1. Who controls your data
Feloosy is the organization responsible for the personal data described here. We operate from Cairo, Egypt. Privacy and data-rights questions can be sent to amr.ghallab.26@gmail.com.
2. Data we collect
| Category | Examples | Why we use it |
|---|---|---|
| Account and personal information | Name, email address, Feloosy user ID, sign-in provider identity, consent history, account status. | Create, secure, recover, and manage your account; communicate important service or security information. |
| Financial information | Accounts, balances, transactions, purchase history, merchants, categories, budgets, bills, installments, commitments, assets, debts, and net-worth information you enter or import. | Maintain your private financial ledger, produce budgets and insights, reconcile transactions, and personalize the service. |
| SMS, messages, and contact-like information | Optional financial SMS content, sender ID, recipient/payee/merchant/person names, account references, and transaction history linked to those messages. Under Google Play's terminology, sender/recipient names and message-linked history may also be classified as Contacts. | Detect and parse financial activity, identify counterparties, prevent duplicates, reconcile records, and present personalized financial history. |
| Photos and documents | Receipt photos and the information extracted from them when receipt capture is enabled and you choose to use it. | Turn a receipt into a transaction draft and preserve the receipt for your records. |
| Audio | Voice or sound recordings you submit to the optional voice-command feature. | Transcribe your instruction and perform the requested app action. |
| App activity and content | Actions in the app, settings, searches, notes, merchant or transaction descriptions, assistant prompts, and other content you provide. | Provide requested features, maintain your records, personalize results, and understand or troubleshoot app behavior. |
| Device, notification, and diagnostic data | App/device identifiers, platform and device model, coarse/truncated IP information, push token, crash logs, diagnostics, and scrubbed breadcrumbs. | Secure sessions, deliver notifications, prevent abuse, diagnose failures, and improve reliability. |
3. How SMS capture works
Android automatic capture is optional. Feloosy requests SMS access only after you choose to set it up. The app does not request access to your device address book and does not query historical SMS inbox content. New messages received after permission is granted are filtered on-device to exclude obvious one-time passwords, login codes, and promotional messages.
When a message appears financial, its content and sender identifier are transmitted to Feloosy's servers. Feloosy may extract and retain the resulting transaction, merchant, payee, recipient or other counterparty name, account reference, and message-linked transaction history. You can disable SMS access in Feloosy or Android settings and continue using manual entry.
4. AI processing
AI is part of Feloosy's financial parsing, receipt extraction, voice transcription, Assistant, and insight features. When needed, relevant content may be sent to a configured AI service provider, which may be Google Gemini, OpenAI, or xAI depending on the deployed feature and configuration. This content can include financial-message text, sender/recipient/payee or merchant names, account references, transaction details, receipt images, voice recordings, or bounded financial records needed to answer a request.
AI providers process this information on Feloosy's behalf under our instructions. We do not permit service providers to use Feloosy data for advertising. Feloosy minimizes each request to what the feature needs, but not every AI request is fully redacted.
5. Other service providers
We use providers to operate the service. Depending on the enabled features, these may include Railway for application and database hosting, Cloudflare R2 for private receipt storage, Sentry's EU service for scrubbed crash diagnostics, Firebase Cloud Messaging for push delivery, and Apple or Google for sign-in. Providers receive only the data needed for their role and must process it for the contracted service.
6. When data is shared
We do not sell or rent personal or financial data and do not share it for targeted advertising. Data may be disclosed to processors acting on our behalf, when you initiate or authorize a transfer, to protect users and the service, or when required by law. If a provider uses data for its own independent purpose rather than solely as our processor, we will update this policy and the applicable app-store disclosure.
7. Retention
- Raw SMS content is retained only while a capture is accepted, parsed, and completed. Successful or terminal processing scrubs the raw text. Failed queued processing is retried for up to approximately 24 hours and then scrubbed.
- Derived transactions, counterparties, merchant/payee names, budgets, and other ledger information remain while your account exists or until you delete the relevant record where supported.
- Receipt images remain while linked to your records, subject to deletion and asynchronous storage cleanup.
- Voice audio is used to transcribe the requested command and is not kept by Feloosy longer than needed for that request; the provider's bounded processing logs may follow its processor retention configuration.
- Crash diagnostics and security/audit records are retained for bounded operational, fraud-prevention, legal, or compliance needs.
8. Security
Feloosy encrypts network traffic in transit and protects stored production data using access controls and encryption at rest where supported. Sensitive application caches use protected local storage. Passwords, recovery codes, and refresh tokens are stored using one-way hashes where applicable. Feloosy employees and providers may access data only when required to operate, secure, support, or comply with law.
9. Your choices and rights
- Use manual entry without granting SMS, microphone, photo, or notification permission.
- Withdraw optional SMS and notification consent in the app and revoke device permissions in system settings.
- Request an export from Settings → Security & privacy → Privacy.
- Request account and associated-data deletion in the app or through our public deletion page.
- Ask to access, correct, restrict, object to, or delete personal data as provided by applicable law.
Deletion may require identity verification. A deletion request disables account access while it is processed. We delete or anonymize associated data, except limited records that must be retained for security, fraud prevention, legal, or regulatory obligations. Any retained category and retention reason will be explained in response to your request.
10. International processing
Some processors may operate outside Egypt. Where data crosses borders, we use contractual and technical safeguards appropriate to the service and applicable law.
11. Children
Feloosy is a personal-finance service for adults and is not directed to children. If you believe a child provided personal data, contact us so we can investigate and delete it where required.
12. Changes to this policy
We may update this policy when features, providers, or legal requirements change. We will update the effective date and provide an in-app notice or renewed consent when a material change requires it.