AllMyWallets

Privacy Policy

Updated September 15, 2026

This policy describes how AllMyWallets accesses, uses, stores and shares personal information, including Google user data. Contact: admin@cpdastudios.com.

1. Information we access and collect

We store your AllMyWallets account email, securely hashed password and recovery code, account preferences, and financial records you import or enter.

When you choose to connect Gmail, Google asks for your authorization. We request openid and userinfo.email to identify the connected Google account, and gmail.readonly to read email. Although this scope permits reading your mailbox, the application searches financial terms within your selected date range to locate bank notices, merchant receipts, subscription and renewal messages.

Downloaded Google user data can include message identifiers, sender and recipient details, subjects, dates, message bodies, and related attachments. These may contain transaction amounts, currencies, merchants, account or card identifiers and balances. Search results may also include messages that are not financial or cannot be interpreted; downloaded sources can be retained for review. We also store the OAuth credentials needed to maintain the connection. We never receive your Google password.

2. How we use Google user data

We use the connected email address to associate Gmail with your private workspace. We use downloaded messages and attachments to organize supported financial information: transactions, income and expenses, institutions, receipts, subscription events and renewal history. Source emails support review, duplicate detection and links back to Gmail. Stored sources and financial versions support your history, export and recovery.

Imports are initiated by you with the Update action. The Gmail permission does not allow AllMyWallets to send, modify or delete your email. We do not sell Google user data, use it for advertising or creditworthiness decisions, or use it to develop or train AI or machine-learning models. The current application does not send Gmail contents to an external AI API.

AllMyWallets' use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. Sharing, transfers and disclosure of Google user data

Hostinger: our hosting provider processes and stores the application, downloaded Gmail sources, attachments, derived financial records and connection credentials on the infrastructure used to operate AllMyWallets. This processing supports the service you request. Data is not shared with other AllMyWallets users.

Google: we communicate with Google's OAuth and Gmail services to authorize the connection, obtain the connected account identity and retrieve the messages you ask us to import. Opening a source-email link takes you to Gmail.

GitHub: hosts the application's source code and supports deployment. Gmail messages, attachments, financial databases and connection credentials are excluded from the source repository and are not sent to GitHub by the application's import process.

We do not disclose Google user data to advertising networks, data brokers or external AI providers. Authorized operators may access specific data with your affirmative consent for support, or when necessary to investigate security issues or abuse, or comply with applicable law. Other disclosures are limited to providing user-facing features with your consent, security purposes, legal obligations, or a merger, acquisition or asset sale after obtaining your explicit prior consent, as permitted by Google's Limited Use requirements.

4. Storage and protection of sensitive data

These measures do not mean every stored file is individually encrypted: downloaded email files, attachments and financial databases are stored in the private server workspace, and are not currently encrypted individually by the application. Access controls protect that workspace. No service can guarantee absolute security.

5. Retention, export and deletion

We retain imported sources, financial records and previous versions while your account is active so that you can review, export and recover your information. Archiving a transaction hides it from active views but does not erase it or its history.

You can revoke Gmail authorization in your Google Account settings. Revocation prevents further authorized Gmail access but does not delete information already imported into AllMyWallets.

To request deletion of your account, connection credentials, imported messages, attachments and derived financial records, email admin@cpdastudios.com from your account address. We verify ownership before deleting the active workspace and application-managed copies. Provider backup copies may persist until they expire under the provider's retention schedule; any legally required retention will be explained when applicable.

6. Cookies and preferences

We use an essential session cookie for sign-in and browser storage for display preferences. The application does not include advertising or analytics trackers.

7. Policy changes and contact

We publish policy changes on this page with an updated date. Questions about Google user data, privacy or deletion can be sent to admin@cpdastudios.com.