← Back to RupeeTrail

Legal · Effective June 2026

Privacy Policy

Your financial data belongs to you.

Our commitment in plain language

RupeeTrail is built on a simple principle: your financial data belongs to you, lives on your device, and goes nowhere else.

We do not collect, upload, sell, or share your transaction data, spending patterns, or personal information. There is no RupeeTrail server receiving your data. No analytics platform. No advertising network. No cloud sync.

1. What data we store — and where

All data is stored locally on your device. Nothing is transmitted to any server operated by us.

The following data is stored on your device in an encrypted SQLite database:

  • Transactions you record (amount, date, category, merchant, account, note, currency)
  • Categories you create or modify
  • Budgets and budget rollover records
  • Savings goals
  • Recurring transaction templates
  • Account records (name, type, balance)
  • Your profile settings (display name, base currency, preferences)
  • Raw notification text used for transaction capture (see Section 3 on purging)
  • Capture diagnostics (source decisions and pipeline outcomes, for your own debugging use)
  • Backup files you create (encrypted and stored where you choose on your device)

2. Encryption

Your database is encrypted at all times using AES-256 via SQLCipher. The encryption key is managed by the Android Keystore, which is hardware-backed on devices with a secure element.

Backup files are encrypted with AES-256-GCM using a passphrase you provide. We never see or store your passphrase.

3. Notification access and raw text

RupeeTrail reads posted notifications from your bank and payment apps to automatically capture transactions. This requires the BIND_NOTIFICATION_LISTENER_SERVICE permission, which you grant explicitly in Android system settings.

What we read: The text content of financial notifications from apps you choose to enable.

What we don't read: Notifications from apps that are not financial sources, or from sources you have disabled in Capture Sources settings.

Raw text retention: The original notification text is stored temporarily to support transaction review and diagnostics. It is automatically purged after a configurable retention window (default: 30 days). You can reduce this window to as few as 7 days in Settings → Privacy.

We never store notification text from non-financial sources. The pipeline immediately drops notifications that do not come from identifiable financial senders.

4. Network access

RupeeTrail makes no network calls by default.

The only optional network feature is live exchange rates, fetched from api.frankfurter.app — a free, open-source exchange rate service. This feature is:

  • Off by default. It must be explicitly enabled in Settings.
  • Limited in scope. Only a request for currency pairs is sent. No transaction data, no user identifiers, no device identifiers.
  • Controlled by you. Disable it at any time and rates will revert to manual entry.

No other network calls are made by the app under any circumstances.

5. Permissions we use

PermissionWhyRequired?
BIND_NOTIFICATION_LISTENER_SERVICERead financial notifications for automatic captureNo — app works in manual-entry mode without it
POST_NOTIFICATIONSPost budget alerts and review-queue notificationsNo — notifications disabled if not granted
USE_BIOMETRIC / USE_FINGERPRINTApp lock via fingerprint/faceNo — app lock is optional
INTERNETExchange rate fetch (opt-in only)No — no network calls by default
RECEIVE_BOOT_COMPLETEDReschedule WorkManager tasks after device restartYes — needed for background workers

We do not request: READ_SMS, RECEIVE_SMS, READ_CONTACTS, ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, READ_CALL_LOG, or any other sensitive permission.

6. Third-party SDKs and services

RupeeTrail contains no third-party analytics, advertising, or crash-reporting SDKs.

The only third-party libraries used are:

  • SQLDelight + SQLCipher: Open-source database layer. All processing is local.
  • Jetpack Compose, Material 3, Koin, WorkManager, DataStore, Biometric, Glance: Android Jetpack libraries from Google. No data is sent to Google by these libraries in our configuration.
  • Vico: Open-source charting library. Renders locally on-device.
  • Kotlinx (serialization, datetime, coroutines): JetBrains open-source libraries. No data transmission.
  • Frankfurter (exchange rates): Only if you enable live rates. See Section 4.

7. Subscriptions and payment data

RupeeTrail offers an annual subscription processed entirely by Google Play. We do not see, handle, or store your payment information (card details, UPI credentials, bank information) at any point. All payment processing is Google's responsibility under their own privacy policy.

When you subscribe, Google Play confirms the transaction to the app. The app receives a purchase token, the product ID, and your subscription state. This information is used only to verify your active subscription and is stored locally on your device. It is never transmitted anywhere.

Your subscription is linked to the Google account you used to subscribe. It renews automatically each year and can be used on any Android device signed into that account. It cannot be transferred to a different Google account, and you can cancel it at any time in Google Play.

Your data if you cancel: Because RupeeTrail stores all data locally on your device, your existing transactions, budgets, goals, and history remain fully readable even if your subscription lapses. Adding new records or enabling premium features requires an active subscription.

8. Data you export

When you use CSV Export or Encrypted Backup, the resulting file is:

  • Saved to a location you choose on your device (Downloads folder, or shared via the Android share sheet to your choice of destination).
  • Under your sole control. We never receive a copy.
  • Encrypted (in the case of backup files).

9. Children's privacy

RupeeTrail is not directed at children under 13 (or under 16 in the European Economic Area). We do not knowingly collect data from children. If you believe a child has used the app, please delete the app and its data from the device.

10. Your rights

Because your data never leaves your device, the usual mechanisms apply directly:

  • Access: Open the app and browse your data at any time.
  • Correction: Edit any transaction, category, or account record in the app.
  • Deletion: Use Settings → Danger Zone → "Reset all data" to permanently delete everything. Or uninstall the app.
  • Export / portability: Use Settings → Export → CSV or create an encrypted backup.

There is no server-side account to contact us to delete.

11. Data Safety compliance (Google Play)

This app is designed to comply with Google Play's Data Safety requirements:

Data typeCollected?Shared?Encrypted in transit?User can delete?
Financial info (transaction amounts, account info)No — stays on deviceNoN/AYes
Personal info (name)On device onlyNoN/AYes
App activityNoNoN/AN/A
Device identifiersNoNoN/AN/A

No data is collected or shared with third parties. The only network interaction is the optional Frankfurter exchange rate request, which contains no user-identifying information.

12. India DPDP Act compliance

RupeeTrail is designed to comply with the Digital Personal Data Protection Act 2023 (India DPDP Act):

  • Consent: Notification access requires explicit user grant in Android system settings. Exchange rate network access requires explicit opt-in.
  • Purpose limitation: Notification text is used only for transaction capture. It is not used for profiling or any other purpose.
  • Data minimisation: We collect only what is needed for the app to function.
  • Storage limitation: Raw notification text is automatically purged after your chosen retention window.
  • Security: AES-256 encryption at rest; Android Keystore key management.
  • No cross-border transfer: All data stays on your device.

13. Changes to this policy

We will update this policy if the app's data practices change. The effective date at the top of this document reflects the date of the most recent update. Significant changes will be highlighted in the app's release notes.

14. Contact

For privacy questions or concerns:

Email: support@rupeetrail.co.in

© 2026 RupeeTrail. Built on-device · No cloud · No tracking.