Legal

Privacy Policy

This policy explains what SpendLens (“we”, “the app”) collects, why, and your choices. It describes only what the app actually does. SpendLens is a personal finance tool — it is not a bank and never asks for your banking password, UPI PIN, card PIN, CVV or OTP.

1. Who we are

SpendLens is published by SpendLens (India). Contact: support@spendlens.online.

2. Data we collect

Account & profile

  • Google Sign-In: when you sign in with Google, we receive a verified token from which the backend derives your Google account identifier, name and email address to create and secure your SpendLens account.
  • Profile: your name, email, optional phone number, default currency and timezone.

Financial data you add or connect

  • Bank account metadata: the bank name, account type, a masked account number (last digits only), currency and the balance you record. We never collect full account/card numbers or any banking credential.
  • Transactions: amount, currency, direction (debit/credit), date/time, merchant/description, category, and the source of each entry (manual, imported, or SMS).

SMS-derived transactions (Android only, optional, off by default)

  • If — and only if — you explicitly enable “Automatic transactions” and grant the Android SMS permission, the app reads incoming messages from recognised bank/UPI senders on your device.
  • Parsing happens on your device. Only normalized fields (amount, direction, currency, date, bank identifier, masked account suffix, merchant, reference, payment method) are sent to our backend. The raw SMS text is never uploaded. Messages from non-financial senders are ignored on the device.
  • Detected transactions are held for your review; you confirm, edit or ignore them.
  • You can turn this off at any time in the app.

On-device data

  • Secure session: your authentication tokens are stored in the device's secure storage (Android Keystore / iOS Keychain), not in plain storage.
  • App-lock settings and balance-visibility preference are stored on the device.
  • Offline queue: detected transactions awaiting upload are stored locally in encrypted storage and hold only normalized fields — never raw SMS.

3. How we use your data

  • To provide the service: show your accounts, transactions, budgets, goals and spending insights.
  • To authenticate you and keep your account secure.
  • To process transactions you add, import or approve from detected SMS.

We do not use your financial data for advertising, and we do not sell your data.

4. App Lock & biometrics

If you enable App Lock, authentication is performed by your device's biometric or passcode system. SpendLens never receives, sees or stores your fingerprint, face data or passcode — it only receives a success/failure result from the operating system.

5. Sharing

We share data only with providers that operate the service on our behalf:

  • Google Sign-In — to verify your identity when you choose to sign in with Google.
  • Hosting — our backend and database are hosted on our infrastructure provider to store your account and transaction data.

We do not sell or rent personal data, and we do not share it with advertisers or data brokers.

6. Storage & security

Data in transit is protected with HTTPS/TLS. Session tokens are held in platform secure storage on your device. Balances are hidden by default in the app. We take reasonable measures to protect your data; no method of transmission or storage is completely secure, and we do not claim “bank-grade” security or any regulatory/compliance certification.

7. Retention

We keep your account and financial data while your account is active. When you delete your account, we delete or anonymise your personal and financial data, except where we must retain limited records to comply with law or resolve disputes.

8. Your rights & choices

  • Access & correction: view and edit your profile and transactions in the app.
  • SMS detection: enable or disable it at any time; revoke the permission in Android settings.
  • Deletion: request account deletion at spendlens.online/delete-account.

9. Children

SpendLens is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data.

10. Changes

We may update this policy; we will revise the “Last updated” date above and, where appropriate, notify you in the app.

11. Contact

Questions about privacy: support@spendlens.online.