Broke?

Privacy Policy

Last updated: July 16, 2026

This is placeholder legal content for Broke? while the product is in closed beta. Broke? is currently the operator named for this policy; this should be updated when a formal legal entity exists.

1. What data we collect

Broke? is a personal finance app for India. To provide transaction tracking, budgeting, split tracking, and AI-powered nudges, Broke? may collect or process the following data when you choose to use the relevant features:

  • Financial SMS content on Android, including sender name, message body, transaction amount, merchant, account reference, timestamp, and transaction direction where available.
  • Gmail message metadata and content that you authorize through the Gmail API readonly scope, limited to detecting transaction notification emails.
  • Your phone number and basic identity details used for login, verification, and the Splits feature.
  • Device identifiers, app version, platform, and diagnostic information needed for security, debugging, fraud prevention, and app reliability.
  • Usage analytics, feature interactions, crash logs, and performance events used to improve the app experience.
  • Budget settings, categories, split records, AI assistant interactions, and anonymized or aggregated classifier feedback.

2. Google user data and Gmail access

If you connect a Google account, Broke? requests Gmail API readonly access so it can identify transaction-related emails, such as card, bank, UPI, bill, refund, or merchant notifications. Broke? uses Gmail data only to detect, parse, categorize, reconcile, and display transactions inside the app.

Broke? does not use Gmail data for advertising. Broke? does not sell Gmail data. Broke? does not share Gmail data with third parties for marketing, advertising, data brokerage, credit-worthiness, or lending decisions.

Gmail-derived transaction data may be stored locally on your device in SQLite and may be processed by Broke? backend systems only as needed to provide or improve transaction detection, categorization, reconciliation, security, and reliability. Where classifier improvement data is synced to Broke? backend systems, it should be minimized, anonymized, or aggregated where practical.

Access to Gmail data is restricted to systems and people who need it to operate or secure the service. Human review of raw Gmail content is not allowed except with your explicit permission, to investigate abuse or security issues, to comply with law, or for aggregated internal operations.

3. Google API Services User Data Policy

Broke?'s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This means Google user data is used only to provide or improve user-facing features that are visible in Broke?, is not transferred except as permitted by the policy, is not used for serving ads, and is protected with reasonable security controls.

You can read Google's policy at developers.google.com/terms/api-services-user-data-policy.

4. Data retention, deletion, and revoking Gmail access

Broke? retains data for as long as needed to provide the app, maintain transaction history, operate Splits, improve classifier accuracy, comply with legal obligations, resolve disputes, and prevent abuse. Local app data may remain on your device until you delete it from the app or uninstall Broke?.

You can revoke Broke?'s Gmail access from your Google Account permissions page at any time. After access is revoked, Broke? will no longer fetch new Gmail data. You may also request deletion of account-linked backend data by emailing privacy@brokeapp.in.

Some data may remain in backups, logs, security records, or legally required records for a limited period before deletion. Aggregated or anonymized data that no longer identifies you may be retained for analytics and classifier improvement.

5. Third-party services and sharing

Broke? may use third-party service providers to operate the app. These providers process data only as needed to provide their services to Broke? and are not allowed to use user data for their own marketing.

  • Firebase may be used for phone authentication, app reliability, notifications, and related infrastructure.
  • Neon Postgres or other Postgres infrastructure may store backend records for Splits, sync, classifier feedback, and anonymized or aggregated model-improvement data.
  • Analytics and crash reporting tools may process app usage, device, diagnostic, and crash information.
  • AI service providers may process anonymized or minimized context for Macha features, but raw SMS and raw Gmail content should not be sent to AI providers unless a future policy and consent flow explicitly says so.

Broke? may also disclose information if required by law, to protect users or the service, to investigate security issues or abuse, or with your consent.

6. Your rights and choices

You may request access to, correction of, or deletion of personal data associated with your Broke? account by contacting privacy@brokeapp.in. You may also revoke Gmail access through your Google Account and manage SMS permissions through Android settings.

Some features may stop working if required permissions are removed, such as SMS-based transaction detection, Gmail transaction sync, or Splits identity features.

7. Children's privacy

Broke? is a finance app and is not intended for children under 18. We do not knowingly collect personal data from children under 18. If you believe a child has provided personal data to Broke?, contact privacy@brokeapp.in so we can review and delete it where appropriate.

8. Contact

For privacy questions, deletion requests, or Google user data questions, contact Broke? at privacy@brokeapp.in.