Privacy policy
Effective from 16 September 2026 — version 2026-09-11.1.
English translation; the Slovak version is the original. Mandatory consumer rights remain unaffected.
Who processes your data
The controller is OnIT s. r. o., company ID 55 010 903, registered office Ľudovíta Fullu 3012/6, 841 05 Bratislava — Karlova Ves, Slovakia, entered in the Commercial Register of the Bratislava III City Court, section Sro, insert 164718/B. Contact: podpora@moneytale.app. We have not appointed a data protection officer.
We do not sell your financial information or use it for targeted advertising. The app uses first-party operational diagnostics, not advertising tracking. Its database runs on a server in Germany; some AI, e-mail and backup providers may also process data outside the EEA.
What we process and why
Account and login. Your e-mail, saved language, settings and login information enable account management and the service, on the basis of a contract (Art. 6(1)(b) GDPR). Passwords are stored as bcrypt hashes. For Google or Apple sign-in, we store the provider's user identifier and supplied e-mail. Those providers are independent controllers for their own login services; we do not send your financial records through the login flow.
Financial overview. We store accounts, IBANs, dates, amounts, currencies, payment descriptions and counterparties, categories, your rules, notes and budgets. You enter this information, upload a statement, or enable a bank connection. Processing needed for records and reports on your account relies on performance of a contract. Your account's financial information is not made available to other users.
Bank connection, where available to you. Licensed provider GoCardless mediates access under its own terms. The connection flow shows the access scope and duration. Disconnecting stops subsequent downloads and sends a revocation request to the provider; failed revocations are retried. Disconnecting alone does not delete imported transactions. Bank authorization is neither AI consent nor general GDPR consent for other purposes.
Sensitive content and information about other people
A statement, payment description, merchant, note, photograph or receipt item may reveal health, religion, political opinions or other special categories under Art. 9 GDPR. Simply storing or reading a document can constitute processing, even without AI analysis. A counterparty name, including a sole trader's name, may be personal data.
Neither this notice nor accepting the terms is explicit consent under Art. 9. AI and receipt-item permissions are requested separately in the app and cover only the stated purpose. Consent concerning your own data does not authorize processing another person's sensitive information. Upload only documents you are entitled to use and remove unnecessary information about other people first. If you cannot remove it, contact support without attaching the sensitive document.
We do not create health, political or religious profiles from your payments or sell such conclusions. Turning AI off does not by itself delete the financial information stored in your account.
Statement import and AI reading
We read known formats using our own server-side parsers without sending them to a reading model. Subsequent AI categorization is a separate choice. When AI is needed for an unknown format, we request separate, revocable consent to the current wording. Without it, the file is not sent for AI reading.
PDF: document reading sends the original PDF or blocks of its pages, including images, to Google Gemini. The model may see everything on the submitted pages, not merely merchants. Tables (.xls, .xlsx, CSV): OpenAI receives a header and sample rows, including real payments, to propose a mapping; the validated mapping then lets us read the file ourselves. The text compatibility route sends extracted statement text to OpenAI. This may include account information, amounts, dates, descriptions and counterparties present in the input.
We apply technical and financial checks to the AI output, but it may still be inaccurate or incomplete. You can inspect the import result and correct payments. We store transactions, the provenance needed to process them and a temporary extraction result. Table mappings contain column names and limited technical values, not arbitrary transaction-cell contents.
AI-reading consent also covers later imports within the same explained scope until you withdraw it in Settings or its version changes. Withdrawal stops further AI submissions; imported payments remain. Use available data controls or support to erase them. Optional AI processing of your own data relies on Art. 6(1)(a), and your own sensitive content on explicit consent under Art. 9(2)(a). This does not resolve the separate legal condition for processing another person's sensitive data.
AI categorization
This is enabled separately from AI statement reading. For card payments we send a cleaned merchant name; for selected uncategorized transfers or direct debits, only a preprocessor-approved cleaned organization name or general service description. This route does not send amounts, IBANs, dates, payment references or original notes. Payments to people and uncertain bank inputs are withheld. Cleaning is not a general guarantee of anonymization.
A bank-payment result is stored against that transaction, not as a global rule. Card categorization also uses shared merchant-to-category rules; they do not contain your account history. This does not imply every merchant name is non-personal data.
The basis is voluntary AI-categorization consent (Art. 6(1)(a), and Art. 9(2)(a) for your own sensitive data in scope). You may withdraw it in Settings and categorize manually. Existing categories are not automatically undone by withdrawal; you can change them.
Documents, photographs and mobile payments
For manual or scanned payments we process the information you confirm. A document can be kept without creating a payment. We store the merchant, date, amount, document identifier or QR contents and, where provided, its number, photograph and your warranty settings and note. Invoice QR decoding and text recognition from photographs run on the phone; this OCR does not send the photograph to an AI provider.
For eKasa scans, the phone contacts the Slovak Financial Administration's verification service directly. Our server receives what you save. Purchased items are stored only with separate explicit consent (Art. 6(1)(a) and Art. 9(2)(a)). They support finding a purchase, warranty and return records, not AI item categorization. We retain them for 36 months from purchase, or until a later active warranty-watch end date. Withdrawing this consent deletes saved items; the document and its photograph are not automatically deleted.
We retain photographs until you delete them or your account, not automatically for only 36 months. A photograph or note may also contain sensitive information. Unconfirmed mobile payment captures remain locally for at most 60 days; only a confirmed entry reaches the server. Offline entries and caches are separated by user.
Support, messages and operation
If you join the waiting list, we process your e-mail and signup source with your consent to send an invitation. A daily cleanup removes entries after an account is created and, at the latest, after one year; you can ask support for earlier deletion or withdraw consent. This is not consent to further marketing.
We send necessary e-mails about account verification and security, password recovery, account deletion, watched warranties and subscription status. These are not marketing consents. The legal basis is performance of a contract. With an active subscription we process purchase identifiers, provider, status and entitlement duration; Moneytale does not store your payment-card number.
If you report a problem, we process your description, support conversation and screenshots you deliberately attach. You can crop and black out an image before submitting it. Automatic diagnostics use minimized technical information, not automatic screenshots. Requested support relies on a contract; security and reliable operation rely on legitimate interests (Art. 6(1)(f)).
The API access log contains method, path without query parameters, status, duration and user/request identifiers. Technical logs may also capture an error; do not add unnecessary financial or sensitive information to support or error reports. In-app operational messages and read records are used for support and service notices, not marketing.
Providers and transfers
Hosting: Hetzner Online GmbH (Germany). AI: Google Gemini API for PDF document reading and categorization; OpenAI for text reading and table mapping. E-mail delivery: Resend (Plus Five Five, Inc.). Support mailbox: WebSupport, s.r.o. Encrypted offsite backups: Backblaze. Bank-access provider GoCardless and sign-in providers act as independent controllers for their own services.
When purchasing features are activated, account identity and subscription information are also processed through RevenueCat and the relevant purchase channel: Apple, Google Play or Stripe. We do not send bank statements or your spending history to these purchase providers. The app shows which channel is available before purchase.
We use business APIs, not public consumer chats. Google Paid Services terms exclude using prompts and responses to improve products; Google nevertheless documents 55-day abuse-monitoring retention, possible authorized human access and specific use for policy-enforcement models. For the standard API route, OpenAI generally documents abuse logs of up to 30 days, with legal exceptions. We do not promise zero retention.
An Irish contractual or billing entity does not guarantee EU-only processing. Depending on the recipient, cross-border transfers rely on adequacy decisions, including an applicable DPF, or standard contractual clauses and necessary supplementary measures. Ask support for information about the applicable safeguards and a copy or where to access them. Encrypting backups with our own key is a safeguard, not a substitute for a legal transfer mechanism.
Retention and deletion
We generally retain transactions, accounts, your rules, documents and necessary provenance while your account exists. The original import file and working AI extractions have a 90-day usable lifetime; physical deletion follows in the scheduled daily sweep. The original is excluded from logical database backups but may remain in a whole-server image until that image expires. Technical records and backups may reach the end of their retention periods after the main record is deleted.
Operational logs: 90 days. Technical error groups: 30 days from the last occurrence. Support screenshots: 90 days from upload. Closed reports: 12 months from closure; open reports until handled. In-app messages: 12 months. Daily backups: 14 days; machine images: 7 days; encrypted offsite backups: 14 days.
Account deletion removes active financial information and initiates related revocations. Limited records of handling your request, necessary accounting or legal records and a temporary deletion notice may remain for their respective purposes. An e-mail digest in the request register is pseudonymous, not anonymous. Rolling backups expire at the end of their retention window; restoration must respect completed erasures. Deleting Moneytale does not itself stop Apple or Google Play subscription renewal — cancel it in that store as well. If a paid App Store or Google Play period remains after account deletion, we keep a pseudonymous identifier of that purchase so support can verify the claim to the remaining period; deleted financial data is not kept for this.
Device storage
We do not use advertising cookies or analytics trackers. The one cookie we set is during sign-in with Google or Apple: __Host-mt_oauth, a random value that ties the return from the provider to the browser you started in. It is strictly necessary for a secure sign-in, lasts at most 10 minutes and is removed on return, so it needs no consent. Device storage supports the service: session token, language, theme and settings, local offline queue and cache. The token authenticates requests to the server; it would be incorrect to say all these values never leave the device. The biometric app lock uses your phone's system; our server receives no fingerprint or face template.
Your rights
You have rights of access, rectification, erasure, restriction, portability and objection under the conditions of Arts. 15–21 GDPR. Withdraw consent in Settings or through support as easily as you gave it; withdrawal does not invalidate earlier lawful processing. You may object to processing based on legitimate interests on grounds relating to your particular situation.
Download your data in Settings and receipt photographs from their detail views. Self-service is not the only way to exercise a right: write to podpora@moneytale.app even if you have no account or are a person named in a document. We verify identity proportionately to the risk, without routinely requiring identity documents. We also protect other people's rights when supplying a copy.
We respond without undue delay, normally within one calendar month of receipt. If the law permits an extension of up to two additional months, we explain the reason within the first month. This is not always 30 days. You can complain to the Slovak Office for Personal Data Protection, Galvaniho 7/B, 821 04 Bratislava.
We do not make automated decisions producing legal or similarly significant effects under Art. 22 GDPR. Categorization and reports are aids, and you can correct the results. This does not mean every automated analysis falls outside the definition of profiling.
Changes and consent
For material processing changes we update this notice and inform you in the app or by e-mail. Where a change needs new consent, we request it before that processing. Publishing a notice or continuing to use the service is not a substitute for voluntary explicit consent. The terms of use are a separate document.