Legal
Privacy Policy
Effective date: 14 August 2026
Applies to the FinLens hosted connection flow, the FinLens API used by businesses
we work with, and this website.
Changed since the 8 August 2026 version: §2.1 now lists one
Google scope rather than three. openid and
email were removed — see §15.
FinLens reads financial documents out of your Gmail and hands them to one business you name. This page says what it takes, why, who receives it, how long it is kept, and how you get rid of it.
- What Google data does FinLens use? PDF attachments sent to you by recognised banks, card issuers, insurers, fund houses and other financial institutions, plus your Google account's identifier and email address. Nothing else in your mailbox is requested.
- Why? A business you are already dealing with asked you for those documents. FinLens fetches them so you do not have to find and upload them.
- Who else receives them? One business — the one named on the page where you approve. Nobody else. That transfer is the service, and §5 describes it.
- How long is anything kept? The source email is never stored. The documents we produce are deleted after three hours.
- Does a person read it? No. No person at FinLens reads your email or your documents, and there is no manual-review step.
- How do I get rid of it? Remove FinLens at myaccount.google.com/permissions, then write to privacy@finlenstech.com. Full route: Delete your data.
Limited Use. FinLens's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. §2 sets out each scope, why it is needed, and what happens to the data received under it.
- Who we are
- Google user data & Limited Use
- How FinLens works
- Data we handle
- Who receives your documents
- What we use data for
- What we never do
- Your permission, and withdrawing it
- How long we keep things, and deletion
- How your data is protected
- Where your data is
- Your rights under Indian law
- Children
- If there is a breach
- Changes to this policy
- Contact & grievances
1. Who we are
FinLens is a product of Value Garage Private Limited (CIN U66190DL2025PTC453505), a company incorporated in India with its registered office at Flat no. 26, Vandana Apartment, East Delhi, Delhi — 110092 ("FinLens", "we", "us").
A business you are already dealing with — a lender, an insurer, a broker or a similar regulated firm — asks you for financial documents. This policy calls it the requesting business. Rather than you hunting for those documents and uploading them, you give FinLens permission to fetch them from your Gmail and hand them to that business.
We decide how your mailbox is read, what is taken out of it and how long anything is kept, and we ask your permission directly. The requesting business decides what it does with the documents once we have handed them over; its own privacy policy governs that, not this one. §12 sets out how India's data protection law divides responsibility between us, and the rights you hold against us.
2. Google user data & Limited Use
Limited Use. FinLens's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2.1 The scope we ask for, and why
One scope, requested through Google's own OAuth consent screen. No other Google scope is requested. Access is refused if gmail.readonly is not granted.
| Scope | What it allows | Why FinLens needs it |
|---|---|---|
| gmail.readonly | Reads mail and attachments. It cannot send, modify, label or delete anything | Fetching the PDF attachments the requesting business asked for. The attachment is the thing being delivered |
2.2 Why nothing narrower works
The attachment is the product, which rules out the lesser Gmail scopes:
- gmail.metadata cannot read attachment bodies. Under it we could see that a bank had sent you a message with an attachment, and could never obtain a single byte of that attachment. It does not give a reduced version of this service — it gives none of it.
- The add-on scopes apply to a message you have open in the Gmail interface. FinLens has no Gmail interface, and the search runs on our own servers after you have closed the browser.
- gmail.modify and full mailbox access are wider, not narrower. We never need to write to your mailbox, and never ask to.
gmail.readonly is the narrowest scope that can return an attachment.
2.3 What happens to the data, including the transfer
FinLens sends document content to a third party. The PDFs we fetch from your Gmail, and the information we read out of them, go to the requesting business. That is not a side effect of the service — it is the service, and it is the thing you approve on a FinLens page that names that business before anything is fetched.
- Use. Gmail data is used for one purpose: finding, opening and reading the financial documents the named business asked for, and delivering them. You are told what that means in plain terms before you approve it.
- Transfer. To that one named business, with your explicit approval given on a page that identifies it, and for that purpose — or as necessary for security or to comply with law. To nobody else.
- Never. Never for advertising. Never sold. Never used by us for credit or lending decisions. Never used to train AI or machine-learning models.
- No people. No human at FinLens reads your Gmail data, and no third party processes it on our behalf.
3. How FinLens works
The whole flow, in order:
step 1 · the business asks
It sends four fields, and nothing else
The requesting business sends us your name, PAN, date of birth and mobile number — nothing else — and says which kinds of document it needs. It gets back a link, which it passes to you.
step 2 · consent at google
You authorise Google
You open the link and sign in with Google. Google's own consent screen asks whether you will give FinLens read-only access to your Gmail. Say no, and nothing happens.
step 3 · consent at finlens
You approve that one business, by name
You then see a FinLens page. It names the business by its registered name, lists the document types it asked for, and states how far back we will look. Nothing is fetched until you approve there. This is not a confirmation screen — it is where you decide whether your documents go to that specific company.
step 4 · the search
We look for financial PDFs, and nothing else
We ask Gmail for PDF attachments from recognised financial senders only, then check that each message genuinely came from the institution it claims to. Anything else in your mailbox is never requested.
step 5 · unlock
We open what we can, and say what we could not
Many Indian statement PDFs are password-protected using your PAN or date of birth. We try to open them with the details the business gave us in step 1. If a document needs an identifier we do not have — a customer ID, a card number, a policy number — we hand it over unopened and say exactly which one was missing.
step 6 · hand over, then delete
The link stops working after three hours
We hand the requesting business the documents and the information read out of them, on a link that stops working after three hours. Everything we produced is then permanently deleted.
Be clear about what this means: the point of FinLens is to give your documents to the business that asked for them. Your statements, and the account details inside them, reach that one named company — the one you approved in step 3 — because that is the service you asked for. They reach nobody else.
4. Data we handle
4.1 Identity details, from the requesting business
We receive your name, PAN, date of birth and mobile number from the business making the request. We do not ask you for them, and we collect no others. They serve one purpose — deriving the passwords that open protected statements — and are held encrypted for the life of the request. When the link expires, they are destroyed with it.
4.2 Your Google account
When you sign in we receive your Google account identifier and email address, and a read-only Gmail access credential. The credential is held encrypted and is destroyed when the search finishes or when you withdraw — whichever comes first.
4.3 What we read from your mailbox
We fetch only PDF attachments, and only from senders in a curated registry of financial institutions — banks, card issuers, insurers, mutual fund houses and registrars, depositories, NBFCs. The limit is applied in the query itself, so messages outside it are never retrieved rather than retrieved and discarded. We do not read personal mail, and there is no query we could run that would return it.
How far back we look depends on what the business asked for:
| Scope | How far back |
|---|---|
| Recognised financial senders generally | 18 months |
| Institutions the business named specifically | Your full history with those institutions |
| Insurers | Full history |
Whatever the scope works out to, it is stated on the approval page in plain terms before you approve it.
A message addressed from a bank is not proof it came from one. After fetching, we check each message's cryptographic sender authentication (DKIM, or SPF for government senders that do not publish DKIM). Messages that fail are dropped.
4.4 What we produce
The documents themselves
Unlocked where we could open them, in their original form where we could not.
Information read out of them
For example account holder name, account or policy number, statement period, balances, transactions and holdings. This is machine-read from the document; it is not analysis, scoring or opinion.
Text is extracted inside our own systems. No third party ever receives your document — there is no external reader, no cloud service and no vendor in that step — and no person reads your documents at any point. There is no manual-review stage in the process at all.
4.5 Records we keep of what we did
We keep an append-only, tamper-evident log of the actions taken on each request — that consent was granted or refused, that access was sealed and later destroyed, that a search started, finished or failed, and that documents were handed over. Each entry is chained to the one before it, so a deletion or alteration is detectable. These entries contain no email content: they hold event names, timestamps, counts and outcome codes, and the system drops any field that would carry mail content rather than trusting itself not to write one.
4.6 Website and technical data
The connection flow collects the minimum technical data needed to operate securely — a session identifier and basic security signals. This website has no advertising, no cross-site tracking and no third-party analytics trackers.
5. Who receives your documents
5.1 The business you approved
One business receives your documents and the information read out of them: the one named on the approval page, which asked for them, and which you approved. It receives them on a link that expires after three hours. It does not receive your Google credential, your mailbox access, your email subjects or sender addresses, or the passwords used to open your files.
Once documents have been delivered, that business holds a copy under its own privacy policy and its own retention rules. Deleting our copy does not delete theirs — to have theirs deleted, ask them.
5.2 Service providers
We use infrastructure providers to run the platform (cloud hosting in India). Document reading and text extraction happen on our own systems. There is no third-party document-processing or OCR vendor in the pipeline, and no external service ever receives your documents.
5.3 Legal requirements
We disclose data where a law, a regulation or valid legal process requires it, after reviewing the demand's validity and scope. Where lawful, we tell you.
5.4 No other sharing
There are no other categories of sharing. We have no advertising partners, no data-broker relationships and no lender data-feeds.
6. What we use data for
Three purposes, and no others:
- Fulfilling the request you approved: finding the documents, opening them, reading them, and delivering them to the business you named.
- Security and integrity: abuse detection, and keeping the tamper-evident record described in §4.5.
- Legal compliance: meeting our obligations under applicable law.
Product improvement uses only aggregated counts that cannot be traced to any individual and contain no document content — for example, how often a given statement format could be opened successfully.
7. What we never do
Some of these are enforced by the code, not only by policy. The interface through which anything leaves our systems has no field for a subject line, a sender address, a filename, a Gmail message id, your Google credential or a derived password. A test walks every response we can produce and fails the build if one of those ever appears.
Your documents are the deliberate exception, and only towards the single business you named. Everything above stays behind the boundary regardless of who is asking.
- We never sell your data, and never use it for advertising or retargeting of any kind.
- We never use your data to determine credit-worthiness, and never provide it for lending decisions. What the requesting business does with documents you agreed to send it is governed by its own policy and its own regulator.
- We never train AI or machine-learning models on your email or your documents.
- We never fetch personal, non-financial mail. Queries are limited to PDF attachments from the registry of recognised financial senders, and messages that fail sender authentication are dropped.
- We never request more than read-only mailbox access. We cannot send, modify, delete or label your email.
- We never give the requesting business your Google credential, your mailbox access, your email subjects or sender addresses, or the passwords derived to open your documents.
- We never share your documents with any party other than the one business you approved by name.
- No person at FinLens reads your email or your documents. The extraction software runs without network access, and there is no human review step in the pipeline.
8. Your permission, and withdrawing it
Your permission is asked for in two separate steps, and both must be given:
| What you approve | How to withdraw | |
|---|---|---|
| Step 1 At Google |
Read-only access to your Gmail for FinLens, through Google's own consent screen. | Remove FinLens at myaccount.google.com/permissions. That takes effect at Google immediately and does not depend on us. Our own copy of the credential is destroyed when processing finishes or when its deadline passes, whichever comes first — and once revoked at Google it can no longer be used regardless. |
| Step 2 On the FinLens page |
That your documents go to one specific business, named on the page, for the document types listed there. | Decline on that page — nothing is fetched. After approval, contact us (§16) while the three-hour window is open. |
Withdrawing is as easy as giving permission. If you decline at either step, no documents are fetched and nothing is delivered.
Timing matters, and we would rather say so than let you find out. Withdrawal stops anything that has not yet happened, and causes us to destroy what we still hold. It cannot recall documents already delivered to the requesting business — for those, ask that business directly. Because our own copy exists for at most three hours (§9), there is no long-lived FinLens store for you to withdraw from afterwards.
9. How long we keep things, and deletion
9.1 What is kept, and for how long
| Data | Kept |
|---|---|
| Email content and attachments as they arrive from Gmail | Never stored. Documents pass through memory while being read and are never written to disk |
| Your identity details (name, PAN, date of birth, mobile), used only to open protected statements | Encrypted, and destroyed when the request's link expires |
| The documents and extracted information we produce | At most 3 hours, then permanently deleted |
| Mailbox access credential | Encrypted, and destroyed when processing finishes or you withdraw — whichever is first |
| Tamper-evident record of actions taken (§4.5) | Retained as legal evidence; contains no email or document content |
We never retain the content of your email, and anything we derive from it lives at most three hours. After that window it is deleted whether or not the requesting business collected it. Deletion is verified, not assumed — a completion record is written for every purge, and a sweep runs on a schedule rather than on request. You can ask us for a deletion receipt.
9.2 How to have your data deleted
Two steps, in this order:
- Remove FinLens's access at Google — myaccount.google.com/permissions. This happens at Google, takes effect immediately, and does not wait on us.
- Write to privacy@finlenstech.com with the subject Delete my data, and tell us which business asked you for documents. We will confirm in writing what was held and what was destroyed.
The full route — including what a deletion request reaches, what it cannot reach, and what survives it — is on Delete your data.
There is no long-term store to delete from, which is the point: the shortest retention period is the one you do not have to trust us to honour.
10. How your data is protected
- Encryption. Mailbox credentials, identity details and stored documents are encrypted with AES-256-GCM envelope encryption under per-record keys. Each record's ciphertext is cryptographically bound to that record, so a value lifted from one row cannot be replayed into another. The master key is held by a managed key service, operated by Google in India, rather than by the application itself — and each service refuses to start in production without one.
- Separation between businesses. Every business we work with is isolated from every other at the database itself, not only in application code, so one client's request cannot reach another's data even if the application were wrong.
- The document systems cannot be reached. The systems that handle documents accept no inbound network connections at all — they claim work from a queue rather than being called. Documents are streamed through memory and never written to disk. Text extraction runs on our own systems, and no third party ever receives a document.
- Logs cannot carry content. The logger drops fields that would carry mail content, credentials or identity material, rather than relying on discipline to keep them out.
- Signed requests. API requests and outbound notifications are cryptographically signed. Credentials held for verification are stored encrypted, not in a form that could be used to impersonate us or a client.
- Assessment. The platform is designed against OWASP ASVS Level 2. As a Google restricted-scope application, FinLens is subject to independent security assessment (CASA); we will not describe an assessment as complete before one has been completed.
11. Where your data is
Your data is stored and processed in India. We do not transfer personal data outside India in the ordinary operation of the service; if that ever changes, this policy will be updated before it does.
12. Your rights under Indian law
India's Digital Personal Data Protection Act, 2023 ("DPDP Act") governs this processing. This section holds the parts of it that decide what you can ask for and whom you ask.
12.1 Who is answerable for what
Value Garage Private Limited is a data fiduciary for the processing described in this policy: we decide how your mailbox is read, what is extracted and how long anything is kept, and we ask for your permission directly. The requesting business is a separate data fiduciary for what it does with the documents after we hand them over — its own privacy policy governs that, not this one.
12.2 What you can ask us for
- Access: ask us what we hold about you and what we did with it. Because our retention is measured in hours, in most cases the honest answer will be the record described in §4.5 and nothing more.
- Correction: ask us to correct identity details we hold. These come from the requesting business, so a lasting correction means correcting them there too.
- Erasure: ask us to destroy what we hold, at any time (§9.2). Documents already delivered to the requesting business must be requested from that business (§5.1, §8).
- Nomination: nominate a person to exercise these rights on your behalf in case of death or incapacity.
Write to us at the address in §16 and we will respond within the time the DPDP Act allows.
12.3 Grievances
Raise a grievance with our grievance officer, whose address is in §16. If we do not resolve it, you can complain to the Data Protection Board of India — a route open to you independently of anything we say here.
13. Children
FinLens is not intended for persons under 18. Requests come to us from regulated businesses that have already established their customer's identity, including age, before asking for documents. If you believe a request has been made in respect of a minor, contact us (§16) and we will destroy anything held and refuse the request.
14. If there is a breach
If a breach involves your personal data, we tell you without delay — there is no 72-hour grace period for telling you, and we do not claim one. You will get a description of what happened, what data was involved, the consequences likely to affect you, what we are doing about it, what you can do to protect yourself, and a named person who can answer questions.
The Data Protection Board of India is notified on a separate schedule: an initial description without delay, and full detail within 72 hours of our becoming aware. Affected requesting businesses are notified in parallel.
This paragraph used to say we would notify you within 72 hours, "as the DPDP Act requires". Both halves were wrong and we are saying so rather than quietly editing. The 72-hour figure comes from the Digital Personal Data Protection Rules, 2025, not the Act — and it applies only to the detailed report we owe the Board. Rule 7(1) gives us no deadline for telling you other than "without delay", which is stricter. We had published a weaker promise to you than the law will require of us.
Those Rules take effect in May 2027. We hold ourselves to this now.
15. Changes to this policy
We will post any changes here with a new effective date. The text shown to you on the approval page is versioned; a change to what you are asked to agree to always produces a new approval request, never a silent expansion of an old one.
14 August 2026 — we now ask for one Google scope instead of three. The previous version of §2.1 listed openid and email alongside gmail.readonly, and said the email scope existed so that you could be told which mailbox was connected. We audited that claim and it was not true of the running service: nothing in FinLens ever read the address, and no screen ever showed it to you. Rather than build the feature to match the wording, we removed both scopes, because a permission held against a use nobody has specified is a permission that should not be asked for. FinLens now requests gmail.readonly and nothing else. This is a narrowing — it takes access away from us and gives none to anyone — so it required no new approval from you, but it is recorded here because you were told something inaccurate and are entitled to know it was corrected.
16. Contact & grievances
Privacy questions · privacy@finlenstech.com
Grievance officer (DPDP) · Suraj Agarwalla — suraj@maximoney.in
Security reports · security@finlenstech.com
Value Garage Private Limited · CIN U66190DL2025PTC453505
Registered office: Flat no. 26, Vandana Apartment, East Delhi, Delhi, India — 110092