Privacy Policy
Last updated:
The short version
Your data stays on your device by default. Monly's server only holds wallets you explicitly share. AI features send only what they need to answer you, and are never used to profile you. We use anonymous product analytics to learn which parts of the app help people. There are no ads, no advertising identifiers, no cross-app tracking, and your data is never sold. You can erase everything from the server yourself, inside the app.
What stays on your device
Everything, by default. Wallets, expenses, budgets, bills, receipts and settings are stored locally on your iPhone. You can use Monly without creating an account. Monly never connects to your bank and never asks for bank credentials.
What is stored on the server
Only wallets you explicitly share. When you share a wallet, its contents — name, currency, transactions, categories, budgets and the member list — are stored on the server so the people you invited can see and sync it. Access is limited to the wallet's members.
Private wallets never leave your device. Stopping sharing, leaving a wallet, or deleting your account removes your shared data from the server as described under Retention below.
AI features
Some features use AI: the assistant ("Ask your wallet"), receipt scanning, typed and spoken expense entry, money plans, insights and monthly reviews. When you use one, Monly sends what that feature needs — for example your message, a receipt photo, or the budgets, bills and transactions relevant to your question — through our AI gateway to Google's Gemini API, which returns the answer. We don't keep these requests or their answers on our servers. Google processes them under its API terms.
Spoken entries are transcribed by Apple's speech recognition before anything is sent. AI features are optional: everything else in Monly works without them.
AI usage allowance
AI features come with a daily allowance. To enforce it, our server keeps a usage record for each request: an anonymous purchase identifier, a random device identifier, which feature was used and how much it cost to run. These records never contain your messages, photos or financial data.
Product analytics
To understand which parts of Monly help people — for example whether setup was finished or which screen a subscription offer was opened from — the app sends a small number of usage events to Mixpanel, our analytics provider, on its EU servers. Each event carries a random identifier for this installation of Monly, the app version, and the event's name and context. Events never contain your amounts, transactions, messages, name or email address; IP addresses are not used to locate you; and the identifier is not linked to your identity.
We also use Mixpanel to run simple experiments, such as comparing two versions of a screen. Analytics data is never used for advertising and never shared with data brokers.
Sign in with Apple
You only sign in when you share a wallet or accept an invitation. Apple provides us an opaque user identifier, an optional relay email address, and the optional display name you choose. We use these only to identify wallet members to each other. We never see your Apple password.
Push notifications
If you enable notifications, we store your device's push notification token so Apple's notification service can reach your device — for example, when something changes in a shared wallet. The token identifies a device, not a person, and is deleted with your account.
Purchases
Subscriptions are bought through Apple and managed by RevenueCat, our purchase-management provider, which assigns your purchases an anonymous identifier. We receive your purchase status — whether a subscription is active — and never your card details or billing address. Apple handles all billing.
What we don't do
No ads and no advertising identifiers. No tracking across other companies' apps or websites. No selling or renting data, to anyone, ever. This website is served without third-party resources of any kind — no external fonts, no analytics scripts, no tracking pixels.
Retention
Server-side wallet data exists only while it is shared. If you stop sharing a wallet or leave one, it stops syncing; if you delete your account, all data tied to your account is erased from the server.
Copies of a formerly shared wallet that other members keep on their own devices belong to those members — much like a spreadsheet you once sent someone.
AI usage records and analytics events are kept only as long as we need them to run the allowance and improve the app.
Deleting your data
In Monly, open Settings → Account → Delete Account. This erases your account and your server-side data. For data that only ever lived on your device, deleting the app is enough. To have usage records or analytics events for your installation deleted, email us.
Changes to this policy
If this policy changes, we will update this page and the date at the top. Meaningful changes will also be announced in the app.
Contact
Questions about privacy? Email us at [email protected].