We take your privacy seriously. This policy explains exactly what data Credzo collects, how it is used, and the choices you have.
🔒 Short version: Credzo stores your expense data securely on our servers. We never sell your data to third parties. With your permission, matched financial SMS messages are transmitted over HTTPS to detect transactions — personal messages are never read or stored.
We collect the following categories of information when you use Credzo:
Account Information
Expense & Financial Data
Usage & Technical Data
We use the information we collect exclusively to provide and improve the Credzo service:
We do not use your data for advertising, profiling for third parties, or any purpose beyond delivering the service described above.
⚠️ The SMS auto-import feature is available on Android only and requires explicit permission (READ_SMS) from you before it is activated.
With your explicit permission (READ_SMS), the App reads SMS messages on your device solely to detect bank and credit card transaction notifications sent by financial institutions. Only messages from financial institution senders — such as 5-digit or alphanumeric bank short codes (e.g., VM-HDFCBK, AD-ICICIB) — are processed. Personal SMS messages are never read, accessed, or stored.
To enable automatic expense detection, the text content, sender address, and timestamp of matched financial SMS messages are securely transmitted over HTTPS to our servers for deduplication and transaction parsing. This data is used solely to extract transaction amounts and merchant names for your expense tracking history. SMS data transmitted to our servers is retained for as long as your account is active and is permanently deleted when you delete your account.
You can revoke SMS permission at any time from your device settings (Settings → Apps → Credzo → Permissions). The App will continue to function for manual expense entry without this permission.
Your data is stored on secure servers. We implement the following technical safeguards:
While we take commercially reasonable measures to protect your data, no method of electronic storage or transmission is 100% secure. We encourage you to use a strong, unique password for your Credzo account.
We do not sell your personal data. We do not share your data with advertisers, data brokers, or marketing companies.
We may share data only in the following limited circumstances:
The AI-powered Planner feature (Elite plan) may transmit your anonymised spending patterns to an AI inference service for generating personalised recommendations. No personally identifiable information (name, email, card details) is included in these requests.
We retain your account and expense data for as long as your account is active. If you delete your account, all associated data — expenses, credit cards, budget limits, membership history, notification preferences, and any SMS transaction data transmitted to our servers — is permanently deleted from our systems within 30 days of account deletion.
Aggregated, anonymised usage statistics that cannot identify you may be retained indefinitely for product improvement purposes.
You have the following rights regarding your personal data:
Credzo is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us at support@credzoapp.com and we will promptly delete it.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you via in-app notification or email.
Your continued use of Credzo after changes are posted constitutes your acceptance of the revised policy. We encourage you to review this page periodically.
If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data, please reach out to us:
📧 Email: support@credzoapp.com
📍 Location: India
We aim to respond to all privacy-related enquiries within 48 hours.