Privacy First

Privacy Policy

Finlyzer is built on a simple principle: your financial data belongs to you and stays on your device.

Last updated: March 2026  ·  Effective: March 2026

Jump to Section

Overview

Your Data Stays On Your Device

Finlyzer is an offline-first personal finance app. We do not operate servers that store your financial data, SMS messages, or transaction history. All data is processed and stored locally on your device, or optionally in your own Google Drive account.

This Privacy Policy describes how Finlyzer ("we", "us", or "our") handles information in connection with your use of the Finlyzer mobile application. We are committed to full transparency about what information we access, why we access it, and how it is protected.

Data Collected

What we collect

We collect your email address via Google Sign-In solely for account identification. It is never sold, shared with third parties, or used for marketing. Everything else — your transactions, budgets, SMS data — stays entirely on your device.

This is the only personal information we collect. It is the minimal data required to identify your account for backup and restore purposes.

Data Type Collected? Shared with Third Parties? Purpose Stored Where?
Email Address Yes No Account identification only — never used for marketing On-device only
SMS Messages On-device only Never Auto-detect bank transactions locally Processed locally, never transmitted
Financial Transactions On-device only Never Expense tracking, budgets, goals Local Hive database / your Google Drive
Biometric Data Not collected Never App unlock (processed by OS only) Never leaves your device
Location Not collected Never
Contacts / Photos Not collected Never

Google Play Data Safety Declaration

In compliance with Google Play's data safety requirements, here is a complete and accurate summary of how Finlyzer handles user data:

Data is encrypted in transit

All data transmitted by Finlyzer (Google Sign-In authentication, Google Drive backup) uses HTTPS/TLS encryption. No unencrypted data is ever transmitted.

Account creation method: OAuth only

Finlyzer uses Google OAuth (Sign in with Google) as the sole account creation method. We do not support username/password accounts. No passwords are ever created or stored by us.

Data collected: Email address only

We collect your email address via Google Sign-In solely for account identification. It is never sold or shared with third parties, and is not used for marketing or any purpose beyond identifying your account.

SMS data: On-device processing only

Finlyzer reads your SMS messages locally on your device to detect and parse bank transaction alerts. This processing happens entirely on your device. SMS content is never transmitted to our servers or any third party — we don't operate servers for this purpose.

App Permissions

Finlyzer requests only the permissions it needs to function. Here's exactly why each permission is needed:

READ_SMS
Required Permission

Reads bank SMS alerts to automatically detect and categorise transactions. All parsing happens on-device. SMS data never leaves your phone.

On-device only
Google Drive
Optional Permission

Used only when you enable backup. Your encrypted data is stored in your own Google Drive account — not ours. You can revoke this at any time.

Your Drive, your data
Biometric / PIN
Optional Permission

Used for app lock when you enable screen protection. Biometric processing is handled entirely by your device's OS — we never receive or store any biometric data.

OS-handled only
Notifications
Optional Permission

Used to send local reminders for bill due dates, subscription renewals, budget warnings, and savings goal deadlines. All notifications are generated locally.

Local notifications

SMS Data — How We Handle It

SMS access is the core of Finlyzer's automatic transaction detection. We understand this is sensitive. Here's our complete commitment:

SMS stays on your device. Always.

Finlyzer reads SMS messages locally to identify bank transaction patterns (debits, credits, UPI payments, etc.). The parsed transaction data is stored in your local Hive database on your device. We do not have servers that receive, store, or process your SMS messages. This is not a policy choice that could change — we simply don't have the infrastructure to collect it.

Google Sign-In

Finlyzer uses Google OAuth for account creation and authentication. When you sign in with Google, we receive:

Information ReceivedWhyShared?
Email address Account identification and backup association Never
Display name Personalising your in-app experience Never
Profile picture URL Displaying your avatar in-app Never

We do not request access to your Google contacts, Gmail, Google Photos, or any other Google services beyond what is listed above. Drive access is requested separately and only when you first use the backup feature.

Backup & Cloud Storage

Your backup lives in your Google Drive — not ours

When you enable backup, Finlyzer creates an encrypted backup file and stores it directly in your personal Google Drive account under a dedicated "Finlyzer" folder. We do not have access to this file beyond the permissions you grant. You can delete this backup file from your Google Drive at any time.

You can disable backup at any time from the app settings. Revoking Google Drive access in your Google Account settings will immediately prevent any further backups.

Account & Data Deletion

Because all your data lives on your device, deleting your data is straightforward and complete.

We hold no server-side data about you

Finlyzer does not maintain a backend database of user accounts or financial data. There is nothing for us to "delete" on our end because we never stored it. Uninstalling the app removes all local data from your device permanently.

Want to delete your account and data?

Visit our dedicated account deletion page for step-by-step instructions on removing all data associated with your Finlyzer account.

Go to Delete Account

Your Rights

You have full control over your data. Because Finlyzer is built offline-first, most rights are exercisable directly within the app — no waiting, no support tickets needed.

Right to Access

All your data is stored on your own device and Google Drive. You can view, export, or inspect it at any time directly from within the Finlyzer app.

Right to Erasure

You can permanently delete all your data at any time by uninstalling the app and removing your Google Drive backup folder. There is no server-side data for us to delete.

Right to Portability

Your data is yours. The backup file in your Google Drive is in a portable format. You are not locked in — you can take your data with you at any time.

Right to Rectification

You can edit or correct any transaction, category, budget, or account data directly inside the Finlyzer app. No request to us is necessary.

Right to Object

You can revoke Google Sign-In and Google Drive permissions from your Google Account settings at any time, immediately stopping any data processing by those services.

Contact Us for Any Request

If you have any data-related request or concern not covered above, email support@finlyzerapp.com and we will respond within 5 business days.

Data Security

Security is baked into Finlyzer's architecture. Our offline-first design means your data never traverses our servers, dramatically reducing the attack surface.

End-to-End Encryption in Transit

All communications with Google services (OAuth, Drive backup) use HTTPS/TLS. No data is ever sent over unencrypted connections.

On-Device Storage with Hive

Financial data is stored in a Hive database on your device. It benefits from your device's own storage security model including hardware encryption on modern Android devices.

Optional Biometric App Lock

You can enable fingerprint or PIN protection to prevent unauthorised access to the app. Biometric verification is handled entirely by your device's operating system — Finlyzer never receives or stores any biometric data.

No Backend Servers Holding Your Data

We do not run servers that store your financial records, SMS data, or personal information. This means there is no central database to breach, no credentials to leak, and no server-side vulnerability that could expose your data.

Google OAuth — No Passwords Stored By Us

Authentication is handled entirely by Google's OAuth 2.0 system. We never create, store, or have access to your Google account password.

Third-Party Services

Finlyzer uses a minimal set of third-party services. Here's a complete and honest breakdown of each:

Service Purpose Data Shared Opt-Out
Google Sign-In (OAuth 2.0) Account authentication Email, display name, profile picture (read only) Revoke access in Google Account settings
Google Drive API Optional encrypted backup storage in your own Drive Encrypted backup file only — stored in your Drive, not ours Disable backup in app settings or revoke Drive permission in Google Account
No analytics SDKs We do not use Firebase Analytics, Crashlytics, Amplitude, Mixpanel, or any behavioural analytics tool N/A
No advertising SDKs We do not use AdMob, Facebook Audience Network, or any ad network N/A

No data brokers. No third-party tracking.

Your data is never sold, rented, or shared with data brokers, advertisers, or marketing platforms. The only third-party services we use are Google Sign-In and Google Drive, both of which are under your own Google account's control.

Children's Privacy

Finlyzer is not directed at children under 13 years of age. We do not knowingly collect any personal information from children. If you believe a child has used the app and provided personal information, please contact us and we will take appropriate steps.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify you via an in-app notice. We encourage you to review this policy periodically.

Contact Us

If you have any questions or concerns about this Privacy Policy or how we handle your data, please reach out:

support@finlyzerapp.com

We aim to respond to all privacy-related enquiries within 5 business days.