Privacy

Why a budget app should not read your email

Inbox scanning is a genuinely useful feature in the right market and an unusually broad permission everywhere. We ship it in exactly one country, and this is the reasoning.

What the permission grants

Gmail read access is not scoped to bank emails. There is no permission that says “only the messages from my bank”. An app with read access can read the inbox — the filtering to transaction alerts happens after the fact, inside software you cannot inspect.

Google treats it accordingly. It is a restricted scope, requiring verification and an annual third-party security assessment, and the review is not a formality. That process exists because the access is broad.

Why we do ship it in India

We are not against the feature in principle, and pretending otherwise would be dishonest given that our Indian app has it.

In India nearly every bank and card sends a structured email alert for essentially every transaction. That makes inbox scanning genuinely transformative there: it turns a manual tracker into an automatic one, in a market where bank aggregation is comparatively limited. The trade — broad permission for a large gain — is a reasonable one to offer, with explicit consent.

Why the international app never will

The same trade does not hold in the US, the UK or Europe. Transaction alert emails are far less universal, so the gain is much smaller, while the permission is exactly as broad. And these markets have open banking, which is a regulated, consented, revocable, purpose-limited flow — strictly better designed for this job than reading an inbox.

So the international app requests no email access and no bank connection either. Manual, voice and receipt entry, and nothing that touches your inbox.

This is enforced on the server, not by hiding a button. A non-Indian account cannot reach the consent screen at all. Hiding an entry point in the client is not a control; a Gmail grant from an EU user would be a real regulatory problem that “the UI did not show it” does not answer.

What to ask if an app offers this

Good answers exist. The point is to ask rather than to tap through.

Common questions

Can an app read only my bank emails?
Not technically. Gmail read access is not scoped to a sender, so an app with it can read the inbox. The narrowing to transaction alerts happens inside the application afterwards, which is a matter of trusting the developer rather than a restriction the platform enforces.
Does the international TLDR Money app read email?
No, and it is not planned. Inbox parsing is India-only and the restriction is enforced server-side, so an account outside India cannot reach the Google consent screen even if the interface somehow offered it.
Is open banking safer than inbox scanning?
For this purpose, yes, by design. Open banking is regulated, purpose-limited, explicitly consented and revocable, and it returns transaction data rather than access to your correspondence. TLDR Money uses neither, but if you are choosing between the two, open banking is the better-designed mechanism.

Where this comes from

The international app touches no inbox

No email access, no bank connection, no SMS permission and no contacts. Voice recognition and receipt text extraction run on the device. What is left is a short list, and the security page sets out both what leaves your phone and what does not.

Not out yet. TLDR Money International is in build for the United States and the United Kingdom first, on iPhone and Android. The calculators are free and need no account.

Published 20 August 2026.