Contents
1. Who we are
FinLens is a product of Value Garage Private Limited (CIN U66190DL2025PTC453505), a company incorporated in India with its registered office at Flat no. 26, Vandana Apartment, East Delhi, Delhi — 110092 ("FinLens", "we", "us"). We operate a consented email-intelligence platform: with your explicit permission, we read financial emails in your mailbox, convert them into structured financial information, and show you — and applications you individually approve — insights about your own money.
Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), Value Garage Private Limited acts as the data fiduciary for the processing described here.
2. Data we collect
2.1 Account and identity data
- Your Google account identifier and email address, received when you sign in with Google. The email address is stored encrypted; a one-way hash is used for lookups.
- A date-of-birth attestation, used once at connection time to confirm you are 18 or older. We store the attestation outcome, not your date of birth, unless you separately provide it for statement passwords (§2.3).
2.2 Email-derived data
With your Layer-1 consent (§7), we access your mailbox read-only and fetch only messages from a curated registry of verified financial senders — banks, card issuers, insurers, mutual fund houses and registrars, depositories, NBFCs, and billers. From those messages we process:
- Documents: bank and card statements, consolidated account statements (eCAS/CAS), insurance policy documents and premium notices, loan and mandate notifications, transaction alerts, bills and receipts.
- Structured financial records parsed from those documents: accounts (with masked numbers), transactions, holdings, policies, mandates, and recurring-payment series.
- Derived insights: the outputs of our analysis (for example, "you paid ₹1,770 in late fees this quarter"), with typed references to the records that support them.
Raw email (message bodies, attachments) is held transiently for parsing and automatically purged within 24 hours. We do not store email subjects, bodies, or sender addresses in our databases; our message index keeps only content-free processing metadata.
2.3 Statement passwords (optional)
Many Indian financial institutions password-protect statement PDFs using PAN- or date-of-birth-derived passwords. If you choose to provide this material, you do so on the FinLens hosted surface only — never inside a partner application. You can choose:
- Vaulted mode: stored as a top-tier secret in a dedicated, encrypted vault partition, used only to unlock your documents, never logged, never shared with anyone.
- Ephemeral mode: used in memory for the current batch of documents and immediately discarded.
2.4 Consent and audit records
For every consent you give or withdraw we record the exact text shown (by content hash), its version and language, a timestamp, and a hashed IP address — so we can prove later precisely what you agreed to. We also keep an append-only, content-free audit log of system and human actions on your data.
2.5 Website and technical data
The hosted Connect flow and portal collect the minimum technical data needed to operate securely (session identifiers, device/browser class, security signals). This website works without advertising or cross-site tracking; we do not use third-party advertising or analytics trackers.
3. What we never do
These prohibitions are enforced in our architecture, not just our contracts. The interface through which data leaves our parsing environment has no representation for raw email — bodies, subjects, sender addresses, attachments, and passwords cannot be transferred to anyone, including our partners, by construction.
- We never sell your data, and never use it for advertising or retargeting of any kind.
- We never use your data to determine credit-worthiness, and never provide it for lending decisions.
- We never train generalized AI or machine-learning models on your email content. Any personalization is computed for you alone, stored per-user, and deleted with your account.
- We never fetch personal, non-financial mail. Mailbox queries are scoped to the verified financial-sender registry, and only messages that pass sender authentication (DKIM/SPF) are processed.
- We never request more than read-only mailbox access, and we cannot send, modify, or delete your email.
- We never give partner applications your mailbox credentials or tokens, your raw email, or your statement passwords.
- Our staff never browse your email. Diagnostic access to the parsing environment requires a just-in-time grant approved by a second person, is time-limited, fully recorded, and logged immutably.
4. How we use data
We process your data for exactly three purposes:
- Providing the service to you: parsing your financial email into structured records and generating insights, shown to you in the FinLens portal and in applications you have individually approved.
- Security and integrity: fraud prevention, abuse detection, incident response, and auditability.
- Legal compliance: meeting obligations under applicable law, including the DPDP Act.
Product improvement uses only aggregated, anonymized metrics (for example, parse success rates per document type) that cannot be traced to any individual and contain no email content.
5. Google user data & Limited Use
FinLens accesses Gmail data via the gmail.readonly scope together with basic identity scopes, through Google's OAuth consent. FinLens's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Gmail-derived data is used only to provide user-facing features that are prominent to you in the requesting application.
- It is transferred only with your consent, to the application you approved, for that feature — or as necessary for security or to comply with law.
- It is never used for advertising, never sold, never used for credit or lending purposes, and never used to train generalized AI/ML models.
6. Sharing & disclosure
6.1 Applications you approve
When you approve a specific application (Layer-2 consent, §7), that application receives derived insights and display-safe evidence summaries for you. Applications with an approved, user-facing need may — only under enhanced review and separate, explicit consent language shown to you at connection time — receive normalized financial records (accounts, transactions, holdings). No application can ever receive raw email content, and each application is identified to you by name before you approve it. The current list of live partner applications is published on our Trust page.
6.2 Service providers (sub-processors)
We use a small number of infrastructure providers to operate the platform (cloud hosting in the Mumbai region). The current register, and any future additions, are published on the Trust page before use. Sub-processors are bound by data-processing terms at least as protective as this policy.
6.3 Legal requirements
We may disclose data where required by law, regulation, or valid legal process, after reviewing the demand's validity and scope. Where lawful, we will notify you.
6.4 No other sharing
There are no other categories of sharing. We have no advertising partners, no data-broker relationships, and no lender data-feeds.
7. Consent & withdrawal
FinLens uses two independent consent layers:
| What you approve | How to withdraw | |
|---|---|---|
| Layer 1 | FinLens may read financial email in your mailbox (read-only), via Google's own consent screen. | One click in the FinLens portal, or revoke FinLens in your Google account settings — both are honored. |
| Layer 2 | FinLens may share your derived insights with one named application. | One click in the portal (or in that app). Sharing stops within one minute; your mailbox connection is unaffected. |
Withdrawing consent is as easy as giving it, as the DPDP Act requires. If you revoke FinLens's access directly at Google, we detect it, treat it as withdrawal, pause all processing, and — after a 30-day re-link grace period — begin erasure automatically. After 12 months of inactivity we proactively ask you to re-confirm consent; if you don't, it expires.
8. Retention & deletion
| Data | Kept |
|---|---|
| Raw email in processing | ≤ 24 hours, then automatically purged |
| Parsed source documents (your statements) | Until you delete them or your account; you may opt for "extract-and-discard" instead |
| Structured records & insights | Until deletion or consent withdrawal |
| Consent ledger & content-free audit log | At least 1 year (legal evidence; contains no email content) |
| Anonymized, aggregated statistics | Indefinitely (cannot be traced to you; anonymization spec is versioned and reviewed) |
When you delete your data: structured records are removed within 24 hours, stored documents within 72 hours, and encrypted backups age out within 35 days. Deletion is verified, not assumed — our orchestrator collects a completion receipt from every store, and a weekly audit checks for orphans. You can request a deletion receipt from support.
9. Security
- Mailbox tokens and statement passwords are stored with AES-256-GCM envelope encryption, per-record keys wrapped by a managed KMS, rotated at most every 90 days.
- All systems that touch email content run in an isolated network boundary with no public ingress; data leaves it only through a typed, reviewed interface (§3).
- The platform is designed to OWASP ASVS Level 2 and undergoes an annual independent security assessment (CASA) as a Google restricted-scope application.
- Logs are content-free by construction; parsing of untrusted documents runs in sandboxed workers; webhooks and API calls are signed.
10. Data residency
Your data is stored and processed in the Mumbai region (asia-south1). We do not transfer personal data outside India in the ordinary operation of the service; if that ever changes, this policy and the Trust page will be updated first.
11. Your rights
Under the DPDP Act you have the right to:
- Access: a self-serve export of your structured records, insights, and consent history is available in the portal (JSON/CSV).
- Correction: dispute any record or insight ("Not right?") and have it corrected or suppressed.
- Erasure: delete everything, self-serve, at any time (§8).
- Grievance redressal: contact our grievance officer (§15); if unresolved, you may complain to the Data Protection Board of India.
- Nomination: nominate a person to exercise these rights on your behalf in case of death or incapacity.
12. Children
FinLens is not available to persons under 18. The connection flow includes an age gate; if it indicates you are a minor, no mailbox access is requested and no data is fetched.
13. Breach notification
In the event of a personal data breach, we notify the Data Protection Board of India and affected users within 72 hours of becoming aware, as required by the DPDP Act, including what happened, what data was involved, and what we are doing about it. We maintain a tested incident-response runbook and pre-drafted notification templates so that clock is met.
14. Changes to this policy
We will post any changes here with a new effective date, and for material changes we will notify you in the portal (and through partner applications where relevant) before they take effect. Consent text shown at connection time is versioned; a change in what you're asked to agree to always produces a new consent event, never a silent expansion.
15. Contact & grievances
Privacy questions: privacy@finlens.example
Grievance officer (DPDP): [name to be appointed] — grievance@finlens.example
Security reports: security@finlens.example
Value Garage Private Limited · CIN U66190DL2025PTC453505
Registered office: Flat no. 26, Vandana Apartment, East Delhi, Delhi, India — 110092