FinCircle is a personal finance and shared-expense app. It records money you tell it about — it does not connect to your bank, and it never holds or moves your money. This policy explains, in plain terms, what information the app collects, why, who it is shared with, and what you can do about it.
The short version. Your financial records are yours. We do not sell them, we do not use them for advertising profiles, and we do not share them with anyone except the service providers that make the app work. Contacts and transaction-alert reading are optional, off until you turn them on, and can be turned off again. You can delete your account and everything in it from inside the app.
1. Who we are
FinCircle is owned and operated by PARUL TRADE ("FinCircle", "we", "us", "our"), Modipuram, Meerut, Uttar Pradesh, Pin 250110, India. For the purposes of India's Digital Personal Data Protection Act, 2023, PARUL TRADE is the Data Fiduciary for the personal data described here; where the EU/UK GDPR applies, we act as the controller.
Contact: parulkarnawal@gmail.com · +91 9119031069
2. What this policy covers
This policy applies to the FinCircle mobile app (Android, published as
com.parultrade.fincircle, and iOS when released), the
FinCircle web app, and this website. It does not cover any third-party
service you reach from FinCircle — your UPI app, your bank, Google Play,
or a payment provider — each of which has its own privacy policy.
3. Information we collect
3.1 Information you give us
| What | Why it exists |
|---|---|
| Account identity — your email address, and (if you sign in with Google) your Google account name and profile picture | To create and secure your account. The verified email address is your identity across the app and is how group invitations reach you. |
| Profile details — display name, optional profile photo, optional mobile number, optional UPI ID, currency and language preference | To personalise the app, show you to fellow group members, and pre-fill a settlement payment. All of these are optional except your name. |
| Financial records you enter — accounts and balances, transactions, amounts, dates, categories, notes, budgets, savings goals, bills and subscriptions | This is the app. It is the record you asked FinCircle to keep. |
| Group data — groups you create or join, members, shared expenses, splits, balances, settlements and group activity | To calculate who owes whom and keep every member's view consistent. |
| Support correspondence — what you write to us and the address you write from | To answer you, and to keep a record of the issue. |
3.2 Information collected automatically
| What | Why it exists |
|---|---|
| Device and app data — device model, operating system version, app version, language, and a device identifier used for push notifications | To deliver notifications, to know which builds a problem affects, and to keep the app working across devices. |
| Usage analytics — which screens are opened and which features are used, in aggregate | To understand what is used and what is broken. Analytics events describe actions, never the amounts or the parties in your transactions. |
| Crash diagnostics — error messages, stack traces and the state of the app when it failed, tagged with your user ID | To fix crashes. Crash reports never carry your financial data. |
| Subscription status — whether your account is Free or Premium, and the purchase token that proves it | To unlock what you paid for. Your tier is written by our server, not by the app on your device. |
3.3 What we never collect
- Your net-banking username, password, PIN, OTP, card number or CVV. FinCircle has no field that asks for them and no reason to.
- Your bank account credentials or any direct connection to a bank.
- Your device's precise location.
- Your biometric data. Fingerprint and face unlock are handled entirely by your device's own operating system; FinCircle is told only "authenticated" or "not authenticated".
- Your PIN in a readable form. An app-lock PIN is stored on your device only, salted and hashed, and never sent to us.
4. Device permissions and optional features
Each of these is optional, requested only when you use the feature it belongs to, and revocable at any time in your device settings.
| Permission | Used for | What leaves your device |
|---|---|---|
| Contacts | Inviting people you already know to a group, instead of typing an address. | Only the specific contact you choose to invite. FinCircle does not upload your address book, and does not read it unless you open the invite screen and grant the permission. |
| Transaction alerts (SMS) | Smart transaction detection: reading a bank or UPI alert as it arrives and preparing an entry for you to confirm. | Nothing. Messages are matched and parsed on your device. FinCircle does not have access to your existing inbox, does not upload message text, and does not read messages that are not transaction alerts. The feature is off unless the build you have supports it and you switch it on, and a detected transaction is never saved without your confirmation. |
| Notifications | Budget alerts, bill reminders, group activity and settlement requests. | A push token identifying your device, so a notification can reach it. |
| Camera / photo library | Choosing a profile picture. | Only the image you pick. |
| Biometrics | Unlocking the app with fingerprint or face. | Nothing. See section 3.3. |
5. How we use information
- To run the app — keep your accounts, balances, budgets, goals and groups correct, and sync them to the devices you sign in on.
- To authenticate you and keep your account secure.
- To calculate shared balances and settlements and show every member of a group the same figures.
- To send the notifications you have enabled.
- To provide AI insights you ask for, as described in section 8.
- To process and verify a Premium purchase and grant the right subscription tier.
- To fix problems — diagnose crashes, investigate a bug, and understand which features are used.
- To answer support requests and communicate about your account, including service and security notices.
- To meet legal obligations and to prevent fraud and abuse of the service.
We do not sell personal data, and we do not share your financial records with advertisers or data brokers. Advertising shown in the free tier is not targeted using the contents of your financial records.
6. Consent and legal basis
We process your information because you asked us to provide the service (performance of a contract with you), because you gave consent for a specific optional feature, or because we have a legitimate interest in keeping the service secure and working — and, where required, to comply with law.
You may withdraw consent for any optional feature at any time by turning it off in the app or revoking the permission in your device settings. Withdrawing consent does not affect processing already carried out, and may make the relevant feature stop working.
7. Groups and other people's information
A group is shared by design. When you join or are added to one, other members can see your display name, profile photo, the email address your account is identified by, the expenses you add or are included in, your share of them, your balance and your settlements.
When you invite someone, you give us that person's email address or phone number for the purpose of delivering the invitation. Please invite only people who would expect to hear from you. Expenses recorded in a group remain part of that group's history even if a member later leaves, because removing them would silently change what everyone else owes.
8. AI features
FinCircle's assistant is powered by Google's Gemini models through Firebase AI Logic. When you ask a question, we build a small, structured summary of your finances — totals, category aggregates and the figures relevant to your question — and send that summary. Your raw transaction history is never sent, and the assistant is not given access to your database.
AI output is generated text. It is provided for information only, it can be wrong, and it is not financial, investment, tax or legal advice.
9. Who we share information with
We share information only with the processors that make the app function, each under their own terms and each only with what they need:
| Provider | Purpose |
|---|---|
| Google Firebase (Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, Analytics, Crashlytics) | Sign-in, cloud storage and sync of your records, server-side calculations, push notifications, usage analytics and crash reporting. |
| Google — Firebase AI Logic (Gemini) | Generating the AI insights described in section 8. |
| Google Play Billing / Apple App Store | Processing and verifying an in-app Premium purchase. |
| Razorpay | Processing a Premium payment where that checkout is offered. Card and banking details are entered with the payment provider and are never seen or stored by FinCircle. |
We may also disclose information where we are legally required to, or to establish or defend a legal claim, or to protect the rights and safety of our users. If FinCircle is ever transferred to another owner, your information may transfer with it, and you will be told before it does.
10. Payments
Premium costs ₹29 per year. Payments are handled by the app store or the payment provider — FinCircle never receives your card number, UPI PIN or banking credentials. We receive confirmation that a payment succeeded, an identifier for the transaction, and the resulting subscription period.
11. Where information is stored, and for how long
A copy of your records is kept on your device so the app works offline. The cloud copy is stored on Google Cloud infrastructure operated by Firebase, which may process and store data on servers outside India, including in the United States. Where the law requires safeguards for such a transfer, we rely on the provider's contractual protections.
We keep your information for as long as your account exists. When you delete your account, your records are removed from your device and from our servers. Some information may persist briefly in backups and in system logs before being overwritten in the ordinary course, and shared group records that belong to other members' history are retained for them. Records we are required by law to keep — for example proof of a payment — are kept for the period the law requires.
12. How we protect information
- Traffic between the app and our servers is encrypted in transit; cloud data is encrypted at rest by the provider.
- Access rules on the server decide what each signed-in account may read or write. Financial calculations that must not be tampered with — group balances, settlements, your subscription tier — are performed and written by the server, never accepted from a client.
- An optional app lock (PIN, plus biometrics on supported devices) protects the app on a shared or lost device, with a lockout after repeated wrong attempts.
- Sensitive values kept on your device are held in the platform's secure storage.
No system is perfectly secure. Keep your sign-in credentials to yourself, use the app lock on a shared device, and tell us promptly if you believe your account has been accessed by someone else.
13. Your rights and choices
- Access and correct — your profile and all of your records are visible and editable inside the app.
- Delete — Profile → Settings → delete your account removes your records from the device and from our servers. You may also write to us and ask.
- Export — Premium includes report export; an exported file is created on your device and goes only where you send it.
- Withdraw consent — turn off any optional feature, or revoke its permission in your device settings.
- Opt out of notifications — in the app's notification settings, or in your device settings.
- Complain — write to us first (section 16). Users in India may also complain to the Data Protection Board of India; users in the EEA or UK may complain to their local supervisory authority.
- Nominate — users in India may nominate someone to exercise their rights in the event of death or incapacity, by writing to us.
We answer rights requests within 30 days. We may need to verify that the request comes from the account holder before acting on it.
14. Children
FinCircle is not directed at children. You must be at least 18 years old to hold an account, as set out in the Terms & Conditions. We do not knowingly collect personal data from a child. If you believe a child has created an account, write to us and we will delete it.
15. Changes to this policy
We may update this policy as the app changes or the law does. The effective date at the top always reflects the current version, and a material change will be notified in the app or by email before it takes effect. Continuing to use FinCircle after a change means you accept the updated policy.
16. Contact and grievances
For any question about this policy, or to exercise a right described in section 13, contact our grievance officer:
PARUL TRADE — FinCircle
Email: parulkarnawal@gmail.com
Phone: +91 9119031069
Address: Modipuram, Meerut, Uttar Pradesh, Pin 250110, India