Google Play Certified
NovaTrax — Privacy Policy & Data Safety
Effective Date: October 2026 | App Version: 2.1+
Key Privacy Commitments
- Zero Third-Party Data Sharing: We never sell, monetize, or disclose your financial records to data brokers or advertising networks.
- Zero Advertising Trackers: NovaTrax does not use Advertising IDs, nor does it embed ad SDKs.
- Local On-Device SMS Detection: Bank transactional SMS parsing is conducted directly on your device. OTPs and personal chats are completely filtered out.
- Strict Data Isolation: Every financial ledger entry is strictly bound to your individual user ID (`WHERE user_id = ?`).
- User-Controlled Data Deletion: Full control over your records with 90-day grace period, instant permanent hard-purge, or "Wipe Financial Records Only".
1. Application Identity & Developer Scope
NovaTrax (accessible at https://novatrax.novacodex.in and available on Google Play) is developed, maintained, and operated by NovaCodex, a registered digital technology entity based in Coimbatore and Bengaluru, India. NovaTrax operates as a personal financial budgeting, expenditure tracking, and cashflow intelligence platform.
2. Bank SMS Detection — Prominent Disclosure & Consent
In compliance with Google Play Developer Policy regarding SMS and Call Log Permissions, we provide explicit in-app disclosure and obtain user consent before accessing SMS messages:
-
Specific Purpose: NovaTrax reads incoming SMS messages solely to identify automated transactional alerts sent by financial institutions (debits, credits, and UPI transfers) to log your expenses and income automatically.
-
Whitelisted Bank Senders: The parser strictly inspects messages sent from recognized financial sender handles (including HDFCBK, SBIINB, SBIPAY, ICICIB, AXISBK, KOTAKB, PAYTM, UNIONB, PNBSMS, BOBSMS, CANBNK, INDUSB, YESBNK, IDFCFB, BHIM, GPAY, and PHONEPE).
-
Zero Access to OTPs & Personal Chats: One-Time Passwords (OTPs), authentication codes, security tokens, personal messages, and private conversations are strictly filtered out and ignored. They are never read, analyzed, stored, or transmitted.
-
On-Device Local Processing: Pattern matching and extraction of the amount, merchant, and transaction date occur locally on your mobile device.
-
User Control: Smart Bank SMS Tracking is disabled by default and requires explicit opt-in. You may toggle between "Manual Review Mode" (swipe to accept or reject each transaction) and "Automatic Direct Posting", or turn off SMS tracking completely in Settings → Automation & SMS Tracking at any time.
3. Information Collected
| Data Category |
Data Elements |
Purpose |
Optional / Required |
| Account Credentials |
Email address, username, encrypted password hash (bcrypt). |
Authentication, account recovery, session security. |
Required for cloud sync. |
| Financial Records |
Expense amounts, categories, income sources, budgets, savings goals, recurring rules, loans, subscriptions. |
Bookkeeping, trend charts, net worth calculations. |
User-entered or auto-detected. |
| SMS Metadata |
Transaction amount, merchant name, masked account digits (e.g. **4821), date, deduplication hash. |
Preventing duplicate transactions and auto-populating ledgers. |
Optional (only if SMS tracking is enabled). |
4. Multi-Tenant Data Isolation & Security
- Parameterized Scoping: Every database query is strictly parameterized with the authenticated user's ID (`WHERE user_id = ?`). It is technically impossible for one user to view or modify another customer's financial entries.
- Encryption in Transit: All communications between the mobile app, web dashboard, and API servers utilize Transport Layer Security (TLS 1.3 / HTTPS) with 256-bit encryption.
- Cryptographic Password Protection: Passwords are hashed with salt using bcrypt (10 rounds) and never stored in plain text.
5. Google Play Data Safety Summary
- Data Shared with Third Parties: NO DATA SHARED.
- Data Transferred Encrypted: YES (HTTPS / TLS 1.3).
- Account Deletion Mechanism Provided: YES (In-app and via web portal).
- Advertising ID: NO (Zero advertising SDKs used).
6. Account & Financial Data Deletion
You can request data deletion at any time:
- Automated 90-Day Deletion Schedule: Account is deactivated immediately. Data remains encrypted for a 90-day grace period, after which all records are permanently shredded. You can cancel deletion anytime within the 90 days by logging back in.
- Instant Permanent Hard-Purge: Immediately destroys your login credentials and all financial records with 0 days retention.
- Wipe Financial Records Only: Preserves your account login credentials and profile, while permanently clearing all financial transactions.
Submit Account Deletion Request →
7. Contact Our Privacy Desk