Security & architecture

The architecture is the privacy policy

There is no warehouse of your finances on our servers to protect, breach, or monetise — because we don’t keep one. TLDR Money holds read-only access to transaction alerts in your mailbox, never your banking credentials, never your SMS, and never your one-time passwords. The point of this page is not to list reassurances; it’s to explain what the design makes impossible, because a limit you can verify is worth more than a promise you can’t.

What TLDR Money cannot do

These aren’t policies we could quietly revise in a changelog. They’re consequences of the access the product holds — the heading above is not a metaphor, because the person who designed this system is an architect by training, and the limits below were decided before anything was built rather than added afterwards.

Cannot move money

Transfers, trades and account opening are not operations that exist in a read-only mail scope. There is no switch to flip.

Cannot reach your bank

We never hold your net-banking credentials, so there is no path to your accounts even in principle.

Cannot see your OTPs

No SMS permission is requested, so one-time passwords and personal messages are never in scope.

Cannot lose what it doesn’t hold

No central store of your financial history exists on our side, so there is no such store to breach.

How the data actually flows

  1. You authorise read-only access to your mailbox. Through Google’s own consent screen, at the narrowest scope the product can work with. You see exactly what is being requested before you agree.
  2. Google tells us when a transaction alert arrives. We do not poll your mailbox or trawl it on a schedule. The Gmail API notifies us when a matching message lands, and that message is what gets read — amount, merchant, date. Nothing else in the mailbox is fetched.
  3. It is categorised immediately, not in a nightly batch. The transaction appears in your spending as it happens, rather than the next morning.
  4. Your numbers are computed. Spending by category, a net worth roll-up including the asset values you enter yourself, and a FIRE projection.
  5. Your financial history stays where it is. Connected to accounts you own, rather than copied into a permanent warehouse on our servers.
  6. You can cut it off at any time. From inside the app, or from your Google Account permissions page without touching our app at all.

That last step is the one worth checking on any app you connect to a financial account: can you revoke access without depending on the vendor? If revocation only works through their interface, you are trusting their interface.

Who checks that any of this is true

Read-only access to a mailbox is what Google classifies as a restricted scope — its most sensitive tier, above the “sensitive” one. An app cannot simply request it and ship. Google requires the app to pass an independent security assessment first, carried out by a third-party assessor against the Cloud Application Security Assessment framework — CASA — and re-verified periodically rather than once.

The assessment covers how the data is stored and transmitted, how access is controlled, how secrets are managed, how the application handles known vulnerability classes, and whether the scope requested is genuinely the minimum the stated feature needs. It is not a questionnaire; it is an external review with evidence.

Why this is worth knowing when comparing apps

An app whose capture layer reads your SMS inbox on Android goes through Google Play’s policy review, which is a different and narrower process. An app that asks you to forward your bank alerts to an email address it controls avoids the API review entirely — there is no scope being granted, because your mail is simply arriving at a third party’s mail server instead. That is a materially different arrangement from scoped, revocable, read-only API access, and it is worth asking any app which of the two it is doing.

The practical consequence for you is narrow but real: choosing to build on the Gmail API rather than on SMS or on mail forwarding means an outside party examines the security of the thing holding your data, on a schedule, and can withdraw the access if it fails. Nothing about that is a substitute for asking the questions on this page. It just means someone else is also asking them.

Why we don’t read your SMS

In India the SMS inbox is the cheapest reliable source of transaction data, and most automatic trackers here are built on it. We aren’t, for two reasons.

The first is scope. Android cannot grant an app access to only your bank’s texts — the permission is the entire inbox, including every one-time password you receive. Google itself treats this as highly sensitive and restricts which apps may request it at all. The full argument is on expense tracking without SMS permission.

The second is that it doesn’t work everywhere. iOS exposes no API for reading messages, so SMS-based tracking cannot function on an iPhone at all — covered on expense trackers for iPhone in India. Building on the mailbox instead means one capture layer that behaves identically on both platforms and needs no sensitive device permission on either.

Your rights under the DPDP Act

TLDR Money is built to India’s Digital Personal Data Protection Act, 2023. Sonal Systems Private Limited is the Data Fiduciary; you are the Data Principal. That gives you the right to:

The mechanics of exercising each one are in the privacy policy. Data requests go to [email protected].

Never sold, never shared

No third-party data brokers, no ad networks, no anonymised-and-resold loophole. This is easier for us to hold to than it is for most of the category, for a structural reason rather than a virtuous one: our revenue is a ₹299 subscription, so there is no advertising business or distribution arm whose economics depend on knowing what you spend. An app funded by placing loans or selling funds has a commercial reason to profile you. We don’t have one. See pricing.

What we will never ask you for

Nobody from TLDR Money will ever ask for your net-banking password, card PIN, CVV or an OTP — not by email, not by phone, not in the app. There is no legitimate situation in which we would need any of them. If someone claiming to be us asks, it isn’t us; tell us at [email protected].

No system is perfectly secure, and we won’t claim otherwise. We use encryption in transit and at rest and access controls limiting which systems and people can reach what — but the load-bearing decision is architectural: the less of your financial life we hold, the less there is to go wrong.

Questions worth asking

Can TLDR Money move money out of my account?

No, and not as a matter of policy — as a matter of what the access permits. TLDR Money reads transaction alerts in your mailbox with read-only access. Moving money, placing a trade and opening an account are not operations that exist within a mail scope, so there is no setting we could change to enable them. We also never hold your banking credentials, so there is no route to your accounts even in principle.

Does TLDR Money store my financial data on its servers?

We don’t keep a central warehouse of your financial history. Your data stays connected to accounts you already own and control, and we read what is needed to compute your numbers rather than copying your whole financial life into a permanent store on our side. That is a deliberate architectural decision: the most effective protection against a breach of a financial data warehouse is not operating one.

Do you need my SMS permission or my bank password?

Neither. TLDR Money never requests SMS access, so it never sees your one-time passwords or your personal messages, and it never asks for a net-banking username, password, PIN or OTP. Nobody from TLDR Money will ever ask you for any of those — if someone claiming to be us does, it isn’t us.

How do I revoke access?

Two independent ways. You can disconnect from inside the app, and you can revoke the connection directly from your Google Account permissions page without opening our app at all. The second matters: it means the ability to cut off access does not depend on us doing anything, or on our app working.

Is TLDR Money DPDP compliant?

TLDR Money is built to India’s Digital Personal Data Protection Act, 2023. You keep the right to access a summary of your data, to have it corrected or completed, to have it erased, to nominate someone to act for you, and to withdraw consent with the same ease you gave it. Sonal Systems Private Limited is the Data Fiduciary and you are the Data Principal. How to exercise each right is set out in the privacy policy.

What happens to my data if I cancel?

You can export everything before you go, and deleting your account deletes the personal data associated with it, except where law requires specific records to be retained — invoices and tax records being the usual case. Cancelling also does not require you to trust us with the connection afterwards, because you can revoke the Google authorisation independently.

Your money data never leaves your side of the fence

Read-only access, no warehouse, no SMS, no credentials. Full access for 14 days, no credit card.

Join the waitlist

We are opening seats in batches. No spam, ever.

This page describes the product’s architecture and the access it holds. The binding statements about how your personal data is handled, and your rights over it, are in the privacy policy.