Finlyzer is built on a simple principle: your financial data belongs to you and stays on your device.
Finlyzer is an offline-first personal finance app. We do not operate servers that store your financial data, SMS messages, or transaction history. All data is processed and stored locally on your device, or optionally in your own Google Drive account.
This Privacy Policy describes how Finlyzer ("we", "us", or "our") handles information in connection with your use of the Finlyzer mobile application. We are committed to full transparency about what information we access, why we access it, and how it is protected.
We collect your email address via Google Sign-In solely for account identification. It is never sold, shared with third parties, or used for marketing. Everything else — your transactions, budgets, SMS data — stays entirely on your device.
This is the only personal information we collect. It is the minimal data required to identify your account for backup and restore purposes.
| Data Type | Collected? | Shared with Third Parties? | Purpose | Stored Where? |
|---|---|---|---|---|
| Email Address | Yes | No | Account identification only — never used for marketing | On-device only |
| SMS Messages | On-device only | Never | Auto-detect bank transactions locally | Processed locally, never transmitted |
| Financial Transactions | On-device only | Never | Expense tracking, budgets, goals | Local Hive database / your Google Drive |
| Biometric Data | Not collected | Never | App unlock (processed by OS only) | Never leaves your device |
| Location | Not collected | Never | — | — |
| Contacts / Photos | Not collected | Never | — | — |
In compliance with Google Play's data safety requirements, here is a complete and accurate summary of how Finlyzer handles user data:
All data transmitted by Finlyzer (Google Sign-In authentication, Google Drive backup) uses HTTPS/TLS encryption. No unencrypted data is ever transmitted.
Finlyzer uses Google OAuth (Sign in with Google) as the sole account creation method. We do not support username/password accounts. No passwords are ever created or stored by us.
We collect your email address via Google Sign-In solely for account identification. It is never sold or shared with third parties, and is not used for marketing or any purpose beyond identifying your account.
Finlyzer reads your SMS messages locally on your device to detect and parse bank transaction alerts. This processing happens entirely on your device. SMS content is never transmitted to our servers or any third party — we don't operate servers for this purpose.
Finlyzer requests only the permissions it needs to function. Here's exactly why each permission is needed:
SMS access is the core of Finlyzer's automatic transaction detection. We understand this is sensitive. Here's our complete commitment:
Finlyzer reads SMS messages locally to identify bank transaction patterns (debits, credits, UPI payments, etc.). The parsed transaction data is stored in your local Hive database on your device. We do not have servers that receive, store, or process your SMS messages. This is not a policy choice that could change — we simply don't have the infrastructure to collect it.
Finlyzer uses Google OAuth for account creation and authentication. When you sign in with Google, we receive:
| Information Received | Why | Shared? |
|---|---|---|
| Email address | Account identification and backup association | Never |
| Display name | Personalising your in-app experience | Never |
| Profile picture URL | Displaying your avatar in-app | Never |
We do not request access to your Google contacts, Gmail, Google Photos, or any other Google services beyond what is listed above. Drive access is requested separately and only when you first use the backup feature.
When you enable backup, Finlyzer creates an encrypted backup file and stores it directly in your personal Google Drive account under a dedicated "Finlyzer" folder. We do not have access to this file beyond the permissions you grant. You can delete this backup file from your Google Drive at any time.
You can disable backup at any time from the app settings. Revoking Google Drive access in your Google Account settings will immediately prevent any further backups.
Because all your data lives on your device, deleting your data is straightforward and complete.
Finlyzer does not maintain a backend database of user accounts or financial data. There is nothing for us to "delete" on our end because we never stored it. Uninstalling the app removes all local data from your device permanently.
Visit our dedicated account deletion page for step-by-step instructions on removing all data associated with your Finlyzer account.
Go to Delete AccountYou have full control over your data. Because Finlyzer is built offline-first, most rights are exercisable directly within the app — no waiting, no support tickets needed.
All your data is stored on your own device and Google Drive. You can view, export, or inspect it at any time directly from within the Finlyzer app.
You can permanently delete all your data at any time by uninstalling the app and removing your Google Drive backup folder. There is no server-side data for us to delete.
Your data is yours. The backup file in your Google Drive is in a portable format. You are not locked in — you can take your data with you at any time.
You can edit or correct any transaction, category, budget, or account data directly inside the Finlyzer app. No request to us is necessary.
You can revoke Google Sign-In and Google Drive permissions from your Google Account settings at any time, immediately stopping any data processing by those services.
If you have any data-related request or concern not covered above, email support@finlyzerapp.com and we will respond within 5 business days.
Security is baked into Finlyzer's architecture. Our offline-first design means your data never traverses our servers, dramatically reducing the attack surface.
All communications with Google services (OAuth, Drive backup) use HTTPS/TLS. No data is ever sent over unencrypted connections.
Financial data is stored in a Hive database on your device. It benefits from your device's own storage security model including hardware encryption on modern Android devices.
You can enable fingerprint or PIN protection to prevent unauthorised access to the app. Biometric verification is handled entirely by your device's operating system — Finlyzer never receives or stores any biometric data.
We do not run servers that store your financial records, SMS data, or personal information. This means there is no central database to breach, no credentials to leak, and no server-side vulnerability that could expose your data.
Authentication is handled entirely by Google's OAuth 2.0 system. We never create, store, or have access to your Google account password.
Finlyzer uses a minimal set of third-party services. Here's a complete and honest breakdown of each:
| Service | Purpose | Data Shared | Opt-Out |
|---|---|---|---|
| Google Sign-In (OAuth 2.0) | Account authentication | Email, display name, profile picture (read only) | Revoke access in Google Account settings |
| Google Drive API | Optional encrypted backup storage in your own Drive | Encrypted backup file only — stored in your Drive, not ours | Disable backup in app settings or revoke Drive permission in Google Account |
| No analytics SDKs | — | We do not use Firebase Analytics, Crashlytics, Amplitude, Mixpanel, or any behavioural analytics tool | N/A |
| No advertising SDKs | — | We do not use AdMob, Facebook Audience Network, or any ad network | N/A |
Your data is never sold, rented, or shared with data brokers, advertisers, or marketing platforms. The only third-party services we use are Google Sign-In and Google Drive, both of which are under your own Google account's control.
Finlyzer is not directed at children under 13 years of age. We do not knowingly collect any personal information from children. If you believe a child has used the app and provided personal information, please contact us and we will take appropriate steps.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify you via an in-app notice. We encourage you to review this policy periodically.
If you have any questions or concerns about this Privacy Policy or how we handle your data, please reach out:
We aim to respond to all privacy-related enquiries within 5 business days.