Privacy Policy

Last updated: August 9, 2026

Overview

Monva ("the App", "we", "us") is a personal finance tracking application. This policy explains what personal data we process, why, on what legal basis, who we share it with, and the rights you have. For the purposes of the EU/UK GDPR, the data controller is the operator of Monva ("MonVa"); you can reach us at support at monva.app.

The short version

Monva is offline-first. Your financial data lives on your device and does not leave it unless you turn on optional features (cloud sync, AI). We don't sell your data, we don't show ads, and we don't access your bank accounts. Optional features that send data off your device are described below, each one clearly opt-in.

Data we process

On your device (always local)

All your financial data — transactions, categories, accounts, budgets, tags, and recurring rules — is stored locally on your device in a SQLite database. This data never leaves your device unless you turn on cloud sync. Simply signing in (for example, to use AI features) does not upload your financial data.

Cloud sync (optional, opt-in)

If you turn on cloud sync in Settings, your financial data is transmitted to and stored on our servers (powered by Appwrite, self-hosted in Germany) to enable backup and multi-device access. It is encrypted in transit (TLS) and at rest. Turn it off and nothing further is uploaded.

Account & authentication

If you sign in, we store your email address to authenticate you. We use magic-link authentication and do not store passwords. Sign-in is protected by Cloudflare Turnstile (bot protection), which processes technical request data (including your IP) but sets no tracking cookies.

AI features (optional, opt-in, premium + sign-in)

Some optional features use a third-party AI provider (Google Gemini) to process your input. Only scoped data is sent for the specific request — your full transaction history is never sent. These features require sign-in and a premium subscription. They cover:

  • Voice / text entry — the phrase you dictate or type, to extract transaction details (amount, category, note).
  • Receipt & screenshot parsing — the image you capture or share, to read the amount(s) and merchant.
  • Vaulty companion chat — your messages plus short, scoped summaries of your finances needed to answer, computed on your device.

Google processes this data to return a result and, per its API terms, does not use it to train its models. AI output can be inaccurate and is not financial advice.

Crash & error diagnostics

To keep the App stable, we use Sentry to collect technical diagnostics when something goes wrong — error details, and device type, OS version, and app version. These reports are technical; we do not intend for them to include your financial data.

In-app bug reports (optional)

If you submit a bug report from within the App, we receive the description you write and basic technical context so we can investigate and reply.

Website analytics (this site only, with consent)

On the Monva website, we use Google Analytics for anonymous, aggregate usage statistics — but only if you accept it on the cookie banner. The App itself contains no behavioural usage-analytics or advertising trackers. See our Cookie Policy.

What we do not do

  • We do not sell or rent your personal data.
  • We do not serve advertisements or use advertising trackers.
  • We do not access your bank accounts or financial institutions.
  • We do not collect your location.
  • We do not put behavioural analytics or tracking SDKs inside the App.

Legal basis for processing (GDPR)

  • Performance of a contract — providing the App, cloud sync, and subscriptions you request.
  • Consent — optional features you switch on (cloud sync, AI) and website analytics cookies. You can withdraw consent at any time.
  • Legitimate interests — keeping the service secure (bot protection) and stable (crash diagnostics), and preventing abuse.
  • Legal obligation — retaining records required for tax and accounting where purchases are made.

Sub-processors we share data with

We share the minimum data needed with the providers below. We do not share your data with anyone else.

Provider Purpose Data Location
Appwrite (self-hosted) Authentication & cloud sync Email; financial data (only if sync on) Germany (EU)
Google (Gemini API) AI parsing & companion chat Scoped text/image/summaries you submit Global (may be outside EU)
RevenueCat Subscription management Purchase/subscription identifiers; app user ID United States
Cloudflare (Turnstile) Bot protection at sign-in Technical request data, IP Global
Brevo Magic-link email delivery Email address EU
Sentry Crash & error diagnostics Technical error & device/app info United States
Google Analytics (website only) Anonymous website statistics (with consent) Anonymised usage data Global

International data transfers

Some providers above (for example Google, RevenueCat, Cloudflare, and Sentry) may process data outside the European Economic Area. Where they do, transfers are covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision. Your synced financial data and magic-link email are handled within the EU (Appwrite in Germany, Brevo in the EU).

Data retention

Local data stays on your device until you delete it or uninstall the App. If you use cloud sync, your synced data is kept on our servers until you delete your account, after which it is erased. AI inputs are processed to return a result and are not retained by us. Diagnostic and email-delivery data is kept only as long as needed for its purpose. You can export all your data as CSV at any time from Settings.

Data security

  • All network communication uses TLS encryption.
  • Server infrastructure is hardened with firewall rules, monitoring, and automatic security updates.
  • Authentication uses magic links — no passwords are stored.
  • Sync servers are hosted in Germany under EU data-protection standards.

Your rights

Subject to applicable law, you have the right to:

  • Access and port your data — export it as CSV from Settings at any time.
  • Rectify inaccurate data — edit it directly in the App.
  • Erase your data — delete your account from Settings, or uninstall the App to remove local data.
  • Restrict or object to certain processing.
  • Withdraw consent — turn off cloud sync or AI features, or change your cookie choice via “Cookie settings” in the website footer.
  • Complain to your local data-protection supervisory authority.

To exercise any right, contact support at monva.app.

Children's privacy

The App is not directed at children under 13, and we do not knowingly collect personal information from them. Where a higher age of digital consent applies in your country, that age governs.

Changes to this policy

We may update this policy from time to time. Material changes will be posted on this page with an updated revision date.

Contact

Questions about this policy or your data? Contact us at support at monva.app.