Last updated: March 21, 2026
Monavo is a personal expense tracking app built on a local-first principle: your financial data lives on your device by default. This policy explains what data is collected, when it leaves your device, which third-party services are involved, and what rights you have over your data.
We do not sell your data. We do not show ads. We do not connect to your bank.
All transactions, categories, recurring expenses, and settings are stored locally on your device in an encrypted SQLite database. This data never leaves your device unless you explicitly enable cloud sync (see section 3). You can delete all local data by uninstalling the app.
You may use Monavo without creating an account. If you choose to enable cloud sync, you will be asked to create an account using your email address. Your email address is used solely for authentication and account recovery — it is not used for marketing or shared with third parties.
Authentication is handled via Supabase Auth (see section 3). Optionally, you may set a local PIN to protect access to the app. The PIN is stored only on your device and is never transmitted.
Cloud sync is entirely optional. If you enable it, your transaction data, categories, and recurring expenses are encrypted in transit (TLS) and stored in a database hosted by Supabase (supabase.com). Supabase is a U.S.-based infrastructure provider. Your data is stored under your account and is not accessible to or used by Supabase for any purpose beyond hosting.
The following data is synced when cloud sync is enabled:
No raw input text or AI responses are stored in the cloud. You can disable cloud sync and request deletion of your cloud data at any time by contacting support@getmonavo.com.
Supabase infrastructure is hosted in the United States. If you are located in the European Union or another jurisdiction with data transfer restrictions, please be aware that enabling cloud sync means your data will be transferred to and stored in the US. Supabase maintains appropriate safeguards for such transfers in accordance with applicable law.
Supabase's privacy policy: supabase.com/privacy
When you use the Quick Add feature, you can type a natural-language description such as "coffee 3.50" or "uber 12 transport". If the app cannot parse the input locally, this input text is sent to a secure server-side function operated by us, which in turn calls the Anthropic Claude API to extract the transaction type (income or expense), category, and notes.
Specifically:
<amount>. For example, "coffee 3.50" becomes "coffee <amount>" — the actual amount never leaves your device.You can always add transactions manually without using the Quick Add feature. Parsing is only triggered when you explicitly submit a Quick Add input.
Anthropic's privacy policy: anthropic.com/privacy
Premium subscription management ($2.99/mo, $19.99/yr, or $59.99 lifetime) is handled by RevenueCat (revenuecat.com). RevenueCat receives a pseudonymous user identifier and purchase receipt information from the App Store or Google Play to verify your subscription status. We do not have access to your payment details — all billing is handled directly by Apple or Google.
RevenueCat may collect anonymous analytics about purchase events (e.g. trial started, subscription renewed) to help us understand subscription health. This data is not linked to your financial data in Monavo.
RevenueCat's privacy policy: revenuecat.com/privacy
We use PostHog (posthog.com) to collect anonymous behavioral analytics that help us understand how the app is used and where to improve it. PostHog is hosted on EU infrastructure (eu.i.posthog.com), meaning your analytics data is stored and processed within the European Union.
What we collect:
cat_food), type (income/expense) — never the amount, currency, or the text you typedWhat we never collect:
Opt-out: You can disable analytics collection at any time in Settings → Your Data → Anonymous Analytics. When disabled, no data is sent to PostHog for the remainder of that session or any future sessions until you re-enable it. This preference is stored on your device.
You can also request deletion of your analytics data by contacting us at support@getmonavo.com.
PostHog's privacy policy: posthog.com/privacy
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, contact us at support@getmonavo.com. We will respond within 30 days.
Monavo is not directed at children under the age of 13 (or 16 in the EU). We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
We take reasonable technical measures to protect your data, including TLS encryption in transit and access controls on our backend infrastructure. However, no system is completely secure. You are responsible for keeping your device and account credentials safe.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date above. For significant changes, we will notify you within the app. Continued use of Monavo after a policy update constitutes acceptance of the revised policy.
If you have any questions or concerns about this Privacy Policy, please contact us at support@getmonavo.com.