Clarity — Privacy Policy
Clarity is a personal finance app that helps you understand your money by automatically detecting transactions from your bank SMS and payment notifications. This policy describes exactly what data Clarity reads, what it stores, what leaves your device, and what never does. It is written to be literally true of the app's code.
Your SMS messages are read and parsed only on your device. The text of an SMS never leaves your phone.
What Clarity reads
- Transactional SMS from bank sender IDs (for example VK-HDFCBK, AD-AXISBK, VA-CANBNK). Clarity identifies bank senders using a curated list and ignores everything else.
- Payment-app notifications from a small whitelist of payment packages — never WhatsApp, Gmail, social, or personal messaging apps.
- Clarity never reads, stores, or transmits personal SMS conversations. A message from a person (not a recognized transactional sender) is not processed.
How processing works
- An SMS arrives. Parsing happens entirely on your device — no SMS text is sent to any server, including ours.
- If the message is a recognized bank transaction, Clarity extracts only the transaction fields: amount, merchant name, date/time, transaction type, payment rail (UPI/NEFT/IMPS/ATM), the last 4 digits of the account or card, and the bank-stated balance when present.
- A one-way SHA-256 fingerprint (hash) of the message is computed for duplicate detection. The hash cannot be reversed into the message text.
- The extracted fields and the hash are saved to your private, authenticated cloud space. The raw message text is then discarded.
What is stored in the cloud
Stored in your login-protected account (row-level security — only your authenticated session can read your rows):
- Parsed transactions: amount, merchant, category, date, type, rail, last-4 digits, sender ID, the SHA-256 hash, and bank-stated balance figures.
- Your accounts and cards as you confirmed them (bank name, last 4 digits, nicknames, colors) — never full account or card numbers, which Clarity never sees in the first place (bank SMS are already masked).
- Your goals, settings, plan status, and (if you enable Family Mode) your family membership.
What stays on your device only
- Raw SMS text — never uploaded, in any form.
- The on-device sample corpus used to improve detection accuracy: “Transactional SMS samples are retained on your device to improve detection accuracy and are never uploaded.”
- Learned parsing templates created when you tag a transaction. Only anonymized, generalized patterns (regular expressions with all numbers, names, and identifiers removed) could ever be synced — never message text.
What Clarity never does
- Never sells or shares your data with third parties.
- Never uses your data for advertising.
- Never transmits SMS text, notification text, contacts, or personal messages off the device.
- Never reads messages from senders it does not recognize as transactional.
Permissions and why
- READ_SMS / RECEIVE_SMS — the core of the product: automatic transaction tracking from your bank's SMS.
- Notification access — to detect transactions from whitelisted payment apps only.
- Battery-optimization exemption (requested) — so transaction detection keeps working in the background without gaps.
Gmail statement reading (optional, early access)
If you sign in with Google, you can optionally connect Gmail so Clarity reads your credit-card statement emails and fills in your card dues.
- Opt-in only. Nothing is read until you tap Connect and approve Google's read-only permission. You can disconnect inside the app at any time, and you can revoke the permission at myaccount.google.com → Security.
- Statement emails only. Clarity searches only for statement notifications from recognized card issuers (for example HDFC Bank, Axis Bank, SBI Card). No other email is opened, and personal mail is never touched.
- Read on your device. Statement emails are fetched and parsed on your phone. Their content is never sent to any server — including ours — and is discarded the moment parsing finishes.
- What is kept: only the parsed statement facts — which card (bank + last 4 digits), total amount due, minimum due, statement date, and payment due date — plus a one-way fingerprint of the email's ID for duplicate detection. Attachments are never downloaded.
Crash reports
If the app crashes, an anonymous crash report (the technical stack trace, device model, and OS version) is sent to our crash-reporting service so we can fix the problem. Crash reports contain no financial data, no message content, and no email address — application logs are explicitly excluded from them.
AI features (Sensei)
When you chat with Sensei, your question and a numeric financial context snapshot (balances, totals, goal progress — never SMS text) are sent to our AI providers to generate a reply. Chat history is stored in your private account space.
Data retention and deletion
- Your data remains in your account until you delete it.
- Deleting your account removes your cloud data; the local corpus is removed when you uninstall the app.
- To request deletion, contact support@privacy-clarityfinance.com.
Security
Cloud data is protected by authentication and row-level security; transport is TLS. On-device data uses Android app sandboxing; local transaction storage is encrypted at rest (SQLCipher).
Children
Clarity is not directed at children under 18.
Changes
We will update this page and the effective date when this policy changes. Material changes will be announced in the app.