Rupello ("the app", "we", "us") is a personal finance application built on a simple principle: your financial data belongs on your device, not on our servers. This policy explains exactly what the app does with your information, what permissions it uses and why, and the choices you have. It applies to the Rupello Android application and the Rupello website.
The short version
- Your transactions, budgets and balances are stored only on your phone, in a local database.
- SMS messages are read and parsed on your device. They are never uploaded, shared or sold.
- We never ask for your bank username, password, OTP or card PIN — and you should never enter them anywhere in the app.
- There are no accounts and no cloud sync. We do not run a server that holds your data.
- Optional anonymous usage and crash data stays off until you choose to enable it in Settings.
- No advertising, no sale of personal data, no third-party data brokers.
- You can export or delete all of your data at any time.
1. Information we do NOT collect
- Bank credentials. Rupello never asks for, stores or transmits your internet-banking username, password, OTPs, card numbers or PINs.
- Your transactions on our servers. Transaction data parsed from SMS or entered by you stays in a local database on your device.
- Your SMS inbox. Non-financial personal messages are ignored by the parser and are never stored by the app.
- Advertising identifiers. The app contains no advertising SDKs and shows no third-party ads.
- Data for sale. We do not sell, rent or trade personal data with anyone, for any purpose.
2. SMS permission — what it does and why (Android)
Rupello requests the Android READ_SMS and RECEIVE_SMS permissions. This is the core of how the app works, so here is the complete picture:
- Purpose. The permissions are used solely to detect and read transaction alert messages sent by banks, card issuers and UPI services (for example, "Rs.340 debited from a/c **4821"), so your expenses and income can be logged automatically.
READ_SMScovers the initial import and catch-up scans of messages already in your inbox;RECEIVE_SMSlets a new bank alert be logged the moment it arrives. - How messages are selected. To find bank alerts, the app scans messages in your inbox on your device and keeps only those that look like a bank or transaction alert. Everything else is discarded immediately and is never stored or transmitted.
- Processing location. All SMS reading and parsing happens locally on your device. Message content is never transmitted off your phone, and is never sent to any analytics or AI service.
- What is stored. Only the structured transaction extracted from a financial message (amount, date, merchant, account hint, category) is saved to the app's local database.
- What is ignored. Personal conversations, OTP messages and other non-financial SMS are not used and not stored.
- Not a default SMS app. Rupello does not act as, and does not ask to become, your device's default SMS handler. It cannot send messages.
- Your choice. SMS access is optional. If you decline the permission, you can still use Rupello by adding transactions manually or importing files. You can revoke the permission at any time in Android Settings, and the app will continue to work in manual mode.
3. Information stored on your device
The following data is created and kept in a local, app-private database on your phone:
- Transactions (parsed from SMS or entered manually), categories, merchants and notes;
- Budgets, savings goals, bills, subscriptions and reminders;
- Account balances, net worth entries and, if you use them, investment and loan records;
- App preferences such as theme, currency and notification settings.
This data is protected by Android's app sandbox. It is removed if you clear the app's data or uninstall the app.
4. Optional anonymous usage and crash data
Anonymous diagnostics are off by default. If you choose to enable them in Settings → Security & Privacy → Share anonymous usage data, Rupello sends a small amount of technical data to PostHog, an analytics provider, using servers in the United States. This is the only information the app sends anywhere.
It is limited to the following:
- That the app was opened;
- That onboarding was completed;
- Whether you granted or declined the SMS permission;
- After an SMS scan, an approximate range of how many transactions were found (for example "11-50") — never the exact number;
- Crash and error reports, including the technical error message and stack trace, so faults can be fixed.
It never includes your SMS messages, transaction amounts, balances, merchant names, account numbers, category names, or anything you have typed. We do not track which screens you visit, and there is no session recording or screen capture of any kind.
This data is not linked to your name, email or any account — there is no account to link it to. It is associated only with a random identifier generated on your device, which cannot be traced back to you. We do not use it for advertising and we do not share it with anyone.
You can turn diagnostics on or off at any time in Settings → Security & Privacy → Share anonymous usage data. The app is fully functional with them switched off.
5. Features that do not exist in this version
Rupello has no user accounts, no sign-in and no cloud sync. We do not operate a server that stores your financial data, so there is no copy of it anywhere but your phone.
This version has no AI assistant and does not transmit your financial records to a cloud service. If a future version adds a feature that sends further data off your device, it will be clearly labelled and this policy will be updated before the feature is made available.
6. Biometric unlock
If you enable app lock, authentication is performed entirely by your device's operating system (fingerprint or face unlock). Rupello only receives a success/failure result. We never see, store or transmit your biometric data.
7. Notifications
With your permission, Rupello shows local notifications such as bill reminders and budget alerts. These are generated on your device and do not involve sending your data anywhere.
8. Third-party services
Rupello embeds exactly one third-party service: PostHog, used for the anonymous usage and crash data described in section 4. PostHog processes this data on servers in the United States under its own privacy policy. No financial data and no SMS content is ever sent to it.
The app embeds no advertising or marketing SDKs, and your financial data is not shared with any third party. Standard platform services (such as Google Play for app distribution and updates) apply their own privacy policies when you download or update the app.
9. Data retention, export and deletion
- Retention. Your data stays on your device for as long as you keep it. We have no copy.
- Export. You can export your full history to CSV or Excel from Settings at any time.
- Deletion. You can delete individual records in the app, erase everything at once from Settings → Delete All Data, clear all app data from Android Settings, or uninstall the app — uninstalling permanently removes the local database.
10. Security
Your data is stored in an app-private database protected by the Android application sandbox, with optional biometric app lock and an automatic screen blur when the app is backgrounded. No system is perfectly secure, so we also recommend using a device screen lock and keeping Android up to date.
11. Children's privacy
Rupello is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children.
12. Your rights
Because your financial data never leaves your device, you already hold it: access, correction, portability and deletion are all available directly in the app. There is no account, so there is no server-side profile of you to request or erase. You can stop the anonymous usage data described in section 4 at any time from Settings. If applicable law (including India's Digital Personal Data Protection Act, the GDPR or the CCPA) grants you additional rights, you may exercise them by contacting us.
13. Changes to this policy
We may update this policy as the app evolves. Material changes (for example, introducing cloud backup) will be announced in the app before they take effect, and the "Last updated" date above will always reflect the current version.
14. Contact us
Questions or requests about privacy? Email octain025@gmail.com.