Legal

Privacy Policy

How FinLens collects, uses, protects, retains, and deletes data — written to be read, not skimmed past.

Effective date: 13 July 2026 · Applies to the FinLens hosted Connect flow, the FinLens user portal, FinLens APIs & SDKs, and this website.

1. Who we are

FinLens is a product of Value Garage Private Limited (CIN U66190DL2025PTC453505), a company incorporated in India with its registered office at Flat no. 26, Vandana Apartment, East Delhi, Delhi — 110092 ("FinLens", "we", "us"). We operate a consented email-intelligence platform: with your explicit permission, we read financial emails in your mailbox, convert them into structured financial information, and show you — and applications you individually approve — insights about your own money.

Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), Value Garage Private Limited acts as the data fiduciary for the processing described here.

2. Data we collect

2.1 Account and identity data

2.2 Email-derived data

With your Layer-1 consent (§7), we access your mailbox read-only and fetch only messages from a curated registry of verified financial senders — banks, card issuers, insurers, mutual fund houses and registrars, depositories, NBFCs, and billers. From those messages we process:

Raw email (message bodies, attachments) is held transiently for parsing and automatically purged within 24 hours. We do not store email subjects, bodies, or sender addresses in our databases; our message index keeps only content-free processing metadata.

2.3 Statement passwords (optional)

Many Indian financial institutions password-protect statement PDFs using PAN- or date-of-birth-derived passwords. If you choose to provide this material, you do so on the FinLens hosted surface only — never inside a partner application. You can choose:

2.4 Consent and audit records

For every consent you give or withdraw we record the exact text shown (by content hash), its version and language, a timestamp, and a hashed IP address — so we can prove later precisely what you agreed to. We also keep an append-only, content-free audit log of system and human actions on your data.

2.5 Website and technical data

The hosted Connect flow and portal collect the minimum technical data needed to operate securely (session identifiers, device/browser class, security signals). This website works without advertising or cross-site tracking; we do not use third-party advertising or analytics trackers.

3. What we never do

These prohibitions are enforced in our architecture, not just our contracts. The interface through which data leaves our parsing environment has no representation for raw email — bodies, subjects, sender addresses, attachments, and passwords cannot be transferred to anyone, including our partners, by construction.

4. How we use data

We process your data for exactly three purposes:

Product improvement uses only aggregated, anonymized metrics (for example, parse success rates per document type) that cannot be traced to any individual and contain no email content.

5. Google user data & Limited Use

FinLens accesses Gmail data via the gmail.readonly scope together with basic identity scopes, through Google's OAuth consent. FinLens's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

6. Sharing & disclosure

6.1 Applications you approve

When you approve a specific application (Layer-2 consent, §7), that application receives derived insights and display-safe evidence summaries for you. Applications with an approved, user-facing need may — only under enhanced review and separate, explicit consent language shown to you at connection time — receive normalized financial records (accounts, transactions, holdings). No application can ever receive raw email content, and each application is identified to you by name before you approve it. The current list of live partner applications is published on our Trust page.

6.2 Service providers (sub-processors)

We use a small number of infrastructure providers to operate the platform (cloud hosting in the Mumbai region). The current register, and any future additions, are published on the Trust page before use. Sub-processors are bound by data-processing terms at least as protective as this policy.

6.3 Legal requirements

We may disclose data where required by law, regulation, or valid legal process, after reviewing the demand's validity and scope. Where lawful, we will notify you.

6.4 No other sharing

There are no other categories of sharing. We have no advertising partners, no data-broker relationships, and no lender data-feeds.

FinLens uses two independent consent layers:

What you approveHow to withdraw
Layer 1FinLens may read financial email in your mailbox (read-only), via Google's own consent screen.One click in the FinLens portal, or revoke FinLens in your Google account settings — both are honored.
Layer 2FinLens may share your derived insights with one named application.One click in the portal (or in that app). Sharing stops within one minute; your mailbox connection is unaffected.

Withdrawing consent is as easy as giving it, as the DPDP Act requires. If you revoke FinLens's access directly at Google, we detect it, treat it as withdrawal, pause all processing, and — after a 30-day re-link grace period — begin erasure automatically. After 12 months of inactivity we proactively ask you to re-confirm consent; if you don't, it expires.

8. Retention & deletion

DataKept
Raw email in processing≤ 24 hours, then automatically purged
Parsed source documents (your statements)Until you delete them or your account; you may opt for "extract-and-discard" instead
Structured records & insightsUntil deletion or consent withdrawal
Consent ledger & content-free audit logAt least 1 year (legal evidence; contains no email content)
Anonymized, aggregated statisticsIndefinitely (cannot be traced to you; anonymization spec is versioned and reviewed)

When you delete your data: structured records are removed within 24 hours, stored documents within 72 hours, and encrypted backups age out within 35 days. Deletion is verified, not assumed — our orchestrator collects a completion receipt from every store, and a weekly audit checks for orphans. You can request a deletion receipt from support.

9. Security

10. Data residency

Your data is stored and processed in the Mumbai region (asia-south1). We do not transfer personal data outside India in the ordinary operation of the service; if that ever changes, this policy and the Trust page will be updated first.

11. Your rights

Under the DPDP Act you have the right to:

12. Children

FinLens is not available to persons under 18. The connection flow includes an age gate; if it indicates you are a minor, no mailbox access is requested and no data is fetched.

13. Breach notification

In the event of a personal data breach, we notify the Data Protection Board of India and affected users within 72 hours of becoming aware, as required by the DPDP Act, including what happened, what data was involved, and what we are doing about it. We maintain a tested incident-response runbook and pre-drafted notification templates so that clock is met.

14. Changes to this policy

We will post any changes here with a new effective date, and for material changes we will notify you in the portal (and through partner applications where relevant) before they take effect. Consent text shown at connection time is versioned; a change in what you're asked to agree to always produces a new consent event, never a silent expansion.

15. Contact & grievances

Privacy questions: privacy@finlens.example
Grievance officer (DPDP): [name to be appointed] — grievance@finlens.example
Security reports: security@finlens.example

Value Garage Private Limited · CIN U66190DL2025PTC453505
Registered office: Flat no. 26, Vandana Apartment, East Delhi, Delhi, India — 110092