Saifu

Privacy policy

Effective 2026-10-05. Saifu is made by Optional Labs. Questions go to privacy@saifu.in.

This policy is published under the Information Technology Act, 2000 and its rules, and is written to meet the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. It covers the Saifu app and this website.

Who to contact

Chandan Kumar Dash, Grievance Officer, Saifu answers questions about how your personal data is handled and handles complaints: privacy@saifu.in. See Grievances for how complaints are handled and how long we take.

No account

You do not sign up or log in. Saifu does not ask for your name, phone number or email, so it holds none of them and cannot call, text or email you. We never ask you to type a card number or a bank login.

What stays on your phone

The cards you add, the spends you log or import, family members, reward points, lounge visits and settings are stored on your phone, encrypted, with a key kept in the phone's secure storage (Keychain on iPhone, Keystore on Android). We run no server that receives them.

Bank messages

On Android, you can switch on message reading, which uses the READ_SMS permission. It is off until you turn it on. The app reads bank and UPI messages on the phone and stores the amount, merchant and last 4 digits. Message text is not sent to us or anyone else. On iPhone, apps cannot read messages, so you can set up a Shortcut that passes each bank message to the app, which reads it on the phone.

Card scan and statements

If you scan a card, the camera reads the number printed on it on your phone so the app can recognise the card. The app keeps only the card name and the last 4 digits. The picture and the full number are not stored or sent. If you import a statement PDF or pasted text, it is read on your phone too. A scanned PDF is read page by page on the phone with Google ML Kit, and the page pictures are deleted afterwards. A statement password, if any, is used to open the file and is not saved. The app tells you how many lines it could not read, you review the lines before anything is stored, and the PDF is not kept.

Eligibility check

On a card's details page you can enter your age, monthly income and whether you are salaried or self-employed. These are stored on your phone with the rest of your data and are used only to compare you with the bank's published rules. Saifu does not pull a credit report, sends nothing anywhere, and the check cannot affect your credit score. The bank decides when you apply and runs its own checks then.

On-device assistant

The Ask Saifu assistant works out answers in the app. You can optionally download a small language model, which then runs on the phone. The download comes from a model host (Hugging Face or a copy hosted by Saifu), which sees your IP address and the file you ask for. What you type to the assistant is not sent anywhere.

Backup file

A backup is one file. The file is encrypted on your phone with a passphrase you choose. You decide where to save or send it. We never receive the file or the passphrase, and we cannot recover a lost passphrase.

The rules update request

The app checks Saifu's servers in the background for a newer card-rules file (hosted on Cloudflare R2). This request reveals your IP address, and standard request details, to the host. It contains none of your wallet data. The file is signed, and the app rejects one that fails the signature check. It also carries the affiliate links the app may show.

No analytics or crash reporting

The app code has no analytics, advertising or crash-reporting. We do not collect usage statistics from it. Card scanning and the optional assistant use Google ML Kit and MediaPipe libraries that run on the phone; we have not independently checked whether those libraries send any technical data to Google.

If you write for Saifu

This is the only place where Saifu receives personal data. When you send a guest post through the write page, we receive:

We use this only to review your post, to talk to you about it by email, and to publish it with your name if we accept it. We ask for your consent on the form, separately from accepting the writing rules, and you must be 18 or older. You can withdraw consent at any time by emailing privacy@saifu.in with the reference number you were given or the email you used. We then delete your submission within 30 days, and if the post is live we take it down.

We keep a submission, and the record of what we decided, for one year from our decision or from the day you sent it if we never decide, then delete it. Published posts stay on the site, with your name and profile link, until you ask us to remove them. Submissions are stored with Cloudflare (Workers KV, behind access controls) and published posts in our code repository on GitHub. Only Saifu's operator can read them.

Affiliate links and what happens after you tap

Some Apply and shopping links are affiliate links, labelled as such. Before opening one, the app tells you where you are going. When you apply on a bank or partner site, that party receives what you enter and may contact you, and its own privacy policy applies. Affiliate networks may set cookies to record that you came from Saifu. Saifu cannot see what you type there. See How we earn.

Face ID and fingerprint

If you turn on the app lock, your phone's operating system does the check. Saifu never receives biometric data.

Notifications

If you allow notifications, reminders such as points expiry are scheduled on your phone. They are not sent from a Saifu server, and Saifu does not use a push notification service.

Deleting your data

Use Delete all my data in the app, which removes your cards, spends and the encryption key from the phone, or uninstall the app. We hold no copy, so there is nothing for us to delete. Backup files you saved elsewhere stay where you put them.

This website

This site sets no cookies and shows no advertising. Fonts are served from this site, not from Google. Our hosting provider, Cloudflare, handles your requests and may keep standard server logs. We use Cloudflare Web Analytics to count visits: it sets no cookies, does not build a profile of you and does not follow you to other sites. It records the page you visited, the site that sent you, your browser and device type, and your country, and we see only totals. The site keeps two things in your own browser's storage, which never leave your device: your light or dark mode choice, and the draft of a guest post while you write it. Clearing your browser's site data removes both. Because the site sets no cookies and does not track you across sites, there is no cookie banner. All calculators run in your browser; nothing you type into them is sent anywhere.

Your rights

For any personal data we hold about you, which today means only a guest post submission, you can ask us to:

Email privacy@saifu.in from the address you used, or quote your reference number, so we can find your record. We reply within 30 days. If you are not satisfied, use our grievance process first; after that you can complain to the Data Protection Board of India.

Security and breaches

Submissions are stored in an access-controlled service that only Saifu's operator can open, over encrypted connections. If a breach ever affects your data, we will tell you without delay what happened, what it means for you, what we are doing and what you can do, and we will report it to the Data Protection Board as the law requires.

Children

Saifu is meant for adults who hold credit cards. Only people aged 18 or older may send a guest post. If we learn that a submission came from someone younger, we delete it.

Changes

If this policy changes, the effective date above changes with it.

Contact

Privacy questions: privacy@saifu.in. Anything else: hello@saifu.in.

Spot a mistake on this page? Tell us