Privacy Policy
Last Updated: September 6, 2026 • Effective ImmediatelyAt DueDash (developed by Mrutyunjay Studio), we value your trust and are strictly dedicated to protecting your privacy. This Privacy Policy details how DueDash collects, uses, handles, and protects your data when you use the DueDash mobile application and related web services.
📱 Which app this policy covers
DueDash ships on two platforms, and they do not collect the same things. Every section below states which one it applies to.
- Android (Google Play): reads bank transaction SMS on your device to detect expenses, and is funded by Google AdMob ads.
- iOS (App Store): does not read SMS - Apple provides no API that would let any app do so - and shows no ads at all. There is no advertising SDK in the iOS app and no advertising identifier is collected. Expenses are entered manually.
🔒 Summary of Core Privacy Commitments
- Zero Financial Selling: We never sell, rent, or trade your personal or financial data to advertisers, data brokers, or lending agencies.
- Local SMS Parsing (Android only): SMS messages are analyzed exclusively on your Android device hardware to detect transactional debit/credit notifications. We do not upload personal messages or OTPs to any remote server.
- Ads Never See Your Money (Android only): the Android app is funded by Google AdMob ads, which receive your device's advertising ID - never your expenses, EMIs, merchant names or SMS content. The iOS app shows no ads.
- No Tracking: Neither app contains an analytics or crash-reporting SDK, and we do not track you across other companies' apps or websites.
- Full User Control: You can export, modify, or permanently wipe your account and all data at any time via the app or our dedicated deletion page.
1. Information We Collect
When you use DueDash, we may collect the following information:
- Account Information: When you sign in using Google Sign-In, we receive your name, email address, profile avatar URL, and an authenticating Google User ID (UID).
- Financial Records: Transaction amounts, merchant names/descriptions, dates, expense categories, payment modes (UPI, Cash, Credit Card, Bank Transfer), and loan/EMI schedules that you add manually or, on Android, approve through SMS auto-detection.
- Advertising ID (Android only): the Android app shows ads through Google AdMob. The Google Mobile Ads SDK collects your device's Android advertising ID and shares it with Google to serve and measure ads. See section 4 below. The iOS app collects no advertising identifier and contains no advertising SDK.
- What we do not collect: DueDash contains no analytics or crash-reporting SDK on either platform. We do not collect your location, contacts, usage analytics or crash diagnostics. We do not track you across other companies' apps or websites. Apart from the Android advertising ID described above, we collect no device identifiers.
2. SMS Permissions & Transparency Policy (Android only)
DueDash requests the following Android system permissions to deliver automated expense detection:
android.permission.RECEIVE_SMSandroid.permission.READ_SMS
Strict Safeguards for SMS Data:
- Only From The Day You Start: DueDash only examines messages that arrive after you enable the feature. Your existing message history is never read or imported.
- Strict Filtering: The app’s regex engine selectively examines only transactional messages originating from recognized commercial bank/financial sender IDs (e.g., HDFC, SBI, ICICI, AXIS, PNB, KOTAK).
- No Personal Messages: DueDash completely ignores personal one-on-one text messages, conversations, contacts, and non-financial notifications.
- No OTPs or Sensitive Codes: DueDash specifically filters out and discards One-Time Passwords (OTPs), verification codes, account passwords, and ATM PINs.
- On-Device Only: The raw content of your SMS messages is never transmitted to our servers or stored in cloud databases. Only the resulting expense record that you review and confirm is synchronized to your private cloud storage.
3. How We Store and Protect Your Data
DueDash uses Google Firebase Realtime Database and Google Firebase Authentication.
- All communications between the mobile application, web services, and Firebase servers are encrypted using industry-standard TLS 1.3/256-bit SSL encryption.
- Your data is protected by Firebase Security Rules that enforce strict user isolation: only the authenticated owner of the Google Account can read or write their respective expense, EMI, and profile records.
4. Advertising (Android only)
The iOS app shows no advertising. It contains no advertising SDK, requests no advertising identifier, and does not use App Tracking Transparency, because there is nothing to track. The rest of this section describes the Android app only.
On Android, DueDash is free and is funded by ads. We use Google AdMob to show a banner at the bottom of some screens, and a single full-screen ad when you leave the app from the home screen.
- What AdMob receives: the Google Mobile Ads SDK collects and shares with Google your device's Android advertising ID, along with technical data such as your approximate (IP-based) location, device type and the ads you were shown. This is used to serve, cap and measure ads.
- Your financial data is never used for ads: your expenses, EMIs, merchant names, SMS content and account details are never shared with AdMob or any advertiser. Ads are not targeted using anything you record in this app.
- Consent in the EEA, UK and Switzerland: if you are in a region covered by the GDPR, the app asks for your consent before any ad is requested, using Google's official consent form. If you decline you still get ads, but non-personalised ones.
- Changing your mind: where that consent applies, you can reopen the form any time from Profile tab → Legal & Privacy → Ad Privacy Settings. On any device you can also reset or delete the advertising ID from Android Settings → Privacy → Ads.
- Google's own terms: Google's use of this data is governed by How Google uses information from sites or apps that use our services.
5. Data Retention & Account Deletion
We store your financial records for as long as your account remains active. If you choose to stop using DueDash, you have the absolute right to have all your data permanently deleted:
- In-App Deletion: Open the app and go to Profile tab → Legal & Privacy → Delete Account & Data, then confirm Delete forever. Your profile, expenses, EMIs, categories, reminders and your Firebase sign-in account are erased immediately and irreversibly.
- Web Deletion Portal: If you have already uninstalled the app, submit a deletion request at our Account Deletion Page. Requests are recorded automatically and the account is purged within 7 days.
6. App Store and Google Play Compliance
Google Play (Android): DueDash operates in full compliance with Google Play's User Data Policy, Financial Services Policy, and Permissions Policy concerning Sensitive App Capabilities. We only request permissions necessary to execute the core features you explicitly enable, and SMS access is requested only after an in-app disclosure that you can decline.
Apple App Store (iOS): the data described in section 1 as collected on iOS - your Google account details and the financial records you enter - is linked to your identity and used solely to provide the app's functionality. It is never used for tracking as Apple defines it: it is not shared with data brokers or advertising networks, and it is not combined with data from other companies' apps or websites. The iOS app requests no permission beyond sign-in and, if you enable them, local notifications for EMI due dates.
7. Changes to this Policy
We may occasionally update this Privacy Policy to reflect new app capabilities or regulatory requirements. Any updates will be posted on this URL with an updated "Last Updated" timestamp.
8. Contact Us & Grievance Officer
If you have questions, feedback, or concerns regarding your privacy or data handling, please contact our developer team at:
Mrutyunjay Studio
Lead Developer: Sharad Sonawane
Email: welldayreview@gmail.com
Website: https://duedash-3778c.web.app