Privacy Policy
Last updated: 17 September 2026
This policy explains what information the Vittova Android app (package com.vittova.app) and web app collect, why, who processes it, how long it is kept, and how to delete it. Vittova is an expense tracker. It does not move money, connect to your bank account, or sell your data.
1. Information you give us
- Account: your email address and name. If you sign in with Google, we receive your name and email address from Google. Passwords are handled by our authentication provider and are never visible to us.
- Expenses: amount, category, description, date, and how it was added (manual, receipt scan, payment notification, or statement import).
- Budget settings: monthly budget, savings target, and recurring bills you add.
- Coach conversations: the questions you ask the money coach and its answers.
2. Information created while you use Vittova
- Round-up totals, logging streaks, weekly Spend Score history and statement-import history (bank name, number of transactions, statement period).
- Usage counters for free-plan limits (for example, coach questions asked today).
- Basic server logs needed to run and secure the service, such as request time and error type. Logs do not contain expense amounts, descriptions or notification text.
- App usage and diagnostics: to understand how Vittova is used and to find problems, we record simple events such as the app being installed or opened, sign-in succeeding or failing (with a short reason category), an expense being added, edited or deleted, an import or receipt scan succeeding or failing, a coach answer being given, and the app showing its error screen (error type only). Each event has a time, the platform (Android or web) and the app version. The app creates a random installation ID on first launch; it is not an advertising ID or device identifier, and a reinstall creates a new one. Events contain no expense amounts, descriptions, payees, coach questions or answers, or notification text. After you sign in, events are linked to your account; if you delete your account, that link is removed.
We do not use advertising IDs, third-party analytics or crash-reporting SDKs, or location data, and we do not show ads.
3. Payment notifications (Android, optional)
If you turn on Android Notification Access for Vittova, the app can detect payments from these supported apps only:
Google Pay, PhonePe, Paytm, BHIM, BHIM SBI Pay, CRED, super.money, MobiKwik, Freecharge, FamPay, HDFC Bank, ICICI Bank iMobile, SBI YONO, Kotak, Axis Bank, Bank of Baroda, Union Bank, PNB, Canara Bank, IndusInd Bank, IDFC FIRST Bank.
- Notifications from every other app (for example WhatsApp, SMS/messages, email and social apps) are ignored and not read.
- A supported notification is analysed on your phone. If it describes a completed payment, Vittova keeps only the amount, payee name, app name, time and payment type in a private queue on your device for up to 7 days. The notification text itself is not saved or uploaded.
- Nothing is sent to our servers unless you tap Add expense. Only then are the amount, payee name and time saved to your account as an expense.
- Vittova does not request SMS permission and does not read SMS.
- You can turn Notification Access off at any time in Android settings.
4. AI features and Google Gemini
Some features send content to Google's Gemini API, operated by Google LLC, to generate a result:
- Receipt scan: the receipt photo you choose. We save the merchant name, item list and total; we do not store the photo.
- Money coach: your question and a summary of your spending figures (for example monthly totals by category, budget and upcoming bills). Your name and email are not included.
- Spending tip: when you are projected to exceed your budget, your budget, amount spent and top spending category.
- Bank statement import (when available): the text of the PDF you upload. The file is processed in memory and not stored; the extracted transactions are saved.
Google processes this content under the Gemini API Terms of Service, which describe how long Google may retain it and how Google may use it. AI output can be wrong. Please check amounts before relying on them.
5. How we use information
- To provide the app: show your spending, budget, forecasts and score, and answer your questions.
- To enforce free-plan limits and prevent abuse (for example rate limiting).
- To keep the service secure and fix problems.
We do not sell or rent personal data, and we do not use your financial data for advertising.
6. Service providers
- Supabase: authentication and database hosting.
- Render: hosting for the Vittova API server.
- Vercel: hosting for the Vittova website.
- Google: Google Sign-In (if you choose it) and the Gemini API (section 4).
These providers process data on our behalf and may store it on servers outside India.
Vittova does not currently offer in-app purchases or subscriptions, and does not send push notifications.
7. Security
Data is sent over encrypted HTTPS connections. Database access rules allow each account to read only its own records, and all changes go through our server. The Android app excludes your sign-in session from device backups. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you as required by law.
8. Stored on your device
The app stores your sign-in session, whether you have completed onboarding, your choice about notification access, and the pending payment queue described in section 3. Signing out removes the session and these app preferences from the device.
9. Retention
- Account and expense data: kept until you delete it or delete your account.
- Pending payment detections on your device: until you add or dismiss them, and at most 7 days.
- Server logs: kept for a limited period for security and debugging.
- Database backups kept by our hosting provider may contain deleted data until they expire on their normal schedule.
10. Your choices and rights
- Access and portability: export your expenses as a CSV file from Settings.
- Correction: edit or delete any expense in the app.
- Deletion: delete your account in Settings → Delete account, or follow the steps at Vittova account deletion. Deleting your account removes your login, profile, expenses, bills, score and streak history, import history and coach conversations, and the group pools you created.
- Withdraw consent: turn off Notification Access in Android settings, or stop using AI features.
To exercise any right or raise a grievance, email support@vittova.in.
11. Children
Vittova is intended for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
12. Not financial advice
Vittova provides expense tracking and general financial education. It does not recommend any security, fund, broker or platform and is not a SEBI-registered investment adviser.
13. Changes
If we change this policy we will update the date above and, for significant changes, tell you in the app before they take effect.