Back to Home
OFFICIAL PRIVACY POLICY • VERSION 2.0

Privacy Policy & Data Protection Charter

Operating Entity: INFYFIN ADVISORS PRIVATE LIMITED

Corporate Identification Number (CIN): U70200GJ2026PTC184743

Effective Date: October 06, 2026 • Governing Laws: Digital Personal Data Protection (DPDP) Act 2023 & IT Act 2000 (India)

Zero-Knowledge & Offline-First Guarantee

INFYFIN ADVISORS PRIVATE LIMITED does not maintain centralized servers that collect, store, harvest, monitor, or broker your personal bank balances, transactions, account numbers, or ledger entries. Your financial data belongs exclusively to you and resides in sandboxed storage on your device.

1Corporate Commitment & Overview

This Privacy Policy governs your use of the InfyFIN mobile application and associated web portals provided by INFYFIN ADVISORS PRIVATE LIMITED (“Company”, “we”, “our”, or “us”). We are steadfastly committed to upholding the privacy, autonomy, and security of your personal and financial information.

Unlike conventional fintech apps that ingest your credentials and monitor your real-time bank feeds on central cloud servers, InfyFIN is engineered from first principles as an “Offline-First, Zero-Knowledge” financial OS.

2Offline-First Architecture & Local Data Custody

All primary financial and personal records entered into InfyFIN are stored solely on your local device's internal sandboxed storage:

  • User Profile: Display name, date of birth, gender, and currency preference.
  • Financial Accounts: Bank accounts, cash balances, credit cards, loans, investments, insurance policies, and person lending ledgers.
  • Transaction Records: Income, expenses, transfers, balance adjustments, dates, categories, tags, and notes.
  • Automation & Rules: Recurring schedules, cash flow forecasts, and monthly category budgets.
  • Confidential Nominee Vault: Encrypted emergency directives, policy notes, and private reminders.

Sensitive authentication keys and credentials on your device are cryptographically protected using operating system keystores, salted SHA-256 hashes, and AES-256 local encryption. We maintain no backdoor or decryption key.

3Information We DO NOT Collect or Harvest

To ensure absolute legal clarity and user peace of mind, INFYFIN ADVISORS PRIVATE LIMITED explicitly affirms that:

We DO NOT collect or store your net banking passwords or MPINs.
We DO NOT collect ATM PINs, OTPs, or debit/credit card CVVs.
We DO NOT monitor your background device SMS or read personal messages.
We DO NOT sell, broker, or rent your data to advertisers or telemarketers.

4Device Permissions Rationale

The InfyFIN mobile app requests only minimal runtime permissions, each serving an exclusive user-directed purpose:

  • Biometric Authentication: To unlock your local app and decrypt the Vault using your fingerprint or Face ID. Biometric scans are processed natively by Android Hardware Keystore; no biometric data ever leaves your device.
  • Storage / Document Access: Used solely when you voluntarily export/import JSON/CSV backups or pick bank statements for AI staging.
  • Notifications: To trigger local on-device reminders for recurring bills, SIP dues, and budget warnings.

5Google Drive Cloud Sync & Backup Security

If you choose to enable automated cloud backups, InfyFIN communicates directly with your personal Google Drive account using Google OAuth 2.0. Backup archives are stored in a restricted, private sandboxed folder (drive.appdata) accessible only by your authenticated InfyFIN client. INFYFIN ADVISORS PRIVATE LIMITED maintains zero custody, intermediary access, or visibility into your Google Drive files.

6InfyFIN AI Document Gateway & Commercial Model Terms

When you upload a statement or loan KFS for parsing, extraction is processed via Google Gemini Flash API under commercial enterprise terms:

  • Customer document payloads are never used to train, retrain, or improve public AI foundational models.
  • Transmission is protected via TLS 1.3 encryption, and memory buffers are purged immediately upon response generation.
  • Extracted records are presented on a Human-in-the-Loop staging screen — nothing is added to your accounts without your explicit tap.

7Zero Third-Party Advertising & Tracking SDKs

InfyFIN contains zero third-party advertising SDKs (no Google AdMob, no Meta Audience Network, no Unity Ads). We do not embed surveillance tracking pixels. Our business model is based purely on software utility subscriptions and transparent referral facilitation.

8Children's Privacy

InfyFIN is designed for adults managing personal and family finances. We do not knowingly market to or solicit personal data from minors under 18 years of age.

9Compliance with Indian Privacy Laws (DPDP Act 2023 & IT Act 2000)

This policy complies with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection (DPDP) Act, 2023. Under our architecture, you maintain primary ownership and physical possession of your digital data.

10Grievance Redressal Officer & Corporate Contact

In accordance with the Information Technology Act, 2000 and Rule 5(9) of the SPDI Rules, 2011, inquiries, legal notices, or privacy grievances may be addressed to our designated Grievance Officer:

Grievance Redressal Officer: Compliance & Legal Desk

Corporate Entity: INFYFIN ADVISORS PRIVATE LIMITED

CIN: U70200GJ2026PTC184743

Registered Address: 301, North Plaza, SP Ring Road, Motera, Ahmedabad, Ahmedabad - 380005, Gujarat, India

Email: support@infyfin.com