AKQR Receipt Companion: Privacy & Consent
Beta app, 8 October 2026. Only install on a phone you own or control. It is not a payment provider or proof of funds received.
What you opt in to
Android Notification Access is optional. You must choose individual payment/SMS-notification apps to filter. The app never requests SMS inbox access or reads old messages. You can alternatively share one received credit alert manually and press Send. The service sees notification content in memory but ignores non-selected app packages and rejects messages containing sensitive OTP/password-type terms.
What is transmitted
Only credit amount, optional bank/UPI numeric reference, timestamp, selected source-app identifier and a random event ID. Full message body, OTP/PIN, account numbers, SMS history, personal conversations and contacts are not sent to AKQR.
How data is protected
The phone encrypts the paired device token using Android Keystore AES-GCM. Requests use HTTPS. Server pairing tokens are hashed; normalized receipt-alert metadata and newly saved UPI receiver identifiers are AES-256-GCM encrypted in database fields. Other existing gateway account/payment fields may have different storage protections: do not interpret this as a claim of full-database encryption.
Encrypted offline queue and signed delivery (v2)
Updated AKQR Merchant App v1.1.0 and Receipt Companion v1.0.2 locally store only filtered credit-alert fields in an Android Keystore AES-GCM encrypted SQLite queue while offline. Queue entries are capped at 300 and expire after 48 hours. JobScheduler (not WorkManager) retries transient delivery failures when Android permits; retry may be delayed by battery or connectivity restrictions. Turning off consent/unpairing clears the local queue. Requests are HTTPS and signed using a unique per-device pairing token, HMAC-SHA256 and a timestamp. No shared secret is hardcoded into the app. Device-reported pending/failed counts on the dashboard are diagnostic and not independently verified.
Review, never automatic success
Amount matching can be wrong, delayed or spoofed. Records are labelled CANDIDATE_REVIEW, AMBIGUOUS or UNMATCHED. No alert itself marks an order paid. Only separately verified provider API/webhooks may confirm a real transaction.
Stop, revoke and delete
Uncheck consent, disable Notification Access, unpair on the phone, and revoke the device in your Merchant Dashboard. Delete receipt alerts in the dashboard. Encrypted records older than 30 days are cleared when the merchant next submits an accepted alert. If no new alerts are received, the merchant should use Delete All to remove old alert records.
Distribution notice
This is a privately signed APK and has not been submitted for Google Play permission review. It does not use READ_SMS, RECEIVE_SMS or SEND_SMS permissions. New versions use RECEIVE_BOOT_COMPLETED for persisted background delivery jobs; this does not grant SMS inbox access. Not every payment provider sends readable notifications; some alerts may not be detected.