Chillar privacy policy
Last updated: 9 October 2026
Chillar is an app that shows what you spend online by reading receipts in the Gmail accounts you choose to link. This policy explains what the app reads, where it is kept, and how to remove it.
The short version
- Chillar has no servers and no user accounts. Nothing the app reads leaves your phone.
- The developer cannot see your email, your transactions, or anything else in the app.
- You can delete everything at any time from inside the app.
What the app reads
When you link a Gmail account, Chillar asks Google for read-only access (gmail.readonly). It then searches that mailbox for:
- order, invoice, payment, refund and subscription emails from known shopping, food delivery, ride and subscription services, and
- debit and card payment alerts from banks.
Messages are found by sender and subject. From each matching email the app extracts the merchant, amount, fees, items, payment method and date. Chillar cannot send, delete or change mail.
Where it is kept
The extracted details are stored in an encrypted database on your phone, along with a log of each email's sender, subject and whether it could be read. The encryption key and the Google sign-in tokens are kept in the system keystore (Android Keystore / iOS Keychain). The body of an email is not stored; when you open "View receipt", the original is fetched from Gmail and shown on screen.
What is shared
Nothing, unless you choose to send it. Chillar does not send your data to the developer or to any third party, contains no advertising, and contains no analytics or tracking.
The app makes two kinds of network connection: to Google, to sign you in and to read your mail; and to GitHub, to download two small public files, the reading rules (sender names and text patterns for recognising receipts) and the list of daily nudges. These downloads send nothing about you or your mail.
A file leaves the app only when you make one and pick where to send it:
- Export CSV: your transactions.
- Send feedback (More → Send feedback): opens a message in your own mail app or the share sheet (for example WhatsApp), addressed to suhi.apps@gmail.com. It contains what you write plus the app version, phone type, reading-rules version and how many Gmail accounts are linked. Nothing is sent until you send it from that app.
- Share reading log (More → Reading health): for helping the developer fix receipts the app could not read. It contains how many emails were read per platform and the text of up to 30 emails that were not, with names, addresses, phone numbers, email addresses and order, card and account numbers masked. Items and amounts are kept. Masking is automatic and may miss details, so the app shows you the whole file before you share it. If you send it to the developer, it is used only to fix reading problems.
Google user data
Chillar's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only to show you your own spending inside the app. It is not transferred to anyone, not used for advertising, and not read by any person.
Notifications
If you turn on reminders, the app schedules them on the phone itself. No push service is involved.
Keeping and deleting data
Data stays on your phone until you remove it. You can:
- unlink a single Gmail account (More → the account), which removes its transactions and revokes its access,
- pause all reading (More → Privacy centre), or
- delete everything (More → Privacy centre → Delete everything), which unlinks every account and erases the database.
Uninstalling the app also removes all of its data. You can revoke Chillar's access at any time at https://myaccount.google.com/permissions.
Children
Chillar is not directed at children under 13 and does not knowingly collect data from them.
Changes
If this policy changes, the new version will be posted at this address with a new date.
Contact
suhi.apps@gmail.com