Privacy Policy for PaySay

f
Effective Date: May 20, 2026  |  Last Updated: August 14, 2026

PaySay ("we," "our," or "us") is a utility for retail merchants in Nepal that announces incoming digital payments out loud in real time, so a shopkeeper doesn't have to look at their phone screen during a sale. This policy explains exactly what data the app accesses, what we store, and what we don't.

1. Notification Access & On-Device Processing

PaySay uses Android's Notification Listener API to detect incoming payment notifications from recognized banking and wallet apps (eSewa, Khalti, IME Pay, Fonepay, and partner banks).

Important technical note: Android's Notification Listener API grants an app visibility into all notifications posted on the device — this is how the API works at the operating system level, and it isn't something an app can narrow at the permission level.

PaySay's own code only reads the text content of notifications from the specific payment/banking apps it supports. Notifications from every other app are ignored immediately, without their text ever being read or processed by our code.

For a recognized payment notification:

2. Data We Collect and Where It's Stored

To keep your subscription and account status working, the app communicates with our servers (paysay.kritishbhattarai.com.np) over an encrypted HTTPS/TLS connection. The following is stored on our servers, not just on your device:

Data Purpose Stored server-side?
Android ID (SSAID) — a hardware identifier, not tied to your name or phone number Uniquely identifies your device/installation for subscription checks Yes
Business/username you enter at registration Displayed in-app, used for support Yes
Subscription status (trial / premium / expired) Determines whether the app is active Yes
Last check-in timestamp Used to track active installs Yes

A cached copy of your username and status is also kept in the app's private local storage on your device so the app works normally without a network connection. This local storage is private to the app (other apps on the device cannot read it) but is not currently encrypted at rest.

We do not collect, store, or have any access to: banking passwords, account numbers, transaction amounts, customer names, or any content of the notifications PaySay reads.

3. Data Sharing

We do not sell, rent, or share your data with any third party. PaySay does not integrate any third-party advertising, analytics, or crash-reporting SDKs — the only network communication the app performs is with our own servers, for the purposes described above.

4. Permissions We Request

Permission Why we need it
Notification access Core function — detecting incoming payment notifications from supported apps
Internet / Network state Communicating with our servers for account and subscription checks
Audio focus / volume control Used to briefly raise media volume so the spoken amount is audible in a busy store, restored to your original volume immediately afterward

You can review or revoke notification access at any time via Settings → Apps → Special app access → Notification access. Disabling it stops PaySay's core function.

5. Data Retention & Deletion

We retain your account data (SSAID, username, status, check-in history) for as long as your installation remains active. To request deletion of your account and all associated server-side data, contact us using the details in Section 7 — we will process deletion requests within [X] business days.

6. Children's Privacy

PaySay is a business tool intended for merchants and is not directed at children. We do not knowingly collect data from anyone under 13.

7. Contact Us

Questions about this policy or requests to delete your data:

8. Changes to This Policy

We may update this policy as the app changes. Material changes will be reflected by an updated "Last Updated" date above.