Legal
Terms of Service
Draft of 10 August 2026 · An effective date will be set when these terms are published in
final form.
They apply to the FinLens connection flow — the pages you pass through after a business sends
you a FinLens link — and to this website.
FinLens collects financial documents out of your mailbox and hands them to the one business you named. These are the terms on which it does that, what we cannot promise, and how to stop it.
- Accepting these terms
- What FinLens does
- What FinLens is not
- Your age
- Your permission, and how to withdraw it
- Once documents are delivered
- What we cannot promise
- Accuracy of what we read
- Acceptable use
- Who owns what
- Limitation of liability
- Indemnity
- Stopping a request
- Businesses that integrate FinLens
- Governing law & jurisdiction
- Changes to these terms
- Contact, grievances & your rights
1. Accepting these terms
FinLens is a product of Value Garage Private Limited (CIN U66190DL2025PTC453505), a company incorporated in India with its registered office at Flat no. 26, Vandana Apartment, East Delhi, Delhi — 110092 ("FinLens", "we", "us"). These terms are an agreement between you — the person whose mailbox is read — and us.
They cover the FinLens connection flow: the link a business sends you, the Google sign-in step, the FinLens approval page that follows it, and the collection of documents that happens after you approve. They also cover this website. Google links to this page from its own consent screen when FinLens asks for access to your Gmail.
You accept these terms by continuing through that flow. If you do not accept them, close the page or decline on the approval page. Declining costs you nothing: no mailbox is read, no document is collected, and nothing is sent to anyone.
FinLens does not charge you anything. There is nothing for you to buy, subscribe to or cancel. Our commercial relationship is with the business that made the request, not with you.
Our Privacy Policy forms part of these terms. It sets out what we do with your data and how long anything is kept, and it carries our Limited Use commitments under the Google API Services User Data Policy. Where these terms and the Privacy Policy describe the same thing, read them together; nothing here reduces a commitment made there.
2. What FinLens does
A business you are already dealing with — a lender, an insurer, a broker or a similar firm ("the requesting business") — needs financial documents from you. Rather than have you find and upload them, it asks us to collect them from your mailbox with your permission. In order:
- The requesting business sends us your name, PAN, date of birth and mobile number — exactly those four fields, and nothing else — together with the kinds of document it needs. It receives a link, which it passes to you.
- You open the link and sign in with Google. Google's own consent screen asks whether you will give FinLens read-only access to your Gmail. This is Google's page, on Google's domain, and we never see your password.
- You then see a FinLens page that names the requesting business by its registered name, lists the document types it asked for, and states how far back we will look. Nothing is fetched until you approve. This is where you decide whether your documents go to that specific company — it is not a confirmation screen.
- We search your mailbox for PDF attachments from recognised financial senders only, and check that each message genuinely came from the institution it claims to. Anything else in your mailbox is never requested.
- Many Indian statement PDFs are password-protected. We try to open them using the four identity details the business already gave us, extract the text inside our own systems, and hand the business the documents and the information read out of them — on a link that stops working three hours after the documents exist. What we produced is then permanently deleted.
Be clear about what you are agreeing to. The purpose of FinLens is to give your documents to the business that asked for them. Your statements, and the account details inside them, reach that one named company — the one you approved — because that is the service you asked for. They reach nobody else.
3. What FinLens is not
There is no FinLens account and no user portal.
You do not sign up. There is no login, no dashboard and no settings page. Nothing durable of yours exists for us to show you — after three hours there is nothing left to show.
Access is one-off, not standing.
A request is a single collection, not ongoing monitoring. We do not watch your mailbox. Permission given for one request does not carry over to another; a new request means a new link and a new approval.
Read-only.
We cannot send, reply to, modify, delete or label your email, and we never ask for the ability to.
Gmail only.
No other mailbox provider is supported.
We do not assess you.
FinLens produces no score, rating, opinion, recommendation or advice about you, and takes no decision about you. It collects documents and hands them over. What the requesting business does with them afterwards is a matter between you and that business, under its own rules and its own regulator.
4. Your age
You must be 18 years of age or older to use FinLens, and you must be legally capable of entering into this agreement.
There is no age check in the connection flow, and we would rather say so than imply one. We never ask your age, and nothing on the approval page verifies it. The requesting business establishes who its customer is before it asks us for anything, and we rely on that. If you believe a request has been made in respect of someone under 18, tell us (§17). We will refuse the request and destroy anything we hold.
5. Your permission, and how to withdraw it
Your permission is asked for in two separate steps, and both must be given. Declining at either one stops everything.
| What you approve | How to withdraw | |
|---|---|---|
| Step 1 At Google |
That FinLens can read your Gmail, read-only, through Google's own consent screen. | Remove FinLens at myaccount.google.com/permissions. That takes effect at Google immediately and does not depend on us. Our own copy is destroyed when processing finishes or when its deadline passes, whichever comes first — and once you have removed access at Google, it cannot be used regardless. |
| Step 2 On the FinLens page |
That your documents go to one specific business, named on the page, for the document types listed there. | Decline on that page — nothing is fetched. If you have already approved, contact us (§17) while the three-hour window is still open. |
Withdrawing is as easy as giving permission. You do not have to give a reason, and you are not asked for one. Delete your data sets out both routes step by step.
Timing matters, and you should know it before you approve rather than afterwards. Withdrawal stops anything that has not yet happened, and causes us to destroy what we still hold. It cannot recall documents that have already been delivered — see §6. Because our own copy exists for at most three hours, there is no long-lived FinLens store for you to withdraw from later.
The link the business sends you expires. If yours has, nothing further happens on it, and you can ask the business for a new one.
6. Once documents are delivered
We cannot get them back. Once your documents and the information read out of them have been delivered to the requesting business, that business holds its own copy. It is held under its terms, its privacy policy and its retention rules — not ours.
Deleting our copy, which happens automatically within three hours, does not delete theirs. FinLens has no ability to recall, retrieve, alter or delete a document once it has left us. To have their copy deleted, or to ask what they did with it, you must ask that business directly.
This is not a limitation we chose to impose; it is what handing something over means. It is the reason the approval page names the business before anything is read.
7. What we cannot promise
FinLens is provided as is. We give no warranty that any particular document exists in your mailbox, will be found, or can be opened. The reasons are specific rather than boilerplate, and you are entitled to know them:
- We only look at PDF attachments from recognised financial senders. If your institution emails you a link to its portal instead of an attachment, or sends from a domain that is not in our registry, or the message fails the sender authentication check, we will not collect it.
- Some protected statements cannot be opened from four fields. We hold your name, PAN, date of birth and mobile number, and nothing else. Where a statement's password is keyed to a customer ID, a card number or a policy number, no combination of those four details will ever produce it. That affects retail banking and life insurance statements in particular.
- Some passwords are yours alone. Where you chose the password yourself, no derivation can reproduce it, and we do not try.
- Some documents cannot be read even once opened — a poor scan, an unusual layout, an image the extraction cannot resolve.
A document we cannot open is still delivered to the requesting business, unopened, with a specific reason attached naming what was missing. It is not silently dropped, and the reason is never a generic "locked".
We also make no promise about availability. There is no service level, no uptime commitment and no guaranteed completion time, and we hold no security certification today — what is built and what is not is set out plainly on our trust page. To the fullest extent permitted by law, we exclude implied warranties of merchantability, fitness for a particular purpose and non-infringement.
8. Accuracy of what we read
Alongside each document we deliver the information read out of it — for example the account holder's name, an account or policy number, the statement period, balances and transactions. This is machine-read from the page in front of it. It is not analysis, scoring or opinion, and it is not checked by a person, because no person at FinLens reads your documents.
Machine reading gets things wrong. A figure can be misread, a row missed, a layout misinterpreted. So:
- The source document governs. Where the extracted information and the PDF disagree, the PDF is correct and the extraction is not. We deliver both, deliberately, so that the original is always available to check against.
- We do not verify the contents of a document against the institution that issued it. Beyond confirming that the message carrying it was authenticated as coming from the sender it claims, we make no representation that a document is genuine, complete or up to date.
- If you spot an error in what was delivered about you, tell the requesting business — it holds the copy that matters — and tell us at privacy@finlenstech.com so we can correct the reading for everyone.
9. Acceptable use
Use FinLens only for a mailbox you control, and only for a request genuinely made of you. Specifically, you agree not to:
- Use FinLens for a mailbox that is not yours. Do not connect an account belonging to another person, whether or not you have their password, and whether or not they said it was fine. The permission we act on is the account holder's, given by the account holder.
- Misrepresent your identity, or complete a flow that was created in respect of somebody else.
- Use the service for any unlawful purpose, or to obtain documents you are not entitled to.
- Interfere with the service — probing, scanning, overloading, circumventing a security control, or attempting to reach data belonging to another user or another business.
- Copy, scrape, resell or reverse engineer the service or this website, or use automated means to interact with the connection flow.
Security researchers are welcome, and the interference clause does not cover them when they act in good faith within the scope described on our trust page. Write to security@finlenstech.com first, and never test against a real person's mailbox.
10. Who owns what
Yours stays yours. Your email and your documents belong to you. We claim no ownership of them and acquire no rights in them beyond the permission you give us to collect, open, read and deliver them for the one request you approved. We do not license them onward, and we do not keep them.
Ours stays ours. The FinLens software, the connection flow, this website, its text and design, and the FinLens and Value Garage names and marks are our property or licensed to us. These terms let you use the connection flow for its purpose, and nothing more — no licence to our software, brand or content is granted by implication.
Sections 11, 12 and 15 are incomplete on purpose. They are the clauses a lawyer must write rather than a draftsman, and they appear here so the page is whole rather than silently short. Each open point is marked [counsel to confirm] rather than invented.
Only one of the three is a figure — the liability cap in §11. The other two are judgements: whether an indemnity belongs in a consumer-facing agreement at all (§12), and whether Indian consumer legislation requires a step before court or preserves a forum nearer to where you live (§15). Nothing here is legal advice, and a placeholder is not a term you are agreeing to.
11. Limitation of liability
To the extent permitted by law, and subject to the paragraph below:
- We are not liable for indirect, incidental, special or consequential loss, or for loss of profit, revenue, business, goodwill or anticipated savings, arising out of or in connection with your use of FinLens.
- We are not liable for what the requesting business does with documents you approved sending to it, for its decisions, or for its handling, retention or disclosure of them (§6). That business is responsible for its own conduct under its own terms.
- We are not liable for a document that could not be found, opened or read (§7), or for an error in machine-read information where the source document was delivered alongside it (§8).
- Our total aggregate liability to you, for all claims arising out of or relating to these terms or your use of FinLens, is limited to [counsel to confirm].
Nothing in these terms limits or excludes any liability that cannot be limited or excluded under Indian law — including liability for fraud or fraudulent misrepresentation, for death or personal injury caused by negligence, and any liability arising under the Digital Personal Data Protection Act, 2023 or under consumer protection legislation. Where a mandatory statutory right applies to you, these terms give way to it.
12. Indemnity
You agree to indemnify us against claims, losses and reasonable costs arising from your use of FinLens in breach of §9 — in particular from connecting a mailbox you do not control, or from completing a flow created in respect of another person.
The precise scope of this indemnity, any monetary limit on it, and whether it is appropriate at all in a consumer-facing agreement of this kind, are [counsel to confirm]. It does not extend to anything arising from our own breach, negligence or unlawful act.
13. Stopping a request
Because there is no account, there is little to terminate — but to be complete:
- You end it at any time. Decline on the approval page, remove FinLens at myaccount.google.com/permissions, or simply do nothing and let the link expire. No notice is required and nothing is owed.
- We can refuse or stop a request. We do so where we reasonably suspect a breach of §9; where a request appears to have been made in respect of a person who did not authorise it or who is under 18; where the law requires it; or where a technical failure prevents us from completing it safely. When we stop a request, we destroy what we hold, and the requesting business is told that the request did not complete.
- Everything ends on its own. Each request expires by design: access is destroyed when processing finishes or you withdraw, and everything we produced is deleted within three hours. Sections 6, 7, 8, 10, 11, 12, 15 and this sentence survive it.
14. Businesses that integrate FinLens
These terms are for the person whose mailbox is read. They are not the terms on which a business uses FinLens. A business integrating FinLens contracts with Value Garage Private Limited separately, under the written agreement at Partner Terms, covering its own obligations, its data-protection responsibilities and its commercial arrangement with us. Nothing on this page governs that relationship, gives a business any right under it, or forms part of it.
If you are evaluating FinLens for a business, read Partner Terms and write to partners@finlenstech.com rather than relying on this page.
15. Governing law & jurisdiction
These terms are governed by the laws of India. Subject to the paragraph below, the courts at Delhi have exclusive jurisdiction over any dispute arising out of or in connection with them.
Two questions are open. Whether any step is required before a court is approached — mediation, for example, or another pre-litigation process under Indian consumer legislation. And whether a consumer keeps the right to bring proceedings before a forum closer to where they live, despite the clause above. Both are [counsel to confirm]. We have not named an arbitration forum or venue, because we will not put one in front of you before counsel has advised that it is appropriate and enforceable.
If you have a complaint, raise it with us first (§17). We would rather resolve it than argue about where to argue.
16. Changes to these terms
We update these terms from time to time. Any revised version is posted on this page with a new effective date, and the version in force when you complete a request is the version that governs that request. We do not apply a later version to something you already approved.
The text you are shown on the approval page is versioned separately. A change to what you are being asked to agree to always produces a new approval request — never a silent widening of one you already gave.
17. Contact, grievances & your rights
Write to us about anything on this page. If something has gone wrong, we would rather hear it from you and fix it.
General and privacy questions:
privacy@finlenstech.com
Grievance officer (DPDP): Suraj Agarwalla
— suraj@maximoney.in
Security reports:
security@finlenstech.com
Business enquiries:
partners@finlenstech.com
Your rights under the DPDP Act
India's Digital Personal Data Protection Act, 2023 gives you rights over the data we hold about you. You can:
- ask what we hold and what we did with it;
- ask us to correct identity details;
- ask us to destroy what we hold;
- raise a grievance with the officer named above;
- nominate someone to exercise these rights for you.
Privacy Policy §12 sets them out in full. Delete your data is the step-by-step route for erasure.
Two limits are worth stating here rather than leaving you to find them. Our retention is measured in hours, so the honest answer to most access requests is that nothing of yours was left by the time the request arrived. And documents already delivered to the requesting business must be requested from that business (§6) — we cannot reach them.
If a grievance is not resolved, you can complain to the Data Protection Board of India, independently of anything we say here.
Value Garage Private Limited · CIN U66190DL2025PTC453505
Registered office: Flat no. 26, Vandana Apartment, East Delhi, Delhi, India — 110092
For what we do with your data and your rights over it, see the Privacy Policy. To cut off access and have what we hold deleted, see Delete your data. For what is built and what is not, see the trust page.