Legal · Effective June 2026
Your financial data belongs to you.
RupeeTrail is built on a simple principle: your financial data belongs to you, lives on your device, and goes nowhere else.
We do not collect, upload, sell, or share your transaction data, spending patterns, or personal information. There is no RupeeTrail server receiving your data. No analytics platform. No advertising network. No cloud sync.
All data is stored locally on your device. Nothing is transmitted to any server operated by us.
The following data is stored on your device in an encrypted SQLite database:
Your database is encrypted at all times using AES-256 via SQLCipher. The encryption key is managed by the Android Keystore, which is hardware-backed on devices with a secure element.
Backup files are encrypted with AES-256-GCM using a passphrase you provide. We never see or store your passphrase.
RupeeTrail reads posted notifications from your bank and payment apps to automatically capture transactions. This requires the BIND_NOTIFICATION_LISTENER_SERVICE permission, which you grant explicitly in Android system settings.
What we read: The text content of financial notifications from apps you choose to enable.
What we don't read: Notifications from apps that are not financial sources, or from sources you have disabled in Capture Sources settings.
Raw text retention: The original notification text is stored temporarily to support transaction review and diagnostics. It is automatically purged after a configurable retention window (default: 30 days). You can reduce this window to as few as 7 days in Settings → Privacy.
We never store notification text from non-financial sources. The pipeline immediately drops notifications that do not come from identifiable financial senders.
RupeeTrail makes no network calls by default.
The only optional network feature is live exchange rates, fetched from api.frankfurter.app — a free, open-source exchange rate service. This feature is:
No other network calls are made by the app under any circumstances.
| Permission | Why | Required? |
|---|---|---|
| BIND_NOTIFICATION_LISTENER_SERVICE | Read financial notifications for automatic capture | No — app works in manual-entry mode without it |
| POST_NOTIFICATIONS | Post budget alerts and review-queue notifications | No — notifications disabled if not granted |
| USE_BIOMETRIC / USE_FINGERPRINT | App lock via fingerprint/face | No — app lock is optional |
| INTERNET | Exchange rate fetch (opt-in only) | No — no network calls by default |
| RECEIVE_BOOT_COMPLETED | Reschedule WorkManager tasks after device restart | Yes — needed for background workers |
We do not request: READ_SMS, RECEIVE_SMS, READ_CONTACTS, ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, READ_CALL_LOG, or any other sensitive permission.
RupeeTrail contains no third-party analytics, advertising, or crash-reporting SDKs.
The only third-party libraries used are:
RupeeTrail offers an annual subscription processed entirely by Google Play. We do not see, handle, or store your payment information (card details, UPI credentials, bank information) at any point. All payment processing is Google's responsibility under their own privacy policy.
When you subscribe, Google Play confirms the transaction to the app. The app receives a purchase token, the product ID, and your subscription state. This information is used only to verify your active subscription and is stored locally on your device. It is never transmitted anywhere.
Your subscription is linked to the Google account you used to subscribe. It renews automatically each year and can be used on any Android device signed into that account. It cannot be transferred to a different Google account, and you can cancel it at any time in Google Play.
Your data if you cancel: Because RupeeTrail stores all data locally on your device, your existing transactions, budgets, goals, and history remain fully readable even if your subscription lapses. Adding new records or enabling premium features requires an active subscription.
When you use CSV Export or Encrypted Backup, the resulting file is:
RupeeTrail is not directed at children under 13 (or under 16 in the European Economic Area). We do not knowingly collect data from children. If you believe a child has used the app, please delete the app and its data from the device.
Because your data never leaves your device, the usual mechanisms apply directly:
There is no server-side account to contact us to delete.
This app is designed to comply with Google Play's Data Safety requirements:
| Data type | Collected? | Shared? | Encrypted in transit? | User can delete? |
|---|---|---|---|---|
| Financial info (transaction amounts, account info) | No — stays on device | No | N/A | Yes |
| Personal info (name) | On device only | No | N/A | Yes |
| App activity | No | No | N/A | N/A |
| Device identifiers | No | No | N/A | N/A |
No data is collected or shared with third parties. The only network interaction is the optional Frankfurter exchange rate request, which contains no user-identifying information.
RupeeTrail is designed to comply with the Digital Personal Data Protection Act 2023 (India DPDP Act):
We will update this policy if the app's data practices change. The effective date at the top of this document reflects the date of the most recent update. Significant changes will be highlighted in the app's release notes.
For privacy questions or concerns:
Email: support@rupeetrail.co.in