Privacy policy
Last updated: 10 September 2026 (version 2026-09-10.1)
A courtesy translation. In case of any discrepancy the Slovak version prevails.
In short: your banking data lives on our server in the EU and is never sold. We have no ads, no analytics and no trackers. AI categorization sees only cleaned merchant names and, for selected bank payments, an organization name or general service description — not amounts, IBANs, references or people's names. And you can erase your account entirely from inside the app at any time, bank consents included.
Who processes your data
The controller is OnIT s. r. o., company ID 55 010 903, registered office Ľudovíta Fullu 3012/6, 841 05 Bratislava — Karlova Ves, Slovakia, entered in the Commercial Register of the Bratislava III City Court, section Sro, insert no. 164718/B.
For anything to do with personal data, write to us at podpora@moneytale.app. We have not appointed a data protection officer. We assessed the conditions in Art. 37 GDPR: we are not a public authority, and our core activity is not regular and systematic monitoring of people on a large scale. We process special categories of data in one case only — the items on your till receipts, if you let us store them — and that is not "large scale" either: they are receipts you scan yourself, and we keep them for three years. We will repeat the assessment whenever the scope of the service changes materially.
What we process and why
- Account
- E-mail and password. The password is stored solely as a bcrypt hash — nobody holds it in readable form, not even us. If you sign in with Google or Apple you need no password here at all; instead we keep the identifier they know you by and the e-mail address they issued for you. Purpose: signing in and managing the account. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Kept for as long as the account exists.
- Signing in with Google or Apple
- You sign in with them directly and we receive only a signed statement of who you are — nothing about your finances ever reaches them. They act as independent controllers under their own terms, not as our processors. Apple lets you hide your real address; the account then runs on its relay address, which to us is an ordinary e-mail.
- Bank accounts and transactions
- After you consent in your bank itself, we download them through a licensed PSD2 access provider: the list of accounts (IBAN, name) and the transactions — date, amount, currency, description and counterparty. When you connect a bank we ask for access to the widest history that bank offers (between 162 days and 2 years, depending on the bank) — it cannot be widened later without a new authorization. The access consent is created for 90 days and you revoke it at any time by disconnecting the bank in the app — we then cancel it at the provider too. Legal basis: performance of a contract.
- Statement import
- We retain the original uploaded file for at most 90 days to diagnose new bank formats; this temporary store is excluded from backups. Transactions and the minimized evidence needed to process them correctly remain stored while your account exists. Statements in known formats are read by our own code on the server and nothing from them leaves it. If no built-in parser recognizes the format, we first ask for separate consent. Only then is the statement sent to the AI model provider used for reading statements. This is a different AI provider from the one that categorizes both card and scrubbed bank payments. How much of the statement leaves depends on the format. For a table (.xls, .xlsx, CSV) we send only a sample — the header and a few rows from the start and the end, real payments among them — and ask nothing but what each column holds; using that answer we then read the whole file ourselves on the server, and nothing further leaves. We keep the answer (column names, not data) so that the same table is read without a model next time. For other formats the whole statement text is sent and the model turns it into transactions — it then sees everything printed on the statement: amounts, dates, payment descriptions, counterparties and the IBAN. A statement read this way is accepted only if the sum of the rows exactly matches the balance movement stated on the statement; otherwise the import is rejected. Here too, the model provider does not use this data to train models, under its own contractual terms. The text sent does, however, stay in its abuse-monitoring logs for up to 30 days; after that it is deleted. We remember your consent: it also covers the statements you upload later that we cannot read ourselves, so we do not ask again on every file. You can turn it off in Settings at any time — statements read until then stay imported, and the next unrecognized format asks anew. Legal basis: consent (Art. 6(1)(a)).
- Payments you record yourself
- A payment no bank reported — cash, or an account that cannot be connected — you record yourself: who you paid, the date, the amount and a category. In the mobile app you can have those fields filled in by scanning the QR code on a till receipt or an invoice. We then also store the contents of that code, so the receipt can be found again later: its identifier for a till receipt, the payee IBAN and reference number for an invoice. The data stays for as long as your account exists. Legal basis: performance of a contract.
- A till receipt can also just be kept — for a warranty or a return — without being recorded as a payment. That is the card case: the bank reports that payment itself, so the receipt enters no report of ours. On any receipt you can switch on a warranty watch: we store the date it ends and your note about what it covers, and e-mail you a month before. It is per receipt, and you can switch it off at any time.
- When you scan, your phone queries the Slovak Financial Administration's receipt verification service directly — the authority that records till receipts by law, exactly as its own app would. We send it nothing, and only what you save ever reaches us. An invoice QR code is decoded on the phone and goes nowhere.
- Purchased items (optional)
- A receipt also says what you bought, and when you return something that is the only thing that identifies the goods — a bank statement cannot. So we store the list of items, but only if you explicitly allow it. We ask because a shopping list can reveal sensitive things, medicines from a pharmacy among them; those are health data, a special category under Art. 9 GDPR. Legal basis: your explicit consent (Art. 9(2)(a)). We keep them for 36 months from the purchase, for as long as you can return it, and then delete them ourselves. You can withdraw your consent in Settings at any time — we then delete what is stored. The receipts themselves stay.
- AI categorization (optional)
- It runs only when you approve it in the app. For a card payment, the model receives a cleaned merchant name (“billa”, “slovnaft”). For a selected uncategorized transfer or direct debit, it may receive only an approved cleaned organization name or general service description. We do not send the amount, IBAN, date, payment reference, payer name or original note; uncertain payments and payments to people are withheld. The same AI provider categorizes card merchant names and scrubbed bank-payment inputs; the other provider only reads unknown statement formats. A bank result is stored only against that particular transaction and is not used as a shared rule for other payments or users. Under the API contractual terms, neither provider uses this data for training; abuse-detection logs keep it for up to 30 days. Legal basis: consent (Art. 6(1)(a)) — withhold it at any time and you categorize payments by hand.
- E-mails
- We send a single message — the password reset link, and only when you ask for it — through a specialized e-mail service provider. No newsletter, no marketing.
- Waitlist
- Your e-mail only, so we can invite you to the beta. Kept until the invitation; ask support to erase it at any time.
- Operational logs
- For every request we log the method, path, outcome, duration and user ID — never content, so no amounts or payment descriptions are in the logs. Purpose: security and diagnostics. Legal basis: legitimate interest (Art. 6(1)(f)). Logs are kept for 90 days and then rotate away automatically.
- Problem reports
- When you report a problem, we keep your description, the support conversation, app version and screenshots you deliberately add. You can crop and permanently black out a screenshot before sending; we remove the original image metadata. Technical errors are grouped without the exception message, screen content, payments or request bodies. A technical group is kept for 30 days, a screenshot for 90 days, and a closed report for 12 months. The purposes are providing the support you requested (Art. 6(1)(b)) and reliable operation (Art. 6(1)(f)).
- In-app messages
- When you open the app we may show you an operational notice or a message about something you reported. We keep its text, who it is addressed to, and a record that you read it, so it is not shown twice. The text is written by hand — it is not derived from your payments and nothing in it is profiled. A message is kept for 12 months from the day it was written. The purposes are providing the support you requested (Art. 6(1)(b)) and delivering operational information (Art. 6(1)(f)).
Who we entrust the data to
Five categories of recipient, each getting only what its job needs. Nobody else — we do not sell the data, do not share it for advertising and do not profile you for marketing. We have an Art. 28 processing agreement in place with every one of them. Hosting, the AI models, e-mail delivery and backup storage act as processors; the PSD2 access provider is a separate controller — it holds its own licence for access to bank accounts, you grant it consent directly when connecting your bank, and it processes your data under its own privacy policy.
| Recipient category | What it receives | Where | Transfer safeguard |
|---|---|---|---|
| Server infrastructure provider | the whole database — it hosts our server | Germany (EU) | none needed, the data does not leave the EU |
| Licensed PSD2 access provider (separate controller) | mediates access to your bank | a country with an EC adequacy decision | EC adequacy decision |
| AI model providers (two — one categorizes card and bank payments, the other reads statements) | cleaned merchant and selected organization names or general service descriptions; the statement text when machine-read | USA, possibly other countries where they operate facilities | EU–US Data Privacy Framework and standard contractual clauses |
| E-mail service provider | your e-mail and the content of the transactional message | USA, sending from the EU region | EU–US DPF + standard contractual clauses |
| Backup storage provider | the daily database backup, encrypted with our key — it holds no key and cannot read the contents | USA | standard contractual clauses; on top of that, encryption on our side — the decryption key never leaves us |
We will name the specific processors on request — write to podpora@moneytale.app.
Where the data lives and for how long
The application and the database run on a single server in a data centre in Germany.
We back up daily, in three layers: on the server itself (14 days), whole-machine images
at the same German provider (7 days), and a copy at a storage provider in the USA
(14 days). That third layer exists in case we ever lose the German account entirely,
and it leaves encrypted with our own key — whoever stores it cannot
read it.
When you erase your account, your data disappears from the database immediately and
from every backup within 14 days at the latest. While the account exists we keep the
data so the report works; nothing is archived “forever”.
Cookies and analytics
Moneytale uses no cookies, no analytics and no third-party trackers — which is why
no cookie banner greets you.
We do keep a few values in your browser's localStorage, because without them the
service would not work the way you asked for it: the session token, the language,
light or dark mode, the chosen shape of three charts, the state of the first-run guide
and a marker for the return from your bank. They are not used for tracking, they never
leave your device, and clearing the site's data removes them; the token additionally
disappears when you sign out.
Your rights
Under the GDPR you have the right of access to your data, and to its rectification, erasure, restriction of processing, portability and objection (Art. 15–21). The most important two need no e-mail at all. You erase the account in the app itself (Settings → Delete account) — the erasure is immediate, complete, and revokes the bank consents at the PSD2 access provider too. And you download everything we hold about you in the same place (Settings → Download your data) as a single JSON file: transactions, accounts and bank connections, categories, your own rules and corrections, a record of the statements you uploaded and the consents you gave. For anything else write to podpora@moneytale.app; we answer within 30 days at the latest.
We keep a record of the request itself — what it concerned, when it arrived and when we handled it — so we can show the deadline was met. It holds no e-mail address of yours, only a one-way digest of it, from which the address cannot be read back. After the account is deleted nothing readable about you remains, and we can still confirm that we deleted it.
We carry out no automated decision-making or profiling with legal or similarly significant effects within the meaning of Art. 22 GDPR. The AI sorts payments into categories you can overwrite at any time; none of it decides anything about you.
If you believe we handle your data incorrectly, you can complain to the Office for Personal Data Protection of the Slovak Republic, Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava, dataprotection.gov.sk.
Changes to this document
When the way we process data changes materially — a new processor, for example — we update this page and let you know by e-mail or in the app. The date of the last update is always at the top.