🔒 Your Data, Your Control

Privacy Policy

Last updated: June 23, 2026 — This policy is governed by the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 (India). Data security practices follow globally recognised standards.

1

Data Fiduciary Information

Under Section 2(i) of the Digital Personal Data Protection Act, 2023 (DPDP Act), Spendwisee operates as a Data Fiduciary — the entity that determines the purpose and means of processing your personal data.

Entity: Spendwisee
Registered in: India
Contact: feedback@spendwisee.com
Grievance Officer: feedback@spendwisee.com

This policy is published in compliance with DPDP Act Section 5 (obligation of Data Fiduciary), Section 6 (consent), and Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

2

Information We Collect

👤 Account Information (Personal Data)

Name, email address, and authentication credentials collected during sign-up. If you use Google Sign-In or Apple Sign-In, we receive your profile name and email from the identity provider. Under DPDP Act Section 2(t), this constitutes personal data.

💰 Financial Data (Sensitive Personal Data or Information)

Expenses, budgets, savings goals, investments, income data, and payment method preferences — all manually entered by you. Under the IT (Reasonable Security Practices) Rules, 2011 — Rule 3, financial information qualifies as Sensitive Personal Data or Information (SPDI). We do not connect to your bank accounts, read SMS, or access transactions automatically.

⚙️ App Preferences

Theme, currency, tracking mode, notification preferences, and onboarding selections. These are functional settings, not personal data.

🛡️ Security Data

To protect the integrity of the App and prevent unauthorised access, we generate a device fingerprint — a one-way cryptographic hash derived from general device characteristics (brand, model, OS version) combined with a random seed. This fingerprint is stored locally in your device's secure enclave and used solely for detecting anomalous device migration patterns. It cannot be reversed to identify your device and is never transmitted to external parties.

📊 Usage Data

We do not collect analytics, IP addresses for profiling, location data, or browsing behavior. We do not use cookies for tracking on our website.

3

Purpose & Legal Basis for Processing

Under the DPDP Act, we process your personal data on the following lawful grounds:

Under the IT (SPDI) Rules, 2011 — Rule 5, we collect SPDI only for a lawful purpose connected with a function of the App, and the collection is necessary for that purpose.

4

How We Use Your Data

Your data is processed solely for the following purposes:

We follow the principle of data minimisation — we only collect and process the minimum data necessary for each stated purpose. We do not process your data for any purpose not disclosed in this policy.

5

Consent & Withdrawal

How We Obtain Consent

As required by DPDP Act Section 6, consent is obtained through clear, affirmative action:

Right to Withdraw Consent

Under DPDP Act Section 6(5), you may withdraw your consent at any time, as easily as it was given:

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. However, withdrawing consent may limit your ability to use certain features of the App.

6

Data Security

In compliance with IT Act Section 43A and the IT (Reasonable Security Practices) Rules, 2011 — Rule 8, we implement security standards aligned with globally recognised frameworks, including ISO/IEC 27001 and SOC 2 Type II practices:

🔐 Encryption

🛡️ Access Control & Authentication

📱 App Integrity

🔒 Infrastructure Security

🧪 Security Testing

We conduct periodic security audits and vulnerability assessments. Our security posture is designed to meet or exceed the "reasonable security practices and procedures" standard prescribed under the IT Act and its Rules.

7

Data Storage & Retention

📱 Where Your Data Lives

Data is stored locally on your device (offline-first architecture) and synced securely to cloud infrastructure. Cloud servers are operated by globally certified providers with data centres in regions not restricted under DPDP Act Section 16(1).

⏱️ Retention Periods

In line with the DPDP Act Section 8(7), we retain data only as long as necessary to serve the purpose for which it was collected, or as required by any law in force.

8

Cross-Border Data Transfers

Your data may be processed on servers located outside India for the purpose of cloud synchronisation, AI processing, and transactional email delivery.

Under DPDP Act Section 16(1), transfers are made only to countries and territories not restricted by the Central Government. Should any restrictions be notified by the Government of India, we will comply immediately.

All cross-border transfers are protected by:

9

Third-Party Data Processors

Under DPDP Act Section 8(2), we engage the following categories of trusted service providers as data processors, each bound by contractual data processing agreements:

We share only the minimum data necessary for each service to function. No third party receives your complete financial dataset. Each provider maintains industry-standard security certifications.

10

Medha AI & Automated Processing

Medha is an AI-powered assistant that processes your data to provide financial insights. We disclose the following about automated processing:

What Medha Does

What Medha Does NOT Do

AI Consent

Before your first Medha interaction, the App displays an explicit consent screen explaining how your data will be processed by the AI service. You must actively accept before any data is sent. This consent can be revoked at any time by ceasing to use Medha.

AI Data Handling

11

What We Never Do

12

Your Rights as a Data Principal

Under the DPDP Act, 2023, you have the following rights as a Data Principal:

How to Exercise Your Rights

International users: see Section 16 for supplemental rights under GDPR and CCPA.

13

Children's Privacy

In compliance with DPDP Act Section 9:

If you believe a child has provided us data without consent, please contact us at feedback@spendwisee.com and we will take immediate action.

14

Data Breach Notification

In the unlikely event of a personal data breach, we will act in accordance with DPDP Act Section 8(6):

Our incident response procedures are aligned with global best practices, including NIST SP 800-61 (Computer Security Incident Handling Guide) and ISO/IEC 27035 (Information Security Incident Management).

15

Grievance Redressal

As required by DPDP Act Section 8(10) and IT Act Section 43A read with IT (SPDI) Rules, 2011 — Rule 5(9), we have appointed a Grievance Officer:

Grievance Officer: Spendwisee Support Team
Email: feedback@spendwisee.com
Acknowledgement: Within 48 hours of receiving your complaint
Resolution: Within 30 days of receiving your complaint
Escalation: If unsatisfied, you may file a complaint with the Data Protection Board of India under DPDP Act Section 13

For general inquiries:

feedback@spendwisee.com

16

Supplemental Rights for International Users

While this policy is governed by Indian law, we respect the data protection rights of users worldwide. The following supplemental provisions apply based on your jurisdiction:

🇪🇺 European Union / EEA (GDPR)

If you are located in the EU or EEA, you have additional rights under the General Data Protection Regulation (EU) 2016/679:

🇺🇸 California (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:

🌍 Other Jurisdictions

Where local data protection laws provide greater protections than this policy, those local laws shall prevail to the extent of any inconsistency. Contact us at feedback@spendwisee.com to exercise any data protection rights available under your local law.

17

Policy Changes

We may update this policy from time to time to reflect changes in our practices or applicable law. When we make changes:

18

Applicable Law

This Privacy Policy is primarily governed by Indian law:

Data security and privacy practices are designed to meet or exceed globally recognised standards. For international users, applicable local laws (including GDPR and CCPA) apply as supplemental protections as described in Section 16.