Privacy policy
Last updated: 18 August 2026 (version 2026-08-18)
A courtesy translation. In case of any discrepancy the Slovak version prevails.
In short: your banking data lives on our server in the EU and is never sold. We have no ads, no analytics and no trackers. AI categorization sees merchant names only — not amounts, IBANs or people's names. And you can erase your account entirely from inside the app at any time, bank consents included.
Who processes your data
The controller is OnIT s. r. o., company ID 55 010 903, registered office Ľudovíta Fullu 3012/6, 841 05 Bratislava — Karlova Ves, Slovakia, entered in the Commercial Register of the Bratislava III City Court, section Sro, insert no. 164718/B.
For anything to do with personal data, write to us at podpora@moneytale.app. We have not appointed a data protection officer. We assessed the conditions in Art. 37 GDPR: we are not a public authority, our core activity is neither regular and systematic monitoring of people on a large scale nor large-scale processing of special categories of data. We will repeat the assessment whenever the scope of the service changes materially.
What we process and why
- Account
- E-mail and password. The password is stored solely as a bcrypt hash — nobody holds it in readable form, not even us. Purpose: signing in and managing the account. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Kept for as long as the account exists.
- Bank accounts and transactions
- After you consent in your bank itself, we download them through a licensed PSD2 access provider: the list of accounts (IBAN, name) and the transactions — date, amount, currency, description and counterparty. When you connect a bank we ask for access to the widest history that bank offers (between 162 days and 2 years, depending on the bank) — it cannot be widened later without a new authorization. The access consent is created for 90 days and you revoke it at any time by disconnecting the bank in the app — we then cancel it at the provider too. Legal basis: performance of a contract.
- Statement import
- We retain the original uploaded file for at most 90 days to diagnose new bank formats; this temporary store is excluded from backups. Transactions and the minimized evidence needed to process them correctly remain stored while your account exists. Statements in known formats are read by our own code on the server and nothing from them leaves it. If no built-in parser recognizes the format, we first ask for separate consent for that specific file. Only then is the whole statement text sent once to the AI model provider used for reading statements (a different provider from the one that sorts payments into categories), which turns it into transactions — the model then sees everything printed on the statement: amounts, dates, payment descriptions, counterparties and the IBAN. A statement read this way is accepted only if the sum of the rows exactly matches the balance movement stated on the statement; otherwise the import is rejected. Here too, the model provider does not use this data to train models, under its own contractual terms. The text sent does, however, stay in its abuse-monitoring logs for up to 30 days; after that it is deleted.
- Payments you record yourself
- A payment no bank reported — cash, or an account that cannot be connected — you record yourself: who you paid, the date, the amount and a category. In the mobile app you can have those fields filled in by scanning the QR code on a till receipt or an invoice. We then also store the contents of that code, so the receipt can be found again later: its identifier for a till receipt, the payee IBAN and reference number for an invoice. We do not store the list of purchased items — we take only the merchant name, the date and the total. The data stays for as long as your account exists. Legal basis: performance of a contract.
- When you scan, your phone queries the Slovak Financial Administration's receipt verification service directly — the authority that records till receipts by law, exactly as its own app would. We send it nothing, and only what you save as a payment ever reaches us. An invoice QR code is decoded on the phone and goes nowhere.
- AI categorization (optional)
- It runs only when you approve it in the app. Only the cleaned merchant name from card payments (“billa”, “slovnaft”) reaches the model — never amounts, IBANs, dates or people's names. Categorization runs at a different provider from statement reading and, under its contractual terms, that provider does not use this data for training; it keeps it in abuse-detection logs for up to 30 days. Legal basis: consent (Art. 6(1)(a)) — withhold it at any time and you categorize payments by hand.
- E-mails
- We send a single message — the password reset link, and only when you ask for it — through a specialized e-mail service provider. No newsletter, no marketing.
- Waitlist
- Your e-mail only, so we can invite you to the beta. Kept until the invitation; ask support to erase it at any time.
- Operational logs
- For every request we log the method, path, outcome, duration and user ID — never content, so no amounts or payment descriptions are in the logs. Purpose: security and diagnostics. Legal basis: legitimate interest (Art. 6(1)(f)). Logs are kept for 90 days and then rotate away automatically.
Who we entrust the data to
Five categories of recipient, each getting only what its job needs. Nobody else — we do not sell the data, do not share it for advertising and do not profile you for marketing. We have an Art. 28 processing agreement in place with every one of them. Hosting, the AI models, e-mail delivery and backup storage act as processors; the PSD2 access provider is a separate controller — it holds its own licence for access to bank accounts, you grant it consent directly when connecting your bank, and it processes your data under its own privacy policy.
| Recipient category | What it receives | Where | Transfer safeguard |
|---|---|---|---|
| Server infrastructure provider | the whole database — it hosts our server | Germany (EU) | none needed, the data does not leave the EU |
| Licensed PSD2 access provider (separate controller) | mediates access to your bank | a country with an EC adequacy decision | EC adequacy decision |
| AI model providers (two — categorization and statement reading) | merchant names; the statement text when machine-read | USA, possibly other countries where they operate facilities | EU–US Data Privacy Framework and standard contractual clauses |
| E-mail service provider | your e-mail and the content of the transactional message | USA, sending from the EU region | EU–US DPF + standard contractual clauses |
| Backup storage provider | the daily database backup, encrypted with our key — it holds no key and cannot read the contents | USA | standard contractual clauses; on top of that, encryption on our side — the decryption key never leaves us |
We will name the specific processors on request — write to podpora@moneytale.app.
Where the data lives and for how long
The application and the database run on a single server in a data centre in Germany.
We back up daily, in three layers: on the server itself (14 days), whole-machine images
at the same German provider (7 days), and a copy at a storage provider in the USA
(14 days). That third layer exists in case we ever lose the German account entirely,
and it leaves encrypted with our own key — whoever stores it cannot
read it.
When you erase your account, your data disappears from the database immediately and
from every backup within 14 days at the latest. While the account exists we keep the
data so the report works; nothing is archived “forever”.
Cookies and analytics
Moneytale uses no cookies, no analytics and no third-party trackers — which is why
no cookie banner greets you.
We do keep a few values in your browser's localStorage, because without them the
service would not work the way you asked for it: the session token, the language,
light or dark mode, the chosen shape of three charts, the state of the first-run guide
and a marker for the return from your bank. They are not used for tracking, they never
leave your device, and clearing the site's data removes them; the token additionally
disappears when you sign out.
Your rights
Under the GDPR you have the right of access to your data, and to its rectification, erasure, restriction of processing, portability and objection (Art. 15–21). The most important two need no e-mail at all. You erase the account in the app itself (Settings → Delete account) — the erasure is immediate, complete, and revokes the bank consents at the PSD2 access provider too. And you download everything we hold about you in the same place (Settings → Download your data) as a single JSON file: transactions, accounts and bank connections, categories, your own rules and corrections, a record of the statements you uploaded and the consents you gave. For anything else write to podpora@moneytale.app; we answer within 30 days at the latest.
We keep a record of the request itself — what it concerned, when it arrived and when we handled it — so we can show the deadline was met. It holds no e-mail address of yours, only a one-way digest of it, from which the address cannot be read back. After the account is deleted nothing readable about you remains, and we can still confirm that we deleted it.
We carry out no automated decision-making or profiling with legal or similarly significant effects within the meaning of Art. 22 GDPR. The AI sorts payments into categories you can overwrite at any time; none of it decides anything about you.
If you believe we handle your data incorrectly, you can complain to the Office for Personal Data Protection of the Slovak Republic, Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava, dataprotection.gov.sk.
Changes to this document
When the way we process data changes materially — a new processor, for example — we update this page and let you know by e-mail or in the app. The date of the last update is always at the top.