Privacy Policy
1. Information Collection & Usage
BudgetTribe requests only permissions required to provide automated, zero-effort expense tracking:
- On-Device Financial SMS Messages: With explicit Android runtime permission, our offline regex engine scans financial notifications locally to calculate your Safe-to-Spend pace. SMS body contents are never sent off your phone.
- Google Account & Gmail Data (Optional / User-Initiated): With explicit OAuth user authorization, BudgetTribe accesses the
https://www.googleapis.com/auth/gmail.readonlyscope solely to scan and detect automated bank transaction alerts and electronic receipts. All parsing is performed locally/directly on your device to import expenses into your Money Tracker. - User-Configured Budgets & Goals: Stored in AES-256 encrypted local storage.
- Technical Crash Logs: Anonymous crash traces collected via Firebase Crashlytics to optimize stability. No financial details or identifiable tokens are transmitted.
2. Google API Services User Data & Limited Use Policy
BudgetTribe's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- No Advertising Use: We never use or transfer Google user data (including Gmail message data) for serving advertisements, including personalized, retargeted, or interest-based advertising.
- No Sale or Third-Party Transfer: We never sell Google user data to data brokers or third parties. Data is only utilized to provide and improve user-facing financial tracking features within BudgetTribe.
- No Human Reading of Email Content: We do not allow humans to read user email data unless we have obtained your affirmative agreement for specific messages, doing so is necessary for security purposes (such as investigating a bug or abuse), to comply with applicable law, or for internal operations where the data is aggregated and de-identified.
- Local-First Processing: All financial email parsing is restricted to bank transaction alerts and executed with end-to-end user privacy in mind.
3. Bank-Grade Local Storage Encryption
All sensitive SQLite/Hive database records are protected by 256-bit AES encryption with hardware-backed encryption keys generated inside the Android Keystore / iOS Keychain.
4. User Data Rights & Instant Deletion
You maintain complete control. You can revoke Gmail access at any time through the in-app Gmail Sync screen or via your Google Account Security Settings. You can also wipe all local logs, ledgers, and database entries at any time directly through Settings → Wipe All Data or by uninstalling the application.
5. Contact & Support
For any inquiries regarding data protection, Google API compliance, and security practices:
Developer: Vipin Nair
Email: support@budgettribe.in