EquofiEquofi
Equofi

Privacy Policy

Last updated: 20 June 2026

DBTech Pvt Ltd ("DBTech", "we", "us", or "our") operates the Equofi mobile application and website (the "Service"). This Privacy Policy explains how we collect, use, disclose, store, and delete personal data when you use Equofi.

Equofi is designed to keep your financial records under your control. In most cases, those records are stored in your own Google Sheets rather than in an Equofi-hosted financial ledger. We process data only as needed to provide, secure, and support the Service.

We handle personal data in accordance with applicable law, including relevant provisions of the Digital Personal Data Protection Act 2023 as they come into force, the Information Technology Act 2000, and applicable rules. The GDPR or UK GDPR may also apply depending on where the Service is offered and used.

1. Data We Collect

We may collect the following categories of information:

  • Account and profile data: When you sign in with Google or phone OTP, we may receive your name, email address, phone number, profile picture, unique user ID, age range, gender, city, country, and household preferences, depending on what you provide. Phone numbers are used for OTP-based identity verification.
  • Google Workspace data: If you connect Google Sheets, we access and process spreadsheet content, filenames, document metadata, and related authorization information needed to provide the Service. We access only spreadsheets that Equofi created or that you explicitly authorized through the OAuth consent flow.
  • Authorization data: We store OAuth tokens and auth credentials needed to access your connected Google resources on your behalf. These are stored with encryption at rest.
  • User-submitted content: This includes receipts (images and PDFs), profile photos, bank and investment statements, transaction descriptions, chat messages, feedback, voice recordings, and other files or content you choose to upload or enter for processing.
  • Financial and household data: This may include transaction entries, card or account details you use for personal-finance tracking, purchase history, balances, budget categories, income, liabilities, investments, insurance policies, financial goals, household member information, notes, and other data you choose to store or process through the Service. This data is stored in your Google Sheet and may be temporarily processed by our servers to provide features.
  • Voice and audio data: If you use voice input, the app records a short audio clip using your device microphone. This clip is transmitted to our backend for speech-to-text transcription. The raw audio is not stored by us after transcription. The resulting text is shown to you before you submit it — nothing is submitted automatically.
  • Location data (approximate): We may infer your approximate country from your IP address or profile settings. This is used for currency defaults, location-based suggestions, and personalization. We do not collect precise GPS location.
  • Usage and device data: We may collect diagnostic information such as app performance data, crash reports, browser type, device identifiers, operating system version, IP address, app interaction events, and log data.
  • Billing and paid-plan data: If you purchase Equofi Pro through the Equofi website, payment processing is handled by Razorpay. We store your plan status and limited billing metadata, such as payment reference IDs. We do not store full card numbers or sensitive payment credentials. The Android app does not currently provide a payment or checkout flow.
  • Email transaction data: If you use the email import feature, we access email metadata and body content from your connected email account to identify financial transactions. This import is explicitly initiated by you and processes only messages you authorize.
  • Support communications: If you contact us, we may collect your message content and related contact details.

2. On-Device Processing (AskEQ / Private Mode)

Equofi includes an optional on-device AI feature ("AskEQ / Private mode") powered by a small language model that runs entirely on your device. When you use this feature:

  • Your questions and your financial summary data are processed entirely on your device. Nothing is sent to any server or third party.
  • The feature uses only the limited financial context needed to answer your request from data already available in the app.
  • No AI provider, cloud service, or DBTech server receives your input or the model's output for this feature.

This feature requires downloading an AI model file to your device (approximately 1–2 GB). You may delete this file at any time from the app settings.

The main AI chat and all other AI-powered features (receipt parsing, voice transcription, document extraction) use server-side AI services described in clause 9.

3. Local Storage on Your Device

Equofi stores data locally on your device in two ways:

  • Local app database (mobile app): A local read cache of your transaction and account data, used for fast rendering, offline access, and queuing changes when you are not connected. This cache is a copy of your Google Sheet data and is not the source of truth. It is wiped on sign-out.
  • Browser localStorage (web app): A transient read cache of the same data for fast rendering. Wiped on sign-out. Never a source of truth.
  • AsyncStorage / SecureStore: Session tokens, preferences, and small metadata items needed to keep you signed in across app launches.

Local data does not leave your device except as part of normal sync to the backend. We do not access your local device storage except through the app itself.

4. How We Use Data

We use personal data to:

  • provide, operate, and maintain the Service;
  • authenticate you via Google OAuth or phone OTP and manage access to your connected Google resources;
  • read, write, organize, and sync your financial data with Google Sheets at your direction;
  • parse receipts, voice recordings, emails, and transaction details using AI-powered tools;
  • provide family or shared-household functionality, including shared ledgers and family invitations;
  • manage paid web-plan access and process related billing via Razorpay;
  • send transactional communications (family invitations, billing confirmations) via Resend;
  • debug, secure, and improve the Service;
  • respond to support requests, grievances, and legal inquiries;
  • detect abuse, fraud, and unauthorized access;
  • comply with legal obligations under applicable law.

5. Legal Bases for Processing

We process personal data only where permitted by applicable law. This generally includes consent and other uses permitted under Indian law. Where the GDPR or UK GDPR applies, processing may also rely on performance of a contract, legitimate interests, or legal obligations.

  • Consent: where you have given us permission, including for Google OAuth permissions, phone OTP verification, optional features, and sensitive data categories. You may withdraw consent at any time;
  • Performance of a contract: where processing is necessary to provide the Service you requested;
  • Legitimate interests: where processing is necessary to operate, secure, and improve the Service, provided those interests are not overridden by your rights;
  • Legal obligation: where we must process data to comply with applicable law, including tax and financial record requirements.

6. How We Store Data

  • Equofi is designed to minimize storage of financial data on our own systems. Your financial records are maintained in your connected Google Sheets, which you own.
  • We may temporarily process data in transit in order to display, transform, categorize, or synchronize it.
  • Authorization tokens, plan metadata, family roles, and limited account data may be stored by our service providers so we can continue to provide the Service.
  • Profile photos you upload are stored in a private storage bucket, not on our own servers. Access is restricted by row-level security and served through short-lived signed URLs (1-hour expiry).
  • Diagnostic logs, backups, and support records may contain limited personal data for operational and security purposes.
  • Deleting a Google Sheet or revoking access from your Google Account will stop future access by Equofi to that sheet, but it may not automatically delete all records already held by us, such as logs, support records, or billing records where retention is required or permitted by law.
  • Data may be stored on servers operated by our infrastructure providers in data centers outside India. Where required, we rely on appropriate safeguards for cross-border transfers, consistent with the DPDP Act.

7. Third-Party Services

We rely on the following third-party service providers to operate the Service. Each may process your data under their own terms:

  • Google Cloud Services: identity verification (Google OAuth and phone OTP), app integrity attestation, and connected-spreadsheet access. Governed by Google's Privacy Policy.
  • AI Providers: AI-powered transaction parsing, receipt and document extraction, chat assistance, classification, and speech-to-text transcription. We use AI only to extract, categorize, or structure data for the Service.
  • Infrastructure Providers: secure storage of account metadata, session data, family roles, sync records, profile photos, hosting, and edge delivery for the app and APIs.
  • Email Providers: transactional email delivery for family invitations and account-related communications.
  • Razorpay: payment processing for Equofi Pro subscriptions. Razorpay processes payment card, UPI, and billing data directly and is PCI DSS compliant. We receive only non-sensitive billing metadata (plan type, payment reference IDs) from Razorpay.

These providers process your data on our behalf or as independent controllers. We only use providers that offer appropriate safeguards, but their own privacy policies govern their processing activities.

8. How Equofi Uses Google Sheets

Equofi uses Google Sheets as the user-controlled ledger for your financial records. In practice:

  • What we access: Spreadsheets that Equofi created on your behalf, along with basic Google account information (name, email, profile picture) for sign-in and account setup.
  • OAuth scope: We request only non-sensitive scopes, which limit our access to files Equofi itself created. We do not request broader Sheets or Drive access.
  • Why we access it: To create, read, update, organize, and sync the financial data needed for Equofi features you choose to use — including transactions, budgets, investments, liabilities, and family records.
  • Family access: Family data is processed only to provide sharing features requested by participating users and according to their roles and permissions.
  • Your control: You can revoke Equofi's access to your Google account at any time from Google Account permissions.

Equofi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

9. AI Processing

Equofi uses AI in two distinct ways, which have different privacy implications:

  • Server-side AI: When you upload a receipt, paste a transaction message, use the AI chat feature, or use voice input, that content is sent to our backend and may be forwarded to our AI providers for analysis. We use AI only to extract, categorize, or structure data for the Service. We do not intentionally use your financial content to train public models. We may retain AI input and output temporarily for debugging, abuse prevention, and service improvement, unless earlier deletion is required by law or policy.
  • On-device AI (AskEQ / Private mode): This optional feature processes your questions and financial summaries entirely on your device using a locally downloaded model. No data is sent to any server, AI provider, or third party. See clause 2 for full details.

AI outputs may be incorrect or incomplete. You are solely responsible for reviewing AI-generated results before relying on them for any financial decisions. Equofi is not a licensed financial, tax, or investment adviser.

10. Data Sharing

We do not sell, rent, or trade your personal information. We may share data only:

  • with service providers listed in clause 7 working on our behalf and under appropriate data processing agreements;
  • with household members or other users you explicitly invite or share data with in the family or shared-household features — at your direction;
  • with Google, as a necessary consequence of writing or reading your Google Sheet via your authorized OAuth token;
  • to comply with legal obligations, court orders, subpoenas, or lawful requests by Indian or other applicable authorities;
  • to protect the rights, safety, and security of DBTech, users, or the public;
  • in connection with a merger, acquisition, restructuring, financing, or sale of assets, subject to appropriate confidentiality and data protection safeguards, and notice to you where required by law.

11. Data Retention

We keep personal data only as long as necessary for the purposes described in this Policy, unless a longer period is required by law:

  • Account and token data: retained while your account is active and for a reasonable period afterward for security and legal purposes;
  • Billing records: retained for the period required by applicable Indian tax and financial regulations, generally 7 years;
  • Logs and diagnostics: retained for security, debugging, and abuse prevention, generally up to 90 days;
  • Support records: retained as needed to resolve issues and maintain records, generally up to 2 years;
  • AI input/output: retained only for the minimum period needed to provide the Service or improve reliability, then deleted.

Deleting your Equofi account removes your account, session data, and associated metadata from our systems. Your Google Sheet remains in your Google Drive and is not affected by account deletion — you may delete it independently from Google Drive. See our account deletion page for the full process and what data is and is not removed.

12. Your Rights

Under the DPDP Act 2023 and other applicable law, you have the following rights:

  • Right to access: request a summary of the personal data we hold about you;
  • Right to correction: request that inaccurate or outdated personal data be corrected;
  • Right to erasure: request deletion of your personal data, subject to legal retention obligations;
  • Right to grievance redressal: lodge a complaint with our Grievance Officer and receive a substantive response;
  • Right to nominate (DPDP Act): nominate a person to exercise data rights on your behalf in the event of your death or incapacity;
  • Right to withdraw consent: withdraw consent for any processing based on consent at any time, without affecting the lawfulness of prior processing;
  • Data portability (where applicable): receive a portable copy of your data in a structured, commonly used format;
  • Right to complain: lodge a complaint with the Data Protection Board of India or another applicable data protection authority, where the relevant right and process are available.

To exercise any of these rights, contact us at the details below or use our account deletion page. We may ask you to verify your identity before responding. We will acknowledge grievances within 7 days and aim to resolve them within 30 days.

13. Security

We use reasonable technical and organizational measures to protect personal data, including:

  • HTTPS/TLS encryption for all data in transit;
  • protections for stored credentials and authorization tokens;
  • access controls for sensitive server-side data;
  • application-integrity and session-security controls designed to reduce unauthorized access.

No system is completely secure. We cannot guarantee absolute security, and you use the Service at your own risk. In the event of a personal data breach that is likely to result in harm to you, we will notify you as required by applicable law.

14. Children

The Service is not directed to children under 18 years of age (or the minimum age required by applicable law to consent to online services). We do not knowingly collect personal data from children. If you believe a child has provided us personal data without appropriate authorization, contact us and we will take appropriate steps, including deletion of the data.

15. International Transfers

Your data may be processed in countries outside India, including where our service providers operate. Where required, we use appropriate safeguards for cross-border transfers and require providers to handle data consistently with our instructions and applicable law.

16. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and may provide additional notice (such as an in-app notification or email) where required by law. We encourage you to review this Policy periodically. Continued use of the Service after changes become effective constitutes acceptance of the updated Policy.

17. Grievance Officer

In accordance with the Information Technology Act 2000 and the DPDP Act 2023, we have designated a Grievance Officer for data-related concerns. You may contact the Grievance Officer to report concerns about our data processing practices or to exercise your rights under applicable law.

Grievance Officer
Deepankar Boro
DBTech Pvt Ltd
Email: privacy@equofi.app

We will acknowledge grievances within 7 days of receipt and aim to resolve them within 30 days.

18. Contact Us

If you have questions about this Privacy Policy or your personal data, contact:

DBTech Pvt Ltd
Email: privacy@equofi.app