Google Play Certified

NovaTrax — Privacy Policy & Data Safety

Effective Date: October 2026 | App Version: 2.1+
Key Privacy Commitments
  • Zero Third-Party Data Sharing: We never sell, monetize, or disclose your financial records to data brokers or advertising networks.
  • Zero Advertising Trackers: NovaTrax does not use Advertising IDs, nor does it embed ad SDKs.
  • Local On-Device SMS Detection: Bank transactional SMS parsing is conducted directly on your device. OTPs and personal chats are completely filtered out.
  • Strict Data Isolation: Every financial ledger entry is strictly bound to your individual user ID (`WHERE user_id = ?`).
  • User-Controlled Data Deletion: Full control over your records with 90-day grace period, instant permanent hard-purge, or "Wipe Financial Records Only".

1. Application Identity & Developer Scope

NovaTrax (accessible at https://novatrax.novacodex.in and available on Google Play) is developed, maintained, and operated by NovaCodex, a registered digital technology entity based in Coimbatore and Bengaluru, India. NovaTrax operates as a personal financial budgeting, expenditure tracking, and cashflow intelligence platform.

2. Bank SMS Detection — Prominent Disclosure & Consent

In compliance with Google Play Developer Policy regarding SMS and Call Log Permissions, we provide explicit in-app disclosure and obtain user consent before accessing SMS messages:

  • Specific Purpose: NovaTrax reads incoming SMS messages solely to identify automated transactional alerts sent by financial institutions (debits, credits, and UPI transfers) to log your expenses and income automatically.
  • Whitelisted Bank Senders: The parser strictly inspects messages sent from recognized financial sender handles (including HDFCBK, SBIINB, SBIPAY, ICICIB, AXISBK, KOTAKB, PAYTM, UNIONB, PNBSMS, BOBSMS, CANBNK, INDUSB, YESBNK, IDFCFB, BHIM, GPAY, and PHONEPE).
  • Zero Access to OTPs & Personal Chats: One-Time Passwords (OTPs), authentication codes, security tokens, personal messages, and private conversations are strictly filtered out and ignored. They are never read, analyzed, stored, or transmitted.
  • On-Device Local Processing: Pattern matching and extraction of the amount, merchant, and transaction date occur locally on your mobile device.
  • User Control: Smart Bank SMS Tracking is disabled by default and requires explicit opt-in. You may toggle between "Manual Review Mode" (swipe to accept or reject each transaction) and "Automatic Direct Posting", or turn off SMS tracking completely in Settings → Automation & SMS Tracking at any time.

3. Information Collected

Data Category Data Elements Purpose Optional / Required
Account Credentials Email address, username, encrypted password hash (bcrypt). Authentication, account recovery, session security. Required for cloud sync.
Financial Records Expense amounts, categories, income sources, budgets, savings goals, recurring rules, loans, subscriptions. Bookkeeping, trend charts, net worth calculations. User-entered or auto-detected.
SMS Metadata Transaction amount, merchant name, masked account digits (e.g. **4821), date, deduplication hash. Preventing duplicate transactions and auto-populating ledgers. Optional (only if SMS tracking is enabled).

4. Multi-Tenant Data Isolation & Security

  • Parameterized Scoping: Every database query is strictly parameterized with the authenticated user's ID (`WHERE user_id = ?`). It is technically impossible for one user to view or modify another customer's financial entries.
  • Encryption in Transit: All communications between the mobile app, web dashboard, and API servers utilize Transport Layer Security (TLS 1.3 / HTTPS) with 256-bit encryption.
  • Cryptographic Password Protection: Passwords are hashed with salt using bcrypt (10 rounds) and never stored in plain text.

5. Google Play Data Safety Summary

  • Data Shared with Third Parties: NO DATA SHARED.
  • Data Transferred Encrypted: YES (HTTPS / TLS 1.3).
  • Account Deletion Mechanism Provided: YES (In-app and via web portal).
  • Advertising ID: NO (Zero advertising SDKs used).

6. Account & Financial Data Deletion

You can request data deletion at any time:

  1. Automated 90-Day Deletion Schedule: Account is deactivated immediately. Data remains encrypted for a 90-day grace period, after which all records are permanently shredded. You can cancel deletion anytime within the 90 days by logging back in.
  2. Instant Permanent Hard-Purge: Immediately destroys your login credentials and all financial records with 0 days retention.
  3. Wipe Financial Records Only: Preserves your account login credentials and profile, while permanently clearing all financial transactions.
Submit Account Deletion Request →

7. Contact Our Privacy Desk

NovaTrax Compliance & Security Desk

Support Email: support@novacodex.in / team.novacodex@gmail.com

Web Dashboard: https://novatrax.novacodex.in

Corporate Office: NovaCodex, 603 Thirumagal Nagar, Peelamedu, Coimbatore, TN 641004, India