SpendYse
SMS Companion privacy policy
Effective 9 August 2026 · Last updated 12 August 2026
Purpose and scope
SpendYse SMS Companion is an optional Android companion that helps a user import financial transaction alerts into that user's private SpendYse family ledger. The direct-distribution build can receive newly delivered SMS after permission is granted. The Play-safe build does not request SMS access and contains no SMS receiver.
Data handled on the phone
The direct build requests only permission to receive new SMS. It does not read SMS history and cannot send SMS. New messages are checked against exact sender and bank-format rules chosen by the user. Messages that do not safely match are not uploaded.
Raw SMS text is kept only temporarily in process memory. At most the ten newest previews are shown; closing the process or using Clear all removes them. Raw SMS text is not written to preferences, files, logs, backups, format synchronization, or the durable outbox.
Saved phone data is limited to approved bank-format configuration, an encrypted pairing token, parsed transaction candidates waiting for secure retry, and the latest 100 privacy-safe synchronization diagnostics. Local diagnostics contain operation/result metadata and counts, not SMS bodies, transaction descriptions, amounts, account details, or credentials. Backup uses an include-only rule for bank-format preferences; pairing credentials, queued candidates, diagnostics, and SMS previews are excluded.
Data sent to SpendYse
For a safely matched alert, the companion can send the SMS sender, account hint, currency, amount, income or expense direction, merchant description, delivery time, and a duplicate-detection fingerprint. It also synchronizes bank-format configuration and device assignment. The raw SMS body is not sent.
SpendYse uses these fields only to prepare a review candidate or apply a user-enabled, safety-limited automatic rule. The service associates the result with the paired user and ledger, checks permissions, and keeps security and audit evidence. Production connections require HTTPS.
The companion also sends bounded synchronization diagnostics such as device operation, trigger, result, time, revision, object counts, and candidate-status change counts. SpendYse adds server-observed registration, configuration, candidate-upload, and status-refresh events. These diagnostics do not include raw SMS text, pairing tokens, authorization headers, descriptions, amounts, or account details.
SpendYse does not sell this data or use it for advertising. Hosting, database, and authentication providers may process data on behalf of the SpendYse operator only to provide and secure the service.
Controls, retention, and deletion
Users can clear in-memory previews, edit or remove bank formats, remove pairing from the phone, revoke or archive a device in SpendYse, reject pending imports, and pause or remove automatic rules. Removing pairing or revoking a device prevents further authenticated uploads.
The companion does not create a separate public account. SpendYse may retain transaction, candidate, device, and audit references needed for ledger integrity, security, and accountability after a device or rule is archived. A user can ask the family-ledger administrator or service operator to remove data that is not required for those purposes.
Local synchronization diagnostics can be cleared from Android. Server synchronization diagnostics remain available while a device is active, disconnected, or revoked, and are deleted when the owner uses Remove from list for that revoked device. Financial candidate, transaction, device-reference, and general audit evidence is preserved separately.
Security and children
Pairing tokens are encrypted with Android Keystore on the phone and stored as hashes on the server. Production pairing requires HTTPS. Server permissions remain authoritative even when a phone is paired.
SpendYse SMS Companion is intended for management of a private family ledger and is not designed for children or directed to children as a standalone service.
Contact
Privacy or deletion questions can be sent to nadeeka.adithya@gmail.com.
This policy must be reviewed whenever the app's data handling, hosting provider, embedded SDKs, or distribution method changes.