Privacy Policy
Effective 4 July 2026
This Privacy Policy explains how Dive collects, uses, shares, and protects your information, including data accessed from Google Gmail with your permission. By using Dive you agree to this policy.
1. Overview
Dive ("Dive", "we", "us") helps you understand your personal finances by reading the bank and financial alert emails in your inbox and turning them into a clear money report. This policy explains what we collect, how we use it, who we share it with, and the choices and rights you have. Dive is operated by Divefs Inc.
Dive is a read-only understanding tool. We never move, send, or hold your money, and we never send, delete, or modify your emails.
2. Information we collect
We collect only what we need to build your money report:
- Account information: your name, email address, phone number (optional), and the password or sign-in link you use to access Dive.
- Financial alert email data: with your explicit permission, and using read-only access, we scan your connected inbox for bank and financial alert messages (for example debit, credit, and transfer alerts) and extract the transaction details they contain.
- Derived financial data: the structured transactions, accounts, subscriptions, alerts, and reports we build from those messages.
- Usage and device data: basic technical logs needed to operate and secure the service.
3. Gmail access and Google Limited Use
When you connect Gmail, Dive requests the gmail.readonly scope. This is read-only: Dive can read messages to find financial alerts, and cannot send, delete, or change any email. We only process messages that look like financial alerts; we do not read your personal correspondence. You can disconnect Gmail at any time from Settings, or revoke access from your Google Account permissions.
Dive's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained from Gmail is used only to provide and improve the user-facing features of Dive; it is not used for advertising; it is not sold; it is not transferred to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition; and it is not used to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models. Humans do not read your Gmail data except with your explicit consent, where necessary for security purposes (such as investigating abuse), or to comply with applicable law.
4. How we use your information
- To build and update your money report, transactions, subscriptions, and alerts.
- To categorize and describe transactions so your report is easy to understand.
- To operate, secure, support, and improve the Dive service.
- To communicate with you about your account (for example sign-in links and verification codes).
- To comply with legal obligations.
5. Service providers and sub-processors
We share data with a small set of service providers only to operate Dive. We do not sell your data, and we do not share it for advertising.
- Google: read-only Gmail access to detect financial alerts (with your permission).
- Google Cloud (GCP): hosting and secure storage of your data.
- AI features providers: some of the smarter parts of Dive — assistant answers, report summaries, and working out what a confusing transaction actually was — are powered by trusted AI partners. They never learn who you are. We strip your identity out before anything leaves Dive: your name, email, phone number, account and card numbers, and your balances are removed, and other people’s names are replaced with anonymous stand-ins. What they see is the bare description of a purchase, like “card payment, groceries, 12 June” — enough to recognise a supermarket, never enough to recognise you. They use it only to answer that one question, and they can’t use it to train their AI. The assistant is stricter still: it sends no transaction descriptions at all. We may change or add AI partners over time; whichever we use, the same rules apply, and the current list is always available on request.
- Resend: to deliver account emails (sign-in links, verification codes).
- Paystack: to process subscription payments if you upgrade to a paid plan.
A current list of sub-processors is available on request at privacy@divefs.com.
6. Data retention and deletion
We do not store the raw contents of your emails. Once a financial alert is parsed into a structured transaction, the raw message content is discarded and only the derived transaction data is kept, so your report stays up to date.
You can delete your account and all associated data at any time from Settings. When you do, we revoke Gmail access and erase your derived financial data, subject to a short grace window and to any records we must keep to comply with law. You can also export your data at any time.
7. Your rights and choices
- Disconnect: remove a connected inbox at any time; we revoke the access token and stop processing new mail.
- Access and export: download a copy of your data.
- Delete: erase your account and data.
- Correct: fix or recategorize any transaction.
8. Security
We protect your data with encryption in transit, access controls, and least-privilege internal access. No method of transmission or storage is perfectly secure, but we work to protect your information and to promptly address any issues.
9. Eligibility
Dive is intended for adults (18 and older). We do not knowingly collect data from children.
10. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you in the app.
11. Contact us
For any privacy question or request, contact privacy@divefs.com.