# Security

Your data, on a need-to-know basis. Including us.

## Read-only by design

Spenco never connects to your bank account and never sees your credentials. You set up a one-time forwarding rule in Gmail or Outlook that sends your bank's alert emails to your private Spenco address. We can only read what you forward — we cannot access your inbox, log in to your bank, or move money. There is no permission you could grant us that would allow it.

## No SMS access, no inbox access

Most Indian expense trackers ask for SMS permission, which exposes your account numbers, balances, and every merchant you pay. Spenco asks for none of it. Forwarded emails are the only input, and you can stop forwarding — or delete everything — at any moment.

## Encryption

All data is encrypted in transit (TLS 1.2+) and at rest. Bank alert emails are parsed, the transaction details extracted, and processed under access controls limited to the systems that compute your forecast.

## Where your data lives

Your data is stored on secure cloud infrastructure that we use solely to run Spenco for you. It is never sold, rented, or shared with advertisers, lenders, or data brokers — our subscription model means we have no incentive to.

## Export and deletion

Your transaction history is exportable as CSV at any time. Deleting your account removes your data — transactions, parsed emails, profile — permanently. No retention tricks, no "deactivation" that keeps everything.

## DPDP-ready

Spenco is built to the consent-first standard of India's Digital Personal Data Protection Act: granular purpose-bound consent, withdrawal as easy as granting, and breach notification obligations we take seriously. We collect the minimum data needed to produce your forecast — nothing else.

## Found a vulnerability?

Write to tyrisappsupport@gmail.com with the details. We respond to security reports first, before anything else in the queue.
