PRIVACY & PRODUCT LIMITS
Clear permissions. Visible sources.
Fettle now has a connected automation implementation. It remains inactive until its services are configured and you sign in and authorize Gmail access and processing. Existing local records are not silently uploaded when you connect an account.
Local and connected storage
Local records and receipts remain in this browser's IndexedDB and can be accessed by anyone using this browser profile. Connected records, source metadata, and processing status are stored in Supabase with user isolation. Gmail refresh credentials and push subscriptions are encrypted by the server. Local storage and exported backups are not encrypted by Fettle.
Gmail and AI processing
Google grants read-only mailbox access. With your specific consent, Fettle queries matching financial emails from the last 30 days and future matching emails. Selected email text and text from supported PDF attachments are sent to the configured OpenAI API for record extraction. Original emails and attachments are not deleted or modified. Common security messages are excluded and some sensitive fields are redacted, but this is not anonymization.
The extraction request uses store: false. Provider abuse-monitoring retention and account-specific data controls still apply; this is not a promise of zero retention. The operator must review Google Limited Use rules, processor agreements, and privacy obligations before enabling real data processing. Google-derived data must not be repurposed for advertising, resale, or lending/creditworthiness.
Bank and travel connections
Bank access has its own Setu consent review and requires an approved FIU or partner arrangement. The connector accepts supported INR deposit accounts, retains masked balances and minimal transaction evidence, and discards full account profiles and narrations. Automatic refund or bill matching requires an explicit settlement reference, exact amount and direction. Sandbox data never counts as bank-matched cash.
Travel monitoring is separately opt-in. Supported booking criteria are extracted from the source and sent to Duffel for comparison, without passenger names or identity documents. Exact matching can fail when required details, INR prices, or supplier inventory are unavailable. A price quote is not a booking, guaranteed saving, or protection benefit.
Control, retention and deletion
Disconnect stops local provider access immediately and queues external revocation. Encrypted Gmail credentials may be retained solely for revocation retries, for up to 24 hours. Imported records remain until deleted or erased. Bank snapshots expire at the earlier of the consent limit, provider data lifetime, or the operator retention limit (30 days by default). Travel observations are retained for at most seven days; expired quotes are not shown as current.
Your data includes connected export and erasure controls. Erasure immediately removes connected records, bank snapshots, source metadata and support cases, disables automation, and queues provider revocation. Optional account deletion runs after revocation attempts. A private receipt checks completion without sign-in and expires 30 days after completion. Failed provider revocation may require action in the provider account. Account reactivation after data-only erasure requires completion, a 15-minute safety interval and a fresh sign-in.
Local browser data, original emails, provider bank records and downloaded backups are outside connected erasure. Hosting logs, backups and vendors' retention are governed by the approved operator policy; erasure is not a promise of instantaneous removal from every backup. Signing out hides connected data but does not stop authorized background processing.
Reminders and other sharing
Background reminders require a configured scheduler and device permission. Notification text contains no merchant names or amounts, but push providers process delivery metadata. Delivery depends on the browser and operating system. Copying drafts uses your clipboard; opening a mail draft or importing a calendar file shares the selected information with those applications. Hosting services may process IP addresses and access logs.
Support and financial boundaries
Support staff see submitted case messages and only those record snapshots you explicitly share. Replies are available in your signed-in workspace. Operational analysts see aggregate health, not support content. Fettle does not move money, cancel services, rebook travel, guarantee refunds, sell insurance, or provide investment advice. Ambiguous or unsupported documents remain exceptions.
Launch status
This is a technical beta notice, not a complete legal privacy policy. Live provider activation has not been completed. Public launch requires the real operator's identity and contacts, approved terms and privacy notices, relevant Google verification/security assessment, processor reviews, retention and erasure rules, and tested hosted operations.
Operator and contacts
Operator identity is pending configuration.
Public support and grievance contact details must be configured before launch.