This page is the living register of FinLens's commitments: what we read, what we refuse to read, every application that can receive your insights, and the controls that let you walk away at any time.
The interface through which data leaves our parsing environment has no data type for raw email — so these are not promises to behave, they are things the system cannot do.
No bodies, subjects, sender addresses, attachments, or passwords ever reach any partner application — on any tier, for any reason.
No data sales, no advertising, no retargeting. Data flows only to apps you approved, for the feature you approved.
Your data is never used to determine credit-worthiness and never provided to lenders. It's excluded from our catalog and contracts.
No generalized AI/ML models are trained on email content. Anything personalized is computed for you alone and deleted with you.
FinLens fetches mail only from a curated, versioned registry of verified financial institutions. Every message must pass sender authentication (DKIM/SPF) before it is parsed — a spoofed "bank email" never enters your financial graph.
| We read (sender-verified only) | We never fetch |
|---|---|
| Bank & credit-card statements and alerts | Personal conversations and personal mail |
| Consolidated account statements (eCAS/CAS from depositories & registrars) | Work email, newsletters, promotions from non-financial senders |
| Insurance policies, premium notices, renewal reminders | Anything from senders not on the registry |
| Loan, EMI & mandate (auto-debit) notifications | Anything that fails DKIM/SPF sender authentication |
| Loan statements & sanction letters | Credit-bureau scores or reports — we read only the bureau's enquiry alerts, to warn you, and never use them for lending decisions |
| Bills, receipts, and subscription confirmations from registered billers | — and we hold read-only scope: we cannot send, alter, or delete mail |
Every application that can request access to FinLens insights is listed here, by name, with the exact data tier it receives. An application you haven't individually approved receives nothing — regardless of what's listed here.
FinLens is currently in its pre-launch phase. When partner applications go live, each will appear here with its name, the data tier it receives (insights-only or normalized records), and the date it was onboarded. This register updates before an application can request its first consent.
| Data tier | What an approved app receives | Review required |
|---|---|---|
| Tier A — default | Derived insights and display-safe evidence summaries only | Standard onboarding, Limited-Use flow-down contract |
| Tier B — restricted | + normalized accounts, transactions, holdings (never raw email) | Enhanced review, explicit enumerated consent shown to you, annual re-attestation |
Everything below is self-serve in the FinLens portal — no partner app required, no support ticket, no waiting.
One dashboard lists your mailbox connection and every app you've approved, with the exact consent text you saw. Revoke any app individually — sharing stops within a minute, your mailbox stays connected. Or disconnect the mailbox entirely.
Download your structured records, insights, and full consent history as JSON/CSV at any time — your DPDP right of access, self-serve.
One button erases your data: structured records within 24 hours, stored documents within 72 hours, encrypted backups age out within 35 days. Deletion is verified per store and receipts are available on request.
Every insight shows its evidence ("because…"). If something's wrong, one tap suppresses it and files a content-free report that improves the parser — without exposing your data to anyone.
Infrastructure providers that process data on our behalf. Any addition is published here before use, with notice in the portal.
| Provider | Purpose | Location | Data exposure |
|---|---|---|---|
| [Cloud provider — GCP planned] | Hosting, storage, queues | Mumbai (asia-south1) | Encrypted at rest & in transit; provider holds no decryption keys for vault secrets |
| Document OCR runs on FinLens's own infrastructure — no third-party OCR service. No AI/LLM vendor is engaged. | |||
Questions about anything on this page: privacy@finlens.example · Full details in our Privacy Policy.