KuberaX
Privacy Policy
Last updated 18 September 2026
KuberaX is a companion app for businesses that keep their books in Tally. It shows you your own accounting data on a phone, and lets your team record a few kinds of entry that are written back into your Tally. This policy explains exactly what reaches our servers, why, and how to get rid of it.
The short version. We collect the account details you sign in with, and a mirror of the business data your own Tally installation sends us. We do not use advertising, analytics or tracking of any kind. We never sell data. Deleting your account from inside the app erases all of it.
Who we are
KuberaX is operated by Wenex E.R.P. Solution Pvt. Ltd., Nepal, which is the data controller for the information described here. You can reach us at support@wenexnepal.com.
What we collect
1. Account information
When an account is created for your business, and when you create a login for a salesman, we store a name, an email address, a role, and a password that is stored only as a bcrypt hash — never in a form we or anyone else can read back.
2. Your business records, mirrored from Tally
The KuberaX desktop connector runs on the computer where your Tally is installed. On the schedule you configure, it reads from Tally and sends us:
- ledger and group masters, and their balances;
- vouchers and their line items, including narrations;
- stock items and quantities;
- outstanding receivables and payables, and their due dates;
- company details such as name, address and financial-year figures.
Some of those records contain personal information about your customers and suppliers — typically a name, a mailing address and a phone number carried on a ledger. We hold that information on your behalf so that the app can display it and dial it. We do not use it for anything else.
3. Records created in the app
Entries your team makes in KuberaX and the app queues for your Tally — receipts, payments, sales and purchase invoices, sales and purchase orders, quotations, credit and debit notes, journals, contra entries, and new ledgers, groups and stock items. Where your account uses approval, the entry also carries who created it and who approved or refused it.
Alongside those, the field-force records: a salesman's trips, their check-ins at a party, and the commission lines the app calculates from payments received.
4. Your company's letterhead
If you set up a company profile, we store what you upload for use on the documents the app produces: your address and contact person, your company logo, and an image of your signature and stamp. These are used only to render your own PDFs and are deleted with your account.
5. Device and notification identifiers
When you sign in, we store an identifier for the device so that one login cannot be used on several phones at once, together with a device label such as "Android 14 · Pixel 7" so we can tell you which phone holds your licence. If you allow notifications, we also store the notification token issued by Google for that installation.
6. Technical logs
Each API request is logged with its method, path, response status, duration and originating IP address, for security monitoring and fault diagnosis. These logs are deleted automatically after 14 days.
What we do not collect
- No location. KuberaX tracks field visits by self-reported check-in, not by GPS. The app never requests location permission.
- No contacts, camera, microphone or photo library. The app requests no device permissions at all.
- No advertising or analytics SDKs, and no cross-app or cross-site tracking. KuberaX carries no advertising network, no analytics product and no attribution or profiling tool of any kind. The single third-party service in the app is Google's Firebase Cloud Messaging, which exists only to deliver the notifications you allow; it receives the notification token for your installation and nothing about your books.
- No payment card details. The app contains no purchasing of any kind.
Why we hold it, and on what basis
| Data | Purpose |
|---|---|
| Account information | To authenticate you and to determine which company's books you may open. |
| Mirrored Tally records | To render your dashboard, reports, ledgers and outstandings without your phone needing a live connection to Tally. |
| Records created in the app | To queue an entry for your Tally, and to keep the commission and field-activity registers the app provides. |
| Your company's letterhead | To print your own logo, address, signature and stamp on the documents the app produces for you. |
| Device and notification identifiers | To hold one login to one device, to name that device when you ask us which phone has it, and to deliver the notifications you allow. |
| Technical logs | Security monitoring, abuse prevention and diagnosing faults. |
We process this data to perform the service contract between your business and KuberaX, and, for the technical logs, on the basis of our legitimate interest in keeping the service secure.
Who else sees it
Your data is visible to the people your business authorises, and to no one else inside it:
- the account owner, who sees every set of books on the account;
- other device logins the owner issues — a manager or an accountant — each of whom sees only the Tally companies the owner has assigned to them, and nothing at all until the owner assigns one;
- salesman logins, each fixed to the single Tally company they were created under;
- where your account uses approval, the people the owner names as approvers, who see the entries waiting for them.
One person's login can be given access to a second business's account — for example an accountant who keeps two sets of books. That is done only at the request of the account that is being joined, it occupies one of that account's device licences, and it grants only the Tally companies that account's owner allows.
Outside your business, access is limited to KuberaX staff who need it to operate or support the service, and to two service providers: DigitalOcean, whose infrastructure the servers and database run on, and Google, whose Firebase Cloud Messaging carries notifications to your device. We do not sell, rent or share your data with anyone else, and we do not use it to train machine-learning models.
Where it is stored and how it is protected
- Data is held in a PostgreSQL database on a private server.
- Passwords are stored as bcrypt hashes and are never recoverable.
- Sessions use signed, expiring tokens that can be revoked; the app stores its token in the iOS Keychain or the Android Keystore, not in ordinary app storage.
- Every page the app serves is fetched over HTTPS. The app refuses an unencrypted connection outright.
- Every request is scoped to your company, so one client's query cannot reach another client's records.
- The database is backed up nightly and the backups are retained for seven days.
How long we keep it
| Data | Retention |
|---|---|
| Account and business records | For as long as the account exists. Deleted immediately when the account is deleted. |
| Technical request logs | 14 days. |
| Notification tokens | Until you sign out on that device, or the token is retired by Google. |
| Cached report rows | Rebuilt on demand; the cache is capped at roughly 15 months. |
| Database backups | 7 days, after which they are overwritten. |
Deleting your account and your data
You can delete your account from inside the app. Open Settings → Account & Legal → Delete Account, confirm with your password, and the deletion happens immediately.
If you are the account owner, this removes your company entirely: every login, every mirrored ledger, voucher, stock item and outstanding, every trip, visit and commission line, and the logo, signature and stamp you uploaded. If you are a salesman, it removes your login; the field and commission records belong to your employer's books and remain with them.
Deleting your KuberaX account does not touch your Tally installation. Your books stay exactly where they are — only the mirror is removed.
Backups containing deleted data are overwritten within seven days.
Your rights
You may ask us to give you a copy of the data we hold about you, to correct anything inaccurate, or to delete it. Deletion is available immediately in the app as described above; for the other requests, write to us using the contact details below and we will respond within 30 days.
Children
KuberaX is business software. It is not directed at children, and we do not knowingly collect information from anyone under 16.
Changes to this policy
If we change what we collect or why, we will update this page and change the date at the top. Material changes will also be notified to account owners by email.
Contact
Wenex E.R.P. Solution Pvt. Ltd., Nepal
Email: support@wenexnepal.com
Phone: +977 9709127873