1. Who we are
This Privacy Policy describes how FinCHealth (“we”, “us”, “our”) handles personal data when you use the FinCHealth Android app and related services hosted at https://finchealth.com (including optional SMS backup APIs and this website).
Contact for privacy requests: privacy@finchealth.com
2. Scope
This Policy covers:
- the FinCHealth mobile application (package
com.finchealth); - optional account authentication (for example Google Sign-In via Firebase Authentication);
- optional consented SMS backup to our servers;
- optional Gmail mailbox connection for read-only bill and payment emails;
- optional notification access for allowlisted payment apps;
- optional Health Connect reads you approve; and
- this public website (home, privacy, terms).
It does not cover third-party sites or apps you open outside FinCHealth (banks, Google, Play Store, payment apps, etc.). Those have their own policies.
3. Data we process
3.1 On your device (local)
Depending on permissions and features you enable, the app may process:
- Financial SMS content you allow the app to read, to classify transactions locally;
- Allowlisted payment-app notifications (for example Google Pay, PhonePe, Paytm, BHIM UPI) when notification access is granted;
- Gmail message metadata and bodies if you connect Gmail with read-only scope;
- Health Connect data such as Steps and Heart Rate if you grant those permissions;
- Household labels and attributions you create locally (names, optional phone numbers you enter or pick one-at-a-time);
- App preferences and onboarding acknowledgements.
The app does not request full contacts database access. When you map spending to a person, you may type a name or use Android’s one-shot contact picker.
3.2 Account & authentication
If you sign in with Google, we receive identity information from Google / Firebase Authentication such as a unique account identifier, email address, and display name. This identifies your account; it does not by itself upload your SMS timeline.
3.3 Optional SMS backup (cloud)
Only after a separate, revocable SMS-backup consent, the app may upload consented SMS messages (sender, body, timestamps, and related metadata) to our servers at finchealth.com so they can be stored, recovered, and managed for your account. Declining backup keeps those messages local.
3.4 Website & operations
Our servers may process technical logs needed to operate the service (for example request timing, IP address as seen by the server, error diagnostics). We also maintain audit events for backup uploads, consent changes, and deletion actions. Authorized operators may access backup metadata and message content through protected admin tools to support the service and investigate issues.
3.5 Data we do not intentionally collect
- We do not sell personal data.
- We do not use your SMS or Gmail content for third-party advertising.
- We do not require an account for local-only use of core on-device features.
4. How we use data
- to provide and improve FinCHealth features you enable;
- to authenticate you and protect accounts;
- to store and retrieve consented SMS backups;
- to show bills and payment-related emails when Gmail is connected;
- to maintain security, prevent abuse, and comply with law;
- to respond to support and privacy requests.
5. Sharing
We share personal data only as needed to run the product:
- Google / Firebase — authentication and (if you connect it) Gmail API access under Google’s terms and your Google account controls;
- Hosting / infrastructure providers that process data on our behalf to run finchealth.com;
- Legal / safety — if required by applicable law, regulation, or valid legal process;
- Business transfers — if we reorganize, the data may transfer under equivalent protections.
We do not sell personal data to data brokers.
6. Retention & deletion
- On-device data remains until you clear app data or uninstall (subject to Android behaviour).
- SMS backups are retained while your consent is active and the account exists, or until you delete them via the product’s deletion controls / API, or request deletion by email.
- Auth records persist while your account is active.
- Operational logs / audit events may be retained for a limited period for security and accountability.
To request deletion of cloud-held backup data associated with your account, email privacy@finchealth.com from your account email and include enough detail for us to locate the account.
7. Security
We use administrative, technical, and organisational measures appropriate to the sensitivity of the data, including encrypted transport (HTTPS) to our servers, access controls for admin tools, and least-privilege operational practices. No method of transmission or storage is perfectly secure.
8. Your choices & rights
- Deny or revoke Android permissions (SMS, notifications, Health Connect).
- Skip or sign out of Google Sign-In.
- Decline or revoke SMS backup consent; use in-app / API deletion where available.
- Disconnect Gmail in the app and/or revoke access in your Google Account permissions.
- Request access, correction, or deletion of cloud-held personal data by contacting us.
Depending on where you live, you may have additional rights under local law (for example access, erasure, restriction, or complaint to a supervisory authority). Contact us to exercise them.
9. Children
FinCHealth is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal data from children. If you believe a child provided data, contact us and we will take appropriate steps.
10. Changes
We may update this Policy to reflect product or legal changes. We will revise the “Last updated” date above and, when changes are material, provide additional notice in the app or on this site.
11. Contact
Privacy: privacy@finchealth.com
Support: support@finchealth.com
Website: https://finchealth.com
Related: Terms of Service.