Akasente

Privacy Policy

What the app holds, where it is kept, and who can reach it.

Last updated 4 October 2026 · Version 1.7

The short version

Akasente writes every record to the phone you typed it into, first and always. The app works with no network at all, because it was built for microfinance businesses in Uganda that work where the network drops.

Records are then copied to a database and a file store run for your business on Google Cloud, in the European Union, so that everyone at a branch sees the same book and the owner sees every branch. That copy includes your customers' details and the photographs taken of them and of their National ID cards. Registering a business and signing in also create an account on that server. The section "If your business uses sync" below sets out exactly what is copied, who can reach it and how long it is kept.

What does not happen: nothing about your business or your customers is sold, rented or handed to advertisers, there is no analytics or tracking in the app, and Tizak Software Solutions does not read your loan book. Your password is stored only as a scrambled form that cannot be turned back into the password, and nobody, including us, can read it.

Who is responsible for what

Tizak Software Solutions writes and publishes this app, and operates the Google Cloud project your records are synced into. We do not run the lending business and we do not use your loan book for any purpose of our own. We hold it only so the app can put it back on your staff's phones. In the language of the Data Protection and Privacy Act, 2019, you are the data controller and we are your data processor.

The business that installs the app, the owner who registered it, is the data controller for everything recorded in it. Under Uganda's Data Protection and Privacy Act, 2019 that carries real duties: collect only what you need, tell people what you are collecting it for, keep it safe, and register with the Personal Data Protection Office if you are required to. Those duties are yours: you decide who is recorded and why, and we act only on your instructions. Ours are the processor's duties, keep the store secure, use it for nothing else, and delete it when you tell us to.

If you are a borrower reading this

You do not install this app and you have no account in it. Your details are held by the microfinance business that lent to you, on their staff's phones, and in the database we run for them. Ask them to show you, correct or remove your record: it is their decision to make, not ours, and we act on it when they tell us to. If you cannot reach them, write to us and we will put you in touch.

What the app holds about you

When an owner registers a business, the app records the business name and type, its district and address, and the owner's name, phone number, email if given, and National Identification Number. Officers and cashiers are added by the owner, and the app records their name, phone number, email, the branch they are posted to and the area they cover.

Everyone who signs in has a password. It is checked on the server, not on the phone, and the phone keeps no copy of it. What is kept on the server is a scrambled form of it that cannot be turned back into the password. This is why signing in needs internet, and why nothing else in the app does.

The app also records who did what, the officer who took a payment, the cashier who logged a handover, the person who closed the cash day. That is not surveillance for its own sake; it is how the money reconciles at the end of the day, and the business owner can see it.

What the app holds about your customers

This is the part that matters most, because your customers did not choose this app. You did. Depending on how much of a form your staff fill in, the app can hold:

Signatures are photographs of signed paper. The app never asks anyone to draw one on a screen.

Collect less than the form allows

Most of those fields are optional. A guarantor's National ID and date of birth are sensitive, and if your lending decision does not turn on them, do not ask. Under the Data Protection and Privacy Act you must be able to say why you hold each thing you hold.

Where all of this is kept

On the phone. The app writes to the device's own storage, in the app's private area, which other apps on the phone cannot read. Photographs are kept as files on the device and referred to by their location.

The phone is always the first place a record is written, and the app is fully usable with no network at all. What happens next depends on whether your business uses Akasente Sync.

Sync switched off
Nothing leaves the phone. Records are saved to the device and stay there. The app keeps a queue of changes in case sync is switched on later; until it is, that queue never goes anywhere.
Sync switched on
Records are copied to a database run for your business on Google Cloud, so that everyone at a branch sees the same book and the owner sees every branch. Photographs, including photographs of National ID cards, are copied to the same place, filed under the branch they were taken at. Read the next section before you switch it on.
Without sync, one phone means one copy

If sync is off there is no backup anywhere. A phone that is lost, wiped or stolen takes its records with it, and anyone who can unlock it can open the app. Give every staff member their own phone lock, and export or print what you cannot afford to lose.

If your business uses sync

Sync exists so that a business is not one dropped phone away from losing its book, and so that an owner can see what their officers collected without standing next to them. It is a real change in where your borrowers' details live, and it is described here in full rather than buried.

Who holds it
Google, as our processor, through Firebase (Cloud Firestore, Cloud Storage, Firebase Authentication and Cloud Functions). Google processes it on our instructions and does not use it for its own purposes.
Where it is held
On Google Cloud servers in the European Union. Uganda has no Google Cloud region, so this is a cross-border transfer under the Data Protection and Privacy Act 2019, made under Google's standard data protection terms.
What is copied
Everything the business records: client names, phone numbers, National ID numbers, home locations, loans, repayments, savings, expenses, staff details and every photograph taken in the app, client photos, both sides of an ID card, photographed signatures, and proof-of-payment shots.
Who can read it
Only accounts belonging to your business, and only while they are active. A staff account that is stopped loses access on the server as well as in the app. We do not read your records, other than where you ask us for support and we need to look at a specific problem.
How long
For as long as the business uses the app, and for 90 days after the last sign-in, after which it is deleted. The owner can delete everything sooner, see "Deleting your data".
What each phone actually holds

A field officer's phone downloads the clients assigned to them, those clients' loans and repayments, and the receipts they wrote themselves, not the rest of the branch. A cashier's phone and the owner's hold the whole branch, because a cash desk serves whoever walks in and the owner's figures add up across it. The hard boundary is the branch: a phone posted to one branch cannot reach another branch's clients, and the database refuses it rather than the app hiding it. Narrowing an officer to their own round is a smaller download and less on a phone that can be lost, but it is not that same hard boundary, treat any staff handset as holding the files it has downloaded.

Which phones an account works on

A member of staff signs in on one phone at a time. If the same staff account is signed in on a second phone, the second one takes over and the first is disconnected.

The business owner is the exception: their account works on every phone they sign in on, side by side, so that a whole office can put an old paper ledger into the app at once. The owner can see that list at any time in Settings, under Phones signed in, and remove any phone on it — which signs that phone out but does not erase what it is holding.

The old phone erases the business data it was holding

When a phone is disconnected this way, it deletes the business records it had downloaded, clients, loans, repayments and the photographs that go with them. It does this only after sending anything it had not yet sent, and if it cannot send that work it keeps everything and waits, so nothing recorded at a door is lost because somebody signed in elsewhere. Your own photos, messages and everything else on the handset are untouched: only this app’s data is removed.

To make this work we record each phone an account is signed in on: a random identifier the app generates for itself, the name the phone gives for itself (usually its model, such as SM-G988N), whether it is Android or iPhone, and when it was last used. The owner of the business sees that list, for their own phones and for their staff’s. None of it is a device serial number, an advertising id, or anything that identifies the handset to anyone else, and it is not shared outside your business.

Recovery codes

When a business is registered, the owner is shown eight recovery codes once and asked to write them down. If the owner ever loses the Google or Apple account they signed up with, one of those codes is what gets them back into the business.

We do not keep the codes themselves. What is stored is a one-way scramble of each one, which is enough to check a code somebody types and not enough to work out what the codes were. That is also why they cannot be shown again: nobody at Tizak Software can read them either. A new set can be generated from Settings at any time, which cancels the old set.

When we can reach your business

Tizak Software can restore access to a business for an owner who has lost both their sign-in account and their recovery codes and has asked us for help. It means attaching the business to a different sign-in account, which the owner tells us to use.

You are told, and it is written down

Every time we do this it is recorded against your business, who did it, when, and the reason they gave, in a record the owner can read and nobody, including us, can edit or delete. We built it that way deliberately: it means we cannot quietly hand your business to somebody else, and if it is ever disputed the record is there.

This does not give us your customers’ records to browse. It is a support action that changes who may sign in, and it is used when an owner asks for it.

Signing in with Google or Apple

Registering a business requires a Google or an Apple account, and requires internet at that moment. It is the only part of this app that does. The account is what proves the business is yours and what gets you back into it from a new phone; the business is created on the server at the same time, so that colleagues can later be added to it.

After that, staff sign in with the phone number and password their owner gave them, or with their own Google or Apple account if the owner put their email address on their record. Signing in checks with the server, so that an account the owner has stopped is stopped everywhere. Staying signed in does not: once you are in, the app works with no network at all.

What they tell us
Your name and email address, and a permanent identifier for the account. That is all we ask for and all we receive. We never get your Google or Apple password, your contacts, your calendar, your files or anything else in that account.
What we do with it
Match you to your business, so the right records reach the right phone. The email is stored so an owner who adds you to their team can have you sign in as yourself instead of typing a code.
What they are told about you
That you signed in to this app. Google and Apple do not receive your clients, your loans, your repayments or anything else this app records.
Apple on an Android phone
Android has no Apple sign-in of its own, so the app opens Apple's sign-in page in a browser tab. Apple sends its answer to our server, which passes it straight back to the app and keeps no copy. In a web browser the same thing happens in a pop-up window.
If you use Apple's Hide My Email
It works normally. We keep the forwarding address Apple gives us and never see your real one.
Why it is worth doing

Your password opens the app on the phone you are holding, and a scrambled version of it is kept on our server so you can sign in on a replacement handset. A Google or Apple account is the stronger of the two: it outlives the phone, and it cannot be guessed. Sign in on a new one and your records come back.

It does not replace your password

The app still asks you to set a password on each phone, because the app has to open in a village with no signal and a Google sheet cannot. The password is what opens the app in the field; the Google or Apple account is what proves who you are to the server when you sign in.

What actually leaves the phone

With sync switched off, four things, and only when somebody makes them happen. With sync on, add everything described in the section above, which goes automatically rather than by hand.

A receipt or report you share
Tapping share or print hands a PDF or a block of text to whichever app or printer you pick, WhatsApp, email, Bluetooth. From that moment it is in their hands and their privacy policy, not ours.
A reminder you send
Call, SMS and WhatsApp reminders open the phone's own dialer or messaging app with the message ready. The app never sends anything on its own, and never in the background.
A check for app updates
The app asks Expo's update service whether a newer version exists. That request tells them the platform, the app version and the device's IP address. It carries none of your records.
Crash information
If the app is downloaded from Google Play or the App Store, the store may collect crash and performance data under its own policy. We have not added any analytics, advertising or tracking software of our own.
Your password, scrambled
When you set or change a password, the phone sends a scrambled version of it to our server. Scrambling is one-way: it lets the server check a password you type later, and it cannot be turned back into the password itself. This is what lets you sign in on a new phone with the password you already know, instead of needing a code from your owner every time. It only happens when sync is on, and the password itself is never stored anywhere, on the phone or on the server.

With sync on there is a fifth: a notification about work a colleague has just recorded. Your phone registers an address with Expo's notification service so the server can reach it, and the message itself, the words you read on the notification, travels through that service and then through Google's or Apple's to arrive. Those words can name a client and an amount, because that is what makes the notification worth having. Nothing else goes with them.

The reminders your own phone raises go nowhere

Most of what this app tells you, who is due today, who has fallen behind, when to open and close the cash desk, is worked out on the handset from records it already holds and shown by the phone itself. None of that is sent anywhere, and it keeps working with no signal and with sync switched off entirely.

What the app does not do

This list matters more than it looks. Lending apps have a bad reputation for harvesting a borrower's contacts and photos to shame them into paying. This app is not installed by borrowers at all, and it asks for nothing it does not use.

Permissions the app asks for

Camera
To photograph a customer, an identification document, a signed agreement, a signed receipt, or proof of a cash handover. Asked for the first time you tap to take a photo.
Notifications
To remind you in the morning who you are collecting from, to prompt a cashier to open and close the day, and to pass on what a colleague has just recorded. Asked once, after you first sign in.
Nearby devices (Bluetooth)
To print a receipt on the Bluetooth receipt printer at the counter or in the bag. Asked the first time you print. The app talks only to a printer you have already paired in the phone’s own Bluetooth settings: it does not search for devices, it cannot see what else is around you, and it sends the receipt to nothing but the printer you picked.

You can refuse all three and still use the app; the screens that wanted a photo will simply carry on without one, everything a notification would have told you is on the Notifications screen inside the app, and printing falls back to the phone's own print dialog. Any of them can be withdrawn at any time in the phone's settings.

Those three are the whole list. The app holds no permission to read the photographs on your phone, and none to read or write its shared storage: both are stripped out of the build. Attaching a picture you already have still works, because it never needed them — choosing Gallery opens the phone's own photo picker, which runs outside this app. You pick one file, and that file is the only thing the app is given. The rest of your gallery stays invisible to it. It also cannot read your contacts, your location, your call log or your messages, and it cannot see what other apps you have installed.

Signing in, and what it does not protect

Your password is checked on the server, not on the phone, so a password changed or an account stopped takes effect everywhere at once. That is also why signing in is the one thing in this app that needs internet.

We would rather say this plainly than let you assume otherwise: signing in does not protect the records on a phone that is already unlocked and already signed in. Whatever the app can show, whoever is holding it can see. Sign out when you hand the phone over, and put a screen lock on it.

What a signed-in person can see is narrowed by the job they do. A field officer sees the customers on their own round. Those clients' loans, payments and receipts, and any payment the officer took themselves. They do not see another officer's customers or what that officer collected. A cashier and the business owner see everything the business has recorded, because the desk has to reconcile the day's cash and the owner is answerable for all of it.

When a customer is moved from one officer to another, their history moves with them: the new officer can see the earlier payments, because they now have to collect on that loan. A payment taken at the desk for a client on an officer's round is visible to that officer too, so they are not chasing money that has already been paid.

This narrowing is done by the app on the phone. It keeps staff out of each other's work in ordinary use; it is not encryption, and it is not a barrier to somebody who takes the handset apart.

Treat a phone with this app on it the way you would treat the ledger it replaced: give it a screen lock, do not lend it out, and report it the day it goes missing.

Working hours, and being locked out

A business owner can set the days and times their business works, and can switch on a setting that stops field officers opening the app outside them. It is off unless the owner turns it on. Cashiers and the owner are never locked out.

If you are a field officer and this is switched on, the app will show a screen saying the business is closed and when it opens again. Everything you have already recorded is saved and keeps being sent to the office while that screen is up. Nothing of yours is deleted, held back, or hidden from you afterwards. You can still sign out and still read these documents.

To work outside those hours you call your office. They give you a four-digit code and you type it in. The code works without either phone having any network, it only works for the person it was given to, and it only works on the day it was given. Your office can also send the same permission to your phone directly if it has signal.

Each time this happens the app records it: who was let in, at what time, by whom, for how long, and the reason if one was given. The business owner can read that record, and it is sent to the server if the business uses sync. If you are an officer, working late is not private from your employer.

We would rather say this plainly too. This lock reads the clock on the officer's own phone, and it is that same phone that decides whether to let them in. It is a working rule between an employer and their staff, like a rota. It is not a security control, and a person who changes their phone's clock can get past it. Nobody should treat it as protection for money or for customer records.

How long records are kept

For as long as the app is installed and you keep them. Nothing expires on its own and nothing is deleted on a schedule, because a loan book is a record you are generally required to keep. Removing the app from the phone removes its data with it, and “Deleting your data” sets out the ways to clear records deliberately.

Your rights, and whose door to knock on

Under the Data Protection and Privacy Act, 2019 a person whose details are held can ask to see them, ask for a correction, object to how they are used, and in some cases ask for them to be erased.

Those requests go to the business holding the record, the microfinance company whose staff entered it. If you are that business, the app lets you show a customer their file, correct it, and print or share their statement. If a request reaches us by mistake we will tell the person who to ask, and that is all we can do, because we hold nothing to show them.

Children

This is a tool for people doing a job. It is not for anyone under 18, we do not knowingly hold a child's details, and lending to a minor is a matter for the law, not for this app.

When this policy changes

If a future version starts sending records to a server, adds analytics, or collects anything new, this page changes in the same release and the date at the top moves. Anything that materially changes what happens to people's data will be put in front of you in the app rather than quietly published here.

Contact

Write to Tizak Software Solutions at support@tizaksoftware.com. Tell us the phone and the business name; it saves a round trip.