Folosy Privacy Policy
This privacy policy applies to the Folosy mobile application for Android (package name com.folosy.app), developed and published by Folosy (“we”, “us”, “the developer”).
Contact: folosy4@gmail.com
Summary
Folosy is a local-first personal finance app. Your financial data — transactions, balance, budgets, categories, and the bank SMS messages the app processes — is stored only on your phone, in storage private to the app. We do not operate any server that stores your personal or financial data, and we cannot see it. The only data that ever leaves your device is (1) an optional backup that goes to your own Google Drive, and (2) standard purchase information if you buy a premium subscription. Both are described in full below.
1. SMS messages (core feature)
Folosy’s core feature is automatic expense tracking: when your bank sends you a transaction SMS, the app reads it and records the transaction for you. To do this, the app uses the Android permissions RECEIVE_SMS and READ_SMS.
How SMS data is handled:
- Processing happens entirely on your device. SMS messages are parsed by code running on your phone. The app never transmits SMS content off your device — not to us, and not to anyone else.
- Only messages from your selected bank are processed. The app checks the sender of each incoming SMS. Messages that are not from the official sender IDs of the bank you chose during setup — personal messages, messages from other services, promotions — are ignored immediately and are never stored or analyzed.
- Non-transactional bank messages are discarded. Bank messages that do not describe money movement (for example one-time passcodes, declined-transaction notices, and marketing) are recognized and discarded without being stored.
- Transactional bank messages are stored on your device. Bank messages that record a transaction, or that the app could not parse and needs to show you for review, are saved in the app’s private on-device database so the app can display them to you.
- Permission is optional. You grant SMS access during onboarding and can decline or revoke it at any time in Android settings. Without it, the app still works fully through manual transaction entry.
2. Financial information you enter or the app derives
Transactions, your account balance, budgets, categories, and app settings are stored only in the app’s private on-device database. This data never leaves your device except as part of the optional backup described in section 3.
3. Backup to your Google Drive (optional)
You can optionally turn on backup so your data survives a lost or replaced phone.
- What is backed up: a copy of the app’s database — your transactions, balance, budgets, categories, settings, and the bank SMS messages the app has processed.
- Where it goes: a hidden, app-specific folder in your own Google Drive (the Drive “app data folder”). The backup belongs to your Google account. It is never sent to us, and we have no way to access it.
- Google Sign-In: enabling backup requires signing in with your Google account. Sign-in is handled by Google on your device; the app requests only the
drive.appdatascope, which limits it to its own hidden folder — it cannot see any of your other Drive files. We do not receive your Google account credentials or profile data on any server, because we do not operate one. - When backups run: automatically while you are using the app (at most roughly once every 30 minutes), only while your device is online.
- Retention: the app keeps one backup per day for up to 14 days and automatically deletes older ones.
- Deletion: you can turn off backup in the app at any time. To delete stored backups, open Google Drive settings → “Manage apps” → disconnect Folosy; Google then deletes the app’s hidden folder and everything in it.
- Security: backups are encrypted in transit (HTTPS) and protected by Google Drive’s storage security and your Google account. The backup file itself is not additionally encrypted by the app in this version.
Folosy’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Payments and subscriptions
Folosy offers an optional premium subscription, purchased through Google Play’s billing system. Your payment details (card numbers, etc.) are handled by Google Play and never reach us or the app.
To validate purchases and manage subscription status, the app uses RevenueCat, a subscription-management service. RevenueCat receives: the purchase token issued by Google Play, a randomly generated app user identifier (not your name or email), and basic device information such as device model, operating system version, app version, and locale. RevenueCat never receives your SMS messages, transactions, balance, or any other financial data from the app. RevenueCat’s privacy policy is available at https://www.revenuecat.com/privacy.
5. Data we do not collect
- No user accounts — the app has no registration, login, email, or password of its own.
- No analytics, tracking, or advertising SDKs of any kind.
- No ads.
- No access to contacts, location, camera, microphone, photos, or files outside the app’s own storage.
- We do not sell or rent any data, and we do not share data with anyone for advertising or marketing.
- We do not operate any server that stores your personal or financial data.
6. Data sharing
The app shares data only with the service providers named above, only for the purposes described:
| Recipient | What | Why |
|---|---|---|
| Google Drive (your account) | Your backup file | Only if you enable backup; stored in your own Drive |
| Google Play | Standard purchase/billing data | Only if you buy a subscription |
| RevenueCat | Purchase token, random app user ID, basic device info | Only if you buy a subscription; validates it |
Nothing else is shared with anyone. We may disclose information if required by law, but since we hold no user data on any server, there is effectively nothing for us to disclose.
7. Data retention and deletion
- On-device data stays on your phone until you delete it. You can delete individual entries in the app, clear the app’s storage in Android settings, or uninstall the app — any of these removes the local data.
- Backups are kept for up to 14 days on a rolling basis in your own Google Drive and can be deleted at any time as described in section 3.
- Purchase records are retained by Google Play and RevenueCat according to their own policies; subscriptions are managed and cancelled through Google Play.
Because we do not hold your data, there is no need to request deletion from us — you are always in direct control of it. If you have any questions or need help, contact us at the email above.
8. Security
App data is stored in Android’s app-private storage, which other apps on your device cannot read. Transfers to Google Drive and to payment services use encrypted connections (HTTPS).
9. Permissions the app uses
RECEIVE_SMS,READ_SMS— the core automatic expense-tracking feature (section 1).INTERNET— used only for the optional Drive backup and for subscription purchases/validation. The app is otherwise fully functional offline.
10. Children
Folosy is a personal finance tool and is not directed at children under 13. We do not knowingly collect personal information from children.
11. Changes to this policy
If we change this policy, we will post the updated version at this same address and update the “Last updated” date above. Material changes (for example, if a future version adds an opt-in way to share unrecognized bank messages to improve parsing) will be clearly reflected here and will require your explicit consent in the app.
12. Contact
For any questions about this policy or your data: folosy4@gmail.com