Privacy Policy

MARK (Money App Re-invented, Kinda)

Effective Date: February 12, 2026

Last Updated: February 12, 2026

1. Introduction

Welcome to MARK (Money App Re-invented, Kinda), a voice-enabled expense tracking application for mobile devices. This privacy policy describes how we collect, use, store, and protect your personal data.

Service Provider: Chinmoy Dutta (Individual Developer)
Contact Email: dattatechom@gmail.com
Jurisdiction: India
Compliance: Digital Personal Data Protection Act (DPDP Act), 2023

By using MARK, you consent to the processing of your personal data as described in this Privacy Policy. This policy applies to all users who download and use the MARK mobile application.

Important Note: MARK follows a local-first, privacy-preserving architecture. Your financial data is stored primarily on your device and never transmitted to our servers. Optional cloud backup is fully under your control via your personal Google Drive.

2. Information We Collect

We collect only the minimum information necessary to provide our expense tracking services. Here's a comprehensive breakdown:

A. Account Information

What We Collect:

Purpose: User authentication, identification, and account management.

Storage: Managed by Firebase Authentication (Google LLC).

Legal Basis: Consent (required for creating an account).

B. Financial Data (Local-First Storage)

What We Collect:

Storage:

Purpose: Core expense tracking functionality, analytics, budgeting, and reporting.

Legal Basis: Consent (necessary for providing the service).

Important: We DO NOT store your financial data on our servers. It remains on your device or your personal cloud storage only.

C. Voice Recordings

What We Collect: Temporary audio recordings when you use voice input for expense logging.

Processing Methods:

Retention: Deleted immediately after transcription completes. We do NOT store voice recordings permanently.

Purpose: Voice-to-text conversion for expense logging.

Legal Basis: Explicit consent (you choose offline or online mode).

D. Device Information

What We Collect:

Purpose: App optimization, selecting appropriate ML models, enabling/disabling battery-intensive features.

Legal Basis: Legitimate interest (necessary for app functionality).

E. Advertising Data (Google AdMob)

What We Collect:

Managed By: Google LLC (AdMob service)

Purpose: Serving rewarded video ads that allow you to earn credits for premium features.

Legal Basis: Consent (you choose to watch ads to earn credits).

Privacy Policy: Google Privacy Policy

F. Push Notification Tokens

What We Collect: Firebase Cloud Messaging (FCM) device tokens.

Purpose: Sending push notifications for trial reminders and important updates.

Storage: Managed by Firebase Messaging (Google LLC).

Legal Basis: Consent (you can disable notifications in device settings).

3. How We Use Your Information

We use the collected information for the following purposes:

We DO NOT:

5. Data Storage & Security

We take data security seriously and implement industry-standard measures to protect your information.

Storage Architecture

Security Measures

Data Location

Important: While we implement strong security measures, no system is 100% secure. You are responsible for maintaining the security of your device and Google account credentials.

6. Third-Party Services

MARK integrates with the following third-party services. Each service has its own privacy policy that governs how they handle your data:

Service Purpose Data Shared Location Privacy Policy
Firebase Authentication User authentication Email, name, photo, UID Asia-South1 (Mumbai) Firebase Privacy
Google Gemini API Voice transcription (online mode) Audio recordings (temporary) Asia region (Mumbai/Singapore) Google Privacy
Google Drive API Optional backup Financial data (user-controlled) User's Google account region Google Privacy
Google AdMob Rewarded video ads Ad ID, IP address, interactions Multi-region (optimized for Asia) AdMob Privacy
Firebase Messaging Push notifications FCM token, device info Asia-South1 (Mumbai) Firebase Privacy
Firebase Cloud Functions API proxy (no data storage) Request data (not stored) Asia-South1 (Mumbai) Firebase Privacy
Google Sign-In OAuth authentication Email, name, photo Asia-South1 (Mumbai) Google Privacy

Data Locality for Indian Users: For users in India, all voice transcription using online mode is processed in Google's Asia region data centers (Mumbai, Delhi, or Singapore). Your audio data does not leave Asia, ensuring compliance with data residency preferences. You can still opt for offline mode to process all voice data entirely on your device without any network transfer.

We are not responsible for the privacy practices of third-party services. Please review their privacy policies independently.

7. Your Rights (Data Principal Rights - DPDP Act 2023)

Under India's Digital Personal Data Protection Act (DPDP Act), 2023, you have the following rights regarding your personal data:

Right to Access

What it means: You can request a copy of all personal data we hold about you.

How to exercise: Settings → Export Data → CSV Export. This generates a machine-readable CSV file with all your expenses, income, budgets, and metadata.

Right to Correction

What it means: You can correct inaccurate or incomplete personal data.

How to exercise: Edit transactions, categories, budgets directly within the app. Changes are saved immediately.

Right to Erasure

What it means: You can request deletion of your personal data.

How to exercise:

What gets deleted:

⚠️ Important: Account deletion is permanent and irreversible. Export your data first if you want to keep records. Learn more about data deletion →

Right to Data Portability

What it means: You can export your data in a machine-readable format.

How to exercise: Settings → Export Data → CSV Export. The CSV file can be imported into other apps or spreadsheets.

Right to Withdraw Consent

What it means: You can withdraw consent for data processing at any time.

How to exercise:

Right to Grievance Redressal

What it means: You can file a complaint if you believe your data rights have been violated.

How to exercise: Contact our Grievance Redressal Officer at dattatechom@gmail.com (see Section 12 for details).

Right to Nominate

What it means: You can nominate another individual to exercise your rights in the event of death or incapacity (as per DPDP Act).

How to exercise: Contact us at dattatechom@gmail.com to register a nominee.

Response Time: We will respond to your rights requests within 48 hours and resolve issues within 7 business days, as required by the DPDP Act.

8. Data Retention & Deletion

Retention Periods

Data Type Retention Period Reason
Account Data While account is active Required for authentication
Financial Data While account is active Core app functionality
Voice Recordings < 1 minute (immediate deletion) Only needed for transcription
FCM Tokens 60 days (auto-refresh) Push notification infrastructure
Device Information Session duration only Not stored persistently
AdMob Data Managed by Google Subject to Google's policies

Inactive Account Policy (DPDP Act Requirement)

As required by the DPDP Act, we cannot store personal data for more than 1 year of user inactivity:

Account Deletion Process

When you delete your account (Settings → Account → Delete Account):

  1. Confirmation Dialog: You must confirm the irreversible action
  2. Immediate Deletion: All data is deleted instantly, including:
    • Firebase Authentication account
    • Local SQLite database
    • Google Drive backup files (if enabled)
    • FCM tokens (invalidated)
    • All transaction history and metadata
  3. Confirmation Email: You'll receive an email confirming account deletion
  4. No Recovery: Deleted data cannot be recovered

Exceptions (Legal Requirements)

In rare cases, we may be legally required to retain certain data:

In such cases, only the minimum necessary data will be retained, and you will be notified if legally permissible.

9. Children's Privacy

Age Requirement

MARK is intended for users 18 years or older. We do not knowingly collect personal data from individuals under 18 years of age.

Why 18 Years?

Parental Notice

If you are a parent or guardian and believe your child under 18 has provided personal data to MARK:

Verification

We do not currently implement age verification mechanisms at registration. Users are expected to comply with the 18+ age requirement. Future versions may include age verification for enhanced compliance.

10. International Users

While MARK is primarily designed for Indian users and complies with India's DPDP Act 2023, we also respect the privacy rights of users in other jurisdictions.

For Users in the European Union (GDPR)

If you are located in the EU, you have additional rights under the General Data Protection Regulation (GDPR):

For Users in California (CCPA/CPRA)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

Data Transfers

Your data processing locations depend on your geographic location and selected features:

No Trans-Border Data Transfers for Indian Users: If you are located in India and use online voice features, your audio data is processed entirely within Asia. We do not transfer Indian user data to US or European servers.

These regional processing arrangements ensure faster performance and data residency compliance. By using MARK, you consent to these processing locations.

11. Changes to Privacy Policy

How We Update This Policy

We may update this Privacy Policy from time to time to reflect:

Notification of Changes

When we make material changes to this Privacy Policy, we will notify you through:

Your Continued Use

By continuing to use MARK after changes to this Privacy Policy, you accept the updated terms. If you do not agree with the changes, you may delete your account.

Material Changes Requiring Consent

If changes involve new data collection or processing that requires consent (under DPDP Act), we will explicitly ask for your consent before implementing such changes. You can decline consent, though this may limit certain features.

Version History

Current Version: 1.0 (February 12, 2026)

12. Grievance Redressal Officer (DPDP Act Requirement)

As required by India's Digital Personal Data Protection Act (DPDP Act), 2023, we have appointed a Grievance Redressal Officer to address your data privacy concerns.

Grievance Officer Details

Name: Chinmoy Dutta
Email: dattatechom@gmail.com
Response Time: Within 48 hours of receiving complaint
Resolution Time: Within 7 business days

How to File a Complaint

  1. Email Us: Send an email to dattatechom@gmail.com with:
    • Your registered email address
    • Subject line: "Privacy Complaint - [Brief Description]"
    • Detailed description of the issue
    • Supporting documents (if any)
  2. Acknowledgment: You'll receive an acknowledgment email within 48 hours with a ticket number
  3. Investigation: We will investigate your complaint thoroughly
  4. Resolution: You'll receive a resolution within 7 business days

Types of Complaints We Handle

Escalation

If you are not satisfied with our resolution, you have the right to escalate your complaint to:

Data Protection Board of India
Website: https://dpb.gov.in (when operational)
Note: The Data Protection Board of India is expected to be fully operational by May 2027.

13. Contact Us

If you have any questions, concerns, or feedback about this Privacy Policy or our data practices, please contact us:

Developer Contact

Name: Chinmoy Dutta
Email: dattatechom@gmail.com
Response Time: Within 48 hours

What You Can Contact Us About

Support

For general app support (not privacy-related), please also email dattatechom@gmail.com with "Support Request" in the subject line.

Security Vulnerability Reporting

If you discover a security vulnerability in MARK, please report it responsibly: