Privacy Policy
Last updated
- Version
- 1.1
- Effective date
- 16 September 2026
Your privacy, at a glance
Plenty helps you understand your cards, spending and debt. This policy explains the information we use to do that and the choices you have.
- You choose what to connect. Gmail is optional. If you connect it, we use read-only access to find relevant financial emails and statements.
- Your information powers your insights. We use it to organise your finances, compare card choices and calculate repayment scenarios. Automated tools, including an external AI service, can process your statements.
- We do not sell your personal information. The launch Service has no sponsored placements or lender referrals.
- You can change your mind. Revoke Gmail access, change device permissions, ask for corrections or request account deletion. Disconnecting Gmail stops new imports; deleting information already imported is a separate step.
- You can reach a person. Email contact@plenty.money for help, or contact our Grievance Officer in Section 13.
The sections below explain these points in more detail. This summary is part of the same policy.
1. Who this policy covers
Plenty is operated by Zilitone Technologies Private Limited, CIN U72900PN2022PTC209055 (“Plenty”, “we”, “us” or “our”). We are responsible for deciding how personal information is used for our Service.
This policy covers the Plenty app, website, waitlist and customer support. The Service is intended for people aged 18 or above ordinarily resident in India.
Plenty provides financial information and planning tools. We do not make payments, hold your money, issue loans or apply for credit on your behalf. The app is free at launch. If future paid features require billing information, we will explain that collection before it begins.
Your bank, sign-in provider and other services you use independently have their own privacy practices. This policy describes Plenty's handling of your information.
Registered or business address: Bangalore, Bangalore, Karnataka, India
2. What information we use
We collect information in connection with the features you use and the permissions you grant.
Information you provide. This includes your name, email address, telephone number and date of birth where supplied; income and financial preferences; cards or loans you add; purchase details; repayment assumptions; and corrections you make. We also receive information you send when contacting support.
Information from connected accounts. If you connect Gmail, we process relevant financial messages and attachments, including their sender, subject, date and contents. These can contain card or loan details, account identifiers, balances, credit limits, interest rates, instalments, due dates, transactions, income observations and recurring charges. We also retain connection details needed to maintain your authorised access.
Information from statements. We process financial documents and the text and financial details extracted from them. A statement may contain your address, a complete account number or information about another person, even if the app displays only a masked number. Statement-unlocking information is explained in Section 4.
Information created while you use Plenty. This includes saved plans, classifications, estimated rewards, repayment projections, the sources behind a result, and a history of relevant changes. These remain personal information when linked to you.
Device and service information. Our systems receive information such as your IP address, request and access records, sign-in status, errors, notification delivery details and preferences. The app also stores preferences and recently retrieved information on your device.
Optional location information. If you allow it, we use your location to suggest nearby merchants. Merchant searches also involve the search text and place you select. Section 5 explains these controls.
Waitlist information. If you join our website waitlist, we collect your email address and signup preferences to send the launch communications you request.
We do not ask for your bank login password, card PIN, CVV, UPI PIN or transaction OTP. A password used to open a statement PDF is different and may be used as described below. We do not require an Aadhaar copy, PAN copy or credit bureau report for the launch Service.
3. Why we use it
We use the information above to:
- Create and secure your account and maintain connections you authorise.
- Bring supported financial information together and keep it up to date.
- Explain spending, compare card choices and calculate repayment scenarios.
- Show where information came from, identify uncertainty and apply corrections.
- Suggest merchants when you use location or search features.
- Deliver enabled notifications and requested waitlist communications.
- Respond to questions, resolve errors, maintain the Service and prevent misuse.
- Handle privacy requests, complaints and legal obligations that apply to us.
For sensitive financial information and permission-dependent features, we request the relevant informed consent. Where the law permits or requires processing without consent, we rely on that ground only for the processing it actually covers.
Some features need particular information to work. Without Gmail access, for example, automatic imports are unavailable; you can use the manual-entry features offered in the app. We explain the consequences of declining a permission where you make the choice.
Reading this policy or accepting our Terms does not give us unrestricted permission to use your information. A new purpose requires appropriate notice and any required consent before processing starts.
4. How connected email and statements work
Connecting Gmail
Connecting Gmail is separate from signing in with Google. Google asks you to approve read-only access; Plenty receives authorisation to use that access, not your Google password.
Google's permission can allow reading across the connected mailbox. Plenty uses filters to select relevant financial messages, but those filters can make mistakes. We do not describe the permission as technically limited to bank emails.
While your connection remains authorised, Plenty can import supported messages in the background. The connection or import flow explains the historical period being used. Read-only access does not let Plenty send, edit or delete your emails.
You can revoke access through your Google Account connections or ask us for help at contact@plenty.money.
Processing your statements
With your permission, we use automated tools to open and analyse financial statements. For protected statements, we may use a password you provide or follow your issuer's password format using details such as your name, date of birth or card information. We may store passwords supplied or tried, and details of those attempts, to complete processing or retry it. This information is covered by this policy's security, access and retention provisions. Only authorise processing of statements you are entitled to use.
We use service providers, including external AI providers, to extract financial details. This may involve sharing a readable copy of your full statement, including personal information beyond the fields shown in Plenty. Before sharing, we identify the provider, explain the processing and obtain the required consent. If you decline, some automatic features may be unavailable; you can use the manual-entry options offered in the app.
We do not use your financial information to train general-purpose AI models or allow providers to do so. Providers may retain limited information for safety, abuse prevention or legal requirements under their applicable terms.
Automated results can be wrong. You can correct or query them. An estimate does not change your bank's records, approve credit or make a payment.
Google data protections
Plenty's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including Limited Use, and the Google Workspace user data and developer policy.
We do not sell this information or use it for advertising, lending, creditworthiness assessment or general-purpose AI training. These restrictions also cover information derived from it. Transfers and human access are limited to the purposes and circumstances permitted by those policies.
These restrictions take precedence over any broader wording elsewhere in this policy.
5. Your device permissions and communications
Location. Nearby-merchant features can use repeated location updates while active, with foreground location permission. Coordinates and search text may be sent to a mapping and place-search provider to suggest relevant merchants. You can decline or revoke location access through your device settings and select a merchant manually.
Device authentication. If you use the local-authentication option, your device handles the biometric check. Plenty receives the authentication result, not your fingerprint template or Face ID image.
Notifications. If you enable push notifications, delivery providers process the information needed to deliver them, including the notification content. Financial details may appear on a lock screen. You can change app preferences or device settings; essential account and security communications may still be sent through an appropriate contact channel.
Device storage and cookies. The app stores settings and recent financial or merchant results so you can return to them more quickly. Authentication and website features may also use necessary cookies or similar storage. Information becoming too old to display does not necessarily mean its device copy has already been erased. Optional tracking for a new purpose requires appropriate notice and choice before activation.
Waitlist messages. Joining the waitlist authorises the requested launch communications, not access to your Gmail or financial records. You can unsubscribe through an available email link or contact us. Removing a waitlist entry is separate from deleting an app account.
The launch Service does not require your contact book, call logs, SMS inbox or microphone.
6. Who we share information with
We share information only for a specific purpose described in this policy, subject to applicable permissions and legal requirements.
Providers that help run Plenty. We use providers for hosting and storage, authentication, document and AI processing, merchant search, notification delivery, waitlist communications, support and security. They receive the information needed for their role. For example, a document-processing provider may receive a statement, while an email-delivery provider receives the contact information needed to send a requested message.
Where providers process information on our behalf, we require appropriate confidentiality, security and purpose restrictions. Using a provider does not give it unrestricted rights to reuse your financial information. If a provider separately processes information for its own sign-in, security or legal obligations, its applicable terms and notices also govern that processing.
Authorised people. Staff or specialists may need limited access to resolve a support issue, investigate a security problem or meet a legal duty. Where access to specific Gmail-derived content requires your permission, we obtain it before inspection. A general support request does not authorise unrestricted browsing of your statements.
Legal and professional assistance. We may disclose information necessary to respond to a valid legal requirement, protect against unlawful activity or obtain advice on a specific matter. We assess the request and limit disclosure to the permitted purpose.
A transfer of the business. A merger or transfer of Plenty may require a transfer of relevant records, subject to legal safeguards and required notice or consent. Google-derived information is subject to Google's explicit-prior-consent requirements for such transfers.
A disclosure you request. We may share information with a recipient you specifically authorise, where law and the source provider's rules allow it.
We do not sell or rent your personal information, publish your individual finances to other users, or supply your records to advertisers, credit bureaus, employers or debt collectors as part of the launch Service. There are no sponsored placements or lender referrals at launch.
7. Where information is handled
Plenty operates in India. Providers supporting the Service may process information in India and other countries.
Any international transfer must satisfy applicable Indian requirements and relevant contractual and source-provider restrictions. Where particular records must be maintained in India, we follow that requirement. Your consent cannot override a transfer or localisation restriction.
Contact contact@plenty.money if you need information about the providers or locations involved in handling your data.
8. How long we keep information
We keep information for the purpose for which it was collected, for as long as that purpose requires, and for any additional period required or specifically justified under applicable law. Relevant factors include whether you still use the feature, whether a document needs processing or correction, and whether a legal obligation or particular dispute requires a record.
Different information has different purposes:
- Your account and financial history support the features you use, including saved plans and explanations of changes. They are subject to your correction, withdrawal and deletion requests.
- Statement files and unlocking information are used for processing and any necessary retry. Successfully processed files are removed when no longer needed; a locked statement may be retained while awaiting an authorised retry.
- Extracted information can remain in your account after the original file is removed so Plenty can show your financial history and calculations. Deleting a PDF is not the same as deleting everything learned from it.
- Support, consent and security records may be kept for resolving requests, demonstrating your choices, preventing misuse or meeting legal duties.
- Backup and provider copies can take additional time to expire or be deleted under their applicable schedules. They are not a reason to resume personalisation after your account is deleted.
We do not retain a complete financial history indefinitely simply by calling it an audit trail. If limited records must remain after deletion, we restrict their use to the reason for retention and remove them when that reason ends.
9. How to withdraw access or delete your account
You can change a device permission in your device settings, revoke Gmail access in your Google Account, or contact us to withdraw a processing consent.
Disconnecting Gmail stops new imports. It does not automatically delete information already imported. You can ask to keep that information for the previously requested features, stop its further use, or delete it. On withdrawal, we stop affected processing and notify relevant providers within a reasonable period, subject to applicable legal requirements.
To delete your Plenty account, open Profile → Delete account, or email contact@plenty.money. Uninstalling the app alone does not close the account.
A deletion request covers the account's personal information, including imported and derived financial records and associated files, subject to lawful retention exceptions. We distinguish accepting your request from completing deletion and explain any material outstanding steps or limited retention.
We may need to verify that a request comes from you. We ask only for information reasonably necessary for that check.
Deleting information from Plenty does not remove original messages from Gmail, change your bank's records or discharge a debt. If you later authorise a new import, information still present in the source account may be imported again.
10. Keeping your information secure
We use technical and organisational safeguards appropriate to financial information, including access restrictions, protection during transfer and storage, and measures to detect and respond to misuse.
No system can guarantee complete security. If an incident affects personal information, we investigate, take corrective steps and notify affected people, authorities or providers when required. We remain responsible for the safeguards and duties that apply to us.
To report a suspected security issue, email contact@plenty.money. Please avoid including unnecessary financial records or credentials.
11. Access, corrections and other requests
You can ask us to explain the personal information we hold about you, provide access or a copy where applicable, correct an error, process a withdrawal or deletion request, or address a concern about its use.
Use the available app controls or email contact@plenty.money. We explain a refusal or limitation and the available complaint route, unless the law prevents that explanation. Correcting Plenty's copy does not correct a bank's records.
We honour rights under applicable Indian law. Rights under the Digital Personal Data Protection Act, 2023, including nomination, apply as the relevant provisions come into force and apply to the processing. You may contact our Grievance Officer for assistance with the applicable procedure.
The Service is not offered to anyone under 18. If you believe a child has provided personal information, let us know so we can restrict the relevant account and arrange appropriate deletion, subject to legal requirements. Please connect only accounts and documents you are entitled to use; another person's information may require their authority as well.
12. Changes to this policy
The current policy is available at plenty.money/privacy. We identify its effective date and version and notify you of material changes through the app or your account contact channel before they take effect where reasonably possible.
If a change introduces a purpose or permission that requires fresh consent, we request it before the new processing begins. Continued use alone does not authorise a new sensitive-data purpose. You can ask us for a copy of the version that previously applied to your account.
13. Contact and grievances
For privacy requests or help, email contact@plenty.money.
Our Grievance Officer is:
Rajan Dube — Founder
Zilitone Technologies Private Limited
Email: rajan@plenty.money
Postal address: Bangalore, Bangalore, Karnataka, India
Please include enough information to identify your account, explain your concern and tell us the outcome you seek. Do not include a bank password, PIN or OTP.
We acknowledge grievances within 48 hours and address them within one month, or an earlier mandatory deadline where applicable. If a matter remains unresolved, we explain the position and available escalation; that does not extend a legal deadline.
You retain the right to approach a competent authority or consumer forum. Once the relevant DPDP complaint provisions apply, you may approach the Data Protection Board of India through the applicable procedure, including first using the required grievance opportunity with us.