PRIVACY POLICY FOR FINDRR

Last Updated: October 07, 2026

This Privacy Policy ("Policy") governs the collection, processing, storage, and disclosure of information by Findrr ("Application", "Service", "We", "Us", or "Our"), developed by Subhajit Das, accessible via the Google Play Store and associated digital interfaces.

By installing, accessing, or utilizing the Application, you ("User", "You", or "Your") acknowledge that you have read, understood, and agreed to be legally bound by the terms set forth herein. If you do not agree to this Policy, you must immediately uninstall the Application and cease all usage.

1. CORE PRIVACY PRINCIPLE: 100% LOCAL & ON-DEVICE FINANCIAL PARSING

Findrr is engineered from the ground up on a strict "Privacy-by-Design" and "Local-First" architecture.

A. LOCAL BANK SMS & NOTIFICATION PARSING:

The Application reads incoming financial SMS and system notification payloads (including, but not limited to, HDFC, SBI, ICICI, Axis Bank, Google Pay, PhonePe, Paytm, and CRED alerts) solely to extract transaction amounts, categories, and merchant titles. THIS PARSING PROCESS OCCURS 100% LOCALLY ON YOUR PHYSICAL DEVICE USING ON-DEVICE REGEX ENGINES.

B. NO SELLING OR MONETIZATION OF PERSONAL DATA:

At no point is your raw SMS text, transaction content, contact list, or bank balance uploaded to external ad-targeting networks, third-party data brokers, or credit card marketers. WE DO NOT SELL, RENT, LEASE, OR MONETIZE YOUR FINANCIAL DATA.

2. INFORMATION WE COLLECT & PROCESS

While Findrr prioritizes local processing, limited data categories are handled as described below:

A. Account Registration Metadata:

When you create an account to enable cloud backup or participate in Findrr Arena, we collect basic profile metadata including your name, email address, state, district, date of birth, mobile number (optional), and avatar selection.

B. Optional Zero-Knowledge Cloud Backups:

If you choose to sync your financial vaults across devices, your transaction and budget records are encrypted on-device using AES-256 GCM encryption derived via PBKDF2 HMAC-SHA256 from your master key and password prior to transmission. The server stores only ciphertext payloads.

C. Payment & Order Processing Data:

When purchasing Findrr Pro subscriptions, payment transactions are processed securely via Razorpay (or authorized payment gateways). We store order metadata (e.g., Order ID, Plan Duration, Payment Reference ID, and Subscription Expiration Timestamp) in our database. We do NOT collect or store raw credit card numbers, CVVs, or UPI PINs.

3. ANDROID SYSTEM PERMISSIONS & PURPOSE

To deliver its specialized automated budgeting and mindful guard features, the Application requests the following explicit Android permissions:

A. BIND_NOTIFICATION_LISTENER_SERVICE:

Required exclusively to detect incoming financial SMS / bank notifications in the background and translate them into structured expense entries.

B. BIND_ACCESSIBILITY_SERVICE (Mindful Spending Guard):

Required to detect when UPI / food delivery payment applications (such as Swiggy, Zomato, PhonePe, Google Pay) are launched, enabling the Application to trigger the 5-minute reflection guard to prevent impulse spending. This service does NOT record, capture, or store passwords, keystrokes, or private messages.

C. POST_NOTIFICATIONS & SCHEDULE_EXACT_ALARM:

Required to send evening cash check-in reminders, delayed payment check alerts, and subscription status notifications.

D. ACCESS_FINE_LOCATION (Optional):

Used strictly for local merchant/shop category suggestions if enabled. Location coordinates are processed on-device and never tracked continuously.

4. DATA SECURITY & ENCRYPTION STANDARDS

We implement industry-leading administrative, technical, and physical security safeguards to protect your information:
- App Security Lock PINs are hashed locally using SHA-256 cryptography.
- Cloud payloads utilize AES-256 GCM zero-knowledge encryption.
- Network communications utilize TLS 1.3 encrypted HTTPS channels.

5. DATA RETENTION & USER DELETION RIGHTS

In compliance with the Digital Personal Data Protection Act (DPDP Act 2023) and Google Play Policies, you maintain full control over your data:

A. In-App Immediate Wiping:

You may permanently delete your account, cloud profiles, Arena rooms, and encrypted backups at any time by navigating to:
`Profile - Account & Security Center - Delete Account (Danger Zone)`.

B. Manual Request:

Alternatively, you may email a formal deletion request to findrrsupport@gmail.com with your Support Reference ID (found in the Helpdesk section). All associated cloud records will be permanently purged within 7 business days.

6. THIRD-PARTY SERVICES & INTEGRATIONS

The Application integrates with select trusted infrastructure providers:
- Supabase (Encrypted PostgreSQL database and authentication)
- Razorpay (Authorized Payment Gateway)

Each third-party service operates under its respective privacy policies and security compliances.

7. CHILDREN'S PRIVACY

The Application is intended strictly for users aged 18 and older. We do not knowingly collect or solicit personal data from minors under the age of 18.

8. UPDATES TO THIS PRIVACY POLICY

We reserve the right to modify this Policy periodically to reflect technological, legal, or operational updates. Material changes will be communicated via in-app notices or updated version dates.

9. CONTACT & GRIEVANCE OFFICER

For any privacy inquiries, data deletion requests, or technical grievances, please contact our official support desk:

Official Support Email: findrrsupport@gmail.com

Developer: Subhajit Das

Application: Findrr