Privacy Policy
The short version.
Genie does not ask for your name, email, or phone number. You sign in with a 16-digit number that you generate on your device.
Genie checks bank-notification SMS messages against the app's server-managed global keyword list. Matching messages are sent through OpenRouter to a large language model (LLM) to be parsed into expense records. Other SMS messages are never sent.
You can delete your account and everything we hold about you at any time from Settings → Delete account.
1. Who we are
Genie ("we", "us") is a personal-finance Android app operated by Osama Adam ("the operator"). This policy covers the Genie mobile app and the Genie sync backend.
For privacy questions or requests: osamaadamme@gmail.com.
2. What we collect
We collect only what we need to make the app work.
- Your account credential. When you create an account, your device generates a 16-digit number. The app stores it locally so you can sign in later. We store a one-way hash of the number on our server so we can recognise you on sign-in. We cannot reverse the hash to learn the number itself.
- Bank-notification SMS messages. When you grant SMS permission, Genie checks incoming SMS on your device against the app's server-managed global keyword list. Only matching messages are sent to our server. The full message body and sender are included so we can parse the transaction. Messages that don't match are never sent.
- Transactions. Every expense, income, transfer, and balance adjustment you record — manually or auto-imported from SMS. Each record includes the amount, currency, account, category, time, and an optional note.
- Accounts and categories. The bank accounts, cards, investment accounts and holdings, and spending categories you set up. Account entries include the bank name and the last four digits of a card if you provide them.
- Technical logs. Standard server logs of API requests (timestamp, request path, HTTP status, response time, anonymous request ID). No SMS bodies, account numbers, or tokens are logged.
- Pseudonymous usage and crash data. To find bugs and understand which features are used, the app sends usage events (e.g. "a record was added manually", screen visits), crash reports, and screen recordings to our analytics processor. These recordings capture what is shown on your screen — including your transactions, merchant names, amounts, balances, and notes — so we can see and fix problems. Your 16-digit account number is always masked and never recorded. All of this data is keyed to a random identifier generated on your device that is never linked to your account, and you can turn it off any time in Settings → Usage & crash reports.
We do not collect: your name, email address, phone number, government ID, biometrics, contacts, photos, files, location, browsing history, advertising identifiers, or any social/Google identity.
3. How we use your information
- To run the app: showing your transactions, computing balances, syncing across your devices.
- To convert bank SMS messages into structured expense records (the core feature).
- To authenticate you on sign-in and keep your session alive.
- To diagnose and fix bugs from anonymous server logs.
We do not use your data for advertising, profiling, or training machine-learning models.
4. Who we share it with
Genie shares data with the following processors only, and only as much as needed to run the service:
- AI processing provider (OpenRouter). Each bank SMS that matches the app's global keyword list is sent through OpenRouter to a third-party large language model (LLM) service to be parsed into a structured record. The provider receives the SMS body and sender; it does not receive your account number or any data that identifies you to us. We select providers whose terms state that API requests are not used to train their models.
- Our hosting provider (Hetzner, Germany). The Genie server runs on a virtual machine rented from Hetzner. They host the infrastructure but do not have access to application data beyond what any infrastructure provider has.
- PostHog (analytics & crash reporting, EU). Pseudonymous usage events and crash reports (described in §2) are processed by PostHog on EU-hosted infrastructure (Frankfurt, Germany). PostHog cannot link this data to your account, and we send it nothing that identifies you.
- Google Play (only if you make a purchase). If we add paid features in the future, purchases go through Google Play. Google sees the payment but not your in-app data.
Connected AI agents
If you connect Genie to an AI agent, you choose the external agent provider that receives the data. The connection is read-only, but the data you authorize is still transferred to that provider:
finance:readtransfers your Genie finance records, including net worth, investment holdings, accounts, transactions, subscriptions, installments, and aggregates permitted by the connected agent tools.sms:readtransfers the complete stored SMS bodies and related metadata that the connected agent requests. This is an optional scope requiring separate consent.offline_accessallows the provider to retrieve authorized data in the future using a refresh token, without asking you to sign in again. This is optional and requires separate consent.
Genie cannot control external agent provider retention, training, exports, or copies already received. Revoking a connection stops future access through Genie, but it does not erase copies the provider already holds. Review the provider's privacy and retention terms before connecting.
We do not sell your data. We do not share it with advertisers or any party other than the processors above, and our analytics processor receives only the pseudonymous data described in §2.
5. Where your data is stored
Our server is located in Germany. Your transaction and SMS data is stored there. SMS messages sent for LLM parsing may be processed on the AI provider's global infrastructure.
6. How long we keep it
We keep your data for as long as your account exists. When you delete your account, all server-side data is removed immediately (see §8).
Standard server logs are retained for 30 days, then automatically deleted.
7. How we protect it
- All traffic between the app and our server is encrypted in transit (HTTPS, TLS 1.2+).
- Your account credential is stored on our server only as a one-way password hash using industry-standard memory-hard hashing.
- Access tokens stored on your device are kept in the Android Keystore-backed secure storage.
- Access to the production server is restricted to the operator and protected by SSH keys.
No system is perfectly secure. Because we do not store your name or contact details, a breach would expose financial data linked to a random 16-digit number rather than to a named person — but determined re-identification through transaction patterns remains a theoretical risk.
8. Your rights
- Access and export. You can view every transaction and SMS we hold about you in the app at any time.
- Deletion. Open the app → Settings → Delete account. This permanently removes your account and every record, SMS, account, and category associated with it from our server. In-app deletion is immediate. Email requests are completed within 30 days. There is no undo. If you no longer have the app or cannot sign in, see how to request deletion by email.
- Connected agents. Account deletion removes your connected-agent grants, authorization codes, access tokens, refresh tokens, and related OAuth state from Genie. It cannot delete data that an external agent provider already received.
- Rectification. You can edit or delete any individual transaction in the app.
- Withdraw consent. Revoke SMS permission in Android Settings to stop SMS auto-import. The app continues to work in manual-entry mode.
Because Genie does not collect your identity, account recovery is not possible. If you lose your 16-digit number, your account cannot be restored.
If you are in the EEA or UK, GDPR/UK GDPR apply. Our lawful basis for processing is performance of the contract with you (delivering the service you signed up for). You may lodge a complaint with your local data protection authority. If you are in Egypt, Law No. 151 of 2020 on the Protection of Personal Data applies and gives you analogous rights.
9. Children
Genie is not directed at children under 18 and we do not knowingly collect information from children.
10. Changes to this policy
If we make material changes to this policy, we will update the "Last updated" date at the top and announce the change in the app before the new policy takes effect. Continued use of the app after that means you accept the updated policy.
11. Contact
Privacy questions, deletion requests, or any other concern: osamaadamme@gmail.com.