Privacy Policy
Effective 19 August 2026. This policy explains the data ATM Cash Checker uses to operate, improve its service, and protect community evidence.
What we collect
- Browsing nearby ATMs and opening navigation do not require an account.
- If you sign in, we store your verified email address, name, language, authentication identity, device token, app version, last-use time, and contribution reputation. Email and name are encrypted; email is separately indexed with a one-way hash.
- Before submitting feedback in app version 1.0.3 or later, you provide an unverified mobile number with country calling code. The number is encrypted and separately indexed with a keyed one-way hash. We do not verify ownership by SMS.
- Reports store the ATM, outcome, optional broad amount band, time, location-match quality, and moderation state. We never request a PIN, card number, account number, bank password, SMS, or exact withdrawal amount.
- With separate consent, version 1.0.3 stores one exact first-location snapshot and one replaceable latest-location snapshot for your account. Each includes coordinates, accuracy, place labels, and time. The latest snapshot is updated at most once when a signed-in app foreground session begins or resumes; we do not retain a route history.
- Every installation sends limited first-party operational events (for example app open, search, nearby/detail views, and report flow) using a stable random metrics-installation ID. Events may include low-cardinality screen, source, ATM-status band, language, permission state, and result-count values. They exclude account identity, email, search text, ATM IDs, and coordinates; the server stores only a one-way hash of the random ID.
- Separately, optional account-linked usage analytics record signed-in foreground-session start/end times, cumulative visible-use duration, app version, platform, and a distinct protected installation identifier. Declining this optional duration analytics does not prevent browsing or feedback and does not disable the basic pseudonymous operational events above.
- Version 1.0.2 included an optional, user-started 45-minute ATM-check feature. Its already-installed clients may continue to upload matched ATM visit summaries during the compatibility period. Version 1.0.3 no longer starts ATM-check sessions or uses a location foreground service.
- We retain limited first-party operational events and security/administrator audit records. We do not include advertising trackers or sell personal information.
How we use data
We authenticate accounts, calculate explainable ATM availability and service estimates, rank nearby options, prevent abuse, moderate evidence, understand app reliability and adoption, and meet deletion/security obligations. Personal or bank-decline outcomes do not affect whether an ATM is scored as empty.
Retention
- OTP records: 24 hours; legacy v1.0.2 matched visit events and session evidence: 30 days.
- Explicit reports: 12 months, then eligible outcome counts become irreversible ATM/day/hour aggregates.
- Detailed account-linked foreground-usage sessions: 12 months, then monthly totals until account deletion.
- Account profile, unverified mobile number, consent record, and exact first/latest location snapshots: until you replace, revoke, or delete them, or until account deletion.
- Google-derived place fields: no more than 30 days before refresh or removal; durable Place IDs may remain as permitted.
- Pseudonymous first-party interaction events: 12 months. Security and administrator audits: 12 months; encrypted backups: 30 days.
Location, permissions, and choices
Location permission remains optional for browsing because manual search is available. In version 1.0.3, submitting feedback requires a current foreground location and affirmative consent to store the account’s exact first/latest snapshots. Location is never collected continuously or while the app is closed. You may decline and continue browsing, or later revoke consent and delete both saved snapshots; feedback stays unavailable until you consent again.
Account-linked foreground-duration analytics is separately optional and measures only signed-in time while the app is visibly in the foreground. Its Profile switch does not disable the basic pseudonymous operational events described above. You may change app language, edit your profile, stop account-linked duration analytics, sign out, revoke Android location permission, remove saved locations, or delete your account. Deletion revokes access tokens immediately and recalculates affected scores. See data deletion instructions.
Google Maps and Places
ATM names, positions, addresses, search, map display, and navigation may be provided by Google. Google processes those interactions under the Google Privacy Policy and Google Maps/Google Earth Additional Terms. Place data shown outside a map carries a compact Google Maps attribution link; map screens retain the Maps SDK branding.
Security and contact
We use HTTPS, encrypted sensitive fields, hashed tokens/OTPs, rate limits, scoped administrator access, and audited moderation. No service can promise absolute security. For privacy questions, use the contact route on our support page.
गोपनीयता का संक्षिप्त सार
आप बिना साइन-इन किए एटीएम खोज और नेविगेशन कर सकते हैं। संस्करण 1.0.3 में फ़ीडबैक के लिए सत्यापित खाता चाहिए। 45-मिनट का एटीएम-जाँच सत्र केवल पहले से इंस्टॉल संस्करण 1.0.2 की सीमित संगतता सुविधा है; 1.0.3 इसे शुरू नहीं करता। पुराने सत्र में भी कच्चा लगातार लोकेशन मार्ग सर्वर पर नहीं भेजा जाता—केवल मिले हुए एटीएम विज़िट और गुणवत्ता का सार भेजा जाता है।
संस्करण 1.0.3 में फ़ीडबैक देने से पहले नाम, बिना-SMS-सत्यापन वाला मोबाइल नंबर और आपकी स्पष्ट सहमति से वर्तमान सटीक लोकेशन चाहिए। सर्वर केवल पहली और सबसे नई लोकेशन रखता है, लगातार यात्रा-मार्ग नहीं। बुनियादी ऐप-इंटरैक्शन मेट्रिक्स सभी इंस्टॉल पर एक यादृच्छिक पहचान से भेजे जाते हैं; उनमें खाता पहचान, खोज-पाठ, एटीएम आईडी या लोकेशन नहीं होती। खाते से जुड़ा अग्रभूमि उपयोग-समय अलग और वैकल्पिक सहमति से एकत्र होता है।
हम कार्ड नंबर, पिन, बैंक पासवर्ड, एसएमएस या निकासी की सटीक राशि नहीं माँगते। ऐप से खाता हटाने पर टोकन, पहचान, मोबाइल, सहेजी गई लोकेशन, उपयोग-सत्र, रिपोर्ट और पुराने जाँच-सत्र डेटा हटते हैं और स्कोर दोबारा बनते हैं।