Glass Money
Built for IndiaYour money, finally in sync.
Limited beta — sign in if you already have a seat, then connect the alert mailboxes that send your transactions.
One login, all inboxes.
No seat yet? Ask for a beta seat on the homepage — web, Android, and iOS are invite-limited while verification continues.
Privacy & your data
What Glass Money does
Glass Money reads the transaction-alert emails Indian banks and card issuers already send you, extracts the transactions in them, and shows you a spends dashboard. That's the whole product; everything below follows from it.
Gmail access
- Sign-in vs Connect: Signing in with Google uses Glass Money's own OAuth client
for identity only (
openid/ email / profile). Connecting Gmail is a separate step and uses whichever Connect path is live for the deployment. - How Connect works today (Composio): Production Connect uses Composio, a
partner whose verified Google OAuth app hosts consent (Google will show Composio on
the consent screen). That managed auth config requests Google's
https://mail.google.com/scope — full Gmail mailbox access as Google defines that scope — and may also include contacts/people-related scopes that Composio's default Gmail toolkit requests. It is not limited to Google'sgmail.readonlyscope. Email content used for sync may transit Composio before it reaches Glass Money servers. - What we do with that access: Regardless of which scopes Google grants to the Connect app, Glass Money only uses email content to power product features — fetching known Indian bank and card-issuer transaction alerts (and related statement mail where applicable) so we can extract transactions into your dashboard. We do not send, delete, modify, or label anything in your mailbox on your behalf. We do not use Gmail data for ads, sale, or training generalized AI/ML models.
- Only emails from known Indian bank and card-issuer senders and domains are fetched (known alert addresses, plus occasional domain-level sweeps for new bank alert addresses). Your personal mail is never downloaded for product use.
- Direct Google path (fallback / legacy tokens): If a deployment uses Glass
Money's own Google OAuth client for Connect, or a mailbox still syncs via a previously
granted Google token (hybrid dual-path), that path uses Google's
gmail.readonlyscope and mail goes Google → our server (no Composio in the mail path for that mailbox). The live product tells you which flow Connect uses. - You can disconnect Gmail at any time from the Account page. Disconnecting deletes our access token / connected-account link immediately; syncing stops on the spot.
How your emails are processed
Extraction is primarily deterministic: transactions are parsed with hand-written and pre-validated templates. When the server has an LLM configured, unrecognised emails may be sent to an AI model for extraction — including during automatic background syncs.
Google Limited Use disclosure
Glass Money's use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.
Google user data obtained via Google APIs — including Gmail content obtained through
Connect (via Composio's managed https://mail.google.com/ scopes, or via
gmail.readonly on the direct Google path) for bank and card
transaction-alert emails — is used only to provide and improve the user-facing features
that are prominent in the app: extracting those alerts into your spending dashboard.
When Composio hosts Connect, consent is granted to Composio's OAuth app and mail may
transit Composio as described under Gmail access; Glass Money's use of the data we
receive still follows Limited Use.
- We do not transfer Google user data to others except as necessary to provide or improve those features (including the Composio connect path when it is enabled), for security purposes, or as required to comply with applicable law. We do not sell Google user data.
- We do not use Google user data for serving advertisements.
- We do not use Google user data for determining creditworthiness or for lending purposes.
- Human reading of Google user data does not occur except: (a) with your consent (for example, when you ask us to investigate a support issue), (b) for security or compliance reasons, or (c) when the data is aggregated and anonymized for internal operations.
Google user data (including Gmail content obtained via Connect) is not used to train, improve, or develop generalized AI/ML models. When an LLM is configured on the server, unrecognised bank-alert emails may be sent to paid third-party AI APIs (such as Google Gemini or OpenAI) only to extract transactions for that user's dashboard. Under our configuration and contracts, those providers are not permitted to use that content to train generalized models, and we do not use it for model training ourselves.
What we store, and where
- Fetched bank-alert emails and the transactions extracted from them are stored in a database that belongs to your account alone — every account has its own isolated database.
- Your Gmail access token is stored encrypted at rest when the server secret key is configured.
- Account data (emails, transactions, tokens) is hosted on Fly.io servers in Mumbai, India.
- We use a single session cookie to keep you signed in. There are no ads in the app.
Analytics
We use PostHog (hosted in the US) for analytics. On the public marketing site, we collect anonymous pageviews, referral information, CTA clicks, and mobile-beta waitlist form status so we can understand which pages help people decide to try Glass Money. In the signed-in product, when analytics is enabled on the server, we send product events such as sign-ins, Gmail connect, sync success/failure, and similar product usage. Signed-in events use an opaque tenant ID with categorical outcomes and aggregate counts. We do not send account email/name, email bodies, message content, exception messages, or extracted transaction details to PostHog, and session replay and automatic browser capture are disabled. Analytics is optional and disabled when no PostHog API key is configured.
Mobile transaction alerts
If you opt in to mobile transaction alerts, one new transaction's amount and merchant may be sent through Expo and the applicable push provider (FCM on Android or APNs on iOS), and may appear on your device lock screen. You can disable alerts at any time in the app's Settings.
What we never do
- Sell, share or monetise your data in any form.
- Send your emails to an AI except to extract unrecognised bank-alert formats when an LLM is configured on the server.
- Touch anything in your mailbox beyond reading bank-alert emails for product features.
Deleting your data
Delete account on the Account page (typed confirmation required) is the only way to revoke Gmail access and remove everything — your database, account, encrypted token and statement files. We revoke Google access immediately, wipe your tenant data from the live server, and remove your user row. Database replicas age out with our backup retention (Litestream snapshots: 72 hours). As a fallback, email us from the Google account you signed in with and we'll remove it all.
The demo
The demo mode runs entirely in your browser on generated sample data. Nothing is sent to or stored on our servers when you use it.
Contact
Questions or deletion requests: varora1406@gmail.com. See also our Terms of service.
Terms of service
The service
Glass Money ("Glass Money", "we", "us") is a personal finance tool that reads transaction-alert emails Indian banks and card issuers already send you, extracts the transactions in them, and shows you a spends dashboard. That is the product.
Glass Money is not a bank, payment service, lender, investment adviser, or tax adviser. It does not give financial advice. It does not connect to your bank accounts via net banking, Account Aggregator, or by storing bank passwords — it only reads alert emails you authorise via Gmail (which may use a partner connect flow such as Composio; see our Privacy policy).
Eligibility and accounts
- You must be able to form a binding contract under Indian law (generally 18 years or older) to use the service.
- You sign in with Google. You are responsible for activity under your account and for keeping access to that Google account secure.
- Connecting Gmail is required for importing your real transactions. Gmail may be authorized through a partner connect flow such as Composio; Google scopes depend on the live Connect path (see our Privacy policy). Glass Money only uses that access to read bank and card alert emails for product features — we do not send, delete, or modify mail on your behalf. Browsing the demo needs no sign-in at all.
Acceptable use
You agree not to:
- Use the service for anything illegal or to infringe others' rights.
- Attempt to access another person's account, mailbox data, or tenant database.
- Probe, overload, scrape, or disrupt the service, or bypass rate limits or security controls.
- Reverse-engineer the service except to the extent applicable law expressly allows.
- Misrepresent who you are or automate sign-ups in a way that harms the service.
We may suspend or terminate accounts that violate these terms.
Subscriptions, billing, and refunds
Parts of Glass Money may be free; paid plans (when offered) are billed in INR through our payment processor (currently expected to be Razorpay). Prices and plan features will be shown at checkout before you pay.
- Refunds. If you purchase a new paid subscription and are not satisfied, you may request a full refund within 7 days of the first successful payment for that subscription, by emailing varora1406@gmail.com from the Google account you signed in with. After that window, fees are non-refundable except where Indian law requires otherwise.
- Cancellation. You may cancel a paid subscription at any time. Cancellation stops future renewals; you keep access through the end of the period already paid for. Unused time after the 7-day refund window is not refunded on a pro-rata basis unless we say otherwise at purchase or Indian law requires it.
- Failed renewals may pause paid features until payment succeeds. We may change prices with reasonable notice before the next renewal.
Your data and privacy
How we collect, process, store, and delete data is described in our Privacy policy, which is part of your agreement with us. You retain ownership of your transaction data; you grant us a limited licence to process it only to provide and improve the service.
Disclaimers
The service is provided "as is" and "as available". Extraction depends on the emails your bank sends and on our parsers; amounts, merchants, dates, or categories may occasionally be wrong or incomplete. You should not rely on Glass Money as the sole record for taxes, disputes, or financial decisions. To the fullest extent permitted by law, we disclaim warranties of merchantability, fitness for a particular purpose, and non-infringement.
Limitation of liability
To the fullest extent permitted by Indian law, Glass Money and its operator are not liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, or data, arising from your use of the service. Our total liability for any claim relating to the service is limited to the greater of (a) the fees you paid us for the service in the 12 months before the claim, or (b) ₹2,000.
Nothing in these terms excludes liability that cannot be limited under applicable law (including for fraud or wilful misconduct).
Governing law and disputes
These terms are governed by the laws of India. Courts in Mumbai, Maharashtra have exclusive jurisdiction, subject to any mandatory consumer protections that apply to you.
Grievance officer (DPDP)
Under the Digital Personal Data Protection Act, 2023, you may raise a grievance with our Grievance Officer:
- Name: Vaibhav Arora
- Email: varora1406@gmail.com
We will acknowledge and address grievances within the timelines required under applicable law. For privacy or deletion requests, see the Privacy policy.
Changes
We may update these terms from time to time. The "Last updated" date at the top will change when we do. Continued use after changes take effect means you accept the updated terms. If a change is material and you have an account, we will take reasonable steps to notify you (for example by email or an in-app notice).
Contact
Questions about these terms: varora1406@gmail.com.
Connect your Gmail
connecting Gmail is the one required step.
- Read-only Gmail access — we can never send, delete or change anything
- Only emails from known Indian banks & card issuers are fetched
- Most extraction is template-based — AI may be used for unrecognised formats
- You'll authorize via Composio, our partner connect flow (Google will show Composio; managed scopes include
mail.google.com, not gmail.readonly)
| Amount | Bank | Mode | |
|---|---|---|---|
| loading… | |||
Wealth
Asset classes
Select a class to focus the ledgerComing soon
These sources are paused until their numbers are reliableAll investments
Across every account| Instrument | Account | Invested | Current value | Returns |
|---|---|---|---|---|
| loading… | ||||
No investments yet
Glass Money syncs your inbox automatically and will combine investments from every connected account here.
Recurring payments
Insights
MONTHLY SPEND (DEBITS)
TOP CATEGORIES
Insights
Chat
Chat isn’t ready yet
Finance AI chat is enabled for your account, but no language model is configured
on the server. An OpenAI-compatible key (GEMINI_API_KEY or
LLM_API_KEY) is required before questions can be answered.
Account
Overview
Your data, security, and preferences in one place.
Financial coverage
Accounts in coverage, by bank. Park what you don’t need — recoverable below.
Expand a row to edit type, nickname, or product. Remove parks it below — nothing is deleted.
Loading accounts…
Parked from gaps. Add back anytime.
Add an account to cover
Add banks, cards, wallets, FASTag, investments, and joint accounts you are authorized to include—even when their data source is still missing.
Connected inboxes
Read-only transaction sources, separate from your login.
0 of 5 active inboxes
Gmail Connect uses Composio, our partner flow — Google will show Composio on the consent screen (managed scopes include mail.google.com, not gmail.readonly).
Disconnecting stops future syncs. Imported transactions stay in your ledger.
Personal details
Used only for statements and wealth features.
Add DOB and PAN to unlock statements
Statement PDFs stay locked until these are set.
Data & privacy
Control your information and account.
Your data
Export a copy of the current transaction view or review how Glass Money handles your data.
Delete account
Permanently remove your account, imported transactions, statements, and connected inbox access. This action is deliberately kept here, away from everyday account actions.
Login & security
Your one Glass Money login.
Login method
This is your single Glass Money login. Inbox permissions are separate.
Notifications
Background sync alerts for this browser.
Get told when a background sync finds new transactions. Notifications show only how many — never amounts or merchants.
Categories
Group transactions and power filters and Insights.
Built-in categories stay consistent. Add your own for the way you spend.
Appearance
Choose how Glass Money looks.
Choose light or dark. Your choice is saved to your account.
Help & feedback
Get help or tell us what you think.
Report a bug, send feedback, or ask for support. Your note goes directly to Glass Money.
About Glass Money
Clear money, from the alerts you already receive.
Glass Money
A private, read-only view of transactions from the inboxes you choose to connect.