← Back

Privacy Policy

Effective: 26 April 2026  ·  Version 1.2

Strums.ai ("we", "us", "our") is committed to protecting your personal and financial data. This Privacy Policy explains how we collect, use, and safeguard your information in compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) and other applicable Indian laws.

1. Data We Collect

2. How We Use Your Data

Your data is used solely to provide and improve our services:

2.1 Parsing & Aggregation

To extract transaction data from your bank statements and provide a consolidated financial view across your accounts and (with your consent) your linked family members’ accounts.

2.2 AI Processing (Google Gemini via Vertex AI)

We use the Google Gemini model accessed through Google Cloud Vertex AI for two purposes:

In both cases, the call runs as a transient, single-shot session via Vertex AI’s enterprise tier: your data is not used to train Google’s foundation models, is processed only in data centres in India (see Section 3), and is not shared with other Google products or customers.

2.3 Family Linking

To enable shared household views when you explicitly invite and link with family members. Each member retains full control over what is shared.

2.4 Data Improvement (Optional)

If you enable the “Data Improvement” toggle, you provide us with a specific sub-consent to allow our engineering team to review anonymized transaction snippets that the AI failed to categorize. This data is stripped of PII (Names, Account Numbers) before review and is used solely to refine our categorization engine. You may withdraw this consent at any time from the Profile page; doing so prevents any future use of your data for this purpose but does not retroactively affect snippets already reviewed.

3. Data Residency & Processing

India First, for your financial data: Bank statements, transactions, account balances, and all derived analytics live in Google Cloud’s data centres in India — both at rest and during AI processing. Your financial data does not leave Indian jurisdiction.

Operational metadata may transit other regions: Your email address and mobile number, when used for sign-up confirmation, password reset, family invites, or SMS OTP, are handled by our delivery providers (Resend for email, MSG91 for SMS) which may route through their own international infrastructure. These providers see only your email address or phone number and the message content, never your financial data.

4. Third-Party Sharing

We do not sell your personal or financial data.

Data processor: Google Cloud (for hosting, database, and Vertex AI). Your bank statements, transactions, and account information are processed exclusively within Google Cloud’s data centres in India under a Data Processing Agreement.

Delivery providers: Resend handles outgoing system emails (sign-up confirmation, password reset, family invites); MSG91 sends SMS OTPs. These providers receive only the destination email address or phone number plus the message content. Resend and MSG91 may process this contact metadata on infrastructure located outside India, per their respective privacy policies.

In the case of Family Linking, your data is shared with linked members of your household as per your configuration.

5. Data Security

We employ industry-standard security measures, including:

6. Our Privacy Commitments

7. Your Rights

Under DPDPA, you have the following rights:

8. Changes to This Policy

We may update this policy from time to time. We will notify you of any material changes via in-app notifications or email.

If we ever weaken a privacy commitment listed in this policy (for example, adding a new processing purpose or a new sub-processor), we will document the change here with the date it took effect and the reason — not silently amend the policy. Material changes will trigger a re-acceptance prompt the next time you sign in.

9. Grievance Redressal

In accordance with the Information Technology Act and the DPDPA 2023, the name and contact details of the Grievance Officer are provided below:

We will acknowledge any grievance within 24 hours and resolve it within 30 days, as required by the DPDPA 2023.