you, at any time. If something is wrong and you cannot fix it yourself, write to privacy@sampati.app.
Security
- Traffic between the app and the backend is encrypted in transit.
- Every backend function resolves who you are from a verified sign-in token. No part of the app can ask for another person's data by passing a different identifier.
- You can turn on an app lock so Sampati asks for your fingerprint, Face ID or device passcode whenever it comes back to the foreground.
- Sign-in tokens are held in the secure storage your phone provides.
No system is perfect. If you believe something has gone wrong, write to privacy@sampati.app and it will be looked at quickly.
Children
Sampati is not directed at children and is not designed for them. You must be 18 or older to hold an account. If you believe a child has created one, write to us and it will be removed.
Changes
If this policy changes in a way that matters, the date at the top changes and the app tells you about it. Continuing to use Sampati after that means the new version applies.
Contact
Sampati Nepal, Kathmandu, Nepal.
Privacy: privacy@sampati.app
Everything else: support@sampati.app