๐Ÿ—„๏ธ Data

Data Policy

Last updated: June 2026  ยท  Effective immediately

โœ… Clari is a zero-upload app. Your transactions, SMS, imported statements, PIN, and settings never leave your device. The only external data flow is a Google Play subscription token check.

โœฆ Complete data map

Every piece of data Clari touches, where it lives, and what happens to it:

Data Where stored Sent anywhere? Purpose
Transaction SMS content Read from device, parsed in RAM โ€” not copied out Never Detect & log expenses automatically
Imported PDF statements Read on-device when you pick a file Never Parse transactions from the statement
Transaction ledger & categories Local device database (SQLite) Never Show your spending history & insights
Dues, EMIs & reminders Local device database (SQLite) Never Notify you before payments are due
PIN (hashed) Local device storage (MMKV) Never App lock authentication
App settings & preferences Local device storage (MMKV) Never Persist user choices & theme
Trial start timestamp Local device storage (MMKV) Never Track 7-day trial period
Google Play subscription token Local device storage (MMKV) Google Play only Verify Pro subscription status
Exported CSV / JSON Saved where you choose (Drive, email, files) Only where you send it Your own backup & portability
Crash reports (opt-in only) Not stored locally Anonymised receipt only Bug fixing โ€” no financial data included

๐Ÿ” Security measures

Even though everything stays on your device, we take security seriously:

๐Ÿ”’
On-device database & encrypted storage
Your ledger lives in a private SQLite database scoped to the app, and settings use MMKV key-value storage. Nothing is synced to a server.
๐Ÿ”‘
PIN never stored in plain text
Your PIN is hashed before storage. Even if someone accessed your device's storage, they could not recover your PIN from the stored value.
๐Ÿ“ต
No network calls to read your money
SMS parsing and statement import run entirely on-device. When a transaction is logged, nothing is sent over the internet โ€” it is instant and private.
โœ…
HTTPS-only for the one network request
The single external call โ€” verifying your Google Play subscription token โ€” uses a TLS 1.2+ HTTPS connection. No plain-text network traffic.
๐Ÿ—‘๏ธ
Full deletion on uninstall
Uninstalling Clari or clearing app data permanently deletes all locally stored information. We have no copy, and cannot restore it.
๐Ÿšซ
No third-party analytics or ad SDKs
Clari does not include Firebase, Google Analytics, Facebook SDK, Adjust, Amplitude, or any other analytics or advertising library.

๐Ÿงฎ How SMS & statement parsing works

Clari turns your messages and statements into a ledger entirely on your phone. Here is exactly how it works:

โฑ Data retention

Because all data is stored locally on your device, you control retention entirely. There is no server-side retention period to manage.

Within the app

Your ledger is retained locally for as long as the app is installed. You can delete individual transactions or clear all data from within app settings at any time.

Support emails

If you email us for support, we retain your email and message for up to 2 years to provide ongoing support, then delete it. You can request deletion sooner at any time.

Crash reports (opt-in)

Anonymised crash reports are retained for 90 days for debugging, then automatically deleted.

โš–๏ธ Your rights & regulatory compliance

Clari is designed to comply with major data protection regulations by minimising data collection to near-zero. Regardless, you retain the following rights:

For EU/EEA users (GDPR), UK users (UK GDPR), California users (CCPA), and Indian users (DPDP Act 2023) โ€” your applicable rights above apply in full. Contact us if you need to exercise any right we handle server-side (e.g., deletion of support emails).

๐Ÿ“ง Data requests: hello@bfyai.in โ€” we aim to respond within 72 hours.

โ–ถ Google Play & payments

All subscription payments are processed by Google LLC through the Google Play Store. bfyaฤฑ does not receive, store, or process any payment card information.

Google may collect device identifiers and payment information in accordance with their own Privacy Policy. We have no control over Google's data practices.

The only data we receive from Google Play is a subscription receipt token confirming whether your subscription is active. This token is stored locally on your device and used only to unlock Pro features.

โœ‰ Questions about your data

bfyaฤฑ โ€” Data & Privacy
Email: hello@bfyai.in
Website: clari.bfyai.in
Response time: within 72 hours


โ† Back to home  ยท  Privacy Policy  ยท  Terms & Conditions

ยฉ 2024โ€“2026 bfyaฤฑ ยท clari.bfyai.in