Moray Privacy Policy
Moray is developed by Vlight Software Solutions (“Vlightsoft”), India, which is the Data Fiduciary (controller) for the personal data described here. Contact and Grievance Officer: admin@vlightsoft.com. We reply within 7 days and resolve grievances within 30 days.
1. The short version
- Moray is a family expense tracker. You decide what goes in; we use it only to run the app for you.
- Bank SMS and payment notifications are read on your phone. Only the details of a payment are sent to your Moray account. Personal SMS, OTPs and promotional messages are skipped on the phone and never stored or uploaded.
- We never ask for your bank login, card number, CVV, UPI PIN or net-banking password. Moray stores at most the last 3–4 digits of an account or card.
- AI is optional. When you turn it on, only the data a feature needs is sent, with account, phone, email, PAN and other ID numbers masked first.
- No ads, no selling, no data brokers, no tracking across apps.
- You can export your data and delete your account from inside the app at any time, or from this page.
2. What we collect and why
| What | Examples | Why | Where it goes |
|---|---|---|---|
| Account | name, email address, password (stored only as a secure hash by our authentication provider), Google account name and email if you sign in with Google, language | sign in, identify you to your family | our cloud database |
| App lock | your MPIN | lock the app on your phone | stays on your phone, as a salted hash only |
| Household | members you invite, their roles, invite links, privacy settings | family sharing | our cloud database |
| Money records | expenses, income, transfers, categories, payees, notes, budgets, bills, loans and EMIs, goals, events and splits, subscriptions, tax tags | the core features | our cloud database |
| Bank, card and wallet accounts | account name, type, bank name, last 3–4 digits, card limit, statement and due day, balances and available limit as reported in bank messages, card bills, fees, reward points, suggested new accounts | balances, card bill reminders, utilisation, reports | our cloud database; visible to you, and to family only as your privacy setting allows |
| Bank and payment messages (optional) | SMS from bank and payment sender IDs; notifications from payment apps | automatic capture of payments | read on your phone; see section 3 |
| Foreign-currency amounts | the original amount and currency, and the exchange rate used | convert to your base currency and show the rate used | our cloud database |
| Receipts and attachments (optional) | photos or files you attach | proof of purchase, warranty reminders | our cloud storage |
| Bank statements (optional) | PDF statements you pick | import past payments | read on your phone; only the rows you import are uploaded; the file and its password never leave the phone |
| Place tag (optional) | place name and coordinates when you add an entry and allow location | “where did I spend” | stored on that entry; coordinates are only shown to you |
| Contacts (optional) | a payee's phone number or UPI ID looked up in your contacts | show a name instead of a number | looked up on the phone; only that payee name is saved; your contact list is never uploaded |
| Voice (optional) | “Hi Moray” wake word, spoken entries | hands-free entry | the wake word runs offline on the phone; spoken entries use your phone's speech service, and Moray receives only the text, never audio |
| AI requests (optional) | the data a feature needs (section 4) | AI features you turn on | our AI gateway and our AI provider |
| Referrals | your invite code, who used it, the first name of the friend who joined, the credits given; the code carried by a Google Play install link | give both of you referral credits, prevent abuse | our cloud database; a friend's email is never shown to you |
| Purchases | plan, Google Play order ID, purchase state, expiry, credit packs (a one-way hash of the purchase token) | give you the plan you paid for | our cloud database; payment is handled by Google Play and we never see your card or UPI details |
| Technical | app version, language, request times, security logs (such as sign-in and role changes) | security, abuse prevention, support | our cloud database |
We do not collect your SMS inbox as a whole, OTPs, personal messages, call logs, contact lists, background location, the advertising ID, device identifiers for tracking, full card or account numbers, CVV, PINs or banking passwords. Moray has no ads and no analytics or crash-reporting SDK; Google Play may show us aggregated crash statistics.
3. Bank SMS and payment notifications
This feature is off until you turn it on after an in-app explanation. You can switch it off at any time in the app (Me › Auto-capture) or by removing the SMS or notification access permission in Android settings.
- Only messages from bank or payment sender IDs (such as VM-HDFCBK) or payment apps are looked at. A message from a person's phone number is rejected without reading its text.
- OTPs, verification codes, promotions, payment requests and failed or declined payments are skipped.
- The phone extracts: amount and currency, paid or received, payee, last 3–4 digits of the account or card, bank name, reference number, date, balance or available limit, card bill amounts and due date, fees, reward points, refunds and EMI conversions.
- Uploaded: those fields, plus the message text (up to 480 characters) so you can check the entry on the review card. The text is deleted when you confirm the entry or mark it “Not mine” or “Duplicate”, unless you choose to keep it.
- If a message mentions a card or account ending we don't know yet, Moray suggests adding it. Nothing is created until you confirm, and suggestions are visible only to you.
- If AI is on and the phone's rules cannot read a bank message, the message may be sent to our AI (section 4) with every long number masked except its last 4 digits and amounts.
4. AI features
AI is off by default and you choose which features run. Requests go from the app to our AI gateway, which checks your plan and credits, masks personal identifiers (email addresses, UPI IDs, PAN, Aadhaar-like and other long numbers except their last 4 digits) and sends the minimum needed to our AI provider (OpenAI, through its API). Income and notes are included only if you allow that in AI settings. Receipt photos sent for reading are not stored by the gateway.
Our provider processes the data only to return the answer and, under its API terms, does not use it to train its models; it may keep it for up to 30 days for abuse monitoring. We keep a log of each AI request (feature, model, time and credits, not the content) and your chat history, which is private to you and expires after 12 months or when you clear it. AI suggestions are suggestions: nothing is saved without your confirmation.
5. Who can see your data
- You.
- Your household, only as each entry's privacy setting allows (Only me, Amount shared, Category shared, Full details). Captured SMS entries, account suggestions and accounts you mark private are “Only me”.
- Our service providers, who process data only on our instructions: Supabase (database, authentication, file storage and server functions), OpenAI (AI features, only if you turn them on), Google (Google sign-in if you use it, Google Play billing and install referrer, your phone's speech service if you use voice entry). Exchange rates are fetched from a public rates service (only currency codes are sent), and the offline voice model is downloaded from alphacephei.com (nothing about you is sent).
- Authorities, only when Indian law requires it.
We do not sell, rent or share your personal data for advertising.
6. Where data is stored and how it is protected
Data is stored with our hosting provider, Supabase. Everything travels over HTTPS; the app refuses unencrypted connections and does not trust user-installed certificates. Data is encrypted at rest. Row-level security in the database means each request can reach only the rows your role and privacy settings allow; server keys never ship in the app. On the phone, your sign-in session is encrypted with a key kept in the Android Keystore, and none of this is included in Android backups or device-to-device transfer.
AI requests to our provider may be processed outside India (United States); we rely on the provider's contractual safeguards and send only masked data. If a personal-data breach happens we will inform you and the Data Protection Board of India as the law requires.
7. How long we keep data
| Data | Kept |
|---|---|
| Your records, accounts, budgets | while your account is active |
| Original SMS or notification text on a captured entry | until you review it, or as long as you choose to keep it |
| AI chat history | 12 months, or until you clear it |
| AI request log (no content) and security logs | up to 24 months |
| Purchase records | as long as tax and accounting law requires (currently up to 8 years) |
| After you ask to delete your account | a 30-day grace period in which you can cancel, then deleted within 30 days, except records we must keep by law (see Delete your account) |
8. Your rights
Under the Digital Personal Data Protection Act, 2023 (and, where it applies to you, the EU or UK GDPR) you can:
- access and export your data (Me › Privacy and data › Export my entries, as a CSV file; or write to us for a complete copy);
- correct it (edit any entry or your profile);
- delete your account (Me › Privacy and data › Delete my account, or vlightsoft.com/moray/delete-account);
- withdraw consent for any optional feature (SMS capture, notification capture, contacts, location, voice, AI) in the app or in Android settings; this does not affect what was done before;
- nominate someone to exercise your rights if you die or are unable to (write to us);
- complain to our Grievance Officer at admin@vlightsoft.com and, if not resolved, to the Data Protection Board of India (or, for the GDPR, your local supervisory authority).
Our legal bases are your consent (optional features and AI) and performance of the service you signed up for.
9. Children
Moray is for adults (18+). Children cannot have their own login. A parent may add a child profile (a display name and optional birthday day and month) to track family spending; no other data about the child is collected.
10. Changes and contact
We will show a notice in the app before a material change takes effect and update the date at the top of this page.
Vlight Software Solutions (“Vlightsoft”), India · admin@vlightsoft.com · Website privacy for vlightsoft.com itself is covered by the Vlightsoft privacy policy.