Privacy Policy — FinSMS
FinSMS helps you track your money by automatically reading bank and financial transaction SMS on your device and organising them into spending, income, and bill insights. This policy explains what we collect, why, and your choices.
1. Information we collect
a. Account information
- Your mobile number, used to sign you in via a one-time password (OTP).
b. SMS / financial transaction data (sensitive)
- The app requests READ_SMS and RECEIVE_SMS permissions to read the SMS messages on your device.
- All reading and filtering happens on your device. FinSMS scans messages only to identify those that are financial/bank transaction messages (matched against known bank sender IDs and transaction patterns).
- Only messages identified as financial transactions are processed further. For those messages, we collect and transmit to our servers: the message content (body), the sender/address, the message date, and the transaction details we extract (amount, currency, transaction type, account number fragment, bank, and any payee/UPI information contained in the message).
- Non-financial and personal SMS are ignored — they are never uploaded, stored on our servers, or shared. We do not read SMS for any purpose other than identifying and organising your financial transactions.
c. Usage, device & diagnostics data
- Via Google Firebase Analytics, Firebase Crashlytics, and Mixpanel, we collect app events, screen views, feature usage, a user identifier tied to your account, approximate device/OS information, and crash/error logs to operate, secure, and improve the app.
d. Data stored on your device
- Your session token and transaction data are cached locally on your device for app functionality.
2. How we use your information
- Detect and categorise your financial transactions and show spending, income, bills, and analytics.
- Authenticate you (OTP sign-in) and maintain your session.
- Provide personalised suggestions and summaries.
- Diagnose crashes, monitor performance, and improve the app.
We do not sell your personal information, and we do not use your SMS or financial data for advertising.
3. Prominent disclosure — SMS permission
FinSMS's core feature is automatic transaction tracking, which requires reading transaction SMS. By granting the SMS permission, you consent to FinSMS reading your messages on-device to identify financial transactions, and to uploading the content and details of transaction messages only to our servers to provide the service. You can revoke this permission at any time in Android Settings; the automatic-tracking feature will then stop working.
4. How we share information
We share data only with service providers that help us run the app:
- Google (Firebase Analytics & Crashlytics) — analytics and crash reporting. See Google's Privacy Policy.
- Mixpanel — product analytics. See Mixpanel's Privacy Policy.
- Cloud hosting — our backend runs on Amazon Web Services (AWS) region: Asia Pacific (Mumbai), India, where your account and transaction data are stored.
We may disclose information if required by law or to protect our rights and users' safety.
5. Data storage & security
- Data in transit is protected using HTTPS/TLS encryption.
- Data is stored on secured cloud infrastructure with access controls.
- No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
6. Data retention & deletion
- We retain your account and transaction data while your account is active.
- You may request deletion of your account and associated data by contacting us at reach@pushmain.com. Optionally: describe an in-app delete option / expected turnaround, e.g. within 30 days.
- Locally cached data is removed when you log out or uninstall the app.
7. Children's privacy
FinSMS is not directed to children under 13 / 16, per your target markets, and we do not knowingly collect their data.
8. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or export your data, and to withdraw consent. Contact us at reach@pushmain.com to exercise these rights.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date and, where appropriate, notifying you in-app.
10. Contact us
Dev Inikhiya
Email: reach@pushmain.com
Optional: postal address