There is no warehouse of your finances on our servers to protect, breach, or monetise — because we don’t keep one. TLDR Money holds read-only access to transaction alerts in your mailbox, never your banking credentials, never your SMS, and never your one-time passwords. The point of this page is not to list reassurances; it’s to explain what the design makes impossible, because a limit you can verify is worth more than a promise you can’t.
These aren’t policies we could quietly revise in a changelog. They’re consequences of the access the product holds — the heading above is not a metaphor, because the person who designed this system is an architect by training, and the limits below were decided before anything was built rather than added afterwards.
Transfers, trades and account opening are not operations that exist in a read-only mail scope. There is no switch to flip.
We never hold your net-banking credentials, so there is no path to your accounts even in principle.
No SMS permission is requested, so one-time passwords and personal messages are never in scope.
No central store of your financial history exists on our side, so there is no such store to breach.
That last step is the one worth checking on any app you connect to a financial account: can you revoke access without depending on the vendor? If revocation only works through their interface, you are trusting their interface.
Read-only access to a mailbox is what Google classifies as a restricted scope — its most sensitive tier, above the “sensitive” one. An app cannot simply request it and ship. Google requires the app to pass an independent security assessment first, carried out by a third-party assessor against the Cloud Application Security Assessment framework — CASA — and re-verified periodically rather than once.
The assessment covers how the data is stored and transmitted, how access is controlled, how secrets are managed, how the application handles known vulnerability classes, and whether the scope requested is genuinely the minimum the stated feature needs. It is not a questionnaire; it is an external review with evidence.
An app whose capture layer reads your SMS inbox on Android goes through Google Play’s policy review, which is a different and narrower process. An app that asks you to forward your bank alerts to an email address it controls avoids the API review entirely — there is no scope being granted, because your mail is simply arriving at a third party’s mail server instead. That is a materially different arrangement from scoped, revocable, read-only API access, and it is worth asking any app which of the two it is doing.
The practical consequence for you is narrow but real: choosing to build on the Gmail API rather than on SMS or on mail forwarding means an outside party examines the security of the thing holding your data, on a schedule, and can withdraw the access if it fails. Nothing about that is a substitute for asking the questions on this page. It just means someone else is also asking them.
In India the SMS inbox is the cheapest reliable source of transaction data, and most automatic trackers here are built on it. We aren’t, for two reasons.
The first is scope. Android cannot grant an app access to only your bank’s texts — the permission is the entire inbox, including every one-time password you receive. Google itself treats this as highly sensitive and restricts which apps may request it at all. The full argument is on expense tracking without SMS permission.
The second is that it doesn’t work everywhere. iOS exposes no API for reading messages, so SMS-based tracking cannot function on an iPhone at all — covered on expense trackers for iPhone in India. Building on the mailbox instead means one capture layer that behaves identically on both platforms and needs no sensitive device permission on either.
TLDR Money is built to India’s Digital Personal Data Protection Act, 2023. Sonal Systems Private Limited is the Data Fiduciary; you are the Data Principal. That gives you the right to:
The mechanics of exercising each one are in the privacy policy. Data requests go to [email protected].
No third-party data brokers, no ad networks, no anonymised-and-resold loophole. This is easier for us to hold to than it is for most of the category, for a structural reason rather than a virtuous one: our revenue is a ₹299 subscription, so there is no advertising business or distribution arm whose economics depend on knowing what you spend. An app funded by placing loans or selling funds has a commercial reason to profile you. We don’t have one. See pricing.
Nobody from TLDR Money will ever ask for your net-banking password, card PIN, CVV or an OTP — not by email, not by phone, not in the app. There is no legitimate situation in which we would need any of them. If someone claiming to be us asks, it isn’t us; tell us at [email protected].
No system is perfectly secure, and we won’t claim otherwise. We use encryption in transit and at rest and access controls limiting which systems and people can reach what — but the load-bearing decision is architectural: the less of your financial life we hold, the less there is to go wrong.
No, and not as a matter of policy — as a matter of what the access permits. TLDR Money reads transaction alerts in your mailbox with read-only access. Moving money, placing a trade and opening an account are not operations that exist within a mail scope, so there is no setting we could change to enable them. We also never hold your banking credentials, so there is no route to your accounts even in principle.
We don’t keep a central warehouse of your financial history. Your data stays connected to accounts you already own and control, and we read what is needed to compute your numbers rather than copying your whole financial life into a permanent store on our side. That is a deliberate architectural decision: the most effective protection against a breach of a financial data warehouse is not operating one.
Neither. TLDR Money never requests SMS access, so it never sees your one-time passwords or your personal messages, and it never asks for a net-banking username, password, PIN or OTP. Nobody from TLDR Money will ever ask you for any of those — if someone claiming to be us does, it isn’t us.
Two independent ways. You can disconnect from inside the app, and you can revoke the connection directly from your Google Account permissions page without opening our app at all. The second matters: it means the ability to cut off access does not depend on us doing anything, or on our app working.
TLDR Money is built to India’s Digital Personal Data Protection Act, 2023. You keep the right to access a summary of your data, to have it corrected or completed, to have it erased, to nominate someone to act for you, and to withdraw consent with the same ease you gave it. Sonal Systems Private Limited is the Data Fiduciary and you are the Data Principal. How to exercise each right is set out in the privacy policy.
You can export everything before you go, and deleting your account deletes the personal data associated with it, except where law requires specific records to be retained — invoices and tax records being the usual case. Cancelling also does not require you to trust us with the connection afterwards, because you can revoke the Google authorisation independently.
Read-only access, no warehouse, no SMS, no credentials. Full access for 14 days, no credit card.
Join the waitlistWe are opening seats in batches. No spam, ever.
This page describes the product’s architecture and the access it holds. The binding statements about how your personal data is handled, and your rights over it, are in the privacy policy.