Privacy Policy
Last updated: July 25, 2026
This Privacy Policy explains how Ginloo (“Ginloo,” “we,” “us,” “our”) collects, uses, shares, and protects your information when you use our website, dashboard, Telegram bot, and related services (together, the “Service”). It should be read together with our Terms of Service. For the purposes of India's Digital Personal Data Protection Act, 2023 (“DPDP Act”), Ginloo is the Data Fiduciary for the personal data described here, and you are the Data Principal.
1. Who we are
The Service is operated under the name Ginloo. For any privacy question, request, or grievance, contact us at support@ginloo.com.
2. Information we collect
- Account & identity: name, email address, phone number, a hashed password (never your plain password), one-time verification codes, and profile preferences. If you sign in with Google, we receive your name and email address from your Google account.
- Financial data you enter: transactions, income, budgets, recurring bills, loans, savings goals, trips, and related notes you choose to record. This data comes only from what you submit — we do not connect to your bank.
- Telegram data: if you link Telegram, your Telegram chat ID and the messages, voice notes, and receipt photos or PDFs you send to the Ginloo bot.
- Payment data: when you buy a subscription, our payment processor (Cashfree Payments, an RBI-authorised online payment aggregator) receives your name, email, phone number, and payment details. We do not store your card numbers or UPI credentials; we keep limited billing metadata such as order status and subscription state.
- Technical data: IP address, device and browser information, timestamps, and diagnostic logs needed to secure and operate the Service.
- Support data: what you send when you contact support, including an optional screenshot attachment.
3. AI-assisted features
Some features use artificial intelligence to process what you submit:
- Voice notes you send to the bot are transcribed using OpenAI's transcription service.
- Text messages you send to the bot are parsed into structured entries (amount, category, and so on) using OpenAI.
- Receipt images are read using OpenAI, with Google Gemini used as a fallback if needed. PDF receipts are converted to images on our servers before any AI processing; raw PDFs are not sent to AI providers.
These providers process your content through their APIs to deliver the feature, under their own terms. AI output can contain mistakes — always review parsed amounts and details. We do not use AI to make automated decisions that produce legal or similarly significant effects about you; AI is used only to help convert what you submit into structured entries you can review and correct.
4. How we use information
- Create and manage your account; authenticate you; send security and transactional messages (e.g. OTP, password reset, billing receipts, statements).
- Provide core features: recording and displaying your financial data, reminders, automations you enable (such as auto-pay tracking), reports, and statements.
- Process subscription payments and manage your plan.
- Improve reliability and security; monitor errors; prevent abuse; comply with law; enforce our Terms.
- Understand product usage through analytics (see Section 6) so we can improve the Service.
Where the DPDP Act applies, we process your personal data on the basis of your consent (given when you sign up and use features) and for legitimate uses permitted by law, such as complying with legal obligations and responding to your own requests.
5. Who we share information with
We do not sell your personal information. We share it only with service providers that help us run Ginloo:
| Provider | Purpose |
|---|---|
| Cashfree Payments | Subscription payments and billing (India) |
| Resend | Sending emails: OTPs, billing, statements, support replies |
| Telegram | Delivering the Ginloo bot, if you link Telegram |
| MongoDB Atlas | Database hosting for your account and financial data |
| Render & Netlify | Hosting our backend and website |
| OpenAI / Google Gemini | AI processing described in Section 3 |
| PostHog | Product analytics (Section 6) |
| Sentry | Error monitoring on our backend |
| ExchangeRate-API | Fetching public currency exchange rates (no personal data is sent) |
Loading the website also involves standard requests to content delivery networks (Google Fonts, Iconify, and the Cashfree checkout script), which receive your IP address and browser details as part of serving those files. We may also disclose information when required by law, court order, or to protect rights and safety, and in a business transfer subject to appropriate safeguards. If we change or add providers in a way that materially affects your personal data, we will update this policy.
6. Analytics
We use PostHog to understand how the Service is used (for example, page visits, sign-ups, and feature clicks). After you create an account, analytics events may be associated with your account ID and email so we can understand product usage. We do not use advertising trackers.
7. Where your data is stored
Our servers and service providers are located in India and other countries, including the United States. By using the Service, you understand that your information may be stored and processed outside India. We transfer data only to countries not restricted under the DPDP Act and require our providers to protect it.
8. Retention & deletion
We keep your data while your account is active. You can delete your account from the dashboard at any time — this permanently removes your account and financial data from our systems, after generating a final report for you. Limited records (such as billing and legal records) may be retained where the law requires. Verification codes and session tokens are kept only as long as needed.
9. Security
We use administrative and technical measures designed to protect your information, including encryption in transit, hashed passwords, and verified payment webhooks. No method of transmission or storage is 100% secure; please use a strong password and protect your devices. If a personal data breach occurs, we will notify affected users and the Data Protection Board of India as required by law.
10. Your rights
Under the DPDP Act and other applicable laws, you have the right to:
- Access a summary of the personal data we hold about you;
- Correct or update inaccurate data (most data can be edited directly in the app);
- Erase your data (via in-app account deletion or by contacting us);
- Withdraw consent, which may limit or end your use of the Service;
- Nominate another individual to exercise your rights if you are unable to;
- Raise a grievance with us, and if unresolved, complain to the Data Protection Board of India.
To exercise any right, email support@ginloo.com. We may verify your identity before acting on a request, and we aim to respond within the timelines required by law.
11. Children
The Service is intended for adults aged 18 and above. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
12. Cookies & similar technologies
Our web dashboard uses browser storage and cookies for login sessions, preferences, and analytics. See our Cookie Policy for details.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the new version here with an updated “Last updated” date and, for material changes, notify you by email or in-app notice.
14. Contact & grievance redressal
For privacy questions, requests, or grievances, contact support@ginloo.com. We will acknowledge and address grievances within the timelines prescribed under applicable law.