1. Who we are
AutoBudget is built and maintained by an individual developer based in India. Contact: ramasubramaniyan.velu@gmail.com. We are not a regulated entity — AutoBudget does NOT move money, provide investment advice, lend, or hold deposits. It is a personal-tracking tool only.
2. What data we collect
None. In v1.0.42 (June 2026) we removed Google Sign-In and the Firebase Auth account system that came with it. As of that release, AutoBudget collects zero personal data from you over the network.
| Data | Where it lives |
|---|---|
| Transactions, budgets, categories, settings, learned merchant→category mappings, display name | Your device only. Encrypted via @aparajita/capacitor-secure-storage backed by Android's Keystore. |
| Bank-statement PDFs / Excel / CSV you import | Your device only. Parsed in-memory and discarded. The PDF password (if any) is held in RAM for the parse and never written to disk. |
We do not collect: name, email, phone number, location, contacts, SMS, call logs, photos, advertising IDs, device IDs, crash reports, analytics, or any other category of user data. We do not operate any backend server that holds your data.
3. What data we don't share
We have nothing to share. AutoBudget makes zero network calls during normal use other than fetching its own static web assets at app launch. There is no analytics SDK, no crash-reporting SDK, no advertising SDK, no auth server, and no third-party endpoint AutoBudget transmits user data to.
When you export a report (Excel), the file is generated locally on the device and you choose where it goes. Before generation, we run our PII-redaction helper that strips VPAs, IFSC codes, account numbers, PAN, Aadhaar last-4, cheque numbers, and UTR references from every transaction narration so accidentally sharing the file doesn't leak identifiers.
4. India DPDP Act 2023 — your rights
The Digital Personal Data Protection Act 2023 grants you specific rights over personal data processed about you. Because AutoBudget processes no personal data — we don't even ask for your name or email — there is in practice nothing on our side for you to access, correct, or have erased. Your DPDP rights with respect to AutoBudget reduce to:
- Right to erasure — clear AutoBudget's on-device storage by going to More → Reset all data (3-tap confirm: read → type RESET → final tap), or by uninstalling the app. Both wipe everything instantly.
- Right to withdraw consent (DPDP §6(3)) — the on-device consent gate (re-enabled in v1.0.43) records your consent against the current policy version. You can withdraw at any time from More → Privacy & Your Rights → Withdraw consent. Withdrawing does NOT delete your data — use Reset all data for that.
- Right to grievance redressal — our named Grievance Officer under DPDP §13 is Ramasubramaniyan Velu. If you have a question or concern, email ramasubramaniyan.velu@gmail.com with the subject "AutoBudget — DPDP request". We acknowledge within 7 days and respond within 30 days, per DPDP §13(3).
- Right to nominate (DPDP §13) — you may nominate another individual to act on your behalf in case of incapacity. Email the grievance officer above and we will record the nomination.
5. Permissions AutoBudget requests
| Permission | Purpose |
|---|---|
| Internet | Required by Android for the app's WebView to load its own bundled HTML / JS / CSS assets at launch. No user data is transmitted — only the app's own static files are fetched from the app bundle. |
| Biometric (USE_BIOMETRIC) | Optional app-lock (fingerprint / Face Unlock) to keep the app locked when not in use. |
| Storage / file access (SAF on modern Android) | Reading bank-statement files you explicitly pick from the file picker. Files are parsed in-memory and discarded. |
We do not request: contacts, SMS, call logs, location, microphone, camera, background data, or any other permission.
6. Children
AutoBudget is for adults managing personal finances. Because the app collects no personal data of any kind, it does not knowingly collect data from anyone, children included.
7. Data retention
All on-device data is kept until you delete it in-app (More → Reset all data), clear the app's storage via Android Settings, or uninstall the app. We retain nothing on our side because we receive nothing on our side.
8. Third-party services we use
None at runtime. AutoBudget bundles open-source libraries (React, pdfjs-dist, ExcelJS, SheetJS, Capacitor plugins for biometric auth and secure storage) into the app binary. These run locally inside the app's WebView and do not transmit user data anywhere. Specifically, AutoBudget does NOT use:
- Google Analytics or Firebase Analytics
- Crashlytics or any other crash-reporting SDK
- Google AdMob or any advertising SDK
- Any AI / LLM service (OpenAI, Anthropic, Gemini, etc.)
- Any payment gateway
- Any SMS / contacts reader
- Any Account Aggregator
- Firebase Auth or any other authentication service (removed in v1.0.42)
9. Changes to this policy
If we add features that change what data we touch, we'll update this page and bump the "Last updated" date and version (currently v4) at the top. Material changes will be surfaced in-app via the consent gate — existing users see a fresh consent prompt against the new policy on next launch. Cosmetic edits don't trigger a re-prompt.
v3 → v4 (31 May 2026): Privacy Policy rewritten to reflect the v1.0.42 removal of Google Sign-In / Firebase Authentication. The app now collects no account or identifier of any kind and makes no outbound network calls beyond loading its own static assets. Existing users will see the consent gate again on next launch and re-affirm against this updated policy.
4 July 2026 (still v4): Named our Grievance Officer (Ramasubramaniyan Velu) per DPDP §13, which previously listed only a contact email. Also, as of app v1.0.94, the last remaining runtime network request (fonts loaded from Google's CDN) was removed in favour of fonts bundled into the app itself — Section 3's "zero network calls" claim is now exactly true at the code level, not just in intent. Neither change affects what data is collected or how it's handled, so this does not re-trigger the in-app consent prompt.
10. Contact
For privacy / DPDP / security questions: ramasubramaniyan.velu@gmail.com. For grievance redressal under DPDP, use the subject line "AutoBudget — DPDP request" and we'll respond within 30 days.
Grievance Officer (DPDP §13): Ramasubramaniyan Velu — ramasubramaniyan.velu@gmail.com