Legal · /privacy

Privacy policy

Last updated: July 2, 2026

Monilibrium is a budgeting app, so we hold ourselves to a strict rule: your financial details — amounts, balances, payees, categories, anything you type — stay between you and the app. This page explains exactly what we collect, which services we use, and the choices you have.

What we collect

Your account. Signing in with Google shares your name and email address with us. We store them in our own database and use them only to operate your account — never for marketing, and we never sell or share them.

Your plan data. Plans, buckets, transactions, amounts, payees, and categories are stored in our own database (encrypted in transit) so the app can work. They are yours: you can export everything or delete your account — and all of its data — from Settings at any time.

What we never send to third parties

No amount, balance, name, email address, payee, category label, or free text you type is ever sent to any analytics, error-monitoring, or logging service. The services below only ever see the scrubbed, minimal signals described for each.

Error monitoring — Sentry (EU)

When something breaks, an error report goes to Sentry, hosted in their European Union data region. Reports are scrubbed of personal data before they leave the app; a signed-in report carries only your random account ID — never your email, name, or any financial detail.

Product analytics — PostHog (EU)

To understand which features help, we use PostHog, hosted in their European Union cloud — and only with your consent where consent is required, and never while your browser sends a Do-Not-Track or Global Privacy Control signal. We send a small, hand-picked set of events (for example "a bucket was created"), identified by your random account ID plus your language, plan, and signup date. Inside the app, automatic capture is off, so what's on your screen — labels, amounts, anything you type — is never collected; on this public marketing site, where none of your money is on screen, we do record which links and buttons get clicked.

Session replay. We record masked replays of consented sessions to diagnose usability problems, under the same consent choice as everything above. Every input field is always hidden before anything leaves your browser, and inside the app so is every amount, balance, name, payee, and anything you type — only fixed interface text, like a button label, stays readable. On this public marketing site, where nothing of yours is on screen, page text is recorded as it appears. You can change your analytics choice at any time in Settings.

Infrastructure logs — AWS CloudWatch

Our servers run on Amazon Web Services, and their operational logs go to AWS CloudWatch in our own account. Logs are structured for debugging and have personal data redacted before they are written; they are kept only as long as operations require.

Security audit trail

For your protection, security-relevant events — sign-ins and sign-outs, data exports, money-affecting changes, and account deletion — are recorded in an append-only audit trail inside our own database. It exists so suspicious activity can be investigated after the fact. It is first-party only: audit records are never sent to any third party. These records deliberately outlive a deleted account, and they hold only your account ID, IP address, and browser — never amounts, balances, names, email addresses, payees, or category labels.

Your choices

Analytics consent. Where consent is required you'll see a banner before anything is collected, and you can grant or withdraw consent at any time under Settings → Privacy.

Do Not Track. If your browser sends a Do-Not-Track or Global Privacy Control signal, we honor it — analytics stays off regardless of any other setting.

Your data. You can export everything, or delete your account and all of its data, from Settings. Deletion happens right then — there is no grace period and no deactivated copy kept for later — with two exceptions: the security audit trail described above, and our encrypted database backups, which age out within 7 days.