Trust & transparency

Exactly who can see your data, and exactly what they get

This page is the living register of FinLens's commitments: what we read, what we refuse to read, every application that can receive your insights, and the controls that let you walk away at any time.

Four commitments, enforced in architecture

The interface through which data leaves our parsing environment has no data type for raw email — so these are not promises to behave, they are things the system cannot do.

NEVER

Expose raw email

No bodies, subjects, sender addresses, attachments, or passwords ever reach any partner application — on any tier, for any reason.

NEVER

Sell data or serve ads

No data sales, no advertising, no retargeting. Data flows only to apps you approved, for the feature you approved.

NEVER

Credit or lending use

Your data is never used to determine credit-worthiness and never provided to lenders. It's excluded from our catalog and contracts.

NEVER

Train AI on your email

No generalized AI/ML models are trained on email content. Anything personalized is computed for you alone and deleted with you.

What we read — and what we don't

FinLens fetches mail only from a curated, versioned registry of verified financial institutions. Every message must pass sender authentication (DKIM/SPF) before it is parsed — a spoofed "bank email" never enters your financial graph.

We read (sender-verified only)We never fetch
Bank & credit-card statements and alertsPersonal conversations and personal mail
Consolidated account statements (eCAS/CAS from depositories & registrars)Work email, newsletters, promotions from non-financial senders
Insurance policies, premium notices, renewal remindersAnything from senders not on the registry
Loan, EMI & mandate (auto-debit) notificationsAnything that fails DKIM/SPF sender authentication
Loan statements & sanction lettersCredit-bureau scores or reports — we read only the bureau's enquiry alerts, to warn you, and never use them for lending decisions
Bills, receipts, and subscription confirmations from registered billers— and we hold read-only scope: we cannot send, alter, or delete mail
Before you connect, the consent screen links the full institution list, so you can see every sender we would read — and the same list is available any time in your portal.

Live partner applications

Every application that can request access to FinLens insights is listed here, by name, with the exact data tier it receives. An application you haven't individually approved receives nothing — regardless of what's listed here.

No external partner applications are live yet

FinLens is currently in its pre-launch phase. When partner applications go live, each will appear here with its name, the data tier it receives (insights-only or normalized records), and the date it was onboarded. This register updates before an application can request its first consent.

Data tierWhat an approved app receivesReview required
Tier A — defaultDerived insights and display-safe evidence summaries onlyStandard onboarding, Limited-Use flow-down contract
Tier B — restricted+ normalized accounts, transactions, holdings (never raw email)Enhanced review, explicit enumerated consent shown to you, annual re-attestation

Your controls

Everything below is self-serve in the FinLens portal — no partner app required, no support ticket, no waiting.

See & revoke every consent

One dashboard lists your mailbox connection and every app you've approved, with the exact consent text you saw. Revoke any app individually — sharing stops within a minute, your mailbox stays connected. Or disconnect the mailbox entirely.

Export everything

Download your structured records, insights, and full consent history as JSON/CSV at any time — your DPDP right of access, self-serve.

Delete everything

One button erases your data: structured records within 24 hours, stored documents within 72 hours, encrypted backups age out within 35 days. Deletion is verified per store and receipts are available on request.

Dispute any insight

Every insight shows its evidence ("because…"). If something's wrong, one tap suppresses it and files a content-free report that improves the parser — without exposing your data to anyone.

Security posture

Sub-processor register

Infrastructure providers that process data on our behalf. Any addition is published here before use, with notice in the portal.

ProviderPurposeLocationData exposure
[Cloud provider — GCP planned]Hosting, storage, queuesMumbai (asia-south1)Encrypted at rest & in transit; provider holds no decryption keys for vault secrets
Document OCR runs on FinLens's own infrastructure — no third-party OCR service. No AI/LLM vendor is engaged.

If something goes wrong

Questions about anything on this page: privacy@finlens.example · Full details in our Privacy Policy.