Privacy Policy

MONETI

Last updated: 12 September 2026 · document v1.2 · app version 2.45.0

Applicable to the mobile application Moneti — Expense Tracker for iOS and Android.

Moneti is a personal finance app that runs inside your phone. Superbites Studios S.A.S. does not operate servers that store your transactions, your balances or your categories: what you record is saved on the device and leaves it only when you decide. This document explains, without evasions, what data the application processes, for what purpose, with whom it is shared when that happens, how long it is kept, and what rights you can exercise over it.

The essentials, in five lines

We do not sell or rent personal data. There is no advertising, no third-party analytics, no advertising identifiers and no cross-app tracking. None of your financial data reaches our servers, because we have none. The sensitive permissions —microphone and notification access— ship disabled and work only if you turn them on. You can erase everything, immediately and permanently, from within the app itself.

1. Data controller

The controller of the personal data described in this document is:

Legal name

Superbites Studios S.A.S.

Tax ID (NIT)

901.861.933-9

Registered address

Carrera 2 # 3-4, Armenia, Quindío, Colombia

Country

Republic of Colombia

Contact email

moneti@superbitesstudios.com

Responsible area

Data subject support — Moneti

Any request, query or complaint concerning personal data must be sent to the email address above. It is the official and only channel for these purposes.

2. Scope and acceptance

This policy applies to the Moneti mobile application distributed through Apple's App Store and Google Play, in all its versions and in every country where it is available. It does not apply to operating systems, app stores or third-party services that operate under their own policies, although section 6 identifies which ones are involved and what they process.

By downloading, installing or using Moneti you confirm that you have read this policy. Where the law requires express consent —as it does in Colombia for personal data, and in the European Economic Area for certain purposes— the application requests it separately, through the operating system's own dialogs, before enabling the corresponding feature.

3. How Moneti works

This section is not decoration: it describes the technical decision from which almost every answer in this document follows.

Moneti is a local application. Your transactions, accounts, categories, goals, budgets, debts and settings are stored in the application's own storage inside your device, using the operating system's standard mechanisms (UserDefaults on iOS and SharedPreferences on Android). Superbites Studios S.A.S. holds no database containing that information and therefore cannot consult it, export it or hand it to a third party, even if it wanted to.

The application creates no user account on any server of ours. You can use it without signing in ("Look around without an account") or sign in with your Google account or, on iPhone, your Apple account. When you sign in, that service gives Moneti an identifier for your account and, if you allow it, your name and email. The name and email —like any you type during initial setup— are stored solely on the device to personalise the interface, and are not transmitted anywhere. The account identifier is sent to RevenueCat for one purpose only: linking any subscription you have or buy to your account, so you keep it if you change phones or reinstall the app (see section 9).

The only network connections Moneti originates on its own are those described in section 6 —signing in with Google or Apple if you choose to, subscription validation and, on iOS, shared-list synchronisation through your own iCloud— plus the operating system's speech recognition service when you use dictation. Beyond those cases, the application works offline.

4. Data processed

The following table is the complete inventory. The "Where it lives" column answers the question that matters most.

Category

What it includes

Purpose

Where it lives

Financial data you enter

Amounts, currency, date, category, free-text note or description, merchant, associated account, whether the expense was split and among whom.

Provide the core functionality: record, classify, budget and display summaries.

On your device only. On iOS, also in your iCloud if you enable shared lists.

Local profile

Name and email, whether you type them or Google or Apple provides them when you sign in; a profile photo if you choose one; language, theme, currency, declared monthly income and savings percentage.

Personalise the interface and calculate the headline figure on the home screen.

On your device only.

Names of people for shared expenses

The name or nickname you type when splitting an expense and keeping accounts clear.

Calculate who owes what to whom.

On your device only, unless you share that list.

Voice audio

What you say while holding the voice-entry screen open.

Turn your sentence into text in order to extract the amount and the category.

Processed by the operating system's speech recognition service. See section 5.1.

Bank notification content Android only

The title and text of notifications from bank and digital wallet apps that look like a transaction.

Propose a pre-filled expense that you confirm or discard.

On your device only. See section 5.3.

Photographs

The image you choose as a profile photo, taken with the camera or selected from your gallery.

Display your avatar inside the application.

On your device only.

Subscription status

An anonymous identifier generated by RevenueCat or, if you signed in, your Google or Apple account identifier; the product purchased, the renewal date, the store country, the device type and the IP address associated with the request.

Verify on the server that the purchase is legitimate, unlock the paid features and keep your subscription if you change phones.

RevenueCat, Apple and Google. See section 9.

Reminder preferences

Which alerts you want and at what time.

Schedule local notifications on the device itself.

On your device only.

Moneti does not request or process card numbers, bank account numbers, online banking credentials, identity documents, biometric data, health data, or any category of sensitive data within the meaning of article 5 of Colombian Law 1581 of 2012. Nor does the application connect to financial institutions or read your statements: transactions exist because you enter them or because you confirm a proposal.

4.1 Legal basis for processing

For people located in the European Economic Area, Switzerland or the United Kingdom, the legal bases under Regulation (EU) 2016/679 are as follows:

For Colombia, processing is carried out with the data subject's prior, express and informed authorisation, under Law 1581 of 2012 and Decree 1074 of 2015.

5. Device permissions

Every permission is disabled out of the box. The application is fully usable without granting any of them.

5.1 Microphone and speech recognition

When you open the voice-entry screen and hold the button down, the microphone activates so you can dictate an expense. The audio is handed to the operating system's speech recognition service —Apple's Speech Recognition on iOS and Google's speech recogniser on Android— which converts it into text.

Important and honest warning

Those recognition services may transmit the audio to Apple's or Google's servers for transcription, depending on your device's configuration and capabilities. That processing is governed by Apple's and Google's privacy policies, not by ours. Moneti does not record, does not store and does not send anywhere either the audio or the transcription: it receives the text, extracts the amount and the category from it, and discards it. If you would rather your voice never left the device, do not use voice entry; typing the expense by hand produces exactly the same result.

The microphone stops listening the moment you release the button or leave the screen. Moneti never listens in the background under any circumstance.

5.2 Camera and photo gallery

These are requested only when you choose to set a profile photo. The image is saved in the application's storage inside your device and is not sent to any server. Moneti does not add photographs to your camera roll, nor does it access your gallery for any other purpose.

The application bundles a text recognition library (Google ML Kit) prepared to read receipts. That feature is disabled in the current version. When it is enabled, it will run entirely on the device, offline, with no receipt image leaving the phone; this document will be updated before it is switched on.

5.3 Notification access Android only

Android allows an application to read the notifications displayed by other applications. Moneti uses that capability for a single purpose: detecting the purchase alerts your bank sends and offering you a pre-filled expense, so you do not have to type it. That is the feature's primary purpose and it is used for nothing else.

How it is built, in a way you can verify:

5.4 Local notifications

The reminders Moneti shows you are scheduled and triggered on your own device. There is no server of ours sending push notifications, and no recipient list. On iOS, if you enable shared lists, Apple may send silent iCloud alerts to indicate that the other person recorded something; those alerts originate from Apple, not from us, and contain none of your data.

6. Third parties involved

Only three parties can process data related to your use of Moneti, and none of them receives your financial transactions for commercial purposes.

Third party

Role

What it receives

Policy

Apple Inc.

Store, payments, iCloud, speech recognition and Sign in with Apple on iOS.

The purchase transaction; the dictation audio when you use it; if you sign in with Apple, the authentication of your account; and, if you enable shared lists, the transactions in that list, which are stored in your own iCloud account.

apple.com/legal/privacy

Google LLC

Store, payments and speech recognition on Android, and Google sign-in.

The purchase transaction, the dictation audio when you use it and, if you sign in with Google, the authentication of your account. It does not receive the content of the notifications Moneti processes.

policies.google.com/privacy

RevenueCat, Inc.

Server-side subscription validation, acting as a data processor.

An anonymous per-installation identifier or, if you signed in, your Google or Apple account identifier; the product purchased, the purchase and renewal dates, the store country, the device model and the IP address of the request. It does not receive your transactions, your name or your email.

revenuecat.com/privacy

These providers act under contract and are required to apply protection measures equivalent to those described in this policy, and to process the data solely in accordance with our instructions and the stated purpose. There is no other provider, advertising network, analytics tool or attribution service integrated into the application.

7. Shared lists iOS only

Moneti lets you share a specific account —"Household", for example— with the people you invite, so that everyone can record entries in the same list. The feature is built on CloudKit, Apple's service, and works as follows:

The feature requires an active iCloud session. If there is none, Moneti tells you so and nothing else happens. This feature is not available on Android.

8. Backups and export

Moneti can generate a file containing all your data so you can keep it or move it to another phone. You generate the file, it is created on your device, and you decide its destination through the operating system's share sheet. From the moment you send it to another application or service —email, messaging, cloud storage— that file becomes governed by the terms of the destination you chose. Bear in mind that it contains your financial history in the clear.

Separately, iOS and Android may include installed applications' data in their own device backups (iCloud Backup and Android Auto Backup) if you have that feature enabled. It is an operating system mechanism, outside Moneti's control, governed by Apple's and Google's policies. You can disable it from the system settings.

9. Subscriptions and payments

Moneti offers paid features through subscription. Purchases are processed exclusively through Apple's App Store or Google Play, depending on the device. Superbites Studios S.A.S. never sees, receives or stores your card details or payment method: that information is handled by the relevant store.

To determine whether a subscription is active, the application queries RevenueCat, which verifies the receipt against Apple's or Google's servers. That verification is performed server-side rather than on the phone, because checking it inside the device would make it possible to bypass. The result is only a "yes" or a "no", together with the product and its renewal date. If you signed in, the query uses your account identifier instead of the anonymous one, so your subscription follows you if you change phones or reinstall the app.

The subscription is managed and cancelled from your Apple or Google account settings, not from Moneti. Cancelling does not erase your data: the application continues to work with its free features and your history remains intact on the device.

10. What Moneti does not do

These statements can be verified by inspecting the application, and form part of the commitments of this policy:

11. Children

Moneti is not directed at children under 13 and does not knowingly collect data from people of that age. The age rating declared in the stores is consistent with this document.

In Colombia, under article 7 of Law 1581 of 2012 and the applicable constitutional case law, processing children's and adolescents' data is lawful only where it respects their best interests and fundamental rights, and requires the legal guardian's authorisation. If you become aware that a minor has provided personal data through the application, write to us at moneti@superbitesstudios.com and we will take the necessary steps. Since the data lives on the device, in practice it is enough to uninstall the application or use the erase option described in section 12.

12. Retention and deletion

12.1 Data on your device

It is kept for as long as the application is installed and you keep it. There is no automatic expiry, because a financial history loses its usefulness if it deletes itself. You have two ways to remove it:

If you generated backups and sent them elsewhere, those copies are yours and you must delete them separately.

12.2 Data in shared lists

It lives in the iCloud account of the list's owner. When you stop sharing, synchronisation ceases. To delete the data hosted in iCloud you can use the iCloud settings on your Apple device.

12.3 Subscription data

Apple, Google and RevenueCat retain transaction records for the periods imposed by their accounting, tax and fraud-prevention obligations, under their own policies. These are purchase records, not records of your activity inside the application. You may ask us to delete from RevenueCat the identifier associated with your installation or your account, together with its purchase history, as explained in section 12.4.

12.4 Deleting your account

Moneti keeps no accounts on servers of its own. Your account is the Google or Apple session open on your phone and, outside it, only that account's identifier and the purchase history RevenueCat associates with it. There are two ways to delete it:

  1. In the app: ProfileDelete account, type the confirmation word and confirm. Everything Moneti stores on the phone is erased immediately, you are signed out, and the phone stops being associated with your identifier at RevenueCat.
  2. By email, whether or not you still have the app: write to moneti@superbitesstudios.com with the subject "Delete account — Moneti". To find your record, include the identifier shown under ProfileAboutMy account ID or, if you ever made a purchase, the order number on your Google Play or Apple receipt. We delete your identifier and purchase history from RevenueCat within the deadlines in section 15.1 and confirm it by email.

Only the transaction records that Apple and Google keep for their own obligations are retained (section 12.3). Deleting your account does not cancel an active subscription: cancel it first in Google Play or in your Apple account settings.

13. Security

We have adopted technical and organisational measures that are reasonable and proportionate to the risk:

No system is infallible. The security of the data living on your phone also depends on you keeping it updated and protected with a passcode or biometrics. If you find a vulnerability, report it to moneti@superbitesstudios.com; we will handle it as a priority.

In the event of a security incident affecting personal data under our responsibility, we will notify data subjects and the competent authorities within the deadlines and conditions required by applicable law, including Colombia's Superintendence of Industry and Commerce.

14. International transfers

The data described in section 6 is processed by providers established outside Colombia, principally in the United States of America. Those transfers rely on the data subject's authorisation and on the contracts signed with each provider, which incorporate equivalent protection safeguards, including the European Commission's Standard Contractual Clauses where applicable. Data living on your device is not transferred at all.

15. Your rights

15.1 Colombia — Law 1581 of 2012 (Habeas Data)

As a data subject you have the right to:

Procedure. Send your request to moneti@superbitesstudios.com stating your name, a means of contact, and a specific description of what you are asking for. Queries are answered within a maximum of ten (10) business days, extendable by a further five (5) business days. Complaints are answered within a maximum of fifteen (15) business days, extendable by a further eight (8) business days; in both cases we will tell you the reason for the extension and the new date. If the request is incomplete, we will let you know within the following five (5) business days so you can complete it.

The supervisory authority is the Superintendence of Industry and Commerce (sic.gov.co), which you may approach once the query or complaint procedure with us has been exhausted.

15.2 European Economic Area, Switzerland and the United Kingdom — GDPR

You have the rights of access, rectification, erasure, restriction of processing, portability and objection, as well as the right to withdraw consent at any time without affecting the lawfulness of processing carried out beforehand. You may exercise them by writing to the contact address, and you may lodge a complaint with the supervisory authority of your country of residence.

Note one direct consequence of the application's design: because we do not hold your financial data, we cannot locate it or hand it over. The rights of access and portability are satisfied immediately and completely through the export feature described in section 8, which gives you the entirety of your data in a machine-readable file.

15.3 California and other U.S. states

We do not sell or share personal information within the meaning of the California Consumer Privacy Act (CCPA/CPRA), and have not done so in the preceding twelve months. We do not process sensitive personal information for purposes other than those permitted by that statute. You may exercise the rights to know, delete, correct and not be discriminated against by writing to the contact address.

15.4 Identity verification

In order to handle a request we may ask you for additional information that allows us to reasonably verify your identity, for the sole purpose of preventing a third party from accessing data that is not theirs. That information is used exclusively for that purpose and is deleted once the request has been handled.

16. Changes to this policy

We may update this document to reflect changes in the application or in applicable law. The version in force will always be published at this address, with its last-updated date visible in the header. When a change is material —in particular, if it broadens the purposes of processing or adds a new recipient— we will announce it inside the application before it takes effect and, where the law requires, we will ask for your authorisation again. Continued use of the application after a change takes effect implies acceptance of it, without prejudice to the rights you may exercise under section 15.

17. Contact

For any query, complaint or request relating to this policy or to the processing of your personal data:

Superbites Studios S.A.S.
Email: moneti@superbitesstudios.com
Suggested subject: "Personal data — Moneti"
Colombia

We respond within the legal deadlines set out in section 15.1.

18. Annex — Correspondence with the store privacy labels

This annex exists so that the information declared in the App Store Privacy Label and in the Google Play Data Safety form matches exactly what this document describes.

What "collect" means on these forms

Apple and Google do not use the word in its ordinary sense. For both stores, data is collected only when it leaves the device in a way that lets the developer or a third party access it beyond the time needed to service the current request. Data that is stored on the phone and never transmitted is not declared, however much the app processes it. Almost everything Moneti handles falls into that case, which is why the table says "No" so often while the rest of the document describes those very same data in detail.

Data type

Where it lives

Declared?

Note

Purchase history

RevenueCat, Apple, Google

Yes

Purposes: app functionality and analytics. Only exists if you buy a subscription. Not used for tracking.

Financial information entered by the user

On the device only

No

Never transmitted to the developer. Described in section 4.

Name and email address

On the device only

No

Optional: typed by the person or provided by Google or Apple at sign-in. Not transmitted.

Photos

On the device only

No

Profile photo only.

Bank notification content Android

On the device only

No

Local analysis. Optional feature, disabled out of the box. Described in section 5.3 for transparency, even though it need not be declared.

Voice audio

Operating system speech service

No

Transcribed by Apple or Google as part of the system. Moneti neither receives nor retains the audio or the transcription.

Shared lists iOS

The person's own iCloud

No

Stored in the user's iCloud container, to which the developer has no access.

User ID

RevenueCat

Yes

Only if you sign in with Google or Apple: that account's identifier, without name or email. Purposes: app functionality and account management. Without a session, an anonymous per-installation identifier is used. Not used for tracking, and no advertising identifiers (IDFA/AAID) are used.

Location

No

The app does not request the permission.

Contacts

No

The app does not request the permission.

Usage and diagnostic data

No

No analytics or telemetry of our own.

Data for advertising purposes

No

No advertising and no tracking.

On Google Play, these answers appear on Moneti's listing as: no data shared with third parties; data collected: user ID and purchase history.