🔒 Security & Data Transparency

Privacy Policy

CardaMon: Smart Credit Card & Expense Manager (Package: com.cardamon.app)
Effective Date: September 2026

🛡️ Overview & Privacy Commitment

At CardaMon ("we", "our", or "app"), we believe your financial information belongs solely to you. We are dedicated to maintaining the highest standard of data confidentiality, privacy, and integrity.

This Privacy Policy explains how CardaMon processes information when you use our Android application and web platform. CardaMon is architected as a privacy-first, local-first utility designed to help you track credit card rewards, monitor billing cycles, and manage daily expenses.

💬 SMS Permissions & 100% On-Device Parsing

To provide automated transaction logging and smart cashback tracking, CardaMon requests access to:

🔒 Strict Local-Only Guarantee
• All SMS messages are processed strictly and entirely on your local device.
• Your SMS messages and bank alerts are NEVER transmitted to, stored on, or analyzed by any external server.
• Only bank and transactional alerts from recognized financial headers (e.g. AXISBK, HDFCBK, ICICIB, SBIINB) are matched locally. Personal conversations, OTPs, contacts, and personal messages are completely ignored and never accessed.

🔔 Notification Access & On-Device Bill Radar Detection

To provide real-time transaction detection and automatic utility bill recognition (electricity, mobile recharges, gas, broadband, water, and credit card payments), CardaMon offers an optional Notification Access integration utilizing:

This permission requires your explicit consent and must be enabled manually in Android System Settings. You can revoke it at any time.

🔒 Strict On-Device Privacy & Targeted Filtering
• 100% Local In-Memory Processing: Notification parsing happens strictly on your local device in ephemeral memory. Raw notification messages are never sent to, stored on, or analyzed by external servers.
• Whitelisted Payment Apps Only: CardaMon exclusively inspects notifications originating from recognized banking and payment apps (e.g., PhonePe, Google Pay, Paytm, BHIM, CRED, Amazon Pay, and official banking apps).
• Zero Access to Personal Communications: Personal messaging apps (WhatsApp, Telegram, Signal, SMS chats, Social Media), personal chats, and sensitive one-time passwords (OTPs) are completely ignored and never accessed, read, or logged.
• Immediate In-Memory Discard: Once transaction details (amount, payee name, timestamp) are identified for your review or confirmation, the raw notification payload is immediately discarded from memory.

📦 Information We Collect & How It Is Used

When you use CardaMon, the following data may be stored to enable core functionality:

No Sale of Data: We never sell, rent, monetize, or disclose your personal or financial data to advertisers, credit bureaus, brokers, or any third parties.

We continuously work to improve CardaMon and adapt to regulatory standards. Because of this, we may occasionally update this Privacy Policy to reflect new features, product updates, or legal requirements.

We will always refresh the "Effective Date" above whenever changes occur, and we will highlight major changes directly in the app or on our site. Your ongoing use of CardaMon after updates take effect means you accept the revised policy.

🗑️ User Rights, Data Deletion & Account Removal

In accordance with Google Play Developer Policies and global data privacy standards (including GDPR and CCPA), you possess total ownership and control of your data:

How to Request Immediate Account & Data Deletion
To delete your account and all associated cloud records (transactions, card entries, preferences), you can submit a deletion request by emailing us directly from your registered account email:
Deletion requests are verified and processed within 48-72 business hours, permanently removing all database records and authentication credentials.

🔐 Security Architecture

All communications between CardaMon and Firebase services are secured with TLS/HTTPS 256-bit encryption in transit. Realtime database nodes are enforced with granular Firebase Security Rules ensuring that only your authenticated User ID can read or write to your partitioned data path.

⚖️ Financial Disclaimer & Limitation of Liability

Personal Self-Tracking & Informational Purposes Only: CardaMon is an independent personal expense tracker and credit card management tool designed solely to assist users in organizing and reviewing their personal financial records, estimating card reward points/cashback, and receiving automated reminders.

⚠️ Important Financial & Legal Disclaimers
• Not Financial, Legal, or Banking Advice: CardaMon, its developers, and affiliates are not a bank, non-banking financial company (NBFC), credit card issuer, registered investment advisor (RIA), or legal counsel. No feature, calculation, or recommendation within the app constitutes financial, investment, tax, or legal advice.
• Zero Liability for Financial or Monetary Loss: Under no circumstances shall CardaMon, its developers, or contributors be held liable or responsible for any financial loss, loss of money, missed cashback, unearned or expired reward points, unexpected charges, interest, finance fees, late payment charges, card annual/renewal fees, or penalty charges incurred by the user.
• Calculations, Estimations & Automated Logic: All reward calculations, fee waiver thresholds, spending milestone projections, automated transaction categorizations, and Zero-Loss fee waiver recommendations are automated estimates provided on a best-effort basis. Banks and card issuers frequently modify their terms, fee structures, reward policies, and exclusion categories without notice. Mathematical estimations or rule discrepancies may unintentionally occur.
• Fee Waiver & Dispute Letters (Zero-Loss Module): Draft emails and dispute templates generated by the Zero-Loss engine are optional suggestions only. CardaMon does not guarantee any refund, reversal, or fee waiver from any financial institution. Banks and service providers retain sole and absolute discretion to approve or reject waiver requests.
• User Verification Mandate: The user is strictly and solely responsible for verifying all transaction details, account balances, billing statements, payment due dates, and official card terms directly with their bank, credit card issuer, or utility service provider before making payment or financial decisions.

📬 Contact Us

If you have any questions, feedback, or privacy-related inquiries regarding CardaMon, please contact our team:

Application: CardaMon (com.cardamon.app)
Support Email: questdroiders@gmail.com
Website: https://cardamonapp.web.app