In short
- Your SMS are read on your phone and never uploaded. The app looks only for bank and card alerts, turns each into a transaction on the device, and discards the message. Our servers have no column for message text.
- What we store is the ledger you see in the app: your profile, accounts, transactions, bills, goals and assets — plus a one-way fingerprint of each imported alert so it is never imported twice.
- We sell nothing and share nothing for marketing. No advertising SDKs, no analytics profiles, no data brokers, no “partners”.
- You can delete everything in one tap from Profile → Delete Account, or by asking us. Deletion is immediate and irreversible.
- India’s Digital Personal Data Protection Act, 2023 governs how we handle your data. Our grievance contact is at the end of this page.
1. Who we are and what this covers
WealthMonk (“the app”) is published by QuickMonk Technologies Private Limited (“QuickMonk”, “we”, “us”), CIN U62020TS2026PTC215610, registered at MIG-01-1106, Chitrapuri Colony, Rangareddy, Telangana 500089, India. We are the data fiduciary for the personal data described here.
This policy covers the WealthMonk Android application, this website (https://wealthmonk.co.in), and support conversations with us. It does not cover your bank, your telecom operator, or Google Play, each of which has its own policy.
2. Information we collect
2.1 Information you give us
| Data | Why we need it |
|---|---|
| Mobile number | To create and sign in to your account with a one-time code. It is your account identifier. |
| Name and, optionally, a profile photo | To address you in the app. The photo is stored in your account’s private storage. |
| Monthly income, monthly budget, savings goal, monthly SIP, current investments | To compute “safe to spend”, budget utilisation, goal affordability and your FIRE projection. |
| Accounts, cards, assets, liabilities, goals, bills and recurring rules you add or edit | They are the ledger. Each carries the name, type, amounts, dates and last-four digits you enter. |
| Transactions you enter manually, including any note or receipt photo | To record them. Notes are encrypted before storage. |
| Preferences | Theme, card order, compact numbers, notification choices, whether biometric lock is on. |
| Support messages | To answer you. Kept in our mailbox as long as needed to resolve the issue. |
2.2 Information derived from your SMS — on your device
With your permission (see section 3), the app reads the SMS inbox on your phone and identifies messages from banks and card issuers by their registered sender IDs and by the shape of the message (an amount, a direction, a masked account). From each such alert it derives, on the phone:
- the amount and direction (debit, credit, transfer);
- the date and time;
- the merchant or payee, normalised against a dictionary of Indian merchants;
- the account or card it relates to, identified by its last four digits and its kind (bank, credit card, prepaid card);
- for card statements and bill alerts: the amount due, minimum due and due date;
- for certain service notices: that a card or account is becoming inactive, or that a KYC or mandate is expiring, and the date;
- a SHA-256 digest (a one-way fingerprint) of the message, used solely to recognise a message that has already been imported.
Only these derived fields and the digest are saved to your account. The text of the message is not stored on our servers, and is not transmitted to them. The digest cannot be reversed into the message. A balance quoted in an alert is used on the phone to set that account’s balance; the alert itself is not kept.
Messages that are not bank alerts — one-time passwords, personal messages, promotions — are skipped by the parser and nothing about them is stored anywhere.
2.3 Information collected automatically
- App version, attached to the optional parser-gap reports described in 2.4.
- Server logs. Our hosting provider keeps standard request logs (IP address, timestamp, request path) for security and reliability, for a limited period.
- Nothing else. The app contains no advertising SDK and no third-party analytics. It does not collect your location, contacts, files, installed apps, or an advertising identifier. If we add crash reporting in a future version, this policy will be updated before it ships.
2.4 Optional, anonymous parser-gap reports
When the parser cannot read a bank message, the app can store the shape of that message on your phone — every digit replaced by 0, every amount by {amt}, every masked account by {acct}, every capitalised name by {name}. The shapes are listed under Profile → Unread bank SMS formats. Nothing is sent unless you tap Send to WealthMonk. What is sent is the redacted shape and the bank’s sender code, aggregated with reports from other users, with no user identifier attached; the server rejects any template that still contains a rupee figure, a long number or an email address.
3. The SMS permission
WealthMonk asks for Android’s READ_SMS permission for one purpose: to read bank and card alerts on your phone so that transactions, bills and card statements are recorded automatically. This is the core function of the app.
- The permission is requested only after an in-app screen explains what will be read and what will not, and only after you tap Continue. You may choose Not now; the app works with manual entry.
- Reading and parsing happen entirely on your device. SMS content is not transmitted to us or to anyone.
- Only messages from banks and card issuers, carrying a financial transaction or a bill, are used. Non-financial and personal SMS are not read into the app, not stored, and not shared.
- We do not use SMS data for advertising, credit scoring, profiling, or any purpose other than the features you see in the app.
- You can revoke the permission at any time in Android Settings → Apps → WealthMonk → Permissions. Transactions already recorded remain in your account until you delete them or the account.
This use is made under Google Play’s permitted use for SMS-based money management, and is declared to Google Play accordingly.
4. How we use information
- To provide the app: record and categorise transactions, track accounts, bills, cards, goals and net worth, and compute insights, scores and projections from them.
- To sign you in and keep your session secure.
- To send you notifications you have enabled — bill reminders, goal and card alerts. These are generated on your phone.
- To sync your ledger between your devices when you sign in on more than one.
- To improve the parser, using only the anonymous redacted shapes you choose to send.
- To respond to support requests and legal obligations.
We do not use your information for advertising, we do not build marketing profiles, and we do not make automated decisions about you that have legal or similar effects.
5. Consent and legal basis
We process your personal data on the basis of your consent, given when you create an account, when you grant a permission, and when you enter information into the app — and, for the limited purposes of security, fraud prevention and legal compliance, on the basis of our legitimate uses under the Digital Personal Data Protection Act, 2023.
You may withdraw consent at any time: revoke a permission in Android Settings, or delete your account (section 9). Withdrawal does not affect processing that happened before it.
6. Who we share information with
We do not sell personal data, and we do not share it with advertisers, data brokers or “partners”. We share it only with the following, each bound by contract to process it solely on our instructions:
| Recipient | What | Why |
|---|---|---|
| Supabase (database, authentication and file storage hosting) | Your account and ledger data as described in section 2 | To host the service. Data is stored in the data-centre region configured for our project. |
| SMS delivery provider for one-time codes | Your mobile number and the code | To deliver the sign-in code by SMS. |
| Google Play | Nothing from us. Google’s own policy governs the install and purchase records it keeps. | App distribution. |
We may also disclose information when required by law, a court order, or a lawful request from a public authority; to protect the rights, safety or property of users or the public; or, in the event of a merger, acquisition or sale of assets, to the successor, who will be bound by this policy.
Where a provider stores data outside India, we ensure that the transfer is permitted under the Digital Personal Data Protection Act, 2023 and that the provider maintains protections consistent with this policy.
7. Storage and security
- On the phone: the app’s local database is encrypted (SQLCipher) with a key held in the Android Keystore; transaction notes are additionally encrypted with AES-256-GCM; Android cloud backup of app data is disabled; the app can be locked with biometrics; screenshots are blocked on financial screens.
- In transit: all traffic uses TLS.
- On the server: every table is protected by row-level security so that a signed-in user can reach only their own rows; balance arithmetic runs in server-side functions; message bodies are structurally excluded from the schema.
No system is perfectly secure. If we learn of a breach affecting your data we will notify you and the Data Protection Board of India as the law requires. Our security page describes these measures in more detail.
8. Retention and deletion
We keep your data for as long as your account exists. When you delete your account — in the app under Profile → Delete Account, or by asking us (see account deletion) — your profile and every row that belongs to it are deleted from our database, your uploaded files are deleted, your login is removed, and the app wipes its local storage. This is a hard delete; there is no recovery period. Residual copies in our hosting provider’s routine backups are overwritten in their normal cycle, typically within 30 days.
Support emails are kept for as long as needed to resolve the matter and for a reasonable period afterwards. Anonymous parser-gap shapes are not linked to you and are retained as engineering data.
9. Your rights
Under the Digital Personal Data Protection Act, 2023 you have the right to:
- Access a summary of the personal data we hold about you and how it has been processed. Most of it is visible in the app; the rest we will provide on request.
- Correct or update your data — in the app, or by asking us.
- Erase your data — by deleting your account.
- Withdraw consent at any time, as described in section 5.
- Nominate a person to exercise these rights on your behalf in the event of death or incapacity.
- Grievance redressal — raise a complaint with our Grievance Officer (section 13), and, if unresolved, with the Data Protection Board of India.
To exercise any of these, write to privacy@wealthmonk.co.in from the number or email associated with your account. We respond within 30 days.
10. App permissions
| Permission | Purpose | Required? |
|---|---|---|
| Read SMS | Automatic capture of bank and card alerts (section 3) | No — manual entry works without it |
| Notifications | Bill reminders, goal and card alerts | No |
| Biometrics | App lock with fingerprint or face | No — off by default |
| Photos (via Android’s photo picker) | Choosing a profile picture | No |
| Internet, network state | Syncing your ledger to your account | Yes |
| Run at boot, background work | Resuming the periodic background SMS sync after a restart | Only with Read SMS |
The app does not request camera, microphone, location, contacts, call-log or storage permissions.
11. Children
WealthMonk is for adults. You must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18; if you believe a minor has created an account, contact us and we will delete it.
12. Changes to this policy
When we change this policy we will update the dates at the top and, for material changes, tell you in the app before they take effect. Continued use after a change means you accept it; if you do not, you can delete your account.
13. Contact and grievances
To raise a grievance about how your personal data has been handled, write to our Grievance Officer at grievance@wealthmonk.co.in. We acknowledge every grievance and respond within 30 days.
For data requests — access, correction, erasure — write to privacy@wealthmonk.co.in. For general support, support@wealthmonk.co.in.
If your grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India.