Privacy Policy

Applies to NetWorth+ on Android and iOS

The short version. NetWorth+ never connects to your bank. There is no bank login, no credential storage, no open-banking integration and no card number anywhere in the app. Everything in NetWorth+ is either typed in by you, read from a receipt you photograph, or (on Android only) extracted on your own device from bank notification messages you explicitly allow it to read. There are no advertisements and no advertising SDKs, we do not use the advertising identifier (IDFA) on iOS, we do not track you across other companies' apps or websites, and we never sell your data.

1. Introduction

NetWorth+ helps you track accounts, transactions, budgets, goals and expenses shared with other people, so that all of it resolves into a single net worth figure. This policy explains exactly what data the app touches, where it goes, and how to get rid of it. It applies equally to the Android and iOS versions of NetWorth+; where the two platforms differ (for example, SMS reading is Android-only because Apple does not permit it), that is called out explicitly.

2. Information we collect

a. Account information

Your display name, your email address, and an anonymous user identifier issued by Firebase Authentication. We do not collect your phone number, your postal address or your date of birth.

b. Financial information you enter

Account names and the institutions you label them with, account types, currencies and balances; transactions with amounts, dates, categories, notes and payees; budgets, goals, loans and liabilities. This is stored in your account so it is available across your devices.

We do not collect bank login credentials, full card or account numbers, CVVs, PINs or government identifiers, because the app has no feature that uses them.

We do store the last four digits of a card or account in two cases: when you add a credit card, where those four digits identify which card a statement or alert belongs to, and when a bank alert you have allowed the app to read quotes them. Four digits on their own cannot be used to pay anyone.

c. Sharing with other people

Four features involve someone other than you, and each shares only what it needs.

Shared expenses. We store the email addresses and display names of the people you add, your group memberships, the shared entries between you, and the resulting balances and settlements. This is visible to the people involved in those entries; see Terms §6. It comes from what you type; the app does not read your device's contact list and requests no contacts permission.

Shared accounts. You can choose to share one of your accounts with another user. They then see that account's name, type, currency and current balance, and may include it in their own net worth figure. Only accounts you explicitly share are visible, and you can withdraw a share at any time.

Being found by others. Your email address, display name and an internal user identifier are stored in a lookup that any signed-in user can query, so that someone who knows your email address can add you as a contact. Nothing else is in that record.

Referrals. If a referral code is used, we store the link between the referring account and the referred account, together with the status of that referral.

d. SMS transaction data (Android only, optional, off by default)

See §4, which describes this separately and in full.

e. Receipt images (optional)

See §5.

f. Device and diagnostic information

Crash reports (including device model, operating system version and the state of the app at the point of failure) via Firebase Crashlytics; usage events such as which screens are opened and which features are used, via Google Analytics for Firebase; a push notification token if you enable notifications; and an app integrity token issued by Firebase App Check, used to confirm that requests come from a genuine copy of the app.

3. How we use information

  • To operate the Service: store your records, calculate balances, budgets, net worth and shared settlements, and sync them across your devices.
  • To send the notifications you have turned on: bill and budget reminders, and alerts when someone shares an expense with you or approves one.
  • To support you: answer questions and troubleshoot problems you report.
  • To keep the Service working and safe: diagnose crashes, understand which features are used, and detect abuse of the shared-expense features.

We do not use your data for advertising. NetWorth+ contains no advertisements and no advertising SDKs. We do not sell, rent or trade personal data, and we do not share it with data brokers.

4. SMS data handling: the detail

Reading bank SMS is an optional, Android-only feature that is off until you turn it on. The app works fully without it. On iOS, this feature does not exist at all: Apple's platform does not permit any app to read SMS messages, so the NetWorth+ iOS app has no SMS permission, no SMS-reading code path, and no way to access your Messages. iOS users add every transaction by typing it in or by scanning a receipt.

What is requested

The READ_SMS permission. Android shows you its own permission dialog, and the app explains what the permission is for before that dialog appears. If you decline, every other feature continues to work.

Why

Bank and card alerts are the only automatic source of transaction data available to an app that does not connect to your bank. Reading them is what saves you from typing every transaction by hand.

What is read

The app reads your SMS inbox on your device and immediately discards everything that is not a plausible bank or business alert. Messages from personal phone numbers are excluded before any parsing happens. The first scan reaches back 30 days only; later scans cover the period since your last scan.

What leaves your device

Message text never leaves your device. We never upload, store or share your SMS history, and no message is readable by us or by anyone else. All reading and parsing happens on the phone.

Two small values are saved alongside each imported transaction, so that the same alert cannot be imported twice: a short non-reversible numeric hash of the message, and the sender ID the bank used (for example “HDFCBK”). Neither can be turned back into the message text.

What does leave your device is the transaction the app extracts: an amount, a date, a merchant or description, and which of your accounts it belongs to. Each extracted transaction lands in your Financial Inbox as a pending entry, and it is saved to your account only after you approve it. That approved entry is stored exactly like a transaction you had typed yourself.

How to turn it off

Revoke SMS permission in Android Settings → Apps → NetWorth+ → Permissions at any time, or turn off automatic scanning in the app's Settings. Nothing already saved is affected; the app simply stops reading messages.

5. Camera, photos and receipt scanning

If you scan a receipt, the app opens your camera and takes a photograph; the operating system asks for camera permission the first time you do this.

If you attach an existing image instead, the app opens the operating system's own photo picker (Android's Photo Picker, or Apple's PHPickerViewController on iOS) and receives only the single image you choose. NetWorth+ holds no permission to browse your photo library, and never asks for one; it cannot see any image you have not handed to it, on either platform.

The image is processed by Google ML Kit Text Recognition running entirely on your device; the photo is not sent to Google, to us, or to anyone else for recognition. The recognised text is used to pre-fill amount, date and merchant so you do not have to type them.

Receipt images are saved in the app's private storage on your phone. They are not uploaded to our servers.

6. Other device access

  • Notifications: used only for reminders and shared-expense alerts you have enabled, delivered via Firebase Cloud Messaging (Android) or, on iOS, via Apple Push Notification service (APNs) through Firebase Cloud Messaging. Apple asks you to approve notifications the first time the app requests them; you can disable them at any time in Settings.
  • File import: if you import a CSV or spreadsheet, the app reads only the single file you pick, and only to create transactions from it.
  • Sharing and export: when you export or share data, it goes wherever you send it, using the operating system's own share sheet (Android's share sheet, or the iOS share sheet). We are not involved in and do not retain a copy of that transfer.

7. Tracking, advertising and Apple's App Tracking Transparency

NetWorth+ contains no advertisements, no advertising SDKs, and no third-party analytics or attribution networks other than the Google/Firebase services listed in §8. We do not use Apple's advertising identifier (IDFA) or any equivalent identifier for advertising or cross-app measurement.

Under Apple's definition, “tracking” means linking data about you with data held by other companies for advertising purposes, or sharing your data with a data broker. NetWorth+ does not do this. We do not combine your information with data from other apps or websites you use, we do not share it with data brokers, and we do not sell it. Because the app does not track you under this definition, it does not show Apple's App Tracking Transparency (ATT) permission prompt.

The device and diagnostic information described in §2f (crash reports, usage analytics, and app integrity checks) is used solely to operate and secure the Service, and is not used for advertising or shared with anyone for their own advertising purposes.

8. Third-party services we use

ServiceProviderWhat it doesWhat it receives
Firebase AuthenticationGoogleSign-inEmail address, user id
Cloud FirestoreGoogleStores your recordsYour account, transaction, budget, goal and shared-expense data
Cloud FunctionsGoogleShared-expense notifications, currency rate refresh, scheduled account deletionThe records involved in those operations
Firebase Cloud MessagingGoogleDelivers push notifications (Android; and on iOS, via Apple Push Notification service)Device push token
Firebase App CheckGoogleBlocks requests from tampered or fake clientsApp integrity token
Google Analytics for FirebaseGoogleAggregate usage measurementUsage events, device and app version
Google Analytics 4 (this website only)GoogleCounts visits to networthplus.inPages viewed, approximate location from IP, browser and device type, referring site
Firebase CrashlyticsGoogleCrash diagnosticsCrash traces, device model, OS version
Google ML Kit Text RecognitionGoogleReads text from receiptsNothing; runs on your device

Exchange rates come from a public rates service (Frankfurter). Rates are fetched by our server and mirrored into the app for everyone; no user data is sent to the rates provider, and the provider cannot tell that you exist.

Your use of these underlying services is also governed by Google's privacy policy. On iOS, push delivery additionally passes through Apple's Push Notification service, governed by Apple's privacy policy; Apple only relays an opaque device token and does not receive the content of your data.

8a. This website

Everything above describes the NetWorth+ app. This website is separate, and it does one thing you should know about: it uses Google Analytics 4 to count visits.

That means when you browse networthplus.in, Google receives which pages you looked at, roughly where you are (derived from your IP address, which Google Analytics 4 does not store), what browser and device you used, and which site sent you here. It is set up with the default configuration: no advertising features, no remarketing audiences, and no Google Signals. We use it to see which pages people find useful, and nothing else.

Google Analytics sets cookies in your browser to tell one visit from another. If you would rather not be counted, any of these work: use your browser's “do not track” or tracking-protection setting, block cookies for this site, use a private window, or install Google's official opt-out add-on. Nothing on this site is gated behind analytics, so blocking it costs you nothing.

This is the only tracking on the website. There are no advertising tags, no advertising SDKs, no social media pixels, no heatmap or session-recording tools, and nothing is sold or shared with data brokers. The free calculators under Tools remain entirely local to your browser; the figures you type into them are not sent anywhere, including to Google Analytics.

9. Data sharing and disclosure

We share your information only in these situations:

  • With the people you share expenses with: as described in §2c and Terms §6.
  • With the infrastructure providers in §8: acting on our instructions, to run the Service.
  • With legal authorities: where required by law or in response to a valid legal request.

We do not sell, rent or trade personal data under any circumstances, and we do not share it with anyone for their own advertising purposes.

10. Data security

Data in transit is encrypted with TLS. Data at rest is encrypted by Google Cloud. Access to your records is enforced by server-side Firestore security rules, so a request that is not yours is rejected by the server rather than merely hidden by the app; those rules are covered by an automated test suite that runs on every change. Firebase App Check rejects requests that do not come from a genuine build of the app.

No system is perfectly secure, and we do not claim otherwise. If a breach affects your data we will notify you as required by applicable law.

11. Data storage and international transfers

Your data is stored on Google Cloud infrastructure and may be processed in countries other than your own. Where required, transfers rely on the safeguards Google provides for its cloud services, including standard contractual clauses.

12. Data retention

We keep your data while your account is open. When you delete your account it is removed as described in §13. Crash and aggregate usage data is retained by Google Firebase according to that platform's retention settings and is not linked to your financial records.

13. Your rights, and how to delete your account and data

This section is the account and data deletion policy for NetWorth+. There is also a dedicated account deletion page with the same information and the request form.

To delete your account and all associated data from inside the app

Open NetWorth+ → ProfileDelete Account, and confirm.

Deletion is scheduled with a 7-day grace period, during which you can cancel it by signing back in. If you do not cancel, a scheduled server process permanently deletes your account and its data at the end of that period.

What is deleted

Your profile, accounts, transactions, budgets, goals, loans, categories, contacts, groups and shared balances, and your authentication record. Receipt images held in the app's private storage are removed when you uninstall the app.

What may be retained

Entries that another person also participates in may remain visible in their copy of a shared expense, because that record is theirs as well as yours. Anonymous, aggregated crash and usage statistics that cannot be traced back to you are not deleted, as they are no longer personal data. We may retain records where law requires it.

To request deletion without using the app

If you cannot sign in, or you have already uninstalled the app, submit the account deletion request form, or email support@networthplus.in from the address on your account. Either route is actioned within 30 days.

You also have the right to

Access the personal data we hold about you, correct it, obtain a copy in a portable form, restrict or object to certain processing, and withdraw consent for anything optional (SMS reading, camera, notifications) at any time. Depending on where you live these rights arise under the GDPR, the UK GDPR, or India's Digital Personal Data Protection Act. Write to support@networthplus.in; you also have the right to complain to your local data protection authority.

14. Children

NetWorth+ is intended for adults and is not directed at children. You must be 18 or older to use it. We do not knowingly collect personal data from anyone under 18; if we learn that we have, we will delete it promptly.

15. Changes to this policy

We may update this policy to reflect changes in the app or in the law. Significant updates will be communicated in the app.

16. Contact

Milan Suresh, NWP Technologies: support@networthplus.in

Questions about this document? Write to support@networthplus.in. For anything about your own data, email from the address on your account so we can identify you.