Privacy Policy — Paisa Sync
Last updated: 1 August 2026
Published by: ROUNAK KUMAR JHA, an individual developer based in Howrah, West Bengal, India
Contact: rounakjha291202.rar@gmail.com
Paisa Sync ("the app", "we", "us") helps you track your spending by reading the transaction SMS your bank already sends you. This policy explains exactly what the app stores, what leaves your phone, and what does not.
We have tried to write this in plain language. Where a claim is technical, we have described what the app actually does rather than what sounds reassuring.
1. Summary
| Stays on your phone | Every transaction, amount, merchant, bank name, account suffix, balance, budget, goal, and the full text of the bank SMS the app read |
| Leaves your phone | Your Google account identity (name, email, profile photo, user ID) and anonymous usage statistics |
| Never collected | Contacts, location, camera, microphone, photos, calendar, call logs |
| Never sold or shared | We do not sell, rent, or share your data with data brokers, lenders, or any third party for their own purposes |
| Never used for ads | Your transactions, amounts, merchants and SMS are never used to choose or target the ads you see |
2. Data stored on your device
The app keeps a database on your phone containing:
- Transactions — amount, debit/credit, category, merchant or payee name, date, which account it belongs to, and the complete original text of the bank SMS the transaction was read from.
- Accounts — bank name, the masked last-4 digits your bank includes in its messages, account type, your nickname for it, and the last balance the bank stated in an SMS.
- Your plan — monthly income, budgets, recurring commitments, savings goals, and any assets or liabilities you enter manually.
- Your corrections — when you rename or recategorise a merchant, the app remembers it so future messages from that merchant are handled the same way.
- A record of which SMS have already been read, so the same message is not imported twice.
- Your display name and app preferences.
Important — this database is not encrypted. It is protected by Android's normal app sandbox, which prevents other apps from reading it. It is not protected against someone with physical access to an unlocked device, a rooted device, or a device backup extracted to a computer. Your PIN locks the app's screens; it does not encrypt the stored data.
Your PIN and biometrics
Your PIN is stored as a salted SHA-256 hash in the platform's secure storage (Android Keystore). The PIN itself is never stored and cannot be recovered — if you forget it, the only way back in is to reset the app, which erases the local data. Biometric unlock is handled entirely by your device's operating system; the app never receives or stores your fingerprint or face data.
3. Reading your SMS
To detect transactions automatically, the app requests permission to read SMS
(READ_SMS) and to be notified of incoming SMS (RECEIVE_SMS).
- Messages are read and analysed entirely on your device.
- No SMS content is ever transmitted off your device, to us or to anyone else.
- The app looks for money-movement messages from banks. It ignores messages it cannot parse as a transaction, and it ignores promotional messages.
- The app cannot tell in advance which messages are from a bank, so the permission technically allows it to read all SMS in your inbox. It only stores the ones it identifies as transactions.
- SMS access is optional. If you decline, the app still works — you add transactions by hand.
You can revoke SMS permission at any time in Android Settings. The app will stop importing new transactions; anything already imported stays until you delete it.
4. Data that leaves your device
4.1 Google Sign-In and your account record
Signing in with your Google account is required to use the app. We use Google Firebase Authentication for this.
When you sign in, we store the following in Google Firestore, in a record identified by your user ID:
- Your Google user ID
- Your email address
- Your display name
- Your profile photo URL
- The sign-in provider (
google.com) - Your device platform (
androidorios) - The date you first signed in, and the date you last used the app
That is the complete list. No transaction, amount, merchant, bank name, account number, balance, budget, goal, or SMS content is ever written to this record or to any server.
4.2 Usage analytics
We use Google Analytics for Firebase to understand how the app is used — for example, how many people finish setting it up, whether the SMS scan succeeds, and which screens are opened.
Events record counts, durations, yes/no flags, and fixed labels. Examples of what is sent: "a scan completed, importing 12 transactions in 4,300 milliseconds", "a budget was set for the category 'food'", "the app was unlocked with biometrics".
The app contains a technical safeguard that blocks financial and personal values from being included in analytics. Amounts, merchant names, account numbers, SMS text, email addresses and names are rejected before an event is sent. This is enforced in code and covered by automated tests.
Analytics is tied to your Google user ID so we can count people rather than installs. Analytics data is not used to target advertising.
4.3 Advertising
The app may show advertisements, supplied by Google AdMob.
Ads are never chosen using your financial data. Your transactions, amounts, merchants, bank names, account numbers, balances and the text of your bank SMS are never sent to any advertising network, and are never used to decide which ad you see. This is a technical boundary in the app, not only a promise: ad requests are built without any access to your transaction data.
What the advertising SDK does receive is the standard information Google collects to serve and measure ads — your device's advertising ID, approximate location derived from your IP address, device type and app version. Google may use its own profile of you to personalise ads. That profile is Google's, built from your wider Google and Play activity, and owes nothing to anything Paisa Sync has read.
You can limit this from your device: Android Settings › Privacy › Ads, where you can delete or reset your advertising ID and opt out of personalised ads. Google's advertising controls are at https://myadcenter.google.com and https://policies.google.com/technologies/ads
Where ads appear is deliberately limited. They are never shown on the dashboard, on any planning screen, during onboarding, or on the lock screen, and the app does not use full-screen or app-open ads.
4.4 Who processes this data
| Service | Provider | What it receives |
|---|---|---|
| Firebase Authentication | Your Google identity | |
| Cloud Firestore | The account record in 4.1 | |
| Google Analytics for Firebase | The usage events in 4.2 | |
| Google AdMob | Advertising ID and the ad-serving data in 4.3 |
Google may process and store this data on servers outside India, in accordance with Google's own privacy policy: https://policies.google.com/privacy
We use no other third-party service. There are no crash-reporting SDKs from other vendors and no social media SDKs.
5. What we never collect
We do not request or access:
- Your contacts
- Your location
- Your camera, microphone, or photos
- Your call logs
- Your calendar
- Your bank login credentials — the app never asks for your net-banking or UPI PIN, password, or OTP, and never connects to your bank
6. Deleting your data
Financial data — anytime, by you
Go to Profile → Erase all data. This permanently deletes every transaction, account, budget, goal, holding, saved correction, and your PIN from your device. It cannot be undone. You will be asked for your PIN to confirm.
Uninstalling the app also removes the local database.
Account details — by email request
To delete the account record described in section 4.1, email rounakjha291202.rar@gmail.com from the email address associated with your account. We will delete it within 30 days and confirm when it is done.
You may also delete your analytics history by contacting us at the same address.
7. Your rights
Under India's Digital Personal Data Protection Act, 2023, you have the right to:
- Access — ask what personal data we hold about you
- Correction — ask us to correct inaccurate data
- Erasure — ask us to delete your data (see section 6)
- Grievance redressal — raise a complaint about how we handle your data
- Nominate — nominate another person to exercise your rights if you are incapacitated or die
To exercise any of these, email rounakjha291202.rar@gmail.com.
Grievance Officer: ROUNAK KUMAR JHA, rounakjha291202.rar@gmail.com
We will acknowledge grievances within 7 days and resolve them within 30 days.
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
8. Data retention
- On your device: kept until you delete it or uninstall the app.
- Account record: kept while your account exists, and deleted within 30 days of a deletion request.
- Analytics: retained according to Google Analytics for Firebase default retention, currently 14 months from your last activity.
9. Children
The app is not intended for anyone under 13. We do not knowingly collect data from children under 13.
Under India's DPDP Act, anyone under 18 is treated as a child, and processing their personal data requires verifiable consent from a parent or guardian. If you are under 18, please use this app only with your parent or guardian's consent and supervision.
If you believe a child has provided us data without such consent, email rounakjha291202.rar@gmail.com and we will delete it.
10. Security
We protect your data by:
- Keeping all financial data on your device rather than on a server
- Storing your PIN only as a salted hash, never as the PIN itself
- Locking the app after 2 minutes in the background
- Limiting PIN attempts, with an increasing delay after 5 wrong tries
- Blocking financial values from analytics in code
Honest limitations: the local database is not encrypted at rest; data sent to Google is subject to Google's security and policies; and no method of electronic storage is completely secure. If we become aware of a breach affecting your personal data, we will notify you and the Data Protection Board of India as required by law.
11. Changes to this policy
If we change this policy we will update the date at the top and show a notice in the app. Material changes — for example, if we ever began sending financial data off your device — will require your renewed consent before taking effect.
12. Contact
ROUNAK KUMAR JHA Howrah, West Bengal, India Email: rounakjha291202.rar@gmail.com