Privacy Policy
Last updated:
The short version
Your wallets are stored on your device. Monly's server holds wallets you explicitly share, your sign-in account if you share or join one, and AI usage records. AI features send only what they need to answer you, and are never used to profile you. We use pseudonymous product analytics to learn which parts of the app help people. There are no ads, no advertising identifiers, no cross-app tracking, and your data is never sold. You can ask us to erase everything we hold on the server at any time.
What stays on your device
Your wallets, by default. Wallets, expenses, budgets, bills and settings are stored locally on your iPhone. Receipt photos are not kept after they are read. You can use Monly without creating an account. Monly never connects to your bank and never asks for bank credentials.
What is stored on the server
Only wallets you explicitly share, and what is needed to sync them. When you share a wallet, its contents (name, currency, transactions, budgets, bills, categories, goals and the member list) are stored on the server, together with a history of changes (what changed, which member made the change, from which device, and when), so the people you invited can see and sync it. Access is limited to the wallet's members.
Private wallets are never stored on our server. What happens to a shared wallet's server copy when sharing ends is described under Retention below.
AI features
Some features use AI: the assistant ("Ask your wallet"), receipt and document scanning, typed and spoken expense entry, money plans and the plan coach, insights, monthly reviews, and categorising new merchants from the Siri and Apple Pay shortcut. The first plan built during setup uses your answers to the setup questions. When you use one of these features, Monly sends what it needs, for example your message and the recent conversation, a receipt photo or PDF, your plan check-in notes, or a summary of the wallet you're using (budgets, recent transactions, bills, balances, goals and plans), through our AI gateway to Google's Gemini API, which returns the answer. We don't keep these requests or their answers on our servers. Google processes them under its API terms. With Monly Pro, opening Insights or a plan runs its AI analysis automatically.
Spoken entries are turned into text by Apple's speech recognition, which may use Apple's servers; Monly only sends the text, and only when you send it. AI features are optional: everything else in Monly works without them.
AI usage allowance
AI features come with a daily and monthly allowance. To enforce it, our server keeps a usage record for each request: an anonymous purchase identifier, a device identifier that Apple assigns to Monly on your device, which feature was used and how much it cost to run. These records never contain your messages, photos or financial data.
Product analytics
To understand which parts of Monly help people (for example whether setup was finished or which screen a subscription offer was opened from), the app sends a small number of usage events to Mixpanel, our analytics provider, on its EU servers. Each event carries the same device identifier that Apple assigns to Monly on your device, the app version, and the event's name and context. Events never contain your amounts, transactions, messages, name or email address; and IP addresses are not used to locate you. If you sign in to share or join a wallet, our server also stores this device identifier with your account, to manage sign-in sessions and to record who changed what in a shared wallet.
We also use Mixpanel to run simple experiments, such as comparing two versions of a screen. Analytics data is never used for advertising and never shared with data brokers.
Sign in with Apple
You only sign in when you share a wallet or accept an invitation. Apple provides us an opaque user identifier, an optional relay email address, and the optional display name you choose; we also store the identifier of the device you signed in on. We use these only to identify wallet members to each other. We never see your Apple password.
Push notifications
Monly's reminders, such as bill due dates, are scheduled on your device. The app does not currently send us a push notification token. If we add push notifications (for example, for changes in a shared wallet), we will update this policy before collecting one.
Purchases
Subscriptions are bought through Apple and managed by RevenueCat, our purchase-management provider, which assigns your purchases an anonymous identifier. We receive your purchase status (whether a subscription is active) and never your card details or billing address. Apple handles all billing.
Service providers and transfers
We use a small number of providers to run Monly: Cloudflare (hosting of the sync server and the AI gateway), Google's Gemini API (AI processing), Mixpanel on its EU servers (product analytics), RevenueCat (purchase status) and Apple (Sign in with Apple, billing and speech recognition). They may process data outside your country, under their own terms and safeguards.
Your rights
You can ask us for access to, correction of, a copy of, or deletion of the data we hold about you on our servers, and you can withdraw from sharing at any time by stopping sharing or leaving a wallet. Email us with your request. You can also complain to Brazil's data protection authority (ANPD) or to the data protection authority where you live.
What we don't do
No ads and no advertising identifiers. No tracking across other companies' apps or websites. No selling or renting data, to anyone, ever. This website is served without third-party resources of any kind: no external fonts, no analytics scripts, no tracking pixels.
Retention
When a wallet stops being shared, it stops syncing and members lose access to the server copy. That copy is kept until the wallet is shared again, the owner's account is deleted, or you ask us to delete it. A member who leaves a wallet has their membership removed.
The change history of a shared wallet is kept for 90 days (the newest 1,000 changes are always kept) and is deleted with the wallet.
Copies of a formerly shared wallet that other members keep on their own devices belong to those members, much like a spreadsheet you once sent someone.
AI usage records and analytics events are kept only as long as we need them to run the allowance and improve the app.
Deleting your data
For data that only ever lived on your device, deleting the app is enough. To delete your account and your server-side data, including shared wallets, email us and we will erase it and confirm. You can also ask us to delete usage records or analytics events for your installation.
Changes to this policy
If this policy changes, we will update this page and the date at the top. Meaningful changes will also be announced in the app.
Contact
Questions about privacy? Email us at support@monlybudget.app.
