In short: Money Manager stores the financial data you give it or connect — bank-alert emails you opt in to, manual entries, and links to Splitwise or an MCP client — behind argon2id-hashed passwords, encryption at rest, and field-level encryption on the most sensitive fields. We request Gmail's read-only scope, never see your full email bodies, and never sell your data.

On this page
  1. What we collect
  2. Gmail data & the gmail.readonly scope
  3. How we use your data
  4. Third parties — Google, Splitwise, MCP clients
  5. Retention & encryption
  6. Your rights — access, export, deletion
  7. Security practices
  8. Children's privacy
  9. Changes to this policy
  10. Contact

1. What we collect

To provide the app, we collect and store:

We do not collect data you don't give us or explicitly connect — there is no background contact-list, location, or ad-identifier collection.

2. Gmail data & the gmail.readonly scope

If you choose to connect a Gmail mailbox, Money Manager requests only Google's gmail.readonly scope, which is read-only. We use it to watch for bank-alert style emails and extract four things from a matched alert: the amount, the date, the merchant name, and the last few digits of the account. We do not store full email message bodies as a matter of course; a raw reference to the source message is kept, field-level encrypted, solely so a mis-parsed alert can be reprocessed, and it is never used to read unrelated mail.

This use of Gmail data complies with the Google API Services User Data Policy, including the Limited Use requirements: we do not use Gmail data for advertising, we do not allow humans to read it except for abuse investigation, security incidents, or to comply with law, and we do not transfer it to any third party except as necessary to provide or improve the app's own features (e.g. pushing a categorized split to Splitwise, if you choose to). You can revoke Money Manager's access at any time from Settings → Integrations in the app, or directly from your Google Account's third-party access page.

3. How we use your data

We use the data above to:

We do not use your financial data for advertising, and we do not build behavioral profiles for marketing.

4. Third parties — Google, Splitwise, MCP clients

We do not sell or rent your data. Data leaves our systems only in these cases, and only for the connections you set up:

We may also disclose data if required by law, to protect the rights or safety of our users, or in connection with a merger or asset sale — in which case we would notify affected users first where legally possible.

5. Retention & encryption

The database is encrypted at rest. On top of that, the most sensitive fields — OAuth access/refresh tokens and raw email source references — get additional field-level envelope encryption, keyed by a KMS-managed key rather than a single static application secret. Account numbers are masked at the API layer before they ever reach the app, not only in the interface.

We retain your data for as long as your account is active. Deleting your account (see §6) removes your transactions, people/loan records, integration credentials and sessions; backups age out on our standard backup retention cycle.

6. Your rights — access, export, deletion

From Settings in the app, without contacting support, you can:

We aim to fulfil export and deletion requests, including any made by emailing us directly, within 30 days. Disconnecting an integration or deleting your account requires step-up re-authentication (your password or biometric) first, to prevent someone else from doing it on your behalf.

7. Security practices

Money Manager handles real financial data, so:

No method of storage or transmission is 100% secure, but this is the standard we hold ourselves to; if you believe you've found a vulnerability, please report it to the contact below.

8. Children's privacy

Money Manager is a personal-finance tool intended for adults managing their own money, and is not directed at children under 13 (or the relevant age of digital consent in your country). We do not knowingly collect data from children; if we learn we have, we will delete it.

9. Changes to this policy

If this policy changes, we'll update the "Last updated" date at the top of this page and, for material changes, note it in the app and record the new policy version and acceptance timestamp against your account. Continued use of the app after a change constitutes acceptance of the revised policy.

10. Contact

Questions about this policy, or requests to access, export or delete your data, can be sent to shreyansh@shrynshjn.com.