Privacy Policy
1. Introduction
Welcome to Trezoriq ("we," "our," or "us"). Trezoriq is an online personal finance calculator and tools platform available at trezoriq.com ("the Website"), offering 349+ financial calculators across categories including tax, loans, investments, insurance, retirement, and more.
We are committed to protecting your privacy. This Privacy Policy explains:
- What information we collect and how
- How your financial data is stored (locally on your device)
- What leaves your device, and what never does
- Your rights and choices regarding your information
By using Trezoriq, you agree to the terms of this Privacy Policy.
2. Where Your Data Lives
| Feature | How it works |
|---|---|
| 349+ Calculators | All of them, free, with no account |
| Data Storage | Your device only, in IndexedDB, encrypted with AES-256-GCM |
| Cross-device Sync | Not offered. Move data yourself with an encrypted backup file, or your own Google Drive. |
| Ads | None |
| PWA (Installable App) | Installable on mobile and desktop, free |
| Account Aggregator Sync | Not offered. We are not an AA and hold no RBI registration. |
| Export / Import | Plain JSON, or an encrypted .trzbak backup you hold the password to |
3. Information We Collect
3.1 Your financial data — stays on your device
There are no plan tiers for this. Everything you enter — income, expenses, holdings, loans, tax figures, documents, vault entries, nominees, travel history — is:
- Held on your device in IndexedDB, encrypted with AES-256-GCM
- Locked by a key derived from your PIN, which is never written to disk and never sent anywhere
- Never transmitted to a Trezoriq server, because there is no account and no user database
- Unreadable to us in every circumstance — we hold no key and no copy
No sign-up, no email, no password. Clearing your browser data deletes your finances, which is why the encrypted backup below exists.
3.2 What does leave your device, always
Loading a web page necessarily contacts servers. This is the complete list for ordinary use — none of it contains your financial data:
- Hosting: your IP address and request metadata reach the server, as they must for any website. The site runs on our own hardware rather than a hosting provider, so this does not pass through a third party.
- Product analytics: none. The code contains a wrapper for a cookieless analytics service, but the script is never loaded, so no usage events are sent anywhere.
- Error monitoring: a stack trace when something breaks, so the bug can be found. Numbers of four digits or more are stripped before sending and browser-storage contents are never attached. Session replay — which records a playback of the screen — is switched off.
- Rate data: requests to public market-data sources for gold, silver, forex, NAV and RBI rates. These carry no information about you.
- Approximate location: an IP-geolocation lookup picks a default pricing city for the Rates page. Used once, not stored.
3.3 Optional features that transmit data — only if you switch them on
Each of these is off by default and each requires a deliberate action:
- AI features (your own API key): the AI does nothing until you supply a key for Gemini, OpenAI, Anthropic or OpenRouter. When you use it, your prompt — and any document image you attach — passes through a Trezoriq proxy endpoint on its way to that provider. We do not store it; the provider handles it under their own terms.
- Backup to your Google Drive: encrypted on your device before it is uploaded, and it goes to your Drive, not ours. We never receive it.
- Statement inbox: if you point it at a Drive folder, files there are read and parsed on your device. The contents are not sent to us.
- Sharing a bundle with your CA: creates an encrypted archive, protected by a password you choose, and stores it temporarily so your accountant can fetch it. It is encrypted before upload, so neither we nor the storage provider can read it, and it is deleted automatically once the expiry you set has passed.
- Reminder notifications: if you switch these on, your browser registers a push endpoint with its own push service (Google, Mozilla or Apple, depending on the browser) and we store that endpoint so a reminder can be delivered. It identifies a browser installation, not you, and turning reminders off deletes it.
- Password breach check: the vault can check a credential against the Have I Been Pwned range API, which receives only a partial hash — never the password.
3.4 Google user data — Limited Use
Drive backup and the statement inbox reach your Google account through Google’s own APIs, so Google’s rules about that data apply on top of everything else on this page:
Trezoriq’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means we ask for the narrowest access that makes each feature work, and we use it for nothing else. Backup uses a hidden application folder that can hold only what this app puts there — it cannot see the rest of your Drive. The statement inbox, where a deployment offers it at all, needs read access to your files; it is used solely to read the statements you place in the folder you name, the parsing happens on your device, and we never receive the contents. No Google data is used for advertising, sold, or given to a human to read, and access tokens are held in memory only for as long as the app is open.
3.5 What we do not do
- We do not serve advertisements, and we do not run advertising trackers.
- We do not sell, rent or share personal data with data brokers.
- We do not build advertising profiles or perform behavioural targeting.
- We do not use Account Aggregator feeds, and we are not registered as a Financial Information User.
- We do not hold a copy of your financial data, so we cannot produce it — to anyone.
4. JSON Export and Import Feature
You can export everything as a JSON file and import it on another device or browser. This is how you exercise data portability here: the file is produced on your device and never passes through us, so it does not depend on us being willing or able to hand anything over.
Export: Writes everything held on this device to a structured .json file. Plain JSON is readable by other software; for a copy you intend to store somewhere else, prefer the encrypted .trzbak backup.
Import: Uploads a previously exported JSON file to restore your data on a new browser or device.
⚠️ Export a backup regularly. Your device holds the only copy — clearing your browser data permanently deletes it, and there is no server-side copy for us to restore from. That is the cost of the privacy guarantee, and it is worth planning around.
5. How We Use Your Information
Purposes we process for
- Serving the website, the calculators and the dashboard
- Keeping the service working — diagnosing errors and crashes
- Understanding which features are used, in aggregate, to decide what to build
- Showing you live market rates
- Carrying out an optional feature you have explicitly switched on
Purposes we do not process for
- Advertising, ad targeting or audience building
- Selling or sharing data with brokers or data markets
- Profiling you, or making automated decisions about you
- Training models on your financial data
- Anything requiring us to read your finances — which we cannot do
We strictly NEVER:
- ❌ Sell your personal or financial data
- ❌ Use financial data for ad targeting
- ❌ Share your data with advertisers
- ❌ Use data beyond operating Trezoriq
6. Cookies, Analytics & Advertising
6.1 Use of Cookies
Trezoriq sets no advertising cookies and no cross-site tracking cookies. There is no login, so there is no session cookie either. What the site does use is:
- Browser storage, not cookies: your settings and your encrypted financial data live in localStorage and IndexedDB on your device. They are never transmitted, and a cookie banner cannot delete them — clearing your browser data will.
- No analytics today: the app contains a wrapper for a cookieless analytics service, but its script is not loaded — so no usage events are sent anywhere. If we ever switch it on, it will be a cookieless one that sets nothing on your device and records that a page was used, not who used it.
- Error monitoring: our error monitor may set an identifier so the events of one crashed session can be tied together and diagnosed. It runs on our own infrastructure, so crash reports are not handed to anyone else. Session Replay — which records a playback of the screen — is switched off. It previously sampled 10% of all sessions, and recording someone moving through their own tax screens is not something this app should do by default.
6.2 Advertising
Trezoriq does not display advertisements. There is no ad network on this site, no advertising cookie, and no advertising identifier. We do not participate in personalised advertising, so there is no ad-preference opt-out for us to offer — there is nothing to opt out of.
6.3 Data Sharing & Service Providers
We share data only with essential service providers to operate our platform:
- Public market-data sources: where published gold, silver, forex, NAV and RBI rates come from. These are outbound requests for public numbers and carry nothing about you.
- Our own server: the site and its database run on hardware we operate, not a third-party host. Server logs stay there.
- Your chosen AI provider: only if you add your own API key. Whatever you send to the assistant goes to that provider under their terms, not ours. Leave the key blank and nothing is sent.
7. Security, Retention and Breach
7.1 How it is protected
- On your device: financial records are encrypted with AES-256-GCM in IndexedDB. The key is derived from your PIN with PBKDF2-SHA256 and held in memory only — it is never written to disk, so the data cannot be read by anything that copies your storage without knowing the PIN.
- Backups you make: a
.trzbakfile is encrypted under a key derived from a password you choose, using Argon2id. Lose that password and the backup is gone; we cannot recover it, because we never had it. - In transit: HTTPS everywhere, HSTS with preload, and a strict Content-Security-Policy that names every origin the app is allowed to contact.
- On our side: the strongest safeguard is that there is almost nothing to safeguard. We hold no accounts, no passwords, and no copy of your finances.
An earlier version of this page listed "Row Level Security" and "Mumbai-hosted servers" among our measures. Neither was substantiated by the system as built, so both have been removed rather than left standing as reassurance we could not back up.
7.2 How long each thing is kept
| Data | Retention |
|---|---|
| Your financial data | On your device until you erase it. We never receive it, so we cannot delete it for you — and equally, we cannot be compelled to produce it. |
| IP address (rate limiting) | About 60 seconds, the length of the rate-limit window, then discarded. |
| Server and edge logs | Held by our hosting provider on their own schedule, to keep the service running and to investigate abuse. |
| Crash and error reports | Held on our own error-monitoring instance. Numbers of four digits or more are stripped before sending, and browser-storage contents are never attached. |
| A bundle shared with your CA | Until the expiry you chose, then the encrypted file and its record are deleted by a job that runs daily. |
| Push reminder endpoint | Until you turn reminders off, which deletes it. |
| AI prompts | Not stored by us at all. They pass through on the way to the provider whose key you supplied, and are handled under that provider's terms. |
Section 8(7) of the DPDP Act requires personal data to be erased once the purpose it was collected for has been served. Where we hold anything at all, that is the rule we apply — which is why a CA share is destroyed on its expiry date rather than merely hidden from view.
7.3 If there is a breach
Should a personal data breach affect anything we hold, section 8(6) of the DPDP Act requires us to inform the Data Protection Board of India and every affected person, in the form and within the time the Act and its Rules prescribe. We will do that, and we will say plainly what was affected and what you should do about it.
It is worth being clear about the shape of that risk. A breach of our systems could expose an encrypted CA bundle, a push endpoint, or server logs. It could not expose your financial records, because they are not there to be taken.
8. Children
Trezoriq is meant for adults managing their own money and is not directed at children. Under the DPDP Act, a child is anyone under eighteen.
- We do not knowingly process a child's personal data. Because there is no account and no sign-up, we never ask for a date of birth and hold no age information about anyone.
- We do not track or behaviourally monitor children — or anyone else. No analytics runs on this site, there is no advertising network, and we build no profiles.
- We do not direct advertising at children, for the simple reason that we serve no advertising at all.
- If a child does use a calculator, what they type stays in their browser and never reaches us.
If you are a parent or guardian and believe a child has given us personal data — realistically that would mean creating a CA share or switching on reminders — write to the Grievance Officer in section 11 and we will erase it.
9. Your Rights Under the DPDP Act, 2023
The Digital Personal Data Protection Act, 2023 gives you the rights below over personal data we process. Each is listed with how to actually use it here, because a right you cannot exercise is not worth much.
Access — section 11
A summary of the personal data we process about you, what we do with it, and who else we have shared it with. Ask the Grievance Officer. For most people the honest answer is an IP address in a rate-limit window that expired a minute later.
Correction and erasure — section 12
Correct, complete, update or erase your personal data. For anything on your device you do not need us at all: Settings has the controls, and clearing site data removes the lot. For the little we hold, ask and we will erase it.
Withdraw consent — section 6(4)
Withdrawing must be as easy as giving, and it is: every optional feature has an off switch where you turned it on. Delete your AI key, revoke a CA link, turn reminders off, disconnect Google Drive. Nothing else stops working when you do.
Grievance redressal — section 13
Complain to us and get a real answer. The Grievance Officer is named in section 11, and we aim to respond within 30 days.
Nominate — section 14
Name someone to exercise these rights for you if you die or become incapacitated; tell the Grievance Officer who they are. The Legacy desk is a different thing: it leaves instructions for your family, runs on your device, and is not a nomination to us.
Your duties — section 15
The Act asks something of you too: do not impersonate someone else, do not suppress material information, and do not raise frivolous complaints. Filing a false grievance is an offence under the Act.
Escalating to the Data Protection Board of India
If we do not answer, or you are not satisfied with the answer we give, you can complain to the Data Protection Board of India, which the DPDP Act establishes to hear exactly this. The Act expects a grievance to be put to the Data Fiduciary first, so please start with us — but you are under no obligation to accept what we say.
10. Where Processing Happens
Your financial data does not travel at all. It is created, encrypted and stored in your browser, so questions of cross-border transfer do not arise for it.
The small amount we do process is handled on our own hardware, with two narrow exceptions that are not:
- Our own server — the site, its database, and server logs, on hardware we run ourselves.
- Public market-data sources — outbound requests for published rates, carrying nothing about you.
- An AI provider you choose — only when you supply your own key, and only for what you send it.
Section 16 of the DPDP Act permits personal data to be transferred outside India except to countries the Central Government restricts by notification. We transfer no personal data to any restricted country. The only processing that can leave the country at all is a crash report, and an AI request you deliberately trigger with your own key — your financial records are not part of either, because they never leave your device in the first place.
11. Grievance Officer and Contact
Section 8(9) of the DPDP Act requires us to publish the contact details of someone who can answer questions about how your personal data is processed. That is:
Grievance Officer & Data Fiduciary
Name
Tejoram Veeramachaneni
Location
Hyderabad, Telangana, India
Response Time
Within 30 days
When you write, say which right you are exercising — access, correction, erasure, nomination, or a complaint — so it can be handled properly. Please do not send financial documents or account numbers to this address; nothing we can do for you requires them.
© 2026 Trezoriq. All rights reserved.
Governed by the laws of the Republic of India.
