1. About This Policy
This Privacy Policy explains how HoliTech Solutions ("we", "our", "us") collects,
uses, and protects information when you use the Gebeta SMS mobile application
("App") available on Google Play (Package: com.gebeta).
By installing or using Gebeta SMS, you agree to this Privacy Policy. If you disagree with any part of this policy, please uninstall the App.
We comply with the Google Play Developer Program Policies, the General Data Protection Regulation (GDPR) where applicable, and the Ethiopian Personal Data Protection Proclamation.
2. Information We Collect
2a. SMS Data (On-Device Only)
The App's core feature is reading incoming SMS messages to automatically detect and extract mobile-money transaction details (e.g., amount, sender, date, balance) sent by financial institutions such as Telebirr, CBE Birr, BOA Mobile, Absa, Hibret Bank, Bunna Bank, Abay Bank, and others.
- SMS content is read only on your device using Android's SMS API.
- Parsed transaction data is stored only in your device's local database.
- We do not transmit, upload, or store SMS content on any remote server.
- We do not access SMS messages from non-financial senders beyond what is necessary to identify transaction patterns.
- We do not send SMS messages on your behalf.
2b. Analytics Data (Anonymised)
We use Firebase Analytics (Google LLC) to collect anonymised, aggregated usage statistics, including:
- App session duration and frequency.
- Feature interaction events (e.g., which screens are visited).
- Device type, OS version, and app version.
- Crash and error reports (via Firebase Crashlytics).
This data does not include SMS content, transaction amounts, account numbers, or any personally identifiable financial information.
2c. Advertising Data
The App displays ads via Google Mobile Ads (AdMob). AdMob may collect:
- Advertising ID (resettable by you in Android settings).
- IP address and general location (country/city level).
- Device model and OS version.
Ad data is governed by Google's Privacy Policy. You can opt out of personalised ads in your device's Google settings.
3. Android Permissions Explained
Below is a full explanation of every Android permission the App requests, why it is needed, and how the data is used — in compliance with Google Play's Permissions and APIs that Access Sensitive Information policy.
| Permission | Category | Why We Need It | Data Handling |
|---|---|---|---|
RECEIVE_SMS |
Core Feature | Listens for incoming SMS messages in real time so transaction details can be parsed the moment they arrive from your bank. | Processed locally. Never transmitted. |
READ_SMS |
Core Feature | Reads the content of incoming transaction SMS messages. Required to extract amount, sender, and balance from the message body. | Processed locally. Never transmitted. |
FOREGROUND_SERVICE |
Core Feature | Runs a foreground service that monitors SMS continuously so transactions are not missed when the app is in the background. | Service metadata only. No personal data transmitted. |
POST_NOTIFICATIONS |
Core Feature | Displays real-time transaction notification alerts on Android 13+ devices when a new mobile-money SMS is detected. | Notification content is derived from local SMS data. Not transmitted. |
SCHEDULE_EXACT_ALARM |
Core Feature | Schedules daily transaction summary notifications at the precise time chosen by the user (e.g., 08:00 AM). Exact timing is essential for the user-defined reminder feature. | Alarm metadata stored locally. Not transmitted. |
RECEIVE_BOOT_COMPLETED |
Support | Restarts the SMS monitoring service automatically after the device is rebooted, so the App continues to work without manual intervention. | Boot event trigger only. No personal data involved. |
WAKE_LOCK |
Support | Prevents the CPU from sleeping while the background service processes a newly received transaction SMS, ensuring the data is saved correctly. | System-level lock only. No personal data transmitted. |
INTERNET |
Support | Required for Firebase Analytics, AdMob advertising, and in-app update checks. Not used to transmit SMS content. | Analytics/ads data only (anonymised). See Section 2b & 2c. |
ACCESS_NETWORK_STATE |
Support | Checks network connectivity before making API calls (analytics, ads). Prevents unnecessary requests when offline. | Connection status only. Not stored or transmitted. |
⚠️ Removed permissions (no longer in the app):
SEND_SMS — The App has never sent SMS messages. This permission was declared in error in
earlier versions and has been fully removed as of version 1.0.0+24.
USE_EXACT_ALARM — Replaced by the more appropriate SCHEDULE_EXACT_ALARM
per updated Google Play policy.
4. How We Use Your Data
- Transaction tracking: Parse and categorise mobile-money transactions from incoming SMS messages and present them in a structured dashboard.
- Notifications: Alert you in real time when a new financial transaction SMS is received, and deliver daily summary reminders at your chosen time.
- PDF reports: Generate downloadable transaction reports from locally stored data. Reports are saved to your device only.
- Calendar view: Display your transaction history in a monthly calendar for easy financial review.
- App improvement: Use anonymised analytics to identify bugs, crashes, and usage patterns to improve future versions.
- Advertising: Display relevant ads through Google AdMob to support free access to the App.
5. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data. The following third-party services process limited, anonymised data:
- Firebase Analytics & Crashlytics (Google LLC) — anonymised usage and crash data. Firebase Privacy
- Google Mobile Ads (AdMob) (Google LLC) — advertising identifiers and device info. Google Privacy Policy
- Google Play In-App Updates — version information only. Google Privacy Policy
We may disclose information if required by law, court order, or government authority in Ethiopia or applicable jurisdiction.
6. Data Retention & Deletion
- All transaction data is stored exclusively on your device and is retained until you manually delete it via Settings → Clear All Data inside the App, or until you uninstall the App.
- Anonymised analytics data is retained by Firebase for up to 14 months per Google's standard retention policy.
- Advertising IDs are managed by Google AdMob and can be reset at any time in your Android device settings under Google → Ads → Reset Advertising ID.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access — View all transaction data stored by the App (available directly in the App's dashboard).
- Delete — Erase all locally stored transaction data via Settings → Clear All Data in the App.
- Withdraw consent — Revoke SMS permissions at any time in Android Settings → Apps → Gebeta SMS → Permissions. Note: revoking SMS permissions will disable the core transaction-tracking feature.
- Opt out of personalised ads — Reset your Advertising ID or opt out of ad personalisation in Android Settings → Google → Ads.
- Data portability — Export your transaction history as a PDF from within the App.
8. Children's Privacy
Gebeta SMS is not directed to children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has used the App and provided personal data, please contact us immediately at the address below.
9. Security
We implement reasonable technical and organisational measures to protect your data:
- All transaction data is stored locally using Android's secure internal storage, inaccessible to other apps.
- Network connections for analytics and ads use HTTPS/TLS encryption.
- The App does not store financial credentials (passwords, PINs, or account numbers).
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in the App, legal requirements, or Google Play policies. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Notify you through an in-app notification or the Play Store release notes.
Continued use of the App after any changes constitutes your acceptance of the updated policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact: