Kebijakan Privasi Sakuwise
Ringkasan Singkat
Sakuwise adalah aplikasi anggaran pribadi yang dirancang dengan prinsip local-first: semua data keuangan Anda tinggal di perangkat Android Anda dan tidak dikirim ke server kami. Kami tidak memiliki server dan tidak mengumpulkan data Anda.
Satu pengecualian: bila Anda secara sukarela mengaktifkan fitur Backup ke Google Drive, file backup terenkripsi Anda di-upload ke folder pribadi aplikasi di Google Drive Anda sendiri. Kunci enkripsi diturunkan dari PIN Anda, jadi Google tidak dapat membaca isi file backup.
Tidak ada iklan. Tidak ada analytics. Tidak ada pelacakan.
1. Data yang Sakuwise Kumpulkan
Sakuwise (kami) tidak mengumpulkan data Anda sama sekali. Kami tidak memiliki server, tidak ada endpoint API milik kami, dan tidak ada SDK pihak ketiga untuk analytics atau telemetry.
Data yang Anda input ke aplikasi (transaksi, nama akun, kategori plan, nominal, catatan, foto struk, info aset emas/properti/deposito, info hutang) tersimpan secara lokal di perangkat Anda, terenkripsi at-rest dengan AES-256 via SQLCipher. Database hanya dapat dibuka dengan kunci yang disimpan di Android Keystore perangkat Anda, dibuka via biometrik atau PIN Anda.
2. Data yang TIDAK Sakuwise Kumpulkan
Untuk transparansi maksimum, berikut yang tidak kami akses:
- Identifier perangkat (Advertising ID, IMEI, MAC, dll.)
- Lokasi (GPS, koarse, atau berdasarkan IP)
- Daftar kontak, kalender, atau aplikasi terpasang
- Riwayat browser atau pencarian
- Mikrofon atau audio
- Phone state, panggilan, atau SMS
- Email atau nama akun Google Anda (kecuali saat Anda opt-in Drive backup — lihat §4)
3. Izin (Permissions) yang Sakuwise Minta
Sakuwise meminta izin berikut di Android. Beberapa bersifat opsional — Anda bisa menolak dan aplikasi tetap berfungsi tanpa fitur terkait.
| Izin | Tujuan | Status |
|---|---|---|
USE_BIOMETRIC | Membuka kunci aplikasi via sidik jari / wajah | Opsional (fallback: PIN) |
CAMERA | OCR struk belanja untuk mengisi otomatis form pengeluaran | Opsional (fitur OCR) |
POST_NOTIFICATIONS | Mengingatkan pembayaran berulang yang Anda set | Opsional (reminder) |
INTERNET | Backup ke Google Drive (lihat §4) | Wajib di manifest, tapi hanya aktif bila Anda opt-in Drive backup |
ACCESS_NETWORK_STATE | Cek koneksi internet sebelum upload Drive backup | Sama dengan INTERNET |
Penting: Tanpa fitur Drive backup yang Anda aktifkan, Sakuwise tidak pernah mengirim traffic apa pun ke internet, meskipun INTERNET ada di manifest.
4. Google Drive Backup (Opsional, Opt-In)
Sakuwise menawarkan fitur opsional untuk mem-backup data Anda ke Google Drive folder pribadi aplikasi (scope drive.appdata).
Apa yang terjadi saat Anda mengaktifkan fitur ini:
- Anda diminta sign-in ke akun Google Anda via standar Google Sign-In.
- Sakuwise meminta consent untuk scope
https://www.googleapis.com/auth/drive.appdatasaja — bukan akses ke file Drive Anda lainnya. - Saat Anda menyimpan backup, file
.sakuwiseAnda di-enkripsi terlebih dahulu menggunakan AES-256-GCM dengan kunci yang diturunkan dari PIN backup Anda via Argon2id (memory 64 MB, iterations 3). Kemudian file terenkripsi tersebut di-upload ke folder AppData pribadi Sakuwise di Google Drive Anda. - Folder AppData adalah folder pribadi per-aplikasi yang tidak terlihat di Google Drive UI Anda secara default, dan hanya dapat diakses oleh Sakuwise (kombinasi package name + signing key).
- Google bertindak sebagai data processor untuk file Anda. Google tidak dapat membaca isi file karena sudah terenkripsi sebelum upload — Google hanya melihat ukuran file dan timestamp.
Email akun Google Anda akan diterima Sakuwise dari Google Play Services hanya saat sign-in. Email ini disimpan secara lokal di perangkat Anda untuk menampilkan "Tersambung sebagai [email]" di Settings, dan tidak dikirim ke kami atau pihak ketiga lain.
Cara nonaktif: Toggle "Backup ke Google Drive" di Settings → Backup & Pemulihan. Sign-out + revoke akses akan menghapus token dari perangkat. Untuk menghapus file backup di Google Drive Anda, Anda dapat me-revoke akses Sakuwise di myaccount.google.com/permissions — folder AppData beserta isinya akan ikut terhapus.
5. Backup Lokal (Penyimpanan Sendiri)
Sebagai alternatif Drive backup, Anda dapat menyimpan file backup secara lokal: ke storage internal, USB drive, atau folder yang ter-sync dengan layanan cloud lain (Dropbox, OneDrive folder, dll.).
File backup lokal di-enkripsi dengan kunci yang sama (Argon2id-derived dari PIN Anda) sebelum disimpan. Saat menyimpan, sistem Android akan menampilkan file picker untuk Anda memilih lokasi — Sakuwise tidak membuat keputusan lokasi sendiri.
File backup lokal tetap ada setelah Anda uninstall Sakuwise, sehingga dapat dipakai untuk restore di perangkat baru.
6. Layanan Pihak Ketiga
| Layanan | Tujuan | Penanganan Data |
|---|---|---|
| Google Play Services (Android Vitals) | Crash & ANR reporting agregat | Otomatis oleh Android OS pada perangkat dengan Play Store. Stack trace anonim dikirim ke Google. Sakuwise hanya membaca dashboard agregat di Play Console. Tidak ada data personal di-share. |
| Google Sign-In | Authentication untuk Drive backup (opt-in) | Hanya aktif bila Anda opt-in Drive backup. Lihat §4. |
| Google Drive API | Upload/download file backup ke folder AppData (opt-in) | Lihat §4. |
| ML Kit Text Recognition | OCR struk on-device | Seluruh pemrosesan on-device, tidak ada gambar dikirim ke server Google. |
Selain di atas, Sakuwise tidak menggunakan SDK analytics (tidak ada Firebase Analytics, Crashlytics, Mixpanel, Amplitude, dll.), tidak ada SDK ads, dan tidak ada tracking library.
7. Penyimpanan & Retensi Data
Karena Sakuwise tidak mengumpulkan data ke server kami, retensi data sepenuhnya dalam kendali Anda:
- Data aplikasi: Tersimpan di perangkat Anda. Hapus semua data via Settings → Reset Aplikasi.
- File backup lokal: Tersimpan di lokasi yang Anda pilih. Hapus manual bila perlu.
- File backup Drive: Tersimpan di folder AppData Google Drive Anda. Hapus dengan revoke akses Sakuwise di myaccount.google.com/permissions.
- Cache: Sakuwise tidak menggunakan cache disk untuk gambar (foto struk render langsung dari database, in-memory cache only).
Uninstall aplikasi akan menghapus database aplikasi dari perangkat (file backup tetap aman).
8. Privasi Anak (Children's Privacy)
Sakuwise tidak ditujukan untuk anak di bawah 13 tahun. Kami tidak secara sadar mengumpulkan data anak. Bila Anda adalah orang tua dan menemukan anak Anda menggunakan Sakuwise, kami sarankan menggunakan kontrol parental Android untuk membatasi akses.
9. Hak Anda (UU PDP Indonesia)
Sesuai Undang-Undang Perlindungan Data Pribadi Republik Indonesia (UU 27/2022), Anda memiliki hak:
- Akses & portabilitas: Export data via Export CSV / XLSX / PDF di Settings.
- Koreksi: Edit/hapus transaksi atau data lain langsung di aplikasi.
- Penghapusan: Settings → Reset Aplikasi, atau uninstall aplikasi.
- Penolakan pemrosesan: Tolak fitur opsional (Drive backup, biometrik, notifikasi, OCR) tanpa kehilangan fungsi utama.
- Komplain: Kontak gakadigilabs@gmail.com.
10. Perubahan Kebijakan Privasi
Bila kami memperbarui kebijakan ini (mis. menambah fitur yang membutuhkan akses data baru), kami akan:
- Update tanggal "Berlaku sejak" di atas
- Menampilkan banner notifikasi di dalam aplikasi pada update berikutnya
- Memberi user kesempatan review sebelum fitur baru aktif
Riwayat versi kebijakan privasi dapat dilihat di repository public: github.com/gustiadhitya/sakuwise-web.
11. Kontak
Pertanyaan, klarifikasi, atau komplain:
- Email: gakadigilabs@gmail.com
- Subject email: "[Sakuwise Privacy] {topik singkat}" untuk respons lebih cepat
Sakuwise Privacy Policy
TL;DR
Sakuwise is a personal budget app built on a local-first principle: all your financial data stays on your Android device and is never sent to our servers. We do not operate any server and do not collect your data.
One exception: if you voluntarily enable the Google Drive Backup feature, your encrypted backup file is uploaded to a private app folder in your own Google Drive. Encryption keys are derived from your PIN, so Google cannot read the contents of your backup file.
No ads. No analytics. No tracking.
1. Data Sakuwise Collects
Sakuwise (we) does not collect any of your data. We do not operate any server, we have no API endpoints of our own, and we do not include any third-party SDKs for analytics or telemetry.
Data you input into the app (transactions, account names, plan categories, amounts, notes, receipt photos, gold/property/deposit asset info, debt info) is stored locally on your device, encrypted at rest using AES-256 via SQLCipher. The database can only be opened with a key stored in your device's Android Keystore, unlocked via your biometric or PIN.
2. Data Sakuwise Does NOT Access
For full transparency, here's what we don't touch:
- Device identifiers (Advertising ID, IMEI, MAC, etc.)
- Location (GPS, coarse, or IP-based)
- Contacts, calendar, or installed apps
- Browser or search history
- Microphone or audio
- Phone state, calls, or SMS
- Your email or Google account name (except when you opt in to Drive backup — see §4)
3. Permissions Sakuwise Requests
Sakuwise requests the following Android permissions. Several are optional — you can deny them and the app still works without the related features.
| Permission | Purpose | Status |
|---|---|---|
USE_BIOMETRIC | Unlock app via fingerprint / face | Optional (fallback: PIN) |
CAMERA | OCR receipts to auto-fill expense form | Optional (OCR feature) |
POST_NOTIFICATIONS | Recurring payment reminders you set | Optional (reminders) |
INTERNET | Backup to Google Drive (see §4) | Required in manifest, but only active when you opt in to Drive backup |
ACCESS_NETWORK_STATE | Check connectivity before Drive backup upload | Same as INTERNET |
Important: Unless you activate the Drive backup feature, Sakuwise never sends any network traffic, even though INTERNET is declared in the manifest.
4. Google Drive Backup (Optional, Opt-In)
Sakuwise offers an optional feature to back up your data to a Google Drive private app folder (scope: drive.appdata).
What happens when you enable this feature:
- You're prompted to sign in to your Google account via standard Google Sign-In.
- Sakuwise requests consent for the
https://www.googleapis.com/auth/drive.appdatascope only — not access to your other Drive files. - When you save a backup, your
.sakuwisefile is first encrypted using AES-256-GCM with a key derived from your backup PIN via Argon2id (memory 64 MB, iterations 3). The encrypted file is then uploaded to Sakuwise's private AppData folder in your Google Drive. - The AppData folder is a private per-app folder that is not visible in your Google Drive UI by default, and can only be accessed by Sakuwise (package name + signing key combination).
- Google acts as a data processor for your file. Google cannot read the file contents because they're encrypted before upload — Google only sees the file size and timestamp.
Your Google account email will be received by Sakuwise from Google Play Services only during sign-in. This email is stored locally on your device to display "Connected as [email]" in Settings, and is not sent to us or any other third party.
To disable: Toggle "Backup to Google Drive" in Settings → Backup & Recovery. Sign-out + revoke access will remove the token from your device. To delete backup files in your Google Drive, you can revoke Sakuwise's access at myaccount.google.com/permissions — the AppData folder and its contents will be deleted accordingly.
5. Local Backup (Your Own Storage)
As an alternative to Drive backup, you can save backup files locally: to internal storage, USB drive, or a folder synced with other cloud services (Dropbox, OneDrive folder, etc.).
Local backup files are encrypted with the same key (Argon2id-derived from your PIN) before being saved. When saving, the Android system presents a file picker for you to choose the location — Sakuwise does not make location decisions on its own.
Local backup files persist after you uninstall Sakuwise, so they can be used to restore on a new device.
6. Third-Party Services
| Service | Purpose | Data Handling |
|---|---|---|
| Google Play Services (Android Vitals) | Aggregate crash & ANR reporting | Automatic by Android OS on devices with Play Store. Anonymized stack traces sent to Google. Sakuwise only reads aggregated dashboards in Play Console. No personal data shared. |
| Google Sign-In | Authentication for Drive backup (opt-in) | Only active when you opt in to Drive backup. See §4. |
| Google Drive API | Upload/download backup files to AppData folder (opt-in) | See §4. |
| ML Kit Text Recognition | On-device receipt OCR | All processing on-device, no images sent to Google servers. |
Beyond the above, Sakuwise does not use any analytics SDK (no Firebase Analytics, Crashlytics, Mixpanel, Amplitude, etc.), no ad SDK, and no tracking library.
7. Data Storage & Retention
Because Sakuwise does not collect data to our servers, data retention is entirely in your control:
- App data: Stored on your device. Delete all via Settings → Reset App.
- Local backup files: Stored at the location you chose. Delete manually as needed.
- Drive backup files: Stored in your Google Drive AppData folder. Delete by revoking Sakuwise's access at myaccount.google.com/permissions.
- Cache: Sakuwise does not use disk cache for images (receipt photos render directly from the database, in-memory cache only).
Uninstalling the app removes the app's database from the device (backup files remain safe).
8. Children's Privacy
Sakuwise is not directed at children under 13. We do not knowingly collect data from children. If you are a parent and find your child using Sakuwise, we recommend using Android parental controls to restrict access.
9. Your Rights
We honor user rights consistent with major data protection frameworks (e.g., GDPR, Indonesia's UU PDP / Law 27/2022):
- Access & portability: Export all data via Export CSV / XLSX / PDF in Settings.
- Correction: Edit/delete transactions or other data directly in the app.
- Deletion: Settings → Reset App, or uninstall.
- Opt-out of processing: Decline optional features (Drive backup, biometrics, notifications, OCR) without losing core functionality.
- Complaints: Contact gakadigilabs@gmail.com.
10. Changes to This Privacy Policy
If we update this policy (e.g., add a feature that requires new data access), we will:
- Update the "Effective" date at the top
- Display an in-app notification banner on the next update
- Give users a chance to review before the new feature activates
Version history of this privacy policy is available in the public repository: github.com/gustiadhitya/sakuwise-web.
11. Contact
Questions, clarifications, or complaints:
- Email: gakadigilabs@gmail.com
- Subject prefix: "[Sakuwise Privacy] {short topic}" for faster response