Privacy Policy
Spend Sutra is a personal expense tracker that reads bank and card transaction alerts already arriving in your SMS inbox or email, and turns them into a spending picture — entirely on your device. This policy explains exactly what the app reads, how it's processed, and what, if anything, ever leaves your phone.
The short version
- Spend Sutra has no backend server. There is nothing for it to send your data to.
- All parsing of SMS and email happens on-device — message content is never uploaded anywhere.
- Your transaction history is stored on-device in an encrypted (AES-256) database.
- Cloud backup is optional, off by default, and — when turned on — goes to a private folder in your own Google Drive that only Spend Sutra can access, not to us.
- No account or sign-in is required to use the app.
Data we read, and why
SMS messages (Android)
With your permission, Spend Sutra reads SMS messages on your device to detect bank and card transaction alerts (debits, credits, bill payments). Detection runs entirely on-device using pattern matching and, for messages that pattern matching can't confidently parse, a small on-device AI model. Raw SMS content is never transmitted off your device — only the transaction details extracted from a matching message (amount, merchant, date, bank, category) are saved to your local transaction history. Messages that aren't transaction alerts (personal texts, OTPs unrelated to a transaction, marketing messages) are read but discarded without being stored.
Email (optional, any platform)
If you choose to connect an email account, Spend Sutra uses the IMAP protocol to fetch transaction alert emails directly from your provider (Gmail, Outlook, Yahoo, iCloud, or a custom IMAP server) over an encrypted connection. Your email credentials are stored encrypted on your device only — they are never sent to us, because there is no server of ours for them to go to. As with SMS, email content is parsed on-device and only the extracted transaction details are saved.
On-device AI classifier
When a message can't be confidently parsed by pattern matching, Spend Sutra falls back to a small language model that runs fully on your device. No message content is sent to any cloud AI service for this — the model file itself is downloaded once from our hosting provider, but nothing about your messages or transactions is ever uploaded during classification.
Optional cloud backup (Android)
Spend Sutra can back up your encrypted transaction data automatically if you sign in with Google during
onboarding or later in Settings. This backup is written to your Google account's private app-data
folder — a storage area tied to Spend Sutra that does not appear in your visible Google Drive files and
that no other app, including ours, can read. The backup itself is encrypted before it's written, using
a key that travels inside the backup file. We never see this data; it is stored by Google, on your
behalf, under your Google account. Signing in only requests the narrow drive.appdata
permission — never access to your existing Drive files.
Currency conversion
For transactions in a foreign currency (currently USD), Spend Sutra queries a public exchange-rate API to convert the amount to INR for display. Only the currency pair and amount are sent in this request — no transaction details, merchant names, or personal information are included.
Data storage and security
- All transaction data is stored locally on your device in an AES-256 encrypted database.
- You can lock the app with your device's biometric authentication (fingerprint/face) if you enable it in Settings.
- Uninstalling the app removes all locally stored data. If you've enabled Google Drive backup, that backup remains in your Google account until you delete it yourself (from Settings, or directly in your Google account's app-data storage).
What we don't do
- We don't operate a server that receives your transaction data, SMS content, or email content.
- We don't sell, rent, or share your personal data with advertisers or data brokers.
- We don't read your personal (non-transactional) text messages or emails beyond what's needed to identify a transaction alert, and we don't store that content.
- We don't require an account to use any core feature of the app.
Advertising
Spend Sutra does not currently show any ads. If ads are enabled in a future release, this policy will be updated, and ad personalization will be governed by your consent choices (shown via a standard consent form on first launch) and, on iOS, Apple's App Tracking Transparency prompt. See the Ads page for details.
Children's privacy
Spend Sutra is a personal finance tool intended for adults managing their own bank and card transactions. It is not directed at children, and we do not knowingly collect data from children.
Your choices
- You can review, edit, or delete any transaction from within the app at any time.
- You can disconnect any linked email account from Settings, which also deletes its stored credentials from your device.
- You can sign out of Google backup at any time from Settings; this stops future backups but does not automatically delete a prior backup.
- You can revoke SMS permission at any time from your device's system settings.
Changes to this policy
If this policy changes, the "Last updated" date at the top of this page will change accordingly. We encourage you to review it periodically.
Contact
Questions about this policy or your data can be sent to sethigoldy@gmail.com.