Money Console

Privacy policy

Money Console for Android · In force from 1 October 2026

The short version

Who we are

Money Console is made by Gokul Prasath, 146, Rana Nagar Road, Annamalai Illam, Bhavani, Erode, Tamil Nadu 638301, India, who decides how the data described here is used (the "data fiduciary" under India's Digital Personal Data Protection Act, 2023). "We" and "us" on this page mean Gokul Prasath.

Privacy questions and complaints: grievance@moneyconsole.in. A person reads every message and replies within 30 days.

What stays on your phone

Everything you add or the app reads stays in an encrypted database on your phone: payments, accounts, balances, bills, goals, loans, notes, categories, the bank SMS it reads, the statements you import and the text of receipts you read (the app's copy of the photo is deleted once it's read). The key is kept in your phone's secure hardware. The app's own backup goes to a hidden folder in your Google Drive, encrypted on the phone first, and it opens only with your phone or your recovery code: neither we nor Google can read it. Android's own backup of the app holds only display settings such as the theme, never your data or its keys.

What can leave your phone, and why

Each of these is shown to you, in the app, before it starts. The words in quotes are the app's own notice.

Reading bank SMS

The app asks Android for permission to read and receive SMS only when you turn on SMS reading, and works fully if you say no. It reads messages on your phone to find payments, bills, EMIs, salary and balances from your bank's own senders; everything else is ignored.

Starts only when you turn on SMS reading. "To read new bank formats, the app sends the message's shape with amounts, account numbers and names removed, plus daily counts of how well each bank was read. Shapes seen on 3 or more phones are kept to help everyone. Your messages themselves are never sent." One-time passwords and promotions are dropped on the phone and never looked at again. The daily counts are added up across phones before they're stored, so they can't be traced back to you.

Importing statements

Only if you turn on its switch on the statement screen. "If we haven't seen this bank's layout, the app sends its headings and 2–3 rows with every amount, date, name and number removed, so it can learn to read the layout on every phone. The statement itself is never sent." A statement's password is used once and never kept.

Voice

The app uses the microphone only while the voice sheet is listening, after you allow it. Speech is turned into words by your phone's own speech service (Android's, from Google or your phone's maker), under that service's terms; nothing is recorded or kept by the app. Smart voice then reads the words on your phone.

Instant voice (Pro)

Asked once, before the first use. "To turn what you said into payments, Instant sends the words, including amounts and names, to our server and an AI service that never learns from them and deletes them within 30 days. We don't keep them. Recordings are never sent to us." If you choose "Use my phone", your words aren't sent.

Sync and sign-in (Pro)

Only if you sign in and turn on sync. "To keep your phones in step, sync sends your changes to our server locked with a key only your phones have, so we can't read them. Signing in gives us your Google email, kept for support, deleting your account and approving family members. Synced data is kept until you delete your account, or 6 months after Pro ends." Your email is stored encrypted.

Category votes

Asked the first time you fix a payment's category. "We send the shop name, its business UPI ID, the category and your country, with a phone code that changes every month. No amount, date or account." It helps sort that shop right for everyone.

Crash reports

Off until you turn it on. "App errors, the phone model and Android version. No financial data." A report says what kind of error it was and where in the app's code it happened. The error's own message is never kept, because it could quote what was on screen.

Usage counts

Off until you turn it on. "Which screens are opened and how fast the app is, as counts. Never an amount, a name or anything you type." Only events on a fixed, reviewed list are sent, numbers go as ranges (such as 10–49), and the server drops anything not on the list again.

Family sharing (Pro)

Only if you join a family. "To join, the family's manager sees your Google email so they can approve you. What you choose to share goes to the family's space, locked so only the family's phones can read it. When you leave, sharing stops."

What the app needs to talk to our server at all

When the app calls our server for any of the above, it sends a random install ID (made on your phone, tied to nothing else) and a check from Google Play that the app is genuine. If you sync, or ask to hear when Family is ready, your phone's push token is stored so we can tell it there's something new. Buying Pro happens in Google Play: we receive the purchase's status, never your card, UPI or bank details. Our server keeps an access log (time, which endpoint, the install ID or account, the result), never what was sent. These don't wait for a separate yes, because the feature you turned on can't work, or be kept safe from abuse, without them; they're used for nothing else.

Who processes it for us

We name them rather than hide them. Each works under a written contract (their standard terms) and only on our instructions. Some of them process data outside India. Indian law allows that except to countries the Government of India restricts, and we stop any transfer it restricts.

Company What for
Cloudflare Our servers, databases, file storage, request counts and one of the AI services (Workers AI) for new SMS and statement shapes and Instant voice
Google Google Play (downloads, Pro purchases, the genuine-app check), Google sign-in, Firebase messaging (sync notifications), Firebase Crashlytics (crash reports from Android's side, only with your yes), Firebase Analytics (usage counts, only with your yes), and the paid Gemini API as an AI service that doesn't train on what it's sent
Sentry Crash reports from the app's own code, only with your yes
Groq An AI service with zero data retention, for Instant voice and new shapes

Any AI service we use must not train on what it's sent and must delete it within 30 days. We never use a free AI tier that may learn from inputs.

How long we keep it

What Kept
Install record 13 months after the app was last seen
Push token Until sign-out or deletion, or 90 days unused
Category votes, SMS and statement shapes' votes 12 months
Daily SMS reading counts 90 days
Crash reports 90 days (Crashlytics), 30 days (Sentry)
Usage counts 2 months in Firebase Analytics. Our own daily totals are added up across phones with no install ID, so they can't be linked to anyone; they're kept for 2 years
Problem-report logs you choose to send 90 days
Synced data Until you delete your account, or 6 months after Pro ends (you're told at 5)
Access log 1 year, including after an account is deleted
Our database backups 12 weeks
Purchase records, with no link to you 8 years, as Indian income tax and GST law require

Your rights

Keeping it safe

Data is encrypted on your phone and, for sync, end to end. Anything that leaves the phone to help read a new format is masked first. Our admin pages are behind a sign-in check, and every admin action is logged. If a breach affects you, we'll tell you without delay: what happened, what it means for you, what we did and what you can do.

Age

Money Console is for people 18 and over.

Changes to this policy

When what something sends changes, the app shows the new notice and asks again before sending anything new. This page shows the date of each change.