Privacy policy
Last updated 17 September 2026 · Applies to this public demo.
This is the public demo of Pathayam, operated by Flaxvin Technologies (flaxvin.tech). For the purposes of the Digital Personal Data Protection Act, 2023, Flaxvin Technologies is the Data Fiduciary for anything described below. Questions, requests and complaints: privacy@pathayam.app.
Do not put anything real into this demo
This instance is shared and public. It is filled with invented data, it resets when it restarts, and anything you type is visible to every other visitor until then. Do not enter a real account number, a real balance, a real PAN, or any other real personal or financial information.
Entering the demo sets one session cookie, so the app knows which invented member you are looking as. It is strictly necessary for the demo to work, expires with the session, and is not used for analytics. There is no other cookie and no tracking of any kind.
What this demo holds
- Nothing about you. There is no account and no sign-in: entering the demo picks one of the invented members to look as. No email address, no name and no profile picture is collected, because none is ever asked for.
- The invented household. Accounts, balances, transactions, envelopes, loans and holdings that ship with the demo. Every figure, name and account in it is made up.
- Whatever you type, until the next reset, visible to everyone else using the demo in the meantime.
- Operational logs. Method, path, status, duration and errors. Never query strings, form bodies, amounts or any financial value.
No Google sign-in, and no access to any mailbox
The full application can sign in with Google and can read bank alerts from Gmail, with permission, when somebody runs it themselves. This demo does neither. It is not configured with a Google project at all, and connecting a mailbox is refused here rather than merely hidden. Nothing you do in this demo can reach an email account, yours or anyone's.
Saving a statement identity — the name, date of birth or PAN used to open a password-protected bank statement — is refused here for the same reason. There is nowhere in this demo to put a real PAN, which is deliberate.
Your rights
- Get a copy. One endpoint returns everything in an open format, at any time.
- Correct it. Every figure in the app is editable directly.
- Erase it. Everything here is invented and goes at the next reset regardless.
- Complain. To privacy@pathayam.app first, and then to the Data Protection Board of India if it is not resolved. Grievances reach the same address and are answered within 30 days.
Security
Sign-in is Google OAuth with PKCE and no password is stored. Session tokens are held as hashes. Writes require a same-origin check. API tokens are scoped, revocable, stored hashed, and cannot reach token management or member administration. Statement passwords and the Gmail token are held separately from exportable data precisely so an export cannot leak them.
Traffic is served over HTTPS. The database is not encrypted at rest beyond the disk encryption the hosting provider applies — which is why the demo contains nothing but invented data.
Children
This demo is not offered to anyone under 18.
Changes
If this policy changes, the date at the top changes with it.
This is the copy the demo serves. The canonical pages, which also cover the website and the hosted service, are at pathayam.app/privacy and pathayam.app/terms.