Your privacy is important to us. Moimoney is built as an offline-first expense manager. Financial data stays on your device unless you choose a cloud or AI feature that requires transmission. Optional usage statistics are collected only after your separate in-app consent.
1. Information We Collect
Local Data (Offline First)
If you use Moimoney without logging in, all your financial data (transactions, wallets, categories, budgets) remains strictly on your device. It is not transmitted to our servers or anywhere else. If you uninstall the app without a backup, that data is permanently deleted.
Cloud Sync Data
If you create an account to use our cloud sync or AI features, your financial data is synced securely to our servers (hosted on Supabase). This includes your transactions, wallets, and preferences, allowing you to access them across multiple devices.
Crash and Stability Data
Firebase Crashlytics is a separate service used to diagnose crashes and stability problems. It may receive:
- App version and operating system version
- Device model information
- Error logs and technical crash traces
2. Optional Usage Analytics
With your opt-in consent, Moimoney uses Google Analytics for Firebase, with Google acting as a data processor, to collect optional pseudonymous usage statistics presented mainly in aggregate reports. Analytics is disabled by default. Declining does not limit any app feature.
- Your choice: You can accept or decline the one-time in-app prompt and change the Analytics toggle at any time under Privacy & Data. Turning it off stops future collection and resets the Analytics identifier stored on the device. We do not send an event recording your consent choice.
- Custom events: We send only controlled feature and action categories, such as opening a report or whether an operation started, succeeded, failed, was cancelled, or was blocked. Some events use a fixed variant or entry-point category.
- Automatic technical events: When Analytics is enabled, Firebase may automatically collect events such as first open, session start, user engagement, app update, operating-system update, app exception, and in-app purchase metadata.
- Technical metadata: Processing may include a pseudonymous app-instance ID, app version, platform and device information, session metadata, and approximate country. Google may use the IP address during collection to derive approximate location and discards the IP before Analytics data is stored.
- Data we prohibit: We do not send your account identity or Supabase user ID, transactions, amounts, wallet/category/ledger names, notes, search terms, receipts, files, audio, transcripts, or other user-created text to Analytics.
- No advertising use: We do not use Analytics for ads, attribution, remarketing, marketing, profiling, personalization, or sale of data. Advertising storage and signals remain disabled.
Analytics is not linked to your Moimoney account. Data already sent remains subject to Google's retention controls; standard aggregate reports may remain available longer than event-level data and cannot be deleted per account because no Supabase User-ID is attached.
3. AI Features and Operational Logs
Moimoney includes AI-powered features such as Receipt Scanning and AI Insight.
- Consent: Before using any AI feature for the first time, we will explicitly ask for your consent. If you decline, no data will be sent to the AI service.
- Processing: If you use the receipt scanner, the image or PDF you provide is sent securely to Google's Gemini API for text extraction.
- No AI Training: Following our provider's (Google API) policies, the data you submit to the AI features is not used to train their AI models by default. Data is temporarily processed solely to return the result back to your app.
To enforce quota, billing entitlement, and abuse-prevention rules, we retain per-account operational records for receipt scans, AI insights, and AI voice usage. These may include account ID, request time, usage status, model/version, quota tier, and limited error or latency metadata. They are not product Analytics and are kept only as long as needed for quota and account operations, then deleted when the account is deleted, subject to short-lived backups and legal obligations.
4. Third-Party Services
We use specific third-party services to operate the app:
- Supabase: For user authentication (Google Sign-In, Apple Sign-In) and storing synced cloud data.
- PowerSync: To facilitate real-time, offline-first data synchronization between your device and Supabase.
- RevenueCat: To manage in-app subscriptions securely. We do not handle or store credit card details.
- Firebase Crashlytics: For monitoring app crashes and stability.
- Google Analytics for Firebase: For optional usage measurement after consent. See Google's Privacy Policy and Google Analytics data information.
5. Retention and Deletion
Your data belongs to you. You can request deletion of your account and all associated cloud data at any time through our account deletion page, including if you can no longer access the app.
- Local Data: Use Delete All Data where available to remove app records, or uninstall Moimoney to remove its local container. Uninstalling does not cancel a subscription or automatically delete a cloud account.
- Cloud Financial Data: Deleting your account in the app starts deletion of account-linked cloud records, including operational AI quota logs, subject to temporary backups and records we must retain by law.
- Analytics: GA4 user- and event-level retention is configured to two months without resetting on new activity. Standard aggregate reports may remain longer. Opt-out resets the local Analytics identifier but cannot erase aggregate reports per account.
- Legacy Voice Aggregate: Old Speak to Log telemetry was stripped of user identifiers and retained only as one-dimensional monthly buckets containing at least five events, for no more than 24 months.
- Crashlytics: Crash records follow Firebase Crashlytics retention controls and are separate from usage Analytics.
6. International Processing and Security
Our providers may process data in countries other than yours. We use providers' contractual and technical safeguards for international transfers where applicable.
We take security seriously. Data synced to our cloud services is transmitted over secure connections (HTTPS) and stored in secure databases managed by Supabase. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
7. Consent and Your Choices
Usage Analytics requires an affirmative in-app choice and can be withdrawn at any time without affecting the app. AI features ask for separate provider consent. Account, sync, and deletion controls remain available in app settings.
8. Changes to This Privacy Policy
We may periodically update this policy. If we make material changes, we will notify you by updating the date at the top of the policy or through an in-app notice.
9. Contact Us
If you have any questions about this Privacy Policy, please reach out to us via our Support page.