Last updated: 17 September 2026
Scope
This policy explains how the MoneyFoam Android app and this website handle information. MoneyFoam is a personal finance organizer; it is not a bank or payment processor.
Account information
When you choose Google Sign-In, Google provides the identifiers needed to authenticate you, including your Firebase user ID, name, email address, and profile photo when available. Firebase Authentication manages your sign-in session. MoneyFoam does not receive or store your Google password.
Financial information you provide
MoneyFoam stores the structured records you create or approve, such as transaction amount, direction, merchant or payer/payee, category, date and time, payment method, masked account details, transaction references, notes, budgets, goals, recurring-payment preferences, categories, theme, currency, and related settings. Smart categories and local analytics process this information to organize transactions and calculate budgets, trends, cash flow, and financial-health indicators.
Notification transaction detection
If you enable Android Notification Access, MoneyFoam reads notification fields from supported financial apps and notifications containing strong transaction evidence. Notification text is passed to the on-device parser and held in a bounded in-memory queue until it is processed or cleared. Non-transaction alerts are rejected. Detected transactions are placed in Smart Import for your review and are not added to your finance history automatically.
Optional incoming SMS detection
If you separately enable SMS detection and grant Android's RECEIVE_SMS permission, MoneyFoam processes newly arriving messages to identify supported debit and credit alerts. It does not request READ_SMS, scan your SMS inbox, or read earlier messages. Raw SMS bodies and sender values exist only during parsing and are not written to storage. A bounded, structured transaction candidate may remain locally for up to seven days while awaiting processing.
Optional Gmail transaction detection
Gmail connection is separate from normal sign-in and is optional. MoneyFoam requests https://www.googleapis.com/auth/gmail.readonly, a broad read-only mailbox scope, then searches a limited recent window for likely financial alerts. It may temporarily fetch message metadata and bounded text parts to parse a transaction. It does not fetch attachments, send email, edit email, or delete email. Gmail access tokens are kept in memory; email bodies, HTML, tokens, recipient lists, and full raw messages are not stored in AsyncStorage or Firestore. Local account-scoped cursor data and a bounded list of processed message identifiers are retained to prevent repeated imports.
Review and structured transaction storage
Notification, SMS, and Gmail results go to Smart Import, where you can approve, edit, or reject them. The app retains structured candidate fields needed for review and duplicate prevention. After approval, only the structured transaction record—not the raw notification, SMS, or email body—is stored as part of your finance history.
Local storage and cloud sync
MoneyFoam uses an account-isolated local cache so the app can work offline. Approved transactions, budgets, profile information, and supported settings are synchronized to user-specific paths in Google Firebase Firestore. Pending offline changes may remain locally until they can be synchronized. Device-only permission consent, reminder identifiers, and detection diagnostics are not intentionally synchronized to Firestore.
Service providers and sharing
MoneyFoam uses Google Sign-In, Firebase Authentication, Firebase Firestore, and—only when you connect it—the Gmail API. These providers process information under their own terms and privacy policies. MoneyFoam does not include an advertising SDK and does not sell your personal or financial data. Information may also be disclosed when required by applicable law or to protect users and the service.
Google API Services User Data Policy
MoneyFoam's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Gmail data is used only to provide the user-facing transaction-import feature you choose to enable.
Retention
Approved finance records and account settings remain in your Firebase account and local cache until you delete individual records, clear local data, or delete your account. Rejected or processed import candidates are removed from the active approval queue. Gmail cursor and processed-message identifiers remain locally until Gmail is disconnected, local data is cleared, or the account is deleted. Limited provider backups or security logs may remain according to Google/Firebase retention practices and applicable legal or security requirements.
Security
MoneyFoam uses Firebase Authentication, user-specific cloud paths, bounded parsers, field allowlists, masked account identifiers, and account-isolated local caches to reduce exposure. No storage or transmission method is completely secure, so you should protect access to your phone and Google account and avoid placing passwords, OTPs, or full account numbers in notes or support requests.
Your controls
You can disable notification or SMS detection, disconnect Gmail, revoke Gmail access from your Google Account, edit or delete transactions, export data, clear the device cache, or delete your MoneyFoam account. Disconnecting Gmail does not delete approved transactions and does not by itself revoke the Google Account grant. See the account deletion instructions for both in-app and email-request options.
Policy changes and contact
We may update this policy as MoneyFoam changes. The current version and its update date will remain on this page. Questions or privacy requests can be sent to moneyfoam.support@gmail.com.