FinLens Talk to us

Your data

Delete your data

Last reviewed 11 August 2026 · Value Garage Private Limited · CIN U66190DL2025PTC453505
Companion to Privacy Policy §9 (retention & deletion) and §12 (your rights).

There is almost nothing to delete. FinLens never stores the content of your email, and what it produces from your documents is destroyed within three hours. Two steps remain, in this order: remove FinLens's access at Google, then write to us.

The honest version. Nothing here is kept long enough to need a delete button. Your documents pass through memory while being read and are never written to disk. What we produce from them is destroyed by a sweep that runs on a schedule — whether or not anyone asked, and whether or not the business collected it. The identity details used to open protected statements expire with the consent link. Your mailbox credential is destroyed when processing finishes or when you withdraw, whichever is first.

So for most people who write to us, the accurate answer is that everything described below had already gone before the mail arrived. We would rather publish that than offer a deletion ceremony over an empty table.

1. Remove FinLens's access at Google

Do this first. It is the step that matters most, because it is the one that does not depend on us.

  1. Go to myaccount.google.com/permissions.
  2. Find FinLens in the list of apps with access to your account.
  3. Select it, then choose Remove access.

That happens at Google. It takes effect immediately and waits on nothing we do. From that moment Google refuses our copy of the credential, even before it is destroyed on our side.

Removing access changes nothing in your mailbox. FinLens only ever asks for read-only Gmail access, so it cannot send, modify, label or delete your mail. There is nothing in your inbox to undo.

If you are still on the FinLens approval page

Decline there instead. It is faster and cleaner than revoking afterwards: a refusal hands the credential back to Google and destroys our copy in the same request, rather than leaving it for the scheduled sweep. No document is fetched at all — nothing is fetched before that page is approved.

If you declined at Google, or never opened the link

Nothing was fetched and no document was ever produced. A consent link that is never opened still had identity details written against it at intake, and those are destroyed on the same sweep when the link expires. There is nothing for you to do.

2. Ask us to delete what we hold

  1. Email privacy@finlenstech.com.
  2. Use the subject line Delete my data.
  3. Tell us the name of the business that asked you for documents.
  4. Tell us roughly when you approved the FinLens page.

We ask for the business rather than for your email address, and the reason is worth knowing: we cannot look you up by your address, because no table in the system stores one (§3). A request is keyed by the business's own reference for you. That is a privacy property, not an inconvenience we are apologising for. It has a cost, though: a request naming no business is often one we cannot locate. Where that happens we will say so, rather than report a deletion we did not perform.

There is no self-serve deletion portal, and no button. There is no FinLens account to log into, no export, and no automated request flow. Deletion is a request to an address, read by a person. The self-serve half of this page is §1, and it is at Google rather than here. That is the half that matters most, because it is the half that does not require you to trust us. §6 lists everything that does not exist.

3. What gets deleted

The right-hand column is not a promise written for this page. It is what the system already does, on a schedule, without being asked. The bracketed names are the ones a purge receipt uses when it records the destruction.

WhatWhen it goes
The content of your email, and attachments as they arrive from Gmail Never stored. Documents pass through memory while being read and are never written to disk — there is nothing to delete
The documents we produced, and the data read out of them (artifact, extracted_json) At most 3 hours from the scan, then hard-deleted — whether or not the business collected them
Your mailbox access credential (oauth_grant) Destroyed when processing finishes or when you withdraw, whichever is first. A refusal on the approval page destroys it in the same request
The identity details used to derive statement passwords — name, PAN, date of birth, mobile (identity) Destroyed when the consent link expires, which is typically well before any document does
Your email address Never stored. No table in the system has a column for one — the request is keyed by the business's own reference for you, not by your address

Deletion is verified rather than assumed. A receipt is written for every purge, naming the request, the moment it happened, how many documents went, and which of artifact, extracted_json, oauth_grant, identity were destroyed. Ask us for it in writing; there is no endpoint that serves one (§6).

4. What we keep, and why

One thing survives deletion, and it is deliberately the one thing that carries none of your content: an append-only, hash-chained ledger of what was done.

Its entries record that consent was granted or refused, that access was sealed and later destroyed, that a scan started, finished or failed, that documents were handed over, and that they were later purged. They contain no email content and no document content. An entry holds event names, timestamps, counts and outcome codes — nothing else. The detail field is not free-form: a key that would carry mail content, a credential or identity material is dropped rather than redacted, because a row recording the shape of a leak is still a record of one.

Each entry commits to the one before it, so removing or editing history breaks the chain at a point an auditor can name. That is the whole reason it is kept. A deletion claim nobody can check is not a control, and this ledger is how someone who is not us can establish that the three hours above were real.

Alongside it, a purged request keeps its counts — how many documents of each type the scan found — so the business that asked can still tell "your documents expired" apart from "nothing was ever there". Those counts carry no document content, and the documents themselves are omitted entirely once purged.

Where a law or a regulator requires us to retain something for longer, we will tell you what and why rather than deleting quietly around it.

5. What we cannot delete for you

Documents already handed to the business you approved sit in that business's systems, under its own privacy policy and its own retention rules. Deleting our copy does not delete theirs, and withdrawing your consent with us cannot recall a file already delivered. To have their copy deleted, ask that business directly.

Being precise about the limits of that, because it is where a page like this usually overclaims:

  • There is no mechanism by which we notify a business of your deletion request. If one is built, it will be described here.
  • No partner business is live today — FinLens has not delivered a document to any client (Trust & Security §13). If nothing was ever delivered, there is nothing sitting anywhere else.
  • Your own mailbox is untouched either way. Deleting data at FinLens deletes nothing from Gmail, and we never had the ability to.

6. What does not exist

Listed rather than left to be discovered, in the same spirit as Trust & Security §14. None of the following is built, and re-reading this page after one is built is the only way it should ever appear here.

  • No self-serve deletion portal. There is no FinLens account and nothing to log into. The B2B model has no end-user login.
  • No delete button and no automated request flow. Deletion is a request to the address in §2.
  • No data export. There is no route that returns what we hold to an end user, and no consent dashboard.
  • No purge-receipt endpoint. Receipts are written internally to the ledger in §4; no route serves one, and the integration docs tell partners the same thing.
  • No record of you if no business asked. A request exists only because a business created one for you. If none did, we hold nothing about you at all.
  • No long-term store to delete from. That is the point rather than a gap: the shortest retention period is the one you do not have to trust us to honour.

7. When each of these happens

StepWhen
Access removed at GoogleImmediately, and it does not depend on us
Declining on the FinLens approval pageThe credential is handed back to Google and destroyed in the same request
The documents and the data read out of themGone at most 3 hours after the scan, on a scheduled sweep rather than on request
The sealed identity detailsGone when the consent link expires
Your written request to usAcknowledged, then answered within the time the DPDP Act allows
Written confirmation of what was held and what was destroyedSent when we answer

No faster figure is published for the last two rows, because none is set. When a response commitment exists it will be stated here as a commitment, not implied by a table.

8. Grievances & your rights under the DPDP Act

India's Digital Personal Data Protection Act, 2023 gives you rights over the data we hold about you. You can:

  • ask what we hold and what we did with it;
  • ask us to correct identity details;
  • ask us to destroy what we hold — that is what this page is the route for;
  • raise a grievance with the officer below;
  • nominate someone to exercise these rights for you.

Privacy Policy §12 sets them out in full.

If you raise a grievance and it is not resolved, you can complain to the Data Protection Board of India. That route is open to you independently of anything we say here.

Grievance officer (DPDP) · Suraj Agarwalla — suraj@maximoney.in
Privacy questions · privacy@finlenstech.com
Security reports · security@finlenstech.com

For the full account of what is collected, who receives it and how long anything is kept, see the Privacy Policy. For the terms you accepted on the way through, see Terms of Service. For who operates FinLens, see About.

Value Garage Private Limited · CIN U66190DL2025PTC453505
Registered office: Flat no. 26, Vandana Apartment, East Delhi, Delhi, India — 110092