1. Scope
This Privacy Policy explains how AppGenie (“PayPilot”, “we”, “us”, or “our”) handles information when you use the PayPilot mobile application and this website. It applies to the app, optional account sync, and reminders.
PayPilot is a personal finance organization tool. It is not a bank, lender, financial adviser, payment processor, or credit-reporting service.
2. Information we handle
Account and sign-in
When you create or access an account, the app may receive an email address, a user identifier, and the name associated with your account. You can sign in with email/password, Google, or Apple. The sign-in provider may process information under its own privacy policy.
Finance records
PayPilot can store records you choose to enter, including expenses, payment methods, subscriptions, autopay items, loans, repayments, currency preferences, reminder settings, and display preferences. Do not enter information you do not need for the app.
Device and app information
The app may process information needed to operate on your device, such as platform configuration, app state, and permission status. The current implementation does not intentionally request contacts, location, camera, microphone, or advertising identifiers. Verify the published app permissions before launch.
Notifications and shortcuts
If you enable reminders, PayPilot schedules local notifications through the operating system. Reminder content is generated from your records and settings. Optional Siri or Shortcuts capture uses a temporary on-device handoff for supported commands; the app removes the temporary snapshot after it is consumed or the session ends.
Optional device features
Some PayPilot versions may offer optional device features. These features are available only when you enable and use them, and availability depends on the published app version and operating-system permissions.
- Bank SMS: If SMS import is offered and you enable it, PayPilot processes only the message information needed to identify supported transaction details. It does not need unrelated messages, and you should review the import permission before enabling it.
- Apple Pay: PayPilot does not receive your full card number, device account number, or Apple Pay security credentials. If you add a transaction manually or through a supported share flow, that information is handled as a finance record.
- Face ID: Biometric matching stays on your device. PayPilot receives only the operating system result that access was granted or denied; it does not receive Face ID images or biometric templates.
- Siri and Spotlight: If you enable these integrations, the operating system may use the shortcut or searchable information needed for the action you request. You can disable these integrations in device settings.
- Exchange rates: Currency conversion rates may be obtained from a third-party rate source when the feature is used. Rates are informational, may be delayed, and should not be treated as a quote for a financial transaction.
Support
If you contact support, we receive the contact details and message you choose to send, plus attachments or diagnostic details you include. Do not email passwords, authentication codes, or full payment-card numbers.
3. How we use information
- Provide sign-in, account recovery, sync, and finance-organizing features.
- Save and display preferences, reminders, and records across devices when sync is enabled.
- Protect the app, prevent misuse, troubleshoot failures, and respond to support requests.
- Send service-related messages for security, account access, or material policy changes.
- Meet legal obligations and enforce our terms.
We do not sell your personal information. We do not use your finance records to provide financial advice or make lending decisions.
4. Local storage, encryption, and cloud sync
PayPilot is designed to work locally first. The app stores working copies of your records on your device so the interface can remain useful without a constant network connection.
When cloud sync is enabled, finance records are encrypted on the device before being written to the PayPilot Firebase/Cloud Firestore project. The cloud layer stores encrypted envelopes and a wrapped data key rather than the app’s plaintext finance records. Access is restricted by the signed-in account and Firestore security rules. No security method is perfect, so keep your sign-in credentials and device secure.
Firebase may process service data needed to operate authentication and Firestore. See Firebase’s privacy and security information for Google’s service-level practices. Confirm final processor/subprocessor and cross-border-transfer wording with counsel.
5. Service providers and third parties
PayPilot currently uses Firebase Authentication and Cloud Firestore for account access and optional encrypted sync, and Google and Apple sign-in services when selected. Mobile operating-system services may deliver local reminders. Those providers may process data under their own terms and privacy notices.
Update this section before enabling a new hosting, email, diagnostics, or other provider. The final policy should list each provider, purpose, data categories, location/transfer mechanism, and retention terms where required.
6. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal information, or withdraw consent where processing is based on consent. You can control notifications in the app and device settings.
You can change or delete many records inside the app. To delete the account and associated synced records, follow the account deletion instructions. For a rights request, contact appgenieteam@gmail.com.
7. Retention and deletion
We keep account and synced information while your account is active. When you request account deletion, we aim to process it within one week after verifying the request. We delete account and app data, except information that must temporarily remain for legal, security, backup, or fraud-prevention purposes.
Account deletion is intended to remove the user’s Firestore documents, encryption key record, local database content, and Firebase Authentication account through the app’s deletion flow. Limited backup, security, or legally required records may remain temporarily and are then deleted or de-identified.
8. Children
PayPilot is not directed to children under 10. We do not knowingly collect personal information from children in violation of applicable law.
9. Changes
We may update this policy when the app, providers, or legal requirements change. We will post the new version here, update the date, and provide any additional notice required by law.
10. Contact
Privacy questions and rights requests: appgenieteam@gmail.com
AppGenie
India