What we cannot see
Security and privacy
Most privacy pages describe how carefully a company guards data it did not need to collect. This one is mostly a list of things the app cannot do, because the safest data is the data that was never taken.
No bank connection. Ever.
The international app does not link to your bank. No Plaid, no open banking, no account aggregation, no screen-scraping, and no request for online banking credentials at any point.
This is a permanent product position rather than a missing feature, so it is worth being clear about the trade. You type, speak or photograph your transactions, which is more work than an app that imports them automatically. In exchange, there is no set of credentials to leak, no third-party aggregator holding a live connection to your account, and no ambiguity about what happens to that connection if the company is sold.
If automatic bank import is what you want, we are genuinely the wrong app, and there are good ones that do it.
No email access
The international app requests no access to Gmail, Outlook or any other inbox, and no such feature is planned.
This differs from the Indian app, which does offer optional Gmail transaction-alert parsing with explicit consent, because Indian banks send a structured email for essentially every transaction and the feature is genuinely useful there. It is a per-market decision, it is enforced on the server rather than by hiding a button, and no user outside India can reach that consent screen at all.
Worth stating plainly since it is the single most common thing people get wrong about these two apps: the international app never touches your email.
No SMS, no contacts
The app does not request SMS read permission or access to your contacts. On Android in particular, SMS permission is a common shortcut for transaction tracking, and it hands an app every message you receive — including the ones that are nothing to do with money.
What happens on your device
Two of the three input methods are designed to keep the raw material local:
- Voice entry uses on-device speech recognition, so audio is not sent anywhere.
- Receipt scanning reads the text on the device and sends only the extracted text for structuring — the photograph itself does not leave your phone.
This is better for privacy and it is also cheaper to run, which is a reasonable thing to admit: the incentives point the same way here.
What does leave your device
Honesty requires the other half of the list. Your transaction records, categories and the asset and liability values you maintain are stored on our servers so the app works across your devices and survives a lost phone. AI insights are generated by sending spending data — amounts, categories and dates — to a language model provider.
Full detail, including retention and the legal basis under GDPR, belongs in the privacy notice. That document is currently a pre-launch draft and is marked as one; it will be complete and reviewed before the app ships.
Deleting everything
Account deletion removes your data rather than deactivating it, and it is reachable from inside the app rather than requiring an email to support. Both app stores now require this, which is a good rule.
A caveat we would rather state than bury
None of this is a security audit
This page describes architecture and intent. It is not a penetration test result, a SOC 2 report or a certification, and we are not going to imply otherwise by using the word “bank-grade”. It is a small company building carefully, and the strongest thing we can honestly say is that most of the data other apps in this category hold, we never collect.
Common questions
Does TLDR Money connect to my bank?
Does it read my email?
Is my data encrypted?
What happens to my data if the company shuts down?
Why does an expense tracker need my data on a server at all?
Last reviewed 20 August 2026.