What we cannot see

Security and privacy

Most privacy pages describe how carefully a company guards data it did not need to collect. This one is mostly a list of things the app cannot do, because the safest data is the data that was never taken.

No bank connection. Ever.

The international app does not link to your bank. No Plaid, no open banking, no account aggregation, no screen-scraping, and no request for online banking credentials at any point.

This is a permanent product position rather than a missing feature, so it is worth being clear about the trade. You type, speak or photograph your transactions, which is more work than an app that imports them automatically. In exchange, there is no set of credentials to leak, no third-party aggregator holding a live connection to your account, and no ambiguity about what happens to that connection if the company is sold.

If automatic bank import is what you want, we are genuinely the wrong app, and there are good ones that do it.

No email access

The international app requests no access to Gmail, Outlook or any other inbox, and no such feature is planned.

This differs from the Indian app, which does offer optional Gmail transaction-alert parsing with explicit consent, because Indian banks send a structured email for essentially every transaction and the feature is genuinely useful there. It is a per-market decision, it is enforced on the server rather than by hiding a button, and no user outside India can reach that consent screen at all.

Worth stating plainly since it is the single most common thing people get wrong about these two apps: the international app never touches your email.

No SMS, no contacts

The app does not request SMS read permission or access to your contacts. On Android in particular, SMS permission is a common shortcut for transaction tracking, and it hands an app every message you receive — including the ones that are nothing to do with money.

What happens on your device

Two of the three input methods are designed to keep the raw material local:

This is better for privacy and it is also cheaper to run, which is a reasonable thing to admit: the incentives point the same way here.

What does leave your device

Honesty requires the other half of the list. Your transaction records, categories and the asset and liability values you maintain are stored on our servers so the app works across your devices and survives a lost phone. AI insights are generated by sending spending data — amounts, categories and dates — to a language model provider.

Full detail, including retention and the legal basis under GDPR, belongs in the privacy notice. That document is currently a pre-launch draft and is marked as one; it will be complete and reviewed before the app ships.

Deleting everything

Account deletion removes your data rather than deactivating it, and it is reachable from inside the app rather than requiring an email to support. Both app stores now require this, which is a good rule.

A caveat we would rather state than bury

None of this is a security audit

This page describes architecture and intent. It is not a penetration test result, a SOC 2 report or a certification, and we are not going to imply otherwise by using the word “bank-grade”. It is a small company building carefully, and the strongest thing we can honestly say is that most of the data other apps in this category hold, we never collect.

Common questions

Does TLDR Money connect to my bank?
No. The international app has no bank connection of any kind — no Plaid, no open banking, no aggregation, no credential request. It is a permanent design position, not a feature that is coming later.
Does it read my email?
The international app, no — it requests no inbox access at all. The separate Indian app offers optional Gmail transaction-alert parsing with explicit consent, because Indian banks email a structured alert for nearly every transaction. The restriction is enforced server-side, so a non-Indian account cannot reach that flow.
Is my data encrypted?
In transit and at rest, yes, which is table stakes rather than a feature. The more meaningful answer is how little there is: no bank credentials, no email contents, no SMS, no contacts.
What happens to my data if the company shuts down?
You can export and delete your data from inside the app at any time, and that is the honest protection. Any promise about a hypothetical wind-down or acquisition is worth exactly what the company is worth at the time it is tested.
Why does an expense tracker need my data on a server at all?
So the app works on more than one device and survives a lost or broken phone. A purely local app cannot do either, which is the trade-off most people would not accept in practice.

Last reviewed 20 August 2026.