Your privacy matters. This policy explains what data Moneux ("we", "us", "our") collects when you use our personal finance app, how we use it, and the rights you have over it. By using Moneux you agree to this policy.
1. Data We Collect
1.1 Account Information
- Name and email address provided by Apple Sign-In or Google Sign-In at registration.
- Profile avatar you optionally upload.
- Preferred language and currency you set in the app.
1.2 Financial Data
- Income, expenses, debts, investments, and savings goals you enter manually.
- Budget settings, recurring transactions, and financial planning targets.
- Net worth snapshots calculated from the data you provide.
This data is entered by you and is never sold or shared with advertisers.
1.3 Subscription & Purchase Data
- Your current subscription plan (Free or Pro) and its expiry date.
- Apple App Store transaction identifiers (used solely to verify and manage your subscription). We never receive your payment card details — all billing is handled by Apple.
1.4 Usage & Diagnostic Data
- Feature interactions and screen visits used for debugging and improving the service.
- iOS version and device model for compatibility purposes.
- Crash reports and error logs (no financial content is included).
1.5 Push Notification Tokens
If you grant permission, we store a device push token to send you reminders and alerts you configure in the app. You can revoke permission at any time in iOS Settings.
1.6 Gmail Data (Email Receipts — optional feature)
When you choose to enable the Email Receipts feature, Moneux requests read-only access to your Gmail account via Google OAuth 2.0. This is entirely optional; the core app works without it.
- OAuth scope requested:
https://www.googleapis.com/auth/gmail.readonly (read-only access). This is the only scope requested by the Email Receipts connection flow. The connected mailbox address is read from the Gmail API itself; Moneux does not request openid, userinfo.profile, or userinfo.email for this connection flow.
- What we read: Moneux searches for and retrieves full email content only from senders you explicitly add to your Trusted Senders list. To identify new trusted-sender emails, our Gmail inbox notification process receives message identifiers and retrieves the From header of new Inbox messages; messages from other senders are immediately ignored and their subjects, bodies, attachments, and other content are not retrieved or stored.
- What we extract: from those trusted-sender emails we extract transaction fields used to create and categorize a record — merchant and transaction name, amount, currency, date, category, payment hint, and order reference when present. The raw email body, HTML, and attachments are processed transiently on our server and are never stored.
- What we store: the connected mailbox address, extracted transaction data (merchant, amount, date, category, card), and limited receipt metadata (sender, subject, short Gmail-provided snippet, and message identifiers) while a receipt candidate is available for review. When you import a candidate, Moneux removes its sender, subject, and snippet. The full raw email body and attachments are never stored.
- AI extraction: before Moneux sends you to Google's authorization page, it asks you to confirm a notice stating that receipt text may be sent to OpenAI. If you continue and complete the connection, Moneux may send the minimum text needed from a trusted-sender receipt to OpenAI solely to resolve uncertain transaction details. This applies only to accounts connected through that confirmation; disconnecting the account stops it. Gmail data is never used to develop, improve, or train any AI or machine-learning model. Moneux sends these requests to the OpenAI API with response storage disabled, has not enabled any data-sharing or model-training option, and OpenAI does not train its models on data submitted through its API.
- What we do not do: we do not read, index, store, or process any emails outside your trusted senders list; we do not use Gmail data for advertising, profiling, or any purpose other than importing the expense transaction you configured; we do not share Gmail-derived data with third parties except OpenAI for the receipt extraction you consented to when connecting the account, as described in Section 4.
- Revoking access: when you select Settings → Email Receipts → Disconnect, Moneux stops its Gmail inbox watch, asks Google to revoke the saved OAuth token, and removes the local connection, trusted senders, and receipt candidates. You can also revoke access directly from your Google Account permissions page. Either action stops future Gmail reads.
2. How We Use Your Data
- Provide the service: store, display, and calculate your financial records.
- Email receipt parsing: read emails from trusted senders you configure to automatically import expense transactions. The full raw email content is not retained. Gmail data is used solely to provide this feature — it is not used for advertising, analytics, profiling, or any other purpose.
- AI-powered insights: Moneux uses OpenAI models only for Moneux's in-app AI features, including chat, health score, budget suggestions, receipt scanning, file import, and financial insights. Before Moneux sends personal financial data to OpenAI, the app shows an in-app permission prompt that identifies OpenAI, explains what data may be sent, and asks for your permission. If you choose Not Now, Moneux does not send the AI request, does not save AI-sharing permission, and will ask again the next time you try to use an AI feature. When you choose Allow and use these features, Moneux sends the minimum financial context needed for the request to OpenAI, such as account balances, income, expenses, debts, investments, budgets, goals, and your chat message, receipt image, or uploaded document/image when relevant. Your name, email address, and contact details are not intentionally included in these AI requests. AI-generated content is for informational purposes only and does not constitute professional financial advice.
- Subscription management: verify purchases with Apple and enforce plan limits.
- Notifications: deliver reminders and budget alerts you have enabled.
- Service improvement: analyse aggregate, anonymized usage patterns to improve features and fix bugs.
We do not sell your data, use your financial data for advertising, or share your financial data with other AI model providers.
3. Data Storage & Location
Your data is stored in Google Cloud Firestore, located in the United States. Data is encrypted at rest and in transit (HTTPS/TLS). Our backend runs on Google Cloud Run.
4. Third-Party Services
| Service | Purpose | Data shared |
| Apple Sign-In | Authentication | Name, email (one-time, at sign-up) |
| Google Sign-In | Authentication | Name, email (one-time, at sign-up) |
| Gmail API (optional) | Email receipt auto-import — only when you enable the feature and add trusted senders | Email content from trusted senders only, processed transiently to extract transaction data; the full raw email body and attachments are never stored |
| Google Firebase / Firestore | Database & hosting | All app data stored here |
| Apple App Store | In-app purchases | Transaction IDs to verify subscriptions |
| OpenAI | Sole AI model provider for Moneux's in-app AI features; Gmail receipt text is sent only for accounts you connected after confirming the notice shown before Google's authorization page | Minimum financial context needed for the request. For receipt extraction: only the minimum trusted-sender receipt text needed to resolve uncertain transaction details. Requests are sent with response storage disabled, and this data is never used to develop, improve, or train any AI or machine-learning model. |
We require third-party service providers that process personal data for Moneux, including OpenAI, to protect that data with the same or equal level of protection described in this policy and to use it only to provide services to Moneux. Each third party also processes data under their own privacy policies. We encourage you to review them.
5. Google User Data — Summary
This section summarises our practices specifically for data obtained through Google APIs, as required by Google's Limited Use policy.
- Data accessed: Google account name and email (via Google Sign-In, one-time at registration); Gmail email content from trusted senders only (via Gmail API, only when you enable Email Receipts).
- Purpose: Google Sign-In data is used solely to create and authenticate your Moneux account. Gmail data is used solely to parse receipt emails and create expense transactions — no other use.
- Storage: Google Sign-In name and email are stored in your Moneux profile. Gmail email content is processed transiently and the full raw email body is never stored. Limited receipt metadata is retained while a candidate is available for review and sender, subject, and snippet are removed after import.
- Sharing: Google user data is not sold, rented, or shared with any third party for advertising or other commercial purposes. For a Gmail account you connected after confirming the notice shown before Google's authorization page, the minimum receipt text required to resolve uncertain transaction details is transferred to OpenAI solely to provide that feature. It is otherwise stored in Google Cloud Firestore as part of your Moneux account data.
- AI and machine learning: Moneux does not use raw or derived Google Workspace API user data to develop, improve, or train any AI or machine-learning model, and does not transfer that data to any third-party service that uses it to train its models. Requests to OpenAI are sent with response storage disabled and are used only to return an extraction result for that single receipt.
- Limited use: Moneux's use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve features you explicitly requested within Moneux.
- Retention & deletion: Google Sign-In profile data is retained while your account is active. Gmail-derived transaction data is retained until you delete the individual record or delete your account. Raw Gmail content is never retained. On account deletion (Settings → Delete Account), a daily purge job permanently erases all Google-derived data, Gmail connections, trusted senders, receipt candidates, and linked account data after the 30-day deletion window.
6. Data Retention
We retain your data for as long as your account is active. If you delete your account (Settings → Delete Account), the account is disabled immediately and a daily purge job permanently erases all personal and financial data from our systems after the 30-day deletion window. Anonymized aggregate statistics may be retained indefinitely.
7. Your Rights
- Access & export: export all your data as CSV from Settings → Export.
- Correction: edit any record directly in the app.
- Deletion: delete your account and all data permanently from Settings → Delete Account.
- Portability: exported CSV files are yours to keep and use freely.
- Withdraw consent: disable push notifications in iOS Settings at any time. Disconnect Gmail from Settings → Email Receipts → Disconnect or via your Google Account permissions. You can also reset AI data-sharing permission in Moneux Settings; if reset, Moneux will ask again before sending financial context to OpenAI. Choosing Not Now in the AI data-sharing prompt is temporary and does not save a denial.
For any other data requests, contact us at the address below and we will respond within 30 days.
8. Security
We protect your data with HTTPS/TLS in transit, encryption at rest in Firestore, and JWT-based authentication (HS256 sessions, ES256 for Apple tokens). Access to production data is restricted to authorised personnel only. No system is 100% secure; please use the app on trusted networks.
9. Children
Moneux is not directed to children under 13 (or under 16 in the European Economic Area). We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this policy from time to time. The Last updated date at the top of this page reflects the most recent revision. For significant changes we will notify you via an in-app message. Continued use of Moneux after changes take effect constitutes acceptance of the revised policy.