Privacy Policy
Last updated: July 29, 2026
InWallet is built by Red Evolve Technologies Private Limited ("we," "us," "our"). This policy explains what information InWallet collects, how it's used, and how it's protected.
What we collect
- Account information: your email address, used solely for authentication.
- Card metadata: bank name, card network, last 4 digits, expiry date, nickname, and optional cardholder name — stored to identify and organize your cards.
- Card numbers and CVV: encrypted on your device using AES-256 encryption before they are ever transmitted. We store only the encrypted ciphertext. The decryption key is generated on and stored only on your device (in your phone's secure hardware storage) and is never sent to or stored on our servers.
- Transaction data (optional, only if you use Gmail sync, clipboard parsing, or statement upload): merchant name, amount, and date, used to track spending milestones, fee payback, and points expiry. Raw email/message content used to extract this data is discarded after processing and is not retained long-term.
- Usage data: basic app diagnostics to help us fix bugs, containing no card numbers, CVVs, or other sensitive fields.
What we never do
- We never store your full card number or CVV in a form we can read.
- We never sell or share your data with advertisers or data brokers.
- We never use your financial data to serve you ads.
- We do not have the technical ability to decrypt your card numbers from our servers alone — decryption requires your device and your biometric or PIN unlock.
Card sharing feature
If you use InWallet' card-sharing feature, the shared card data is encrypted end-to-end: the decryption key is included only in the link you create and share, and is never sent to or stored on our servers. Anyone with the exact link can view the shared details until it expires or you revoke it — treat a share link like a password.
Optional Gmail connection
If you choose to connect Gmail (optional, off by default), we request read-only access scoped to identifying bank transaction emails. We do not read, store, or have access to any other email in your inbox. Email content used for parsing is processed and then discarded; we retain only the extracted transaction fields (amount, merchant, date).
Data deletion
You can permanently delete your account and all associated data at any time from Settings → Delete Account. This action is irreversible and removes your cards, transaction history, shares, and account information from our systems.
Third-party services
We use Supabase for backend infrastructure and authentication, and Anthropic's Claude API to help process card benefit and statement data. These providers do not have independent access to your unencrypted card data.
Your rights
You may request a copy of your data or its deletion at any time by contacting us at redevolvereviews@gmail.com.
Changes to this policy
We'll update the "Last updated" date above if this policy changes, and will notify users of material changes via the app.
Contact
Red Evolve Technologies Private Limited
GSTIN: 07AANCR2428R1ZN
redevolvereviews@gmail.com