What Oinc collects
Oinc stores account profile details, sign-in session metadata, derived financial records, local uploaded-file records, optional upload notes, and Gmail sync state that is required to power the product surfaces you explicitly enable.
When you connect Gmail, Oinc requests the narrow gmail.readonly scope and uses it to detect finance-related messages, review eligible receipts, statements, and finance PDFs, extract structured fields such as merchant, amount, due date, account last-4, and statement period, and maintain the inbox and dashboard workflows you can review in the app.
When you upload a receipt, statement, invoice, image, or PDF, Oinc stores the file metadata, selected file type, optional note, processing status, and derived transaction or document fields needed to show the result in your account.
How Gmail, uploads, and derived data are handled
Refresh tokens are stored encrypted at rest, provider revocation is attempted when you disconnect Gmail, and privacy export packages exclude raw Gmail content plus stored secrets.
Operational logging is structured and redacted. Successful Gmail classification and verification prune raw subject, sender, snippet, and body fields immediately, and any remaining raw message content falls back to a 1-day retention window instead of becoming a long-lived mailbox replica.
If a finance email includes a statement, receipt, or similar PDF or image attachment, Oinc may download that file, extract the document fields needed for the visible workflow, and link the resulting transaction or document summary back to your account.
If you upload a local file, Oinc may send the uploaded file, selected file type, optional note, and required document metadata to the same controlled extraction routes so the app can create the visible transaction or document summary you requested.
Google user data is protected with encryption in transit, encrypted token storage, access controls, redacted operational logging, and retention limits for raw message content.
When Gmail-powered extraction or uploaded-file processing runs, Oinc sends only the minimized finance-related fields, eligible document files, selected file type, optional upload note, and document metadata required for the visible feature to approved external AI processors through controlled routes. The current reviewed processors are OpenRouter-managed calls pinned to OpenAI and Google Vertex AI with deny-collection and zero-data-retention controls enabled.
Raw prompt text and raw model responses are not retained in Oinc's normal observability path. Privacy export packages include derived transaction history, durable financial document metadata, and extracted document text, but exclude raw Gmail content, encrypted Gmail secrets, stored password secrets, and password HMAC values used during document processing.
Oinc personnel do not manually review raw Google user data except when you request support and consent to review, when review is necessary for security or abuse investigation, when required by valid legal process, or when aggregated data is used for internal operations under applicable privacy requirements.
Oinc does not use Gmail-derived data for ads, broad profiling, marketing enrichment, or shared-model training. Gmail-derived data stays limited to user-facing finance workflows, security operations, and the short-lived diagnostics documented in the repository compliance inventory.
Oinc may personalize the order of discount offers based on your explicit in-app preferences and interactions with the discount catalog. Oinc does not use Google user data or Gmail-derived data to target, rank, personalize, or advertise discounts.
Who receives Google user data and uploaded files
Oinc does not sell Google user data, share it with advertising platforms, data brokers, or information resellers, or use it for ads, lending decisions, broad profiling, or shared-model training.
Oinc shares, transfers, or discloses Google user data only to service providers and processors that help operate the user-facing product features you enable.
Oinc may disclose or transfer Google user data only to service providers that help operate the user-facing product features you enable, including secure hosting, database, storage, logging, authentication, notification, and support infrastructure providers. These providers may process the data only for Oinc's documented product, security, support, and legal-compliance purposes.
When Gmail-powered extraction or uploaded-file processing is needed for a visible finance workflow, Oinc may send minimized finance-related fields, eligible document files, selected file type, optional upload note, and document metadata to approved external AI processors, currently OpenRouter-managed calls pinned to OpenAI and Google Vertex AI with deny-collection and zero-data-retention controls enabled.
Oinc requires these service providers and AI processors to protect the data with the same or equal privacy and security protections described in this policy, including purpose limits, access controls, retention limits, and no shared-model training for Oinc user data.
Oinc may also disclose Google user data if necessary to investigate abuse or security incidents, comply with applicable law or valid legal process, enforce user-requested deletion or provider-disconnect controls, or complete a merger, acquisition, or sale of assets after obtaining explicit prior user consent.
Oinc's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your controls
Signed-in users can review privacy status, request an account deletion window, cancel a pending deletion, and request an export of their account data from the in-product privacy surfaces.
Deletion requests place the account into a read-only state while the grace period is active so you can review or reverse the request before the final purge runs.
Disconnecting Gmail stops future sync, clears Oinc's stored Gmail token material for that connection, and asks Google to revoke the provider grant. Imported finance history, including derived transactions, merchants, and document summaries, remains in your account until you reconnect, export it, or complete account deletion.
Dominican Republic privacy rights
For Dominican Republic Ley No. 172-13 privacy rights, Oinc Labs, LLC is responsible for deciding how personal data is processed in Oinc. You can contact Oinc Labs, LLC at admin@oinc.app or at 30 N Gould St, STE R, Sheridan, WY 82801, USA.
Verified users can request access, rectification, update, suppression, deletion, or Gmail disconnect support through admin@oinc.app and in-product controls. Routine account deletion keeps the configured recovery window; verified legal suppression requests can be escalated through admin export, forced logout, and immediate deletion.
Oinc