Security & architecture

The architecture is the privacy policy

This page describes the automatic version, which is in development. In it, your mailbox is read on your phone, not on our servers. It is parsed, stripped and redacted there — and what crosses the wire is a short snippet with the identifying details already removed. No raw email ever reaches us. What we do keep is the result: amount, merchant, date, category, stored in India and deletable by you. This page explains what the design makes impossible, and is exact about what it does not.

What TLDR Money cannot do

These aren’t policies we could quietly revise in a changelog. They’re consequences of the access the product holds, and they were settled before anything was built — by a founder who is an architect by training.

Cannot move money

Transfers, trades and account opening are not operations that exist in a read-only mail scope. There is no switch to flip.

Cannot reach your bank

We never hold your net-banking credentials, so there is no path to your accounts even in principle.

Cannot see your OTPs

No SMS permission is requested, so one-time passwords and personal messages are never in scope.

Cannot store your email

Your mail is parsed on your own device and never uploaded. There is no copy of your mailbox on our side to breach.

How the data actually flows

  1. You authorise read-only access to your mailbox. Through Google’s own consent screen, at the narrowest scope the product can work with. You see exactly what is being requested before you agree.
  2. Your device reads the mailbox and strips it down. Finding the transaction alerts, discarding everything else, removing headers, signatures and boilerplate, and redacting identifying details all happen on your phone, and no raw email is ever sent to our servers.
  3. Only a short redacted snippet leaves. Over a TLS 1.3 encrypted channel — enough characters to recognise a transaction, and nothing more. The mail itself stays in your mailbox and on your device.
  4. A model in Mumbai turns the snippet into a record. Amount, merchant, date, category. It has its own section below.
  5. The record is stored in India, and your numbers are computed. It is written to our database in the Mumbai region, encrypted at rest, and your spending by category, net worth roll-up and FIRE projection are calculated from it. That record is the only copy we keep.
  6. You can cut it off at any time. From inside the app, or from your Google Account permissions page without touching our app at all.

That last step is the one worth checking on any app you connect to a financial account: can you revoke access without depending on the vendor? If revocation only works through their interface, you are trusting their interface.

What the model sees

Turning “UPI/P2M/523847182/SWIGGY” into “Swiggy, food delivery, ₹487” is a language problem, and we use a language model to solve it. Most apps in this category do too and don’t mention it. Here is exactly what that involves, because “we use AI” is not a disclosure.

The model runs on Amazon Bedrock in the Mumbai region — ap-south-1. The models are OpenAI’s open-weight gpt-oss-20b and gpt-oss-120b, which AWS deploys and runs itself. Three consequences follow, and each is checkable against Amazon’s own published documentation rather than against our word:

And because the weights are open and AWS runs them, there is no third-party model provider on the other end receiving your data. Nothing is used to train any model — not ours, not anyone else’s.

The model receives a redacted snippet, after your device has already stripped the headers, the signature, the boilerplate and the identifying details. It does not receive your mailbox, your email address, your account numbers, or the message the alert arrived in.

Who checks that any of this is true

Read-only access to a mailbox is what Google classifies as a restricted scope — its most sensitive tier, above the “sensitive” one. An app cannot simply request it and ship. Google requires the app to pass an independent security assessment first, carried out by a third-party assessor against the Cloud Application Security Assessment framework — CASA — and re-verified periodically rather than once.

The assessment covers how the data is stored and transmitted, how access is controlled, how secrets are managed, how the application handles known vulnerability classes, and whether the scope requested is genuinely the minimum the stated feature needs. It is not a questionnaire; it is an external review with evidence.

Why this is worth knowing when comparing apps

An app whose capture layer reads your SMS inbox on Android goes through Google Play’s policy review, which is a different and narrower process. An app that asks you to forward your bank alerts to an email address it controls avoids the API review entirely — there is no scope being granted, because your mail is simply arriving at a third party’s mail server instead. That is a materially different arrangement from scoped, revocable, read-only API access, and it is worth asking any app which of the two it is doing.

For you, choosing to build on the Gmail API rather than on SMS or on mail forwarding means an outside party will examine the security of the thing holding your data, on a schedule, and can withdraw the access if it fails. Nothing about that is a substitute for asking the questions on this page. It just means someone else is also asking them.

Why we don’t read your SMS

In India the SMS inbox is the cheapest reliable source of transaction data, and most automatic trackers here are built on it. We aren’t, for two reasons.

The first is scope. Android cannot grant an app access to only your bank’s texts — the permission is the entire inbox, including every one-time password you receive. Google itself treats this as highly sensitive and restricts which apps may request it at all. The full argument is on expense tracking without SMS permission.

The second is that it doesn’t work everywhere. iOS exposes no API for reading messages, so SMS-based tracking cannot function on an iPhone at all — covered on expense trackers for iPhone in India. Building on the mailbox instead means one capture layer that behaves identically on both platforms and needs no sensitive device permission on either.

Your rights under the DPDP Act

TLDR Money is built to India’s Digital Personal Data Protection Act, 2023. Sonal Systems Private Limited is the Data Fiduciary; you are the Data Principal. That gives you the right to:

The mechanics of exercising each one are in the privacy policy. Data requests go to hello@tldrmoney.in.

Never sold, never shared

No third-party data brokers, no ad networks, no anonymised-and-resold loophole. This is easier for us to hold to than it is for most of the category, and not because we are better people: our revenue is a subscription, so there is no advertising business or distribution arm whose economics depend on knowing what you spend. An app funded by placing loans or selling funds has a commercial reason to profile you. We don’t have one. See how we make money.

What we will never ask you for

Nobody from TLDR Money will ever ask for your net-banking password, card PIN, CVV or an OTP — not by email, not by phone, not in the app. There is no legitimate situation in which we would need any of them. If someone claiming to be us asks, it isn’t us; tell us at hello@tldrmoney.in.

No system is perfectly secure, and we won’t claim otherwise. We use encryption in transit and at rest, keys managed through AWS KMS, and access controls limiting which systems and people can reach what — but the load-bearing decision is architectural: the mail is parsed where it already lives, so the most sensitive thing in this system never travels to us at all.

Questions worth asking

Can TLDR Money move money out of my account?

No, and not as a matter of policy — as a matter of what the access permits. The planned automatic version reads transaction alerts in your mailbox with read-only access, and version one reads nothing at all. Moving money, placing a trade and opening an account are not operations that exist within a mail scope, so there is no setting we could change to enable them. We also never hold your banking credentials, so there is no route to your accounts even in principle.

Does TLDR Money store my financial data on its servers?

Yes — the parsed records, once automatic tracking ships. When your device turns an alert into a transaction, that record (amount, merchant, date, category) will be stored in our database in the Mumbai region, encrypted at rest, so your history is there when you open the app. What we will never store is the mail it came from. Your mailbox will be read on your device, not on our servers, and no raw email will be retained anywhere in our systems. You will be able to export the records or delete them with your account.

Do you need my SMS permission or my bank password?

Neither. TLDR Money never requests SMS access, so it never sees your one-time passwords or your personal messages, and it never asks for a net-banking username, password, PIN or OTP. Nobody from TLDR Money will ever ask you for any of those — if someone claiming to be us does, it isn’t us.

How do I revoke access?

Two independent ways. You can disconnect from inside the app, and you can revoke the connection directly from your Google Account permissions page without opening our app at all. The second matters: it means the ability to cut off access does not depend on us doing anything, or on our app working.

Is TLDR Money DPDP compliant?

TLDR Money is built to India’s Digital Personal Data Protection Act, 2023. You keep the right to access a summary of your data, to have it corrected or completed, to have it erased, to nominate someone to act for you, and to withdraw consent with the same ease you gave it. Sonal Systems Private Limited is the Data Fiduciary and you are the Data Principal. How to exercise each right is set out in the privacy policy.

What happens to my data if I cancel?

You can export everything before you go, and deleting your account deletes the personal data associated with it, except where law requires specific records to be retained — invoices and tax records being the usual case. Cancelling also does not require you to trust us with the connection afterwards, because you can revoke the Google authorisation independently.

Know exactly what it cannot do

Read-only access, parsed on your device, stored in India — the design for the automatic version, which has not shipped. Version one asks for no access at all, and is free.

Join the waitlist

We’ll email you when it’s ready. No spam, ever.

This page describes the product’s architecture and the access it holds. The binding statements about how your personal data is handled, and your rights over it, are in the privacy policy.