1. Controller and scope
This notice applies to the Monetari marketing website, waitlist, Android application, web application, account services, finance APIs, and related support. In this notice, “Monetari”, “we”, “us”, and “our” mean the operator identified below.
- Controller / trader
- [Insert the controller/trader legal name before publication]
- Postal address
- [Insert the registered or business postal address before publication]
- Privacy contact
- hello@info.monetari.app
- DPO / representative
- No data protection officer or EU representative has been appointed.
Monetari is a personal expense-tracking service. It is not a bank, payment institution, or open-banking provider. We do not ask for online-banking credentials and do not connect to your bank account.
2. Data we process
Account and authentication data
When you create or use an account, we process your username, email address, account identifier, email-verification state, profile and security settings, and records needed to manage sign-in, token refresh, password reset, and account security. Your password is transmitted over an encrypted connection to the authentication service and handled by Amazon Cognito; Monetari does not store or display a readable copy.
Financial records and preferences
We process the information you enter, confirm, or generate through the service, including transaction amounts, currencies, dates, merchants, descriptions or notes, categories, budgets, reporting currency, merchant rules, review decisions, recurring patterns, and calculated spending insights. These are personal financial records, even though Monetari does not retrieve them from your bank.
Payment-notification captures
If you enable Android notification access and select source apps, Monetari processes the notification content needed to identify a payment. A local capture includes the source app package, notification title, text and expanded text, posting and capture times, and an opaque local identifier. In the normal authenticated service, Monetari selects the raw text needed for processing and uploads it with an app-generated device identifier, the source app package, and posting time. Server-side parsing can derive an amount, currency, merchant, masked card digits, and processing or review status.
Notification wording is controlled by the app that sent it. It may include masked card digits, account labels, merchant details, or other information that app chose to show. In unusual cases, purchase text may indirectly reveal sensitive information such as health, religion, or political activity. Monetari does not ask you to provide or use such information to infer sensitive traits. The app does not currently classify or redact possible special-category details before upload. If a selected notification contains them, they may be included in the cloud raw text and, where AI fallback is used, in the context processed by Amazon Bedrock. Do not enable a source whose notifications you do not want Monetari to process.
Subscription and purchase data
If you buy Premium through Google Play, we process the product and plan, purchase token or a protected representation of it, subscription state, entitlement, renewal or expiry information, acknowledgement status, and billing events such as cancellation, refund, grace period, or account hold. Google processes the payment instrument; Monetari does not receive your full card details.
Device, usage, and service data
We may process app version, operating-system and device information, screen or feature events, a pseudonymous account identifier, request metadata, timestamps, error and diagnostic information, security events, and IP-derived network information. Optional product analytics in the mobile app are configuration-dependent and use the limited event set described below.
On the website we process a pageview record for each page opened: the page address including any campaign parameters, the referring address, your browser's user-agent string, and the country reported by our hosting platform. The record is made on our server; your IP address is not passed to the analytics provider. No identifier is stored on your device and none is reused between requests, so these records cannot be linked to you or to each other across visits.
On-device and browser storage
The mobile app stores authentication tokens in Expo SecureStore, capture records in a local SQLite database, and selected settings or session state in app storage. If you enable biometric sign-in, an authentication refresh token is protected by the device's biometric gate; Monetari receives only the operating system's success or failure result, not your fingerprint or face template. Web sessions and local-only settings may use browser localStorage or sessionStorage.
Waitlist, support, and rights requests
The public website collects the email address you submit to the waitlist. If you contact us, we also process the contents of your message and any information needed to answer, verify your identity, or handle a privacy request.
We receive data directly from you, from notifications on a device where you enabled capture, from Google Play for subscription administration, and from the service itself when it derives categories, totals, confidence scores, recurring patterns, or diagnostics. We do not buy personal data or obtain bank-account data from data brokers or open-banking providers.
3. Purposes and legal bases
- Performing our contract — GDPR Article 6(1)(b): creating and securing your account; receiving the records you ask us to process; creating, synchronising, displaying, editing, exporting, and deleting your ledger; calculating budgets and insights; administering Premium; and providing requested support.
- Your consent — GDPR Article 6(1)(a): sending optional waitlist or launch messages. If optional product analytics are enabled in the mobile app, they must remain off until any consent required for non-essential device access has been obtained. Website analytics does not rely on consent because it stores nothing on your device; it rests on the legitimate interest below. You can withdraw consent at any time without affecting earlier lawful processing.
- Our legitimate interests — GDPR Article 6(1)(f): protecting accounts, preventing fraud and abuse, maintaining service reliability, diagnosing failures, measuring feature performance with data minimisation, understanding how many people reach the website and which pages they open, and establishing or defending legal claims. You may object where the GDPR gives you that right, including to website analytics.
- Legal obligations — GDPR Article 6(1)(c): complying with tax, accounting, consumer-protection, security, law-enforcement, and data-protection duties.
Account and core finance data are necessary to provide the service. If you do not provide them, the relevant account or feature cannot work. Notification access, in-app product analytics, the waitlist, and Premium are optional; refusing them does not prevent manual expense tracking unless a specific feature necessarily depends on that data. Website analytics is not a feature you opt into: it is limited, cookieless measurement of the site itself, and a browser sending a “Do Not Track” signal is excluded from it entirely.
4. Notification capture and automated categorisation
Your device remains the first filter
Android requires you to grant notification-listener access in system settings. You then choose the source apps Monetari is allowed to use. Notifications from unselected apps are discarded before they enter Monetari's capture queue. Google Wallet is selected by default until you change that choice. The selected-app allowlist is stored on the device and is not synchronised to Monetari's backend. The source package attached to each notification that passes that local filter is, however, included in the capture uploaded for server-side processing. You can revoke access or remove a source at any time; this stops new captures but does not remove pending records already on the device or records already uploaded or added to your ledger.
What happens after a capture
A selected notification is first saved in an on-device SQLite queue. Each queue entry is tied to the verified Monetari account that was active when the notification arrived; notifications received while no verified account is active are not added to that queue. The app uploads pending captures when it is active, regains connectivity, or receives an Android background-work opportunity. Each batch names its owning account, and the API rejects it unless that account matches the authenticated session. The backend then applies plan limits and duplicate protection, stores the capture, and sends a capture reference through an Amazon SQS queue for asynchronous processing.
The processing service retrieves the stored raw text, parses candidate transaction fields, applies your merchant rules, converts currencies where needed, and creates a transaction or review item. Low-confidence, uncategorised, and failed results are recorded rather than silently treated as correct. The app removes its local queue entry when the API reports that the capture was accepted or was already received; it does not wait for the asynchronous categorisation to finish. Upload failures and captures paused by the Free-plan limit remain queued locally for retry, subject to the configured local retention period. Only fixture and end-to-end test mode use the local-only parser and fixture ledger.
AI-assisted suggestions
If your own merchant rules do not resolve a capture, the current backend may send the relevant context to Amazon Bedrock to suggest a category and confidence score. That context can include raw notification text, transaction type, merchant, amount, currency, date and hour, your available categories, and up to five earlier categorisation decisions. The result is validated by Monetari and can be reviewed or corrected by you. Categorisation affects how an expense appears in your ledger; it does not make a decision that produces legal or similarly significant effects about you. We do not use transaction data to make lending, insurance, employment, or eligibility decisions.
Amazon states that Bedrock model providers cannot access customer prompts or completions and that those inputs and outputs are not used to train the underlying foundation models. See the Amazon Bedrock data-protection documentation.
6. International transfers
Monetari is intended for users in Croatia and the wider European Union. Deployment documentation targets AWS's Frankfurt region, and the Bedrock categorisation policy restricts inference to EU regions; the production account and region must be verified before publication. Some providers or their subprocessors, including Loops and globally distributed website infrastructure, may process data outside the European Economic Area. Website analytics is sent to PostHog's European Union region; the host configured for any mobile release must be verified before analytics is enabled there.
Where personal data is transferred outside the EEA, we use a lawful transfer mechanism appropriate to the destination and provider, such as an adequacy decision, the European Commission's Standard Contractual Clauses, and supplementary technical or organisational safeguards. You may contact us for information about the safeguard applicable to a particular transfer.
7. Retention and deletion
We keep personal data only for the period needed for the purpose described below, then delete or anonymise it unless law requires a longer period.
- Authentication tokens: current access tokens are issued for 60 minutes and refresh tokens for 30 days. Local secure-token entries are removed when you sign out; the Cognito identity remains until account deletion.
- Account and ledger: kept while your account is active. Individual records remain until you delete them or delete the account. A plan downgrade hides older history but does not delete it.
- On-device notification captures: pending records are kept in the local SQLite store for the retention period selected in the app, with a current default of 90 days. If you select Immediately, an unuploaded record may remain for up to 1 day so the requested capture can reach the service. A local record is normally removed sooner after the server accepts it or confirms it as a duplicate. Failed or quota-paused uploads remain pending until retry, expiry, sign-out, account deletion, or local clearing. Signing into another account does not upload or display the first account's pending queue.
- Cloud raw capture text: uploaded capture text uses the configured server-side retention period, with a current default of 90 days. If you select Immediately, pending text may remain for up to 1 day so processing can finish; once processing reaches a terminal result, the raw text is removed. Shortening the period starts a background retention sweep, so retroactive deletion is not instantaneous. Derived transaction fields, transactions, raw-text-free parser correction signals, and review records may remain until they are separately deleted.
- Exports: generated files are temporary and expire after 7 days. A generated download link is valid for no more than 24 hours and never beyond the file's expiry. Current server exports exclude raw notification text. The underlying account data is unaffected.
- Waitlist: kept until you unsubscribe, ask for deletion, or the waitlist purpose ends. A minimal suppression record may be retained so an unsubscribe request is respected.
- Support and privacy requests: kept while we handle the request and afterwards only for the period reasonably needed to document the response, meet legal duties, or establish or defend a claim.
- Analytics and operational logs: kept for the configured provider or security-retention period, then deleted or aggregated. Current AWS application logs are configured for 1 month in non-production and 3 months in production. Website pageview records are held by PostHog under the retention period set for that project and are not linked to an account; because nothing is stored on your device, they cannot be traced back to you to be retrieved or removed individually. Other security records may be retained longer where necessary to investigate abuse or establish legal claims.
- Billing and legal records: kept for the period required by tax, accounting, fraud-prevention, chargeback, and consumer-protection law, even if the service account is deleted.
Account deletion starts an asynchronous erasure process for finance data, captures, settings, generated exports, and the Cognito identity, and also initiates the billing cancellation workflow before erasure completes. Data stored only on your device may require you to clear the app's storage or uninstall it. Temporary backups and logs may disappear later as they rotate out under their protected retention schedules. Data already anonymised so it can no longer identify you is not personal data and may be retained.
8. Security
Monetari uses measures designed for the sensitivity of account and financial data, including authenticated per-user access, encrypted network transport, managed encryption at rest, least-privilege service permissions, isolated service roles, validation of AI output, duplicate protection, protected purchase records, and monitored operational logs.
No service can guarantee absolute security. Keep your account credentials and device secure, install updates, and contact us promptly if you suspect unauthorised access.
9. Your rights and choices
Subject to the GDPR and applicable exceptions, you may ask us to:
- confirm whether we process your personal data and provide access to it;
- correct inaccurate or incomplete data;
- delete data or your account;
- restrict processing in qualifying circumstances;
- provide data you supplied in a structured, commonly used, machine-readable format;
- object to processing based on legitimate interests or to direct marketing;
- withdraw consent at any time; and
- receive information about safeguards used for an international transfer.
- obtain human intervention and contest a qualifying solely automated decision if Monetari ever introduces one with legal or similarly significant effects.
One limit is worth stating plainly. Website analytics records carry no identifier and are not linked to your account, so for those records we cannot identify you — which means access, correction and erasure cannot be applied to them individually. You can still object to this processing, and a browser sending a “Do Not Track” signal is excluded from it before any record is created.
You can edit many records, use self-service export for records available within your plan's history window, change raw-capture retention, revoke Android notification access, unsubscribe from waitlist emails, and request account deletion through the product. Regardless of plan, you can also email hello@info.monetari.app to request access or portability. We may need to verify your identity and normally respond within one month.
You may complain to the supervisory authority where you live, work, or believe an infringement occurred. In Croatia, the authority is the Croatian Personal Data Protection Agency (AZOP). You can also find EU authorities through the European Data Protection Board.
10. Children
Monetari is intended only for people aged 18 or older. We do not knowingly offer accounts to children. If you believe a person under that age has provided personal data, contact us so we can investigate and delete it where required.
12. Changes and contact
We may update this notice when the service, providers, or law changes. We will post the new date here and give additional notice in the app or by email when a change materially affects your rights or how we use personal data. Prior versions will be made available on request where needed to understand how data was handled at an earlier time.
Questions, objections, and rights requests can be sent to hello@info.monetari.app. For the contractual rules governing Monetari, read the Terms and conditions.