PaySay ("we," "our," or "us") is a utility for retail merchants in Nepal that announces incoming digital payments out loud in real time, so a shopkeeper doesn't have to look at their phone screen during a sale. This policy explains exactly what data the app accesses, what we store, and what we don't.
PaySay uses Android's Notification Listener API to detect incoming payment notifications from recognized banking and wallet apps (eSewa, Khalti, IME Pay, Fonepay, and partner banks).
PaySay's own code only reads the text content of notifications from the specific payment/banking apps it supports. Notifications from every other app are ignored immediately, without their text ever being read or processed by our code.
For a recognized payment notification:
To keep your subscription and account status working, the app communicates with our servers (paysay.kritishbhattarai.com.np) over an encrypted HTTPS/TLS connection. The following is stored on our servers, not just on your device:
| Data | Purpose | Stored server-side? |
|---|---|---|
| Android ID (SSAID) — a hardware identifier, not tied to your name or phone number | Uniquely identifies your device/installation for subscription checks | Yes |
| Business/username you enter at registration | Displayed in-app, used for support | Yes |
| Subscription status (trial / premium / expired) | Determines whether the app is active | Yes |
| Last check-in timestamp | Used to track active installs | Yes |
A cached copy of your username and status is also kept in the app's private local storage on your device so the app works normally without a network connection. This local storage is private to the app (other apps on the device cannot read it) but is not currently encrypted at rest.
We do not collect, store, or have any access to: banking passwords, account numbers, transaction amounts, customer names, or any content of the notifications PaySay reads.
We do not sell, rent, or share your data with any third party. PaySay does not integrate any third-party advertising, analytics, or crash-reporting SDKs — the only network communication the app performs is with our own servers, for the purposes described above.
| Permission | Why we need it |
|---|---|
| Notification access | Core function — detecting incoming payment notifications from supported apps |
| Internet / Network state | Communicating with our servers for account and subscription checks |
| Audio focus / volume control | Used to briefly raise media volume so the spoken amount is audible in a busy store, restored to your original volume immediately afterward |
You can review or revoke notification access at any time via Settings → Apps → Special app access → Notification access. Disabling it stops PaySay's core function.
We retain your account data (SSAID, username, status, check-in history) for as long as your installation remains active. To request deletion of your account and all associated server-side data, contact us using the details in Section 7 — we will process deletion requests within [X] business days.
PaySay is a business tool intended for merchants and is not directed at children. We do not knowingly collect data from anyone under 13.
Questions about this policy or requests to delete your data:
We may update this policy as the app changes. Material changes will be reflected by an updated "Last Updated" date above.