Privacy Policy for Monetic

Effective Date: September 5, 2026 β€’ Last Updated: September 5, 2026 Independent Developer

1. Introduction & Overview

Welcome to Monetic ("the App", "we", "us", or "our"). Monetic is an advanced personal finance, budget tracking, and expense management mobile application developed and operated by an independent software developer for Android and iOS, accessible at https://monetic.app.

We are deeply committed to protecting your privacy and safeguarding your personal and financial information. This Privacy Policy outlines our transparent data practices in strict compliance with:

  • The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) for users located in the European Union (EU) and European Economic Area (EEA);
  • The ePrivacy Directive (Directive 2002/58/EC as amended);
  • The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) for California residents;
  • Google Play Developer Program Policies (including Financial Services, Data Safety, and Account Deletion mandates);
  • Apple App Store Review Guidelines (including Guideline 5.1 on Privacy, Data Collection, and Account Deletion).

By downloading, accessing, or using Monetic, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, please do not use the App.


2. Data Controller & Contact Information

For the purposes of the GDPR and applicable international data protection laws, the Data Controller responsible for your personal data is:

If you have any questions, concerns, or requests regarding this Privacy Policy or your statutory privacy rights, please email us directly at [email protected].


3. Core Architectural Principle: Local-First Storage vs. Cloud Synchronization

Monetic is engineered around a privacy-first, local-first architectural foundation:

πŸ”’ Local Storage by Default (Offline-First Invariant)

By default, and during all offline usage, all of your financial data is stored solely on your physical device.

Your transactions, account balances, custom categories, recurring payment reminders, notes, and photos are saved in a local encrypted SQLite database (Room persistence library / SQLite). We cannot see, read, access, or analyze your local data.

  1. No Mandatory Cloud Registration: You can use Monetic completely anonymously in Guest Mode without ever registering an account or synchronizing data to the internet.
  2. Cloud Backup Requires Explicit Opt-In & Authentication: Remote cloud backups (Google Drive AppData on Android, or Google Firebase Cloud Firestore on iOS/Android fallback) never occur without your explicit affirmative consent and authenticated login.
  3. Strong Encryption in Transit and at Rest: Whenever you choose to synchronize backups to the cloud, data is encrypted in transit using TLS 1.3 and encrypted at rest using industry-standard AES-256.
  4. Zero Commercial Data Selling: We never sell, rent, lease, monetize, or broker your personal financial records or transaction data to data aggregators, advertisers, credit bureaus, or third parties under any circumstances.
  5. User Ownership of Backups: On Android, cloud backups are stored in your own private Google Drive appDataFolder. You retain sole ownership and control over your files.

4. Categories of Data We Process

4.1. Information You Provide to Us

Category Description & Specific Data Points Purpose
Account Credentials Email address, hashed password, Firebase Authentication UID, Google profile identifier (when using Google Sign-In), account creation date. Authentication, account recovery, session security, multi-device backup access.
Financial Records Account names, balances, native account currencies, transactions (amount, date/time, type: income/expense/transfer, category designation, optional notes). Core app functionality: budget calculation, expense tracking, statistics, multi-currency conversion.
Scheduled & Recurring Payments Bill names, recurring frequencies (daily, weekly, monthly), due dates, notification reminder times. Scheduling local device notifications for payment reminders.
Receipt Photographs & Custom Logos Photographic images of paper receipts, invoices, custom category logos, or account avatars selected from your device's photo library or captured via camera. Associating proof-of-purchase images with transactions and personalizing user interface avatars.

4.2. Information Processed Locally on Device (Never Transmitted to Servers)

Category Technical Implementation Privacy Invariant
Internal 4-Digit Security PIN Salted with 128-bit random salt and hashed using SHA-256 in private device storage (SharedPreferences / NSUserDefaults). NEVER transmitted to or stored on our servers. Does not alter or sync with cloud passwords.
Biometric Authentication Touch ID, Face ID, Android BiometricPrompt (fingerprint or face unlock). Processed strictly inside the hardware Secure Enclave / Android Keystore of your device. Monetic only receives a binary success/failure token. Raw biometric data is never accessible.

4.3. Information Collected Automatically & Technical Telemetry

Category Source & Technical Points Purpose
Diagnostic & Crash Telemetry Device hardware model, OS version (Android/iOS), CPU architecture, application version, timestamp of crash, stack traces (collected via Firebase Crashlytics). Identifying software bugs, diagnosing fatal errors, enhancing application stability and performance. Retained for 90 days then purged.
Device & Network Identifiers Ephemeral IP address (anonymized/truncated by Firebase), system language and locale settings, time zone. Remote configuration routing, localized currency and date formatting, maintenance mode checks.
Purchase & Entitlement Data RevenueCat App User ID, transaction ID, store product identifiers (monetic_pro_monthly, monetic_pro_yearly, monetic_pro_lifetime), purchase timestamp, subscription status. Granting and managing Monetic Pro feature entitlements and auto-renewal status.
Advertising Identifiers (Free Plan Only) Google Advertising ID (GAID) on Android, IDFA on iOS (subject to user consent via Google UMP / App Tracking Transparency). Serving non-intrusive advertisements in the Free version through Google AdMob, strictly subject to user consent.

5. Legal Bases for Processing under GDPR (EU/EEA Users)

If you are located in the European Union or European Economic Area, we process your personal data under the following lawful bases set out in Article 6(1) of the GDPR:

  • Performance of a Contract (Art. 6(1)(b) GDPR): Processing account credentials, financial records, transaction calculations, and cloud backups to fulfill our contractual obligation to provide the Monetic service.
  • Your Explicit Consent (Art. 6(1)(a) GDPR): Accessing your device camera or photo library to capture and attach receipt photos; serving personalized advertisements via Google AdMob, managed dynamically through the Google User Messaging Platform (UMP) Consent Management Platform.
  • Legitimate Interests (Art. 6(1)(f) GDPR): Monitoring app reliability, debugging crashes, and analyzing technical errors via Firebase Crashlytics to deliver a secure, performant software product; preventing fraudulent use of subscriptions.
  • Compliance with Legal Obligations (Art. 6(1)(c) GDPR): Maintaining digital purchase records required by tax, consumer protection, and commercial accounting regulations.

6. Cloud Backup Architecture & Zero Developer Cost Model

Monetic provides a hybrid dual-channel backup system designed to maximize privacy and eliminate unnecessary third-party data retention:

6.1. Google Drive Cloud Backup (Primary on Android)

  • Storage Location: Backups are written directly to your personal Google Drive account in the hidden appDataFolder.
  • Isolation: Files stored in the appDataFolder are private to Monetic and cannot be accessed, viewed, or modified by other applications on your device or Google Drive.
  • Scope of Access: Monetic requests strictly limited scopes (drive.appdata and drive.file). The App cannot see, read, modify, or delete any of your personal documents, photos, spreadsheets, or folders on Google Drive.
  • Unified Identity: When signed in via Google Sign-In, your Monetic profile and Google Drive backup destination are unified 1:1.

6.2. Firebase Cloud Firestore (Secondary / Fallback)

  • Storage Location: Used on iOS or on Android when Google Drive is unlinked. Data is stored in secure Google Cloud Firestore database instances (/users/{uid}/backup/snapshot).
  • Security: Data in transit is protected using Transport Layer Security (TLS 1.3), and data at rest is encrypted using 256-bit Advanced Encryption Standard (AES-256).

7. Third-Party Service Providers & Sub-Processors

We work with trusted third-party technology providers to power authentication, infrastructure, crash reporting, subscription validation, and advertising. All sub-processors are bound by strict Data Processing Agreements (DPAs):

Sub-Processor Location Role / Services Provided Privacy Policy
Google LLC / Google Ireland Ltd. USA / Ireland Firebase Authentication, Cloud Firestore, Firebase Crashlytics, Firebase Remote Config, Google Drive API, Google AdMob. Google Privacy Policy
Apple Inc. USA / Ireland Apple In-App Purchase (StoreKit 2), Face ID local verification, Apple Push Notifications. Apple Privacy Policy
RevenueCat, Inc. USA In-app subscription lifecycle management, receipt validation, entitlement verification. RevenueCat Privacy Policy

8. International Data Transfers

Our sub-processors (such as Google and RevenueCat) maintain servers in the European Union, the United States, and worldwide.

Whenever personal data originating from the European Economic Area (EEA), the United Kingdom, or Switzerland is transferred outside these territories, we ensure an adequate level of data protection by relying on:

  • The EU-U.S. Data Privacy Framework (DPF) and the UK Extension to the EU-U.S. DPF;
  • Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Article 46(2)(c) of the GDPR;
  • Technical safeguards, including end-to-end transport layer encryption (TLS 1.3) and AES-256 storage encryption.

πŸ—‘οΈ 9. Account & Associated Data Deletion Policy

Google Play Data Safety & Apple App Store Review Guideline 5.1.1(v) Compliance Notice:

Monetic provides complete, transparent, and readily accessible mechanisms allowing you to permanently delete your account and all associated personal and financial data. You may execute deletion at any time using either of the following methods:

Method 1: In-App Self-Service Deletion (Immediate & Automated)

If you currently have the Monetic app installed on your device:

  1. Open the Monetic application.
  2. Navigate to Settings β†’ My Profile (or Account Details).
  3. Scroll to the bottom of the screen and tap Șterge Contul / Delete Account.
  4. Confirm your choice in the confirmation dialog.

Result: Your account, authentication credentials, and remote cloud backups stored in Firebase Firestore are instantly, automatically, and permanently erased.

Method 2: Non-In-App / Direct Email Request (Web Form / Store Submission)

If you have uninstalled the app, lost access to your device, or prefer submitting an external request via web/email:

  1. Compose an email from the email address associated with your Monetic account to [email protected].
  2. Use the subject line: Account Deletion Request or Data Deletion Request.
  3. State that you request the permanent deletion of your Monetic account and associated data, specifying your registered email address and, if known, your Monetic User ID.
  4. Our team will verify your ownership and process the permanent deletion within 30 days (typically within 48 to 72 hours). You will receive a final confirmation email once all cloud data has been erased.

Scope of Data Permanently Purged:

  • Firebase Authentication Record: Your user profile, registered email address, hashed password, and unique User Identifier (UID) are permanently purged.
  • Cloud Database Records: All remote backups, account balances, transaction histories, custom categories, tags, and snapshots stored in Firebase Cloud Firestore (/users/{uid}) are permanently and irreversibly destroyed.
  • Session & Diagnostic Identifiers: Active device session tokens and diagnostic bindings are completely wiped.
  • Google Drive AppData Backups (Android): Data stored in your private Google Drive AppData folder is owned exclusively by your personal Google account. You can delete it directly through Google Drive:
    • Visit Google Drive on the Web.
    • Click Settings (gear icon) β†’ Settings β†’ Manage Apps.
    • Locate Monetic, click Options, and choose Delete hidden app data.

Data Retention & Exceptions:

  • Local Data: Data stored on your physical device remains on your device until you clear application storage or uninstall the App. Monetic cannot remotely delete files on your physical device.
  • Diagnostic Telemetry: Aggregated, de-identified crash logs in Firebase Crashlytics contain no personal identifiers and are automatically purged after 90 days.
  • In-App Purchases: Subscription billing transactions processed through Apple (StoreKit) or Google Play Billing are maintained by Apple or Google under their respective statutory accounting and tax retention periods. Monetic does not hold payment card numbers.

10. Your Privacy Rights

Depending on your country or state of residence, you have statutory rights regarding your personal information:

10.1. Rights under the EU General Data Protection Regulation (GDPR)

  • Right of Access (Art. 15 GDPR): Request confirmation of data processing and obtain a copy of your personal data.
  • Right to Rectification (Art. 16 GDPR): Correct inaccurate or incomplete personal information directly within the App.
  • Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): Request the permanent deletion of your data via the in-app "Delete Account" button or by emailing [email protected].
  • Right to Restriction of Processing (Art. 18 GDPR): Request restriction of data processing under certain statutory conditions.
  • Right to Data Portability (Art. 20 GDPR): Export all financial transactions and accounts at any time via Settings β†’ Data Management β†’ Export to CSV or via Google Drive archive download.
  • Right to Object (Art. 21 GDPR): Object at any time to data processing based on legitimate interests.
  • Right to Withdraw Consent (Art. 7(3) GDPR): Withdraw consent for personalized ads or camera access at any time via the in-app consent manager or device settings.
  • Right to Lodge a Complaint: File a complaint with your local Data Protection Supervisory Authority (in Romania: ANSPDCP, www.dataprotection.ro).

10.2. Rights for California Residents (CCPA / CPRA)

  • Right to Know & Access: Request details on the categories and specific pieces of personal information collected over the past 12 months.
  • Right to Delete: Request the deletion of your personal data.
  • Right to Non-Discrimination: We will never discriminate against you for exercising your CCPA privacy rights.
  • Notice Regarding "Sale" or "Sharing": We do not sell your personal or financial data for monetary consideration. For ad-supported Free tier users, third-party cookies or advertising identifiers (Google AdMob) may be considered "sharing" for cross-context behavioral advertising under California law. You can opt-out at any time via your device settings (Opt out of Ads Personalization on Android, or Ask App not to Track on iOS).

11. Security of Your Information

We implement rigorous technical and organizational security measures to protect your personal data against accidental loss, unauthorized access, destruction, or alteration:

  • Transport Encryption: All communications between the App, Google APIs, Firebase, and RevenueCat are enforced using TLS 1.3 encryption.
  • Cryptographic Salting & Hashing: Internal application PINs are secured with 128-bit random salts and SHA-256 cryptographic digests.
  • Biometric Enclave Isolation: Biometric verification is sandboxed inside the operating system's hardware Secure Enclave.
  • Restricted API Access: Cloud Firestore and Google Drive connections are governed by strict security rules requiring authenticated tokens matching the user's verified identity.

12. Protection of Children's Privacy

Monetic is not intended or designed for use by children under the age of 16 (or under 13 in the United States). We do not knowingly solicit, collect, or process personal data from children. If we discover that a child has provided us with personal information without verified parental consent, we will take immediate steps to permanently delete such information from our databases. If you believe that a minor has provided us with personal data, please contact us immediately at [email protected].


13. Changes & Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect modifications to our software architecture, newly introduced features, changes in legal obligations, or updates from regulatory authorities.

When we make material changes, we will notify you by:

  1. Updating the "Last Updated" and "Effective Date" at the top of this document;
  2. Publishing the revised policy at https://monetic.app/privacy.html;
  3. Providing an in-app notice or alert dialog when a significant architectural change occurs.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.


14. Contact Us & Developer Details

If you have questions, feedback, or legal inquiries regarding this Privacy Policy or wish to exercise any of your statutory data protection rights, please contact: