Privacy Policy
AutoPay Alert ("we", "our", "the app") is committed to protecting your privacy. This policy explains what data we collect, why, and how we handle it.
Last updated: 31 August 2026
1. Data We Collect
- Account info: Name, email address, and Firebase authentication token (via Google Sign-In).
- SMS messages: Raw SMS messages stay on your device and are never uploaded. The app reads them locally to detect recurring payment notifications.
- Optional redacted-template sharing: With separate consent, you may share a redacted structural template and sender/stage metadata to improve SMS detection. This is a derived diagnostic, not the raw SMS message.
- Optional merchant discovery: With separate, versioned consent, you may share parsed business names that AutoPay cannot recognize, how many times each name appeared during the consented reporting window, the broad detection type (for example, a merchant UPI purchase, card purchase, commerce order, or subscription), technical app/protocol version metadata, a merchant-specific repeat-report code, and a separate per-report retry/deduplication code. Reports exclude raw SMS text, amounts, account details, personal payees, exact transaction dates, your AutoPay account ID, Android ID, and the telemetry device ID.
- UPI app notifications (premium, optional): With your explicit permission, the app reads notifications from a fixed whitelist of UPI payment apps (PhonePe, Google Pay, Paytm, BHIM, Amazon Pay, BharatPe, and major bank apps) to detect payments and warn you before any autopay debit. Notification content is parsed on your device only and never uploaded to our servers.
- Subscription data: Payment status, subscription ID, and transaction amounts managed through Razorpay.
- Premium service-activity records: To help verify paid service delivery and handle payment disputes, we may record a small set of authenticated premium-service milestones (premium session opened, notification monitoring enabled, onboarding completed, or SMS scan completed), the app version, and our server receipt time. We do not collect or upload SMS content, notification content, transaction details, contacts, device identifiers, or timestamps from your device for these records.
- Referral codes: If you use or share a referral code, we store the referral relationship.
2. How We Use Your Data
- To authenticate you and manage your account.
- To process subscription payments via Razorpay.
- To track referral rewards.
- To verify paid service provisioning and investigate or respond to payment disputes, fraud, and chargebacks.
- When you separately opt in, to improve redacted SMS-template detection or review unrecognized parsed business names before a human publishes a merchant mapping.
- To measure advertising performance. The app sends trial-start events to Meta and Firebase Analytics with a pseudonymous, truncated subscription key. Meta may also receive the Google Play install-referrer string for ad-click attribution. Server-side purchase matching may include SHA-256-hashed identifiers and the IP address and app user-agent captured during checkout.
3. Data Sharing
We do not sell your personal data. We share limited data with:
- Firebase / Google Analytics: Authentication, push notifications, and pseudonymous app conversion events. Analytics events may later be imported into Google Ads after the services are linked.
- Razorpay: Payment processing.
- Meta: App conversion events, a pseudonymous subscription key, Play install-referrer attribution data, and—where server-side purchase matching is used—hashed identifiers plus checkout IP address and user-agent.
Important: Raw SMS and UPI notification content remains on your device. Optional derived redacted templates and parsed business names are sent only after their separate consent controls are enabled.
4. SMS Permission
AutoPay Alert requests SMS read permission to detect recurring payment notifications on your device. Raw SMS content is parsed locally and is not uploaded. Optional redacted templates or parsed business names use separate consent and never include the raw message.
5. UPI Notification Access (Premium Feature, Optional)
With your explicit permission, AutoPay Alert reads notifications only from a fixed whitelist of 21 known UPI payment apps (PhonePe, Google Pay, Paytm, BHIM, Amazon Pay, BharatPe, SBI Pay, SBI YONO, HDFC Bank, ICICI Bank, Axis Mobile, PayZapp, iMobile Pay, MobiKwik, Freecharge, Airtel Thanks, and select others). Notifications from any other app are filtered out before any text extraction occurs.
From these UPI app notifications we extract only: transaction amount, direction (credit, debit, or upcoming autopay), the last 4 digits of the bank account when present, and the name of the UPI app. This data is stored on your device only and is never transmitted to our servers or shared with third parties.
This permission is optional and only requested from premium subscribers. You can revoke it at any time: Settings → Notifications → Special access → Notification access → AutoPay.
6. Data Retention
Account data, including premium service-activity records, is retained while your account is active. You can request deletion at any time by contacting us; we may retain limited records where necessary to handle a payment dispute or meet legal obligations. On-device data (SMS- and notification-derived transactions) is removed when you uninstall the app or clear app data.
Accepted merchant-discovery reports are retained for up to 180 days. Turning the setting off stops future reports. Reports contain no account or device identifiers. A merchant-specific random reporter code lets AutoPay recognize repeat reports for the same merchant; that code cannot be used to recognize reports about a different merchant. A separate per-report code is used only to recognize retries of that same report. Ordinary application and network infrastructure processes request and IP metadata. Because the codes are not tied to your account or device identifier, we cannot find and delete earlier reports for you.
7. Security
All server communication uses HTTPS/TLS. Passwords are never stored; authentication is handled by Firebase. Merchant discovery is identity-free at the application layer: it sends no account token, account ID, Android ID, telemetry device ID, or cookie. At the network layer, normal network infrastructure processes IP addresses and access metadata under its operational retention controls.
8. Children's Privacy
The app is not intended for children under 13. We do not knowingly collect data from children.
9. Your Rights
You may request access to, correction of, or deletion of your personal data by emailing us.
10. Contact
Email: panicquantum@gmail.com
11. Changes
We may update this policy from time to time. Changes will be reflected on this page with an updated date.