Last updated: August 17, 2026
GenesisCipher Labs (“we”, “us”) builds Pact, an invoicing and payment-tracking app for creators and freelancers — it turns a brand-deal email into a tax invoice and tracks when you get paid. Pact stores your records on your device and we operate no server that receives them. This policy explains exactly what is processed, what leaves the device, and the rights you have under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and, if you live elsewhere, under laws such as the EU/UK GDPR and the California Consumer Privacy Act (CCPA).
This is the Android policy. The iOS and macOS version of Pact is a different build with different components — it uses Apple Intelligence and Apple’s StoreKit, neither of which exists here, and it does not contain the Google component described below. Its policy is at /pact/privacy/. Where the two differ, the difference is real, not editorial.
INTERNET permission.GenesisCipher Labs is the controller for the limited processing described here. Because effectively all processing happens on your device, your device does the work. Contact for privacy questions, data-rights requests and grievances (including the grievance contact required under the DPDP Act): genesiscipherlabs@gmail.com.
| Data | Where it is processed | Why | Lawful basis (DPDP Act) |
|---|---|---|---|
| Your business profile — legal name, PAN, GSTIN, registered address, email, bank account name/number/IFSC, UPI ID | On your device | To render tax invoices identifying you as the supplier | The specified purpose you voluntarily provided the data for |
| Brand / client records — name, tax registration, billing address, place-of-supply state, contact name, accounts-payable email, phone, notes | On your device | To address invoices and determine the correct GST treatment (CGST+SGST, IGST, or export) | The specified purpose you voluntarily provided the data for |
| Deal details — title, deliverables, amount, currency, payment terms, and the original pasted/shared text or screenshot | On your device | To create the deal, generate the invoice, and let you re-read it if needed | Your consent when you paste or share it |
| Invoices and payment records — invoice PDFs, tax breakup, supplier/brand snapshots, due dates, amounts, paid/overdue status | On your device | To track who owes you what, and to keep each invoice reproducible | The specified purpose you voluntarily provided the data for |
| Notification schedule entries | On your device | To schedule and cancel payment reminders | Your consent via the Android notification permission |
We do not profile you for advertising and we do not make solely-automated decisions producing legal effects. Extraction confidence is a hint shown to you for your own review; you confirm every invoice before it exists.
Pact includes Google’s ML Kit Text Recognition so it can read a screenshot of a brand’s message. The recognition model ships inside the app and runs offline — your screenshot and the text recognised from it are never uploaded, to us or to anyone.
However, the ML Kit component itself reports usage and diagnostic data to Google. Per Google’s ML Kit Android data disclosure, this includes:
Google states that this data is encrypted in transit over HTTPS and is not transferred by ML Kit to
third parties. Google does not document any way for an app to switch this off, so we cannot
honestly offer you a toggle for it; the only way to avoid it entirely would be to remove screenshot
reading from the app. We have chosen to keep the feature and tell you plainly instead. This is the
reason Pact for Android declares the INTERNET and ACCESS_NETWORK_STATE permissions, and the
reason the Google Play Data safety section for this app declares Device or other IDs and
App info and performance as collected for analytics and diagnostics — by Google, not by us.
To be unambiguous about the boundary: no invoice, no amount, no client, no profile field, no email text and no image ever forms part of that transmission.
Apart from the ML Kit diagnostics described above, Pact transmits nothing on its own. Everything below happens only when you tap something, and in each case you choose the destination:
Pact sets android:allowBackup="false". Your Pact records are therefore excluded from Android’s
automatic cloud backup and from device-to-device transfer — they do not travel to Google Drive with
the rest of your phone. The trade is deliberate and you should know it: if you lose the device, the
only copy is whatever backup pack you exported yourself. Nominate a backup folder in Settings.
Your records stay on your device until you remove them. You can delete any deal, brand, invoice or payment inside the app at any time, and edit your profile freely. Uninstalling Pact removes all of it, because there is no server copy to survive. We hold nothing to delete on your behalf; a data-deletion request to us would find no data. Files you have already exported or shared are outside Pact and must be deleted wherever you sent them.
Under the DPDP Act you have the right to access, correct and erase your personal data, and to grievance redressal. Because Pact holds your data only on your device, you exercise access, correction and erasure directly in the app — every field is editable and every record is deletable. For anything else, including grievances, write to genesiscipherlabs@gmail.com.
If you are outside India: the same direct, on-device control is how you exercise your rights under the EU/UK GDPR, the CCPA, or your own local law — access, rectification, erasure, portability and objection are all in your hands, because your device is the only place your records exist and we receive, sell and share nothing. The one transmission from the app — Google’s ML Kit diagnostics, described above — is Google’s own processing under Google’s privacy policy, and never includes your records. You can also contact us at the address above, or lodge a complaint with your local supervisory authority.
Pact is a business tool and is not directed at children under 13, and we do not knowingly process children’s data.
| Permission | Why |
|---|---|
POST_NOTIFICATIONS |
To show your payment reminders. Decline it and the app still works; you just get no reminders. |
INTERNET, ACCESS_NETWORK_STATE |
Required by the bundled Google ML Kit component. Pact itself makes no network requests. |
RECEIVE_BOOT_COMPLETED, WAKE_LOCK, FOREGROUND_SERVICE |
Declared by Android’s WorkManager and Google’s data-transport libraries, which arrive as dependencies of ML Kit. |
Pact requests no location, contacts, camera, microphone, SMS or call-log permission, and does not
request QUERY_ALL_PACKAGES.
If this policy changes materially we will update the date at the top and, where the change affects what leaves your device, say so in the app’s release notes.
Questions: genesiscipherlabs@gmail.com