Privacy and SMS filtering

    Tab.it is an expense tracking app for iPhone and Android that reads bank, card and UPI alert messages — and nothing else. Messages are filtered on your phone first, so anything that is not a payment alert is discarded before it ever leaves the device. These answers cover exactly how that filtering works and how to control it.

    How does Tab.it pick which SMS to track?

    Every message passes a series of checks across three stages before it's ever saved:

    • Stage 1 · On your device — Is it from a saved contact (Android, if contacts access is on)? Does it contain numbers? Does it clear the default and your custom negative keywords? Does it match expense-like positive keywords? Fail any of these and it's dropped on your phone.
    • Stage 2 · In the cloud — a positive-keyword check (credit, debit, spent, currency symbols…), then negative-keyword checks (including your own) to rule out non-expenses.
    • Stage 3 · AI confirmation — a final AI check that it's a genuine expense.

    Only messages that clear all the checks become an expense. In total that is 9 checks on Android and 8 on iPhone, and 4 of them run on your device — so most (~95%) messages are ruled out before anything leaves your phone.

    What does "on device" mean?

    The first, sensitive step — deciding whether a text is even worth looking at — happens on your phone, not on a server.

    Every SMS is checked on your device first:

    • Does it contain numbers?
    • Is it from a saved contact? (Android only)
    • Does it hit a blocked keyword?
    • Does it look like a payment?

    Anything that fails is ignored on your phone and never leaves it. Only messages that look like real expenses are securely processed.

    How do keyword filters improve my privacy?

    Keyword filters let you tell Tab.it to ignore any message containing that word or phrase you choose, so messages you never want tracked never become expenses and never even get read. Just ensure the word or phrase you enter matches exactly as you receive in your messages. Add them under Controls → Privacy Filter Settings → Keyword SMS Filter.

    How do I keep Tab.it from reading SMSes from my contacts?

    Android only

    Once you give Tab.it access to your contact list it automatically skips every SMS from any contact saved on your phone — messages from friends and family are never read. Your contact list NEVER leaves your device: the check runs natively ON YOUR phone itself.

    1. Go to Controls → Privacy Filter Settings → Contact SMS Filter.
    2. Grant contacts access.

    If you do want a particular saved contact's messages processed — someone who forwards you payment messages, say — you can allow their SMS to get processed individually on the same screen.

    How do I exclude specific bank A/Cs or cards?

    If a particular account should never show up as a personal expense — say a corporate card or a salary account — add a negative keyword that uniquely identifies its messages.

    • Pick something that appears in every SMS from that account: the card's last 4 digits (e.g. `XX4821`) prefixed by 'XX', the bank account's last 3 digits prefixed by 'XX', or a distinctive sender tag.
    1. Go to Controls → Privacy Filter Settings → Keyword SMS Filter.
    2. Add that identifier. From then on, those messages are ignored before they become expenses.

    Positive vs negative keywords

    • Positive keywords are the signals that a message is an expense — "debited", "spent", "purchase", currency symbols, and so on. Tab.it maintains these; a message with no expense signal is dropped.
    • Negative keywords are the signals to ignore a message — Tab.it ships a default set (bill reminders, OTPs, promos, investments…), and you add your own on top for anything specific to you.
    • You can only edit the negative side; that's the control you have over what gets filtered out.

    Can I watch the filter work in real time?

    Yes — turn on the Privacy Filter Notification to see, live, which messages Tab.it keeps and which it ignores on your device. It's the easiest way to confirm your keyword and contact filters are doing what you expect.

    1. Go to Settings → App Permissions.
    2. Toggle Privacy Filter Notifications on.

    Why does Tab.it need background activity permission?

    Android only

    Android pauses or kills background apps to save battery. If Tab.it is paused, it can't process incoming bank SMS messages — so your expenses won't be recorded automatically.

    Allowing background activity tells Android to let Tab.it stay available in the background so it can pick up new SMS messages as they arrive.

    How do I allow background activity?

    Android only

    The exact steps vary slightly by phone manufacturer, but the core flow is the same:

    1. Open Tab.it → Settings → App Permissions
    2. You'll see a prompt to Allow Background Activity — tap it
    3. Android will show a system dialog asking to let Tab.it run in the background — tap Allow

    If you've already dismissed the prompt, you can also do it from your phone's Settings:

    1. Open Settings → Apps → Tab.it → Battery
    2. Select Unrestricted (or disable battery optimization for Tab.it)

    My expenses stopped being recorded automatically

    Android only

    If expenses that used to appear automatically have stopped showing up, the most common cause is Android restricting Tab.it's background activity.

    This can happen after a software update, if you haven't opened the app in a while (app hibernation), or if a battery saver mode was turned on.

    To fix this:

    1. Make sure SMS permission is still granted — go to Settings → App Permissions and check
    2. Allow background activity — this prevents Android from pausing Tab.it
    3. Check that app hibernation is disabled — Android 12+ can revoke permissions on apps it considers unused