Lazy Wallet Privacy Policy
Effective date: July 25, 2026
Last updated: July 25, 2026
Document version: 1.0-alpha
This Privacy Policy explains how Tilak Thapa, operating as jrTilak (“jrTilak,” “we,” “us,” or “our”), handles information when you use the Lazy Wallet application, API, and related services (collectively, the “Service”).
1. Scope
This Policy applies to the worldwide alpha release of Lazy Wallet. By using the Service, you acknowledge the practices described here. If you do not agree, do not submit information to or use the Service.
Lazy Wallet is a manual record-keeping service. It does not connect to a bank account, process payments, or automatically retrieve financial transactions.
2. Information we handle
Depending on how you use the Service, we may handle:
- Account information: name, email address, username, profile image, verification status, authentication method, and account identifiers.
- Authentication and session information: login credentials processed by the authentication system, session tokens, login method, IP address, device or browser user-agent information, and security events.
- Google sign-in information: when you choose Google authentication, the profile and account information Google makes available for sign-in.
- Financial records you enter: wallet names, balances, identifiers, currencies, categories, contact names, record types, amounts, dates, line items, notes, tags, and relationships between those records.
- Attachments: receipts, images, documents, filenames, file types, file sizes, and related upload metadata.
- Support communications: information you include when contacting us.
- Local application data: authentication state, preferences, and cached application data stored on your device.
You decide which documents to attach for your own future reference or supporting proof. The Service processes attachment files only as technically necessary to upload, store, retrieve, display, or delete them at your direction. We do not analyze, classify, independently inspect, or verify their contents, and we do not use them for advertising or AI training.
Attachments are not routinely reviewed by a person. Access may occur only when you request support or give permission, when reasonably necessary to investigate security or abuse, or when required by law. An attachment remains user-supplied material and is not certified as authentic or legally valid by Lazy Wallet.
3. How we receive information
We receive information directly from you when you register, create records, upload attachments, or contact support. We also receive limited information from Google when you choose Google sign-in and technical information generated when your device communicates with the Service.
4. How we use information
We use information to:
- create and secure accounts and authenticated sessions;
- store, synchronize, calculate, and display your financial records;
- upload, retrieve, and manage record attachments;
- operate, maintain, troubleshoot, and improve Service reliability;
- prevent abuse, investigate security incidents, and enforce the Terms;
- respond to support requests; and
- comply with applicable law and valid legal requests.
The current alpha does not use third-party advertising or analytics and does not sell or rent personal information. We do not use your records to make credit, lending, insurance, employment, or other automated eligibility decisions.
5. When information may be shared
We may share only the information reasonably necessary in these circumstances:
- Service providers: infrastructure, database, hosting, and storage providers that process information to operate the Service. Attachments are stored using Cloudflare R2.
- Authentication providers: Google receives and provides information when you choose Google sign-in, subject to Google’s own terms and privacy policy.
- Legal and safety reasons: when required by law, legal process, or a valid government request, or when reasonably necessary to protect rights, safety, security, and the integrity of the Service.
- Business changes: if the Service or its assets are reorganized, transferred, or acquired, subject to applicable law and appropriate notice.
6. Storage and international processing
Application records are stored in a cloud-hosted database, and attachments are stored in object storage. Authentication state and cached data may also remain on your device.
Because Lazy Wallet is available worldwide and uses online service providers, information may be processed in countries other than the one where you live. Where required, we will use reasonable safeguards and comply with applicable law for such processing.
7. Retention and deletion
We generally retain account information while the account remains active and retain User Content until you delete it through an available feature, the account or Service is closed, or retention is no longer reasonably necessary. Limited information may be retained where required for security, fraud prevention, dispute resolution, backups, or legal obligations.
Because this is an alpha release, records and attachments may be reset or deleted during development. Deletion from active systems may not immediately remove limited backup, security-log, or recovery copies, which may remain for only as long as reasonably necessary for operational, security, or legal purposes.
Self-service account deletion is not available in the current alpha. It is
under development for a future release. Until then, contact
contact@jrtilak.dev to ask about available account or data-deletion options.
We may need to verify your identity before acting on a request. This alpha
limitation does not remove any privacy right provided by applicable law.
8. Your choices and rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, or a copy of personal information. You may also:
- update or delete records using controls currently available in the Service;
- sign out to end the active session on a device;
- revoke Google account access through your Google account settings; and
- contact us about your information at
contact@jrtilak.dev.
We may request reasonable verification before responding. Legal exceptions may apply, and we will explain them where required.
9. Children
Lazy Wallet is not intended for children under 13, and we do not knowingly collect their personal information. Users below the legal age of majority where they live should use the Service only with permission and supervision from a parent or legal guardian.
If you believe a child under 13 has provided personal information, contact
contact@jrtilak.dev so we can review and take appropriate action.
10. Security
We use reasonable technical and organizational measures intended to protect information against unauthorized access, loss, misuse, or alteration. However, no application, device, transmission, or storage system can be guaranteed completely secure. You are responsible for protecting your credentials and device access.
11. Changes to this Policy
During alpha, we may update this Policy without an advance waiting period. We will notify users through the application, email, our website, or another reasonable channel, and the update may take effect when notified.
After the stable release, we will provide at least seven days’ advance notice before a material change takes effect, unless an earlier change is required for law, security, fraud prevention, or an urgent technical reason.
12. Contact
Lazy Wallet is operated by Tilak Thapa, operating as jrTilak, Nepal.
- Email: contact@jrtilak.dev
- Website: https://jrtilak.dev