Scale — Privacy Policy
In short: Scale lets you see your own record with a business you already deal with — what you owe, what you have paid. Almost everything you see was entered by that business, not by you. Scale shows you no ads, builds no profile of you, and sells nothing to anybody.
- We identify you by your mobile number, and nothing else. No password, no email sign-in, no social login.
- You are shown only your own records, only for businesses that already added your number. You can never see another customer.
- Your app PIN never leaves your phone, and is not stored on our servers in any form (section 4).
- Your fingerprint or face is never given to the app. Android checks it and returns only yes or no (section 4).
- No advertising, no analytics SDK, no tracking, and no contacts, location, camera or microphone access at all (section 7).
Scale ("Scale", "the app", "we", "us") is published by Rohan Surve. This policy explains what information the app handles, why, where it goes, and the choices you have. By using Scale you agree to this policy.
Scale is the customer's app. The business owner uses a separate app called Scale Partner, which has its own policy — see Scale Partner — Privacy Policy.
1. How your record comes to exist
This is the most important thing to understand about Scale, so it comes first.
A business you deal with — your gym, your tiffin service, your tuition class — uses Scale Partner to keep its records. When it adds you as a customer, it enters your name, your mobile number, and the payments you owe or have made. That business created your record, not you, and it did so before you ever opened this app.
When you install Scale and sign in with that same mobile number, the app matches your number to those records and shows them to you. That is the whole purpose of the app: it gives you sight of a ledger that somebody else is already keeping about you.
It follows that:
- The business is responsible for the accuracy of what it entered — your name, your number, the amounts, the dates. If something is wrong, the business must correct it in Scale Partner; we cannot change another party's records on our own initiative.
- Version 1.0.0 of Scale is read-only for business records. You can look at them and copy a phone number; you cannot edit, dispute or hide them from inside the app. If you believe a business has added you wrongly, contact that business, or contact us (section 12).
2. Signing in — your mobile number
Scale signs you in with your mobile number and a one-time password (OTP) sent by SMS, handled by Firebase Authentication, a Google service (section 6).
- Your mobile number is sent to Google's Firebase Authentication service so it can send the SMS and confirm the code you type back.
- Your number is stored against your account and shown to you in Settings, so you always know which account you are signed in to.
- To stop automated abuse of the SMS system, Firebase runs an app verification check before sending — on Android, Google Play Integrity, falling back to an invisible reCAPTCHA check, which may briefly open a web view. These are operated by Google; Scale receives only a pass or fail.
- There is no password.
In Settings → Profile you may optionally add:
- Your name — optional, and yours. The name a business gave you in its own records is that business's label for you; it is never copied onto your account, and the name you set here is never pushed back into a business's records.
- Your email address — optional. It is stored on your account and shown back to you; the app does not send email and we do not use it for marketing.
3. What you can see, and what we hold about you
Held on your account: your mobile number, and the name and email you chose to add.
Shown to you, having been entered by a business that added your number:
- The business's own details — its name, category, phone and WhatsApp number, address.
- The name and status that business recorded for you.
- Your payment records with that business — amounts, due dates, what is outstanding, what has been marked paid and when.
You are shown only your own records. The access rules are enforced on our servers, not merely hidden in the app: a request for another person's record is refused, whatever the app asks for. If several businesses have added your number, you will see each of them separately.
4. Your app PIN and biometric unlock
Signing in with an OTP proves who you are. A separate 4-digit PIN controls access to the app on this phone, which matters on a shared phone.
- The PIN is never sent to us and never stored on our servers, in any form. It exists only on your device.
- On the device it is not stored as digits either, but as a PBKDF2-HMAC-SHA256 hash with a random salt, in Android's Keystore-backed secure storage.
- It is tied to the account it was set for; a different account signing in on the same phone discards it.
- After 5 wrong attempts the PIN is erased and you are signed out, so getting back in needs a fresh OTP. That is also the "forgot PIN" route.
- The PIN and your session are excluded from Android cloud backup and device-to-device transfer. A new phone always means a fresh OTP and a new PIN. This is deliberate.
Biometric unlock is optional and off until you turn it on. If you enable it, Android's own biometric prompt checks your fingerprint or face. Scale never sees, receives or stores any biometric data — Android performs the match in secure hardware and returns only yes or no.
5. What is stored on your phone
- An offline copy of the records you are allowed to see, so the app opens and works without a signal.
- Your app language (English, हिन्दी or मराठी) — a device setting, not tied to your account, so the login screen itself is already in your language and the choice survives signing out.
- Your PIN hash and biometric preference — section 4.
- Your signed-in session, so you do not re-enter an OTP every time.
Uninstalling removes all of the above from the phone. It does not delete your account from our servers — see section 9.
6. Service providers
Scale is built on Google Firebase, which processes data on our behalf under Google's terms:
- Firebase Authentication — your mobile number, and the sending and checking of the OTP SMS.
- Cloud Firestore — your account record and the business and payment records you are shown. Hosted in Google's asia-south1 (Mumbai, India) region.
- Cloud Functions for Firebase — server-side routines, also in asia-south1 (Mumbai, India), that match your mobile number to the right records when you first sign in.
- Google Play Integrity and, as a fallback, reCAPTCHA — the anti-abuse check in section 2.
Google is a global provider and may process some operational data outside India; see Google's own privacy documentation.
We do not sell your data, and we do not share it with advertisers or data brokers.
7. What Scale does not do
- No advertising. No ad SDK is present in the app.
- No analytics SDK and no crash-reporting SDK. Version 1.0.0 ships without Firebase Analytics, without Crashlytics, and without any third-party analytics or attribution library.
- No advertising identifier is read.
- No contacts access. The app requests no contacts permission at all.
- No location, camera, microphone, photos, files or calendar permissions.
- No payment instruments. Scale never collects a card number, UPI ID or bank account, because it never moves money — it only shows a record of what a business says you owe or have paid.
- No purchases and no subscriptions in version 1.0.0.
8. Who can see your information
- You.
- A business that has your number in its own records — it sees the record it created about you, in Scale Partner. It does not see your Scale account name or email, and it does not see your dealings with any other business.
- Us — limited to what is genuinely needed to run and support the service, for example investigating a fault you report.
- Nobody else, unless legally required, or you ask us to.
9. Keeping and deleting data
Your account is kept for as long as it exists. Records that a business created about you belong to that business's ledger and are kept while that business keeps them.
You can delete your account inside the app. Open My Profile → Close your account → Delete my account. The screen lists exactly what goes and what stays, asks you to confirm, and then asks for your app PIN. Deletion runs immediately — there is no waiting period and no request to approve.
If you cannot sign in, or you no longer have the app, use the request page at rohansurve.in/scale/delete-account, or email rohan.surve5@gmail.com from a message that identifies the mobile number on the account. We may need to verify that you control that number before acting.
Deleting in the app removes your Scale account and the profile details you added — your name, your email and your verified mobile number — together with your sign-in. A request made by email is completed the same way; we aim to do it within 30 days. Records may persist briefly in routine encrypted backups before those expire.
Deleting your Scale account does not erase a business's own ledger. The record a business keeps about its own customer is that business's record. It will stop being shown to you, and you may ask the business directly to delete it; tell us and we will pass the request on and help.
Uninstalling the app is not a deletion request. It clears the phone, not the server.
10. Security
- All traffic between the app and Google's services is encrypted in transit (TLS/HTTPS). Data is encrypted at rest by Google Cloud.
- Access is enforced server-side by Firestore security rules, so a request for someone else's record is refused whatever the app asks for.
- The device PIN is hashed and held in Android Keystore-backed storage, and is excluded from cloud backup and device transfer (section 4).
- No system is perfectly secure. Please keep your phone locked and do not share your OTP with anyone. We will never ask you for your OTP or your PIN.
11. Children
Scale is not directed at children and is intended for people aged 18 or over. We do not knowingly collect information from children. If a business has added a minor's number to its records, that is the business's responsibility; contact us and we will help resolve it.
12. Your rights
You may ask us for a copy of the data on your account, to correct it, or to delete it — see section 9 and the contact details below. We may need to confirm that you control the mobile number on the account first.
Where the information was entered by a business about you, we will pass your request to that business and support it, since the record is theirs.
13. Changes to this policy
If this policy changes materially we will update the date at the top and publish the new version at this address before the change takes effect.
14. Contact
Rohan Surve
Email: rohan.surve5@gmail.com
Deletion requests: rohansurve.in/scale/delete-account