Privacy Policy
Trei ("we", "us", "the developer") built AlertBox: UPI Voice Alert as an Android application that reads payment notifications aloud using text-to-speech, designed for accessibility and for shopkeepers. This privacy policy explains how the app handles your data.
The short version: AlertBox uses the Android Notification Listener service to detect payment notifications from your banking, UPI, and default messaging apps, then reads the amount aloud locally on your device. Notification content, parsed amounts, sender details, messages, and transaction history never leave your device. To enforce the Free daily voice allowance across reinstalls, AlertBox sends only hashed quota identifiers and count metadata. The app also uses ad and subscription SDKs (see below), which collect device-level data under their own policies.
Data Collection by the App Itself
AlertBox does not transmit notification content, amount, sender, message, or transaction history to any server we operate. It sends one-way hashed event/device identifiers, an optional signed-in Firebase user identifier, and daily quota count metadata solely to prevent duplicate counting and reset abuse.
- No account is required; users who sign in use their Firebase identifier for cross-device quota continuity.
- Notification parsing is performed entirely on-device.
- Transaction history (if enabled) is stored locally only.
- Daily quota records expire automatically; identifier links are retained only to preserve quota continuity across app-data clearing and sign-in changes.
Data Stored on Your Device
- Parsed transaction history - amount, sender, and timestamp extracted from matching payment notifications.
- Per-sender rules and preferences - TTS voice, muted senders, volume overrides.
- App settings - theme, language, notification preferences.
All local data is deleted when you uninstall the app.
Permissions and Why We Need Them
- BIND_NOTIFICATION_LISTENER_SERVICE - Read notifications from banking, UPI, and default messaging apps to detect payment alerts. See disclosure above.
- RECEIVE_SMS - Direct incoming bank-SMS capture when Android or the device maker redacts payment notification text. Matching messages are parsed locally; AlertBox does not read stored SMS or transmit SMS content.
- POST_NOTIFICATIONS - Show in-app status notifications.
- INTERNET / ACCESS_NETWORK_STATE - Serve ads, verify subscription status, and synchronize privacy-safe daily voice quota metadata.
- VIBRATE - Optional haptic feedback on alert.
AlertBox declares RECEIVE_SMS only for the direct incoming bank-SMS fallback described above. It does not request, declare, or use READ_SMS, SEND_SMS, call-log, location, contacts, microphone, or camera permissions.
Third-Party Services
AlertBox integrates the following third-party SDKs, each subject to their own privacy policies:
- Google AdMob - serves ads on the Free tier. Google Privacy Policy.
- Meta Audience Network - ad mediation fallback. Meta Privacy Policy.
- RevenueCat - subscription management for Premium unlimited spoken amounts and ad removal. RevenueCat Privacy Policy.
- Google Firebase (Crashlytics, Analytics) - crash diagnostics and anonymous usage analytics. Firebase Privacy.
Children's Privacy
AlertBox is not directed at children under 13. We do not knowingly collect data from children.
Data Security
All local data is protected by Android's app sandboxing. No notification content is transmitted off-device by AlertBox.
Changes to This Policy
We may update this policy when new features are added. Any changes will be posted here with an updated "Last Updated" date.
Contact
Trei
Email: contact@trei.dev
Phone: +91 85500 77767
Website: trei.dev · Contact form