Last Updated: February 27, 2026 (v1.2.0)
We collect information necessary to provide financial analytics, including your email address for account identification and transaction data extracted from bank-related notifications.
Grip accesses your Gmail account using OAuth 2.0 Restricted Scopes (gmail.readonly). We strictly search for and process only bank transaction notifications, credit card alerts, and financial statements.
How We Use This Data:
AI Role & Restrictions:
Restricted Scope Compliance: Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Grip uses a two-stage, privacy-first extraction pipeline to process bank notification emails:
Our logic-based intelligence engine performs rigorous financial calculations to provide variance analysis and "Safe to Spend" metrics. Safe-to-Spend is a deterministic mathematical calculation based on your current balance minus unpaid bills and projected recurring commitments. It includes a safety buffer based on your actual 30-day discretionary spending averages.
We implement Privacy-by-Design via a local sanitization layer that operates before any data is processed by our extraction engines or sent to any external service. Our system automatically detects and masks highly sensitive fields including:
This ensures that even during fallback external processing, your most sensitive identifiers are never exposed in raw format.
We use TLS encryption for data in transit and industry-standard AES-256 encryption at rest for sensitive financial markers. Passwords utilize salted cryptographic hashing.
For privacy inquiries, contact us at amitkr.dey1998@gmail.com