Privacy Policy
Last updated: February 23, 2026
1. Introduction
Welcome to RUPI ("we", "our", or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our personal finance application.
2. Information We Collect
Account Information
- Email address (for authentication)
- Name (for personalization)
- Password (encrypted, never stored in plain text)
Financial Data
- Bank account names and balances (entered by you)
- Transaction details from uploaded bank statements
- Categories and tags you create
- Budget information
What We DO NOT Collect
- ❌ Bank login credentials (we never ask for them)
- ❌ Credit card numbers
- ❌ Aadhaar, PAN, or government ID numbers
- ❌ Real-time location data
3. How We Use Your Information
We use your information solely to:
- Provide and improve our personal finance tracking service
- Parse bank statements you upload
- Power AI chat features to help you understand your finances
- Send important account notifications
4. Data Storage & Security
- Encryption: All data is encrypted at rest and in transit (TLS 1.3)
- Data Residency: All your data is stored exclusively in India on Google Cloud Platform (Mumbai — asia-south1 region). Your financial data never leaves Indian borders.
- Backups: Daily automated backups with 30-day retention, also within India
- Access Control: Only you can access your data
- Database: Managed PostgreSQL with automatic encryption and network isolation
5. AI & Third-Party Services
Our AI chat feature uses Google Gemini to process your questions. When you use AI chat:
- Your question and relevant financial context are sent to Google Gemini
- Google does not store or train on your data
- AI responses are generated in real-time and not retained by Google
6. Data Sharing
We DO NOT sell, rent, or share your data with third parties.
Exceptions:
- If required by law (court order, legal process)
- To protect our rights or prevent fraud
7. Your Rights
You have the right to:
- Access: View all data we have about you
- Export: Download your data in standard formats
- Delete: Request complete deletion of your account and data
- Correct: Update or correct your information
8. Data Retention
- Active accounts: Data retained as long as your account is active
- Deleted accounts: Data permanently deleted within 30 days
- Backups: Deleted from backups within 90 days
9. Cookies
We use essential cookies for authentication and session management only. We do not use tracking cookies or third-party advertising cookies.
10. Children's Privacy
RUPI is not intended for users under 18 years old. We do not knowingly collect information from children.
11. Digital Personal Data Protection Act, 2023 (DPDP)
RUPI is committed to compliance with India's Digital Personal Data Protection Act, 2023. In accordance with the DPDP Act:
- Lawful Purpose: We process your personal data only for the purpose of providing personal finance tracking services, as consented by you at registration
- Data Minimization: We collect only the data necessary to provide our services
- Data Localization: All personal data is stored and processed within India (Google Cloud, Mumbai region)
- No Cross-Border Transfer: Your financial data is not transferred outside India. AI processing via Google Gemini sends only anonymized transaction descriptions, not personal identifiers
- Right to Erasure: You can delete your account and all associated data at any time from Settings → Profile
- Right to Grievance Redressal: Contact our Data Protection contact below for any privacy concerns
- Consent Management: You can withdraw consent by deleting your account. We do not process data beyond your active consent
12. Open Source & Transparency
RUPI's frontend dashboard is open-source software, built upon the foundations of Maybe Finance and Sure Finance. Our code is publicly auditable at github.com/pkamalssn/rupi, licensed under AGPLv3. AI features are powered by our proprietary RUPI Engine.
13. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes via email or in-app notification.
14. Contact Us
If you have questions about this Privacy Policy, your data, or DPDP-related concerns:
- Data Protection Contact: privacy@rupiapp.in
- General Support: pkamalssn@gmail.com
By using RUPI, you agree to the collection and use of information in accordance with this policy.