Privacy Protocol.
How BWJ Tech Solutions protects your personal data, expenses, and usage within the VoiceSpend App.
1. Introduction
Welcome to VoiceSpend ("the App"), a personal expense tracking application operated by BWJ Tech Solutions Private Limited ("we", "our", or "us"). This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our App, and your rights regarding that data.
By downloading or using VoiceSpend, you agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the App.
2. Applicability of Indian Data Protection Law (DPDP Act, 2023)
VoiceSpend complies with the **Digital Personal Data Protection Act, 2023 (DPDP Act)** of India.
- We process your **personal data** only for the purposes described in this policy.
- You have the right to **consent, withdraw consent, access, correct, and erase** your personal data.
- We do not sell your personal data to any third party.
- We appoint ourselves as the **Data Fiduciary** under the DPDP Act for the personal data we collect.
- Where required, we will register as a **Significant Data Fiduciary** if our processing meets applicable thresholds.
- You may raise a complaint with the **Data Protection Board of India** if you believe your rights have been violated.
3. Information We Collect
3.1 Information You Provide Directly
- Account Information: Name, email address, profile photo (optional)
- Financial Data: Expense amounts, categories, merchants, notes, payment methods, and dates that you enter manually or via voice
- Preferences: Home currency, budget settings, notification preferences
3.2 Information Collected Automatically
- Device Information: Device model, operating system version, app version, unique device identifiers
- Usage Data: Features used, screens viewed, frequency of app opens, crash logs and error reports
- Voice Input: When you use the voice entry feature, your speech is temporarily processed to extract expense data. We do not store raw audio recordings.
3.3 Information from Third-Party Sign-In
If you sign in using Google, Apple, Facebook, or Microsoft, we receive your name and email address as provided by those platforms, and a unique identifier from the provider to link your account. We do not receive your passwords.
3.4 Payment & Subscription Information
Subscription purchases are processed entirely by **Apple App Store** (iOS) or **Google Play Store** (Android) via RevenueCat. We do not store your credit card or payment details. We receive confirmation of your subscription status but not your payment method.
4. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Create and manage your account | Contractual necessity |
| Sync your expenses across devices | Contractual necessity |
| Provide AI-powered voice expense entry | Contractual necessity / Consent |
| Generate spending insights and budget alerts | Contractual necessity |
| Send transactional notifications (OTP, budget alerts) | Contractual necessity |
| Send promotional communications (with opt-in) | Consent |
| Improve app performance using anonymised analytics | Legitimate interest |
| Prevent fraud and ensure security | Legitimate interest / Legal obligation |
| Comply with legal obligations under DPDP Act and other laws | Legal obligation |
5. Microphone and Camera Access
Our core features require temporary hardware access, requested only when you attempt to use those features:
You may revoke these permissions at any time in your device settings.
6. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data. We share data only in limited circumstances:
- Service Providers: Firebase (notifications, analytics), RevenueCat (subscriptions). Our AI features (Voice & OCR) are powered by our own private, in-house infrastructure.
- Authentication Providers: Google, Apple, Facebook, Microsoft — for identity verification.
- Legal Requirements: If required by law, court order, or governmental authority.
- Business Transfers: In the event of a merger, acquisition, or sale of assets.
7. Data Retention & Security
Retention
Your account data and expense history are retained as long as your account is active. When you delete your account, your personal data and expenses are permanently deleted within 30 days.
Security Measures
- Encrypted transmission of data using TLS/HTTPS
- Encrypted storage of authentication tokens on your device
- Access controls limiting data access to authorised personnel only
- Regular security reviews
8. Children's Privacy
VoiceSpend is not directed at children under the age of 13 (or 18 where required by local law). We do not knowingly collect personal data from children.
9. Your Rights Under DPDP Act and GDPR
You have the following rights regarding your financial footprint:
To exercise these rights, email **support@bwjts.net** with the subject "Data Rights Request".
10. Cross-Border Transfers & Links
Your data may be processed on servers located outside India (including the United States) by our service providers (e.g., Firebase, RevenueCat). Such transfers are made under appropriate safeguards in compliance with the DPDP Act.
The App may integrate with third-party platforms for authentication. We are not responsible for the privacy practices of those platforms.
Contact Grievance Officer
In accordance with the **DPDP Act, 2023** and **Information Technology Act, 2000**, the details of the Grievance Officer are: