Privacy Policy for Vylor


**Last Updated: February 6, 2026**


Vylor ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use the Vylor mobile application and related services.


1. Information We Collect


### A. Sensitive Permissions

To provide its core features, Vylor requests access to the following sensitive components of your device:

- **Camera:** Used exclusively for **Vylor Vision** to scan and extract data from paper receipts.

- **Microphone:** Used exclusively for the **Voice Assistant** to process your financial commands and queries.


### B. Financial Data

All transaction data, account balances, and category information are stored **locally on your device** using an encrypted SQLite database. We do not store your raw financial data on our servers.


### C. AI Processing

When you use voice commands or Vylor Vision, data (audio snippets or receipt images) is sent to the **Google Gemini API** via an encrypted proxy.

- **Receipt Images:** Processed to extract text, and **only the extracted text is retained by Vylor. The original image is then immediately discarded.**

- **Audio:** Processed to understand your command, and **only the transcribed text is retained by Vylor. The original audio snippet is then immediately discarded.**


### D. Third-Party Data Processing with Google Gemini

When your voice data (audio snippets) or receipt images are sent to the Google Gemini API:

* **Google's Role:** Google (as the provider of the Gemini API) acts as a data processor for Vylor. This means Google processes the data on our behalf and according to our instructions, primarily for the purpose of transcribing voice into text or extracting text from images.

* **Data Minimization:** We only transmit the necessary audio snippets or receipt images required for processing to the Google Gemini API. We do not send any personally identifiable information (such as your name, email, or other account details) along with these snippets unless explicitly required for the Gemini API functionality and with your explicit consent.

* **Data Security:** All communications between your device, Vylor's encrypted proxy, and the Google Gemini API are secured using industry-standard Transport Layer Security (TLS/HTTPS) encryption to protect your data in transit.

* **Data Retention by Google:** For abuse monitoring purposes, Google may retain prompts, contextual information, and generated output. Additionally, for free tier usage of the Gemini API, Google may use the content you submit (including voice data and responses) to provide, improve, and develop Google products and services, including their machine learning technologies. We encourage you to review Google's official terms of service and privacy policies for the Gemini API, particularly for the free `gemini-flash-native-audio` variant, to fully understand their data handling, retention, and usage practices.


2. How We Use Your Information

- To log transactions and manage your personal finance ledger.

- To provide predictive insights via the "Oracle" feature.

- To improve the accuracy of our voice and vision AI models.


3. Data Security

We use industry-standard encryption to protect your data:

- **Biometric Vault (Pro):** Access to the app is secured via native device biometrics.


4. Third-Party Services

Vylor integrates with the following third-party providers:

- **Google Gemini API:** For natural language and image processing.

- **RevenueCat:** For subscription management.

- **Firebase/AdMob:** For analytics and ad serving (Essential tier).


5. Your Rights and Choices

You have the right to:

- Delete all local data at any time from the app settings.

- Revoke camera and microphone permissions through your device settings.

- **AI Feature Consent:** The first time you use an AI-powered feature (either the **Voice Assistant** or **Vylor Vision** for receipt scanning), you will be asked to provide explicit consent for your data (audio snippets or receipt images) to be processed by Google's Gemini API. This consent covers all AI features within the app. You can manage or revoke this consent at any time within the app's settings.


6. Contact Us

If you have questions about this policy, please contact us at info@vylor.money.