Privacy Policy
Last updated: April 24, 20261. Overview
FiSense ("we", "our", "the app") is a financial transaction tracker for Android. This policy explains what data we collect, how it is used, and what controls you have over it.
FiSense is designed around a zero-knowledge architecture: your transaction data is encrypted on your device before it reaches our servers. We technically cannot read your financial records.
2. Data We Collect
Account information
- Email address (if you sign in with email OTP)
- Google ID and display name (if you sign in with Google)
- Username, country, and preferred currency (set during onboarding)
- Phone number (optional, digits only)
- Subscription tier and expiry timestamp
Transaction data (encrypted)
- Transaction amounts, merchant names, and references - stored as AES-256-GCM ciphertext only. We cannot read these values.
- Unencrypted index fields used for server-side queries: transaction date, category label, transaction type (DEBIT/CREDIT), and source (SMS or manual).
- Monthly budget amounts - also stored encrypted.
3. SMS Handling
FiSense reads incoming bank SMS messages to extract transaction data. This is the core function of the app.
Default cloud mode
The SMS body is sent to our server and forwarded to Groq or Cerebras for structured data extraction. Both providers are configured with zero data retention - they do not log or store any content sent for inference. The raw SMS text is used only during this parsing step and is never stored in our database or logs. Once parsed, the extracted fields are returned to your device.
Local AI mode (opt-in beta)
When local AI mode is enabled, the NuExtract model runs entirely on your device. Your raw SMS never leaves your phone in this mode. Only pre-extracted structured fields (amount, merchant, currency signals) are sent to the cloud, and only if local extraction was incomplete.
FiSense never reads personal SMS messages - only messages from recognized bank senders.
4. Encryption and Zero-Knowledge Architecture
All transaction and budget data is encrypted on your device using AES-256-GCM before it is sent to our servers.
- Your encryption key is derived from a BIP-39 recovery phrase generated at account setup.
- The key is stored in the Android Keystore (hardware-backed where available).
- Your encryption key and recovery phrase are never transmitted to our servers - we have no ability to decrypt your data.
- Our server stores only ciphertext, initialization vectors (IV), and authentication tags. Even a complete server breach would expose no readable financial information.
5. Third-Party Services
The following third-party services may receive portions of your data:
- Groq / Cerebras - Receive the SMS body text for AI parsing in cloud mode. Both are configured with zero data retention - no content is logged or stored by them after inference. They do not receive your account identity.
- Google - Receives your Google ID token for authentication verification only. We do not share any financial data with Google.
- open.er-api.com - Used for foreign exchange rate lookups. Requests contain only a currency code (e.g. USD) - no account information, identifiers, or personal data of any kind is transmitted.
- SMTP email provider - Used only to deliver one-time authentication codes to your email address.
- Cloudflare - Operates as a reverse proxy for our servers. Traffic is encrypted end-to-end.
We do not use any advertising networks, behavioral analytics platforms, or crash reporting services (no Firebase, Sentry, Amplitude, or equivalent).
6. Data Retention and Deletion
Your account data and encrypted transactions are retained on our servers until you request deletion.
- Signing out clears your session and device-side data.
- Individual transactions can be soft-deleted from within the app.
- To request full account deletion, contact us at support@fisense.cc. We will delete your account and all associated server-side data.
- Deleted transactions are tombstoned (not immediately purged) to allow sync propagation across devices, then permanently removed.
7. Transaction History Access
Access to your transaction history within the app depends on your subscription tier.
- Free tier: Up to 7 days of transaction history visible in the app.
- Premium tier: Full transaction history visible in the app.
Data export is not currently available. All your transactions remain stored in encrypted form on our servers regardless of tier and are accessible when you upgrade.
8. Children
FiSense is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children. If you believe a child has used the app and provided personal data, contact us at support@fisense.cc and we will delete the account.
9. Your Rights
Depending on your location, you may have the right to access, correct, or delete your personal data. To exercise any of these rights, contact us at support@fisense.cc.
Because transaction data is encrypted with a key only you hold, we cannot access or provide the content of your financial records - only you can decrypt them.
10. Changes to This Policy
We may update this policy. When we do, the "Last updated" date at the top of this page will change. Continued use of FiSense after changes constitutes acceptance of the updated policy.
11. Contact
Questions about this policy? Reach us at support@fisense.cc