Skip to main content
Monetari

Privacy policy

This notice explains what personal data Monetari processes, why it is needed, where it goes, how long it is kept, and the choices available to you.

Effective 12 September 2026

1. Controller and scope

This notice applies to the Monetari marketing website, waitlist, Android application, web application, account services, finance APIs, and related support. In this notice, “Monetari”, “we”, “us”, and “our” mean the operator identified below.

Controller / trader
[Insert the controller/trader legal name before publication]
Postal address
[Insert the registered or business postal address before publication]
Privacy contact
hello@info.monetari.app
DPO / representative
No data protection officer or EU representative has been appointed.

Monetari is a personal expense-tracking service. It is not a bank, payment institution, or open-banking provider. We do not ask for online-banking credentials and do not connect to your bank account.

2. Data we process

Account and authentication data

When you create or use an account, we process your username, email address, account identifier, email-verification state, profile and security settings, and records needed to manage sign-in, token refresh, password reset, and account security. Your password is transmitted over an encrypted connection to the authentication service and handled by Amazon Cognito; Monetari does not store or display a readable copy.

Financial records and preferences

We process the information you enter, confirm, or generate through the service, including transaction amounts, currencies, dates, merchants, descriptions or notes, categories, budgets, reporting currency, merchant rules, review decisions, recurring patterns, and calculated spending insights. These are personal financial records, even though Monetari does not retrieve them from your bank.

Payment-notification captures

If you enable Android notification access and select source apps, Monetari processes the notification content needed to identify a payment. A local capture includes the source app package, notification title, text and expanded text, posting and capture times, and an opaque local identifier. In the normal authenticated service, Monetari selects the raw text needed for processing and uploads it with an app-generated device identifier, the source app package, and posting time. Server-side parsing can derive an amount, currency, merchant, masked card digits, and processing or review status.

Notification wording is controlled by the app that sent it. It may include masked card digits, account labels, merchant details, or other information that app chose to show. In unusual cases, purchase text may indirectly reveal sensitive information such as health, religion, or political activity. Monetari does not ask you to provide or use such information to infer sensitive traits. The app does not currently classify or redact possible special-category details before upload. If a selected notification contains them, they may be included in the cloud raw text and, where AI fallback is used, in the context processed by Amazon Bedrock. Do not enable a source whose notifications you do not want Monetari to process.

Subscription and purchase data

If you buy Premium through Google Play, we process the product and plan, purchase token or a protected representation of it, subscription state, entitlement, renewal or expiry information, acknowledgement status, and billing events such as cancellation, refund, grace period, or account hold. Google processes the payment instrument; Monetari does not receive your full card details.

Device, usage, and service data

We may process app version, operating-system and device information, screen or feature events, a pseudonymous account identifier, request metadata, timestamps, error and diagnostic information, security events, and IP-derived network information. Optional product analytics in the mobile app are configuration-dependent and use the limited event set described below.

On the website we process a pageview record for each page opened: the page address including any campaign parameters, the referring address, your browser's user-agent string, and the country reported by our hosting platform. The record is made on our server; your IP address is not passed to the analytics provider. No identifier is stored on your device and none is reused between requests, so these records cannot be linked to you or to each other across visits.

On-device and browser storage

The mobile app stores authentication tokens in Expo SecureStore, capture records in a local SQLite database, and selected settings or session state in app storage. If you enable biometric sign-in, an authentication refresh token is protected by the device's biometric gate; Monetari receives only the operating system's success or failure result, not your fingerprint or face template. Web sessions and local-only settings may use browser localStorage or sessionStorage.

Waitlist, support, and rights requests

The public website collects the email address you submit to the waitlist. If you contact us, we also process the contents of your message and any information needed to answer, verify your identity, or handle a privacy request.

We receive data directly from you, from notifications on a device where you enabled capture, from Google Play for subscription administration, and from the service itself when it derives categories, totals, confidence scores, recurring patterns, or diagnostics. We do not buy personal data or obtain bank-account data from data brokers or open-banking providers.

4. Notification capture and automated categorisation

Your device remains the first filter

Android requires you to grant notification-listener access in system settings. You then choose the source apps Monetari is allowed to use. Notifications from unselected apps are discarded before they enter Monetari's capture queue. Google Wallet is selected by default until you change that choice. The selected-app allowlist is stored on the device and is not synchronised to Monetari's backend. The source package attached to each notification that passes that local filter is, however, included in the capture uploaded for server-side processing. You can revoke access or remove a source at any time; this stops new captures but does not remove pending records already on the device or records already uploaded or added to your ledger.

What happens after a capture

A selected notification is first saved in an on-device SQLite queue. Each queue entry is tied to the verified Monetari account that was active when the notification arrived; notifications received while no verified account is active are not added to that queue. The app uploads pending captures when it is active, regains connectivity, or receives an Android background-work opportunity. Each batch names its owning account, and the API rejects it unless that account matches the authenticated session. The backend then applies plan limits and duplicate protection, stores the capture, and sends a capture reference through an Amazon SQS queue for asynchronous processing.

The processing service retrieves the stored raw text, parses candidate transaction fields, applies your merchant rules, converts currencies where needed, and creates a transaction or review item. Low-confidence, uncategorised, and failed results are recorded rather than silently treated as correct. The app removes its local queue entry when the API reports that the capture was accepted or was already received; it does not wait for the asynchronous categorisation to finish. Upload failures and captures paused by the Free-plan limit remain queued locally for retry, subject to the configured local retention period. Only fixture and end-to-end test mode use the local-only parser and fixture ledger.

AI-assisted suggestions

If your own merchant rules do not resolve a capture, the current backend may send the relevant context to Amazon Bedrock to suggest a category and confidence score. That context can include raw notification text, transaction type, merchant, amount, currency, date and hour, your available categories, and up to five earlier categorisation decisions. The result is validated by Monetari and can be reviewed or corrected by you. Categorisation affects how an expense appears in your ledger; it does not make a decision that produces legal or similarly significant effects about you. We do not use transaction data to make lending, insurance, employment, or eligibility decisions.

Amazon states that Bedrock model providers cannot access customer prompts or completions and that those inputs and outputs are not used to train the underlying foundation models. See the Amazon Bedrock data-protection documentation.

5. Service providers and sharing

We do not sell personal data, rent it to data brokers, or use financial records for third-party advertising. We disclose data only when needed to provide the service, follow your instructions, complete a transaction, protect the service, or comply with law.

ProviderPurposeData involved
Amazon Web ServicesAuthentication, APIs, databases, queues, object storage, monitoring, email delivery, and the backend's optional AI-assisted categorisation capability.Account, server-side financial, export, security, and diagnostic data. Android capture data can include an app-generated device identifier, originating app package, raw notification text, posting and receipt times, parsed transaction fields, processing status, and categorisation context.
Google PlayApp distribution, purchase processing, subscription verification, and billing status notifications.Store account and payment data held by Google; Monetari receives purchase and entitlement records, not full payment-card details.
PostHogCookieless page analytics on the website. In the mobile app, optional product analytics, only if enabled for a release after the required consent and withdrawal controls are available.A pseudonymous workspace identifier and limited events such as app opened, registration completed, capture enabled, budget or category created, Premium screen viewed, biometric login enabled, and export requested. Autocapture, session replay, location enrichment, surveys, and automatic lifecycle capture are disabled in code. Event properties are limited to the app variant and, where relevant, a result, source, or export format; no custom person profile is set.
LoopsWaitlist and launch-email delivery.Email address, subscription status, source label, and email-delivery activity.
VercelHosting, delivery, security, and server execution for the public website.Request and diagnostic data such as IP address, user agent, requested URL, and waitlist request metadata.

Providers act under their own terms and data-protection commitments. We may also disclose information to professional advisers, authorities, courts, or a successor operator where legally permitted and necessary. If ownership of Monetari changes, users will be informed before personal data becomes subject to a materially different privacy notice.

6. International transfers

Monetari is intended for users in Croatia and the wider European Union. Deployment documentation targets AWS's Frankfurt region, and the Bedrock categorisation policy restricts inference to EU regions; the production account and region must be verified before publication. Some providers or their subprocessors, including Loops and globally distributed website infrastructure, may process data outside the European Economic Area. Website analytics is sent to PostHog's European Union region; the host configured for any mobile release must be verified before analytics is enabled there.

Where personal data is transferred outside the EEA, we use a lawful transfer mechanism appropriate to the destination and provider, such as an adequacy decision, the European Commission's Standard Contractual Clauses, and supplementary technical or organisational safeguards. You may contact us for information about the safeguard applicable to a particular transfer.

7. Retention and deletion

We keep personal data only for the period needed for the purpose described below, then delete or anonymise it unless law requires a longer period.

  • Authentication tokens: current access tokens are issued for 60 minutes and refresh tokens for 30 days. Local secure-token entries are removed when you sign out; the Cognito identity remains until account deletion.
  • Account and ledger: kept while your account is active. Individual records remain until you delete them or delete the account. A plan downgrade hides older history but does not delete it.
  • On-device notification captures: pending records are kept in the local SQLite store for the retention period selected in the app, with a current default of 90 days. If you select Immediately, an unuploaded record may remain for up to 1 day so the requested capture can reach the service. A local record is normally removed sooner after the server accepts it or confirms it as a duplicate. Failed or quota-paused uploads remain pending until retry, expiry, sign-out, account deletion, or local clearing. Signing into another account does not upload or display the first account's pending queue.
  • Cloud raw capture text: uploaded capture text uses the configured server-side retention period, with a current default of 90 days. If you select Immediately, pending text may remain for up to 1 day so processing can finish; once processing reaches a terminal result, the raw text is removed. Shortening the period starts a background retention sweep, so retroactive deletion is not instantaneous. Derived transaction fields, transactions, raw-text-free parser correction signals, and review records may remain until they are separately deleted.
  • Exports: generated files are temporary and expire after 7 days. A generated download link is valid for no more than 24 hours and never beyond the file's expiry. Current server exports exclude raw notification text. The underlying account data is unaffected.
  • Waitlist: kept until you unsubscribe, ask for deletion, or the waitlist purpose ends. A minimal suppression record may be retained so an unsubscribe request is respected.
  • Support and privacy requests: kept while we handle the request and afterwards only for the period reasonably needed to document the response, meet legal duties, or establish or defend a claim.
  • Analytics and operational logs: kept for the configured provider or security-retention period, then deleted or aggregated. Current AWS application logs are configured for 1 month in non-production and 3 months in production. Website pageview records are held by PostHog under the retention period set for that project and are not linked to an account; because nothing is stored on your device, they cannot be traced back to you to be retrieved or removed individually. Other security records may be retained longer where necessary to investigate abuse or establish legal claims.
  • Billing and legal records: kept for the period required by tax, accounting, fraud-prevention, chargeback, and consumer-protection law, even if the service account is deleted.

Account deletion starts an asynchronous erasure process for finance data, captures, settings, generated exports, and the Cognito identity, and also initiates the billing cancellation workflow before erasure completes. Data stored only on your device may require you to clear the app's storage or uninstall it. Temporary backups and logs may disappear later as they rotate out under their protected retention schedules. Data already anonymised so it can no longer identify you is not personal data and may be retained.

8. Security

Monetari uses measures designed for the sensitivity of account and financial data, including authenticated per-user access, encrypted network transport, managed encryption at rest, least-privilege service permissions, isolated service roles, validation of AI output, duplicate protection, protected purchase records, and monitored operational logs.

No service can guarantee absolute security. Keep your account credentials and device secure, install updates, and contact us promptly if you suspect unauthorised access.

9. Your rights and choices

Subject to the GDPR and applicable exceptions, you may ask us to:

  • confirm whether we process your personal data and provide access to it;
  • correct inaccurate or incomplete data;
  • delete data or your account;
  • restrict processing in qualifying circumstances;
  • provide data you supplied in a structured, commonly used, machine-readable format;
  • object to processing based on legitimate interests or to direct marketing;
  • withdraw consent at any time; and
  • receive information about safeguards used for an international transfer.
  • obtain human intervention and contest a qualifying solely automated decision if Monetari ever introduces one with legal or similarly significant effects.

One limit is worth stating plainly. Website analytics records carry no identifier and are not linked to your account, so for those records we cannot identify you — which means access, correction and erasure cannot be applied to them individually. You can still object to this processing, and a browser sending a “Do Not Track” signal is excluded from it before any record is created.

You can edit many records, use self-service export for records available within your plan's history window, change raw-capture retention, revoke Android notification access, unsubscribe from waitlist emails, and request account deletion through the product. Regardless of plan, you can also email hello@info.monetari.app to request access or portability. We may need to verify your identity and normally respond within one month.

You may complain to the supervisory authority where you live, work, or believe an infringement occurred. In Croatia, the authority is the Croatian Personal Data Protection Agency (AZOP). You can also find EU authorities through the European Data Protection Board.

10. Children

Monetari is intended only for people aged 18 or older. We do not knowingly offer accounts to children. If you believe a person under that age has provided personal data, contact us so we can investigate and delete it where required.

11. Website, waitlist, and cookies

The Monetari landing site counts pageviews using PostHog, hosted in the European Union. The count is made on our server as it answers your request: no analytics code runs in your browser, and none is sent to it. Each record holds the page address, the referring address, your browser's user-agent string, and the country our hosting platform reports for the request. We rely on our legitimate interest in understanding whether the site reaches the people it is meant for.

It is configured to collect no more than that. Your IP address is not passed to PostHog and its location lookup is switched off, so the country above is the most precise location involved. Nothing is stored in cookies or in your browser's storage, and the identifier attached to each pageview is generated fresh for that single request and never kept — so nothing links two pageviews to the same person. The figures we see are visits, not people. There is no capture of clicks or form interaction, no session recording, and no profile is created for you. Requests from a browser sending a “Do Not Track” signal, and requests that appear to come from bots, are discarded before any record is made.

The site carries no advertising pixels and no behavioural advertising. The hosting platform still processes ordinary HTTP request and security data needed to deliver the site.

When you join the waitlist, the site sends your email address to Loops with a source label identifying the Monetari landing-page waitlist. Loops and its subprocessors process data in the United States under its data-processing terms and transfer safeguards. Every promotional message must include a working unsubscribe route.

If we add non-essential cookies, advertising technology, or new analytics to the website, we will update this notice and obtain consent before activating them where required.

12. Changes and contact

We may update this notice when the service, providers, or law changes. We will post the new date here and give additional notice in the app or by email when a change materially affects your rights or how we use personal data. Prior versions will be made available on request where needed to understand how data was handled at an earlier time.

Questions, objections, and rights requests can be sent to hello@info.monetari.app. For the contractual rules governing Monetari, read the Terms and conditions.