This policy explains how CatTech Enterprise ("we", "us") handles personal data in the MyPurrse Android app (com.cattech.mypurrse) and on https://mypurrse.com. It is written for people in Malaysia and is meant to meet Google Play's privacy policy rules and the Personal Data Protection Act 2010.
Contact: cattech.enterprise@gmail.com
Who we are
MyPurrse is operated by CatTech Enterprise, an SSM-registered sole proprietorship in Malaysia. The public developer name on Google Play is CatTech Enterprise. The app is listed at Google Play (coming soon).
What MyPurrse does
MyPurrse reads payment notifications from banking and e-wallet apps you choose, sends that text to our self-hosted API for AI classification, and saves valid MYR income and expense notes. Free-tier notes are written to a Google Sheet in your own Google Drive. Our servers keep your sign-in, plan, linked accounts, and usage counts.
Data we process
Google account
When you sign in with Google we receive your Google user id and email so we can create a MyPurrse account and issue a session. We store a refresh token on our server so the app can stay signed in.
Google Drive and Sheets (free tier)
If you connect Drive, the app asks for Spreadsheets and Drive file access. Those files belong to you. We create a MyPurrse folder and monthly sheets such as "MyPurrse yyyy-MM", and optional receipt photos under MyPurrse/Receipts. CatTech does not copy free-tier transaction rows into our database.
Notification text
After you grant Android notification access and pick apps to watch, MyPurrse reads the title and body of those notifications. That text can include amounts, merchant names, and other payment details. We send it to our API so a language-model provider can classify it (income, expense, transfer, or ignored). We do not read notifications from apps you did not select, and we do not read your other apps' private screens.
Receipt scans
If you scan a receipt, the photo is read on your phone. Only the extracted text is sent to our API. If you keep receipt photos on, the image is saved in your Drive, not on our server.
Linked accounts and usage
We store the bank or e-wallet names and Android package names you link, your plan, and how many auto-reads and receipt scans you have used. This enforces Free, Starter, and Pro limits.
Google Play purchases
If you subscribe, Google Play tells us the product id, purchase token, and whether the plan is active. Payments are handled by Google. We do not see your full card number.
Optional "Help improve MyPurrse"
This is off unless you turn it on in the app (Den, Privacy). If you opt in, we keep a masked copy of what was sent to the model, what it answered, and what we did with it, for up to 180 days, so we can improve accuracy. Emails, one-time codes, and long number sequences are masked first. Turning it off stops new samples. You can delete kept samples in the app at any time.
Merchant category memory (Starter and Pro)
If you correct a category, we may remember that merchant for your account so later payments can be labelled the same way across your devices.
How we use data
- To sign you in and keep your session.
- To classify alerts and receipts you ask us to read.
- To save notes to your Google Sheet (free tier) or to show them in the app.
- To enforce plan limits and restore Play subscriptions.
- To improve classification, only if you opt in to Help improve MyPurrse.
- To answer support mail you send us.
We do not show ads in the app. We do not sell personal data. We do not use your payment alerts for advertising.
Where data lives
- Your Google account: identity, Drive folder, Sheets, optional receipt photos.
- Our VPS (currently in Singapore): user id, email, refresh tokens, linked accounts, usage, Play subscription state, optional AI samples, merchant corrections.
- Language-model provider (currently Google Gemini, and we may use another contracted provider): alert or receipt text, for classification. We do not store that text on our server unless you opted in to Help improve MyPurrse.
Some processing happens outside Malaysia (Singapore VPS, and the model provider's regions). We use this because the app cannot classify alerts without that infrastructure.
Who we share with
- Google: Sign-In, Drive/Sheets (your account), Play Billing.
- Our language-model provider: notification or receipt text, to return a classification.
- Our hosting provider: the VPS that runs the API and database.
We may disclose data if required by Malaysian law or to protect the service from abuse. We do not share data with data brokers.
How long we keep it
- Account, linked apps, plan, and usage: while your MyPurrse account exists.
- Refresh tokens: until you sign out, or until they expire and are cleaned up.
- Help improve samples: up to 180 days, or sooner if you delete them.
- Google Sheet rows and receipt photos: until you delete them in Drive. Signing out does not delete Drive files.
- Server backups: nightly dumps are kept on the VPS for about 14 days.
- Support email: as long as needed to handle your request.
Your choices
- Pick which apps are watched. You can unlink them in the app.
- Turn notification access off in Android settings. Tracking stops on that phone.
- Turn Help improve MyPurrse off, and delete kept samples, in Den, Privacy.
- Disconnect Google Drive in the app. Existing sheets stay in your Drive.
- Cancel a paid plan in Google Play.
- Ask us to delete server-side account data. See Delete account.
Under the PDPA you may request access to, or correction of, personal data we hold, and you may limit processing where the law allows. Email cattech.enterprise@gmail.com from the Google address you use in the app.
Children
MyPurrse is a personal finance app. It is not directed at children under 18. We do not knowingly create accounts for children. If you believe we have, email us and we will delete the server record.
Security
The API is reached over HTTPS. Sessions use signed tokens. The language-model API key and database password stay on the server, not in the Android app. Notification text is truncated before it is sent. Free-tier ledgers stay in your Google account. No method is perfect. Please protect your Google account and your phone.
Permissions the app uses
- Internet, to reach our API and Google.
- Notification access, only for apps you select.
- Post notifications, so MyPurrse can tell you what it filed.
- Battery-optimisation exceptions and boot restart, so capture can keep running.
- Optional camera or photos, only if you scan a receipt.
This website
The marketing site at https://mypurrse.com is static. It does not require an account. It may store your companion-cat and light/dark choice in the browser (localStorage) so the page looks the same on the next visit. We do not run advertising pixels on this site.
Changes
If we change this policy in a material way, we will update the date above and publish the new text at https://mypurrse.com/privacy. If in-app Help improve wording changes, older consent stops recording until you accept again.
Contact
CatTech Enterprise
Malaysia
cattech.enterprise@gmail.com