Moniquid is paused. The app isn't currently available and isn't accepting sign-ups. These pages are kept online for reference.
← Moniquid
Moniquid is paused. This page is kept for reference. The in-app controls mentioned below — exporting your data, deleting your account from the You tab — are no longer available. For any data access, export or deletion request, email support@moniquid.co.uk.

Privacy Policy

Last updated: 17 April 2026

Your data rights

Under UK GDPR, you can access, correct, export, or delete your personal data at any time.

1. Information We Collect

  • Account: email address, name, and a hashed password
  • Financial data: the transactions, budgets, accounts, goals, and debts you enter
  • Usage: IP address, device/browser info, and activity logs for security
  • Payment: handled by Stripe — we never see or store your card details

2. How We Use Your Information

  • Provide and maintain the Moniquid service
  • Generate AI-powered categorisation and coaching
  • Process subscriptions through Stripe
  • Send important account notifications
  • Improve our service and user experience
  • Prevent fraud and ensure security

3. Data Sharing & Subprocessors

We never sell your personal data. We share data only with the following subprocessors, each for a specific purpose. Each one has its own privacy policy and is contractually required to protect your data:

  • Supabase (Postgres database, EU region): stores your account, transactions, accounts, savings goals, debts, budgets, recurring items, and audit logs. Data is encrypted at rest (AES-256) and in transit (TLS).
  • Railway (application hosting): ran the Moniquid server.
  • Stripe (subscription billing): handled premium subscriptions. We never see or store your card details — they go directly from your browser to Stripe's PCI-compliant servers.
  • Google Gemini (AI processing): merchant text and bank-statement files (PDF/CSV/images) were sent to Google Gemini for categorisation, coaching, and OCR. Files are processed and discarded by Gemini after the response is returned. The Gemini integration was configured to opt out of using your data to train Google's models.
  • Resend (transactional email): delivered verification, password-reset, password-change, account-deletion, and subscription emails. Resend stores only the email address and the subject/body of those messages.
  • Namecheap / Cloudflare (DNS and static hosting): no personal data is shared.

4. Data Security

We protect your data with:

  • TLS encryption for all data in transit
  • AES-256 encryption at rest (Supabase managed Postgres, EU region)
  • PBKDF2-hashed passwords — stored as salted hashes, never in plaintext
  • Row-level security policies on every table that holds your data
  • Account lockout after repeated failed logins
  • Audit logging of security-relevant events

5. Your Rights (UK GDPR)

You have the right to access, rectify, erase, and port your data, and to object to non-essential communications. While the app is paused, email support@moniquid.co.uk to exercise any of these.

6. Data Retention

We keep your data for as long as your account is active. When an account is deleted:

  • Personal information is anonymised immediately
  • Financial data is deleted after 30 days
  • Minimal audit logs are retained for legal compliance (anonymised)

7. Cookies

Only essential cookies were used — session management, security, and preferences. No tracking or advertising cookies. The static pages you are reading now set no cookies at all.

8. Children's Privacy

Moniquid is not intended for users under 18. We do not knowingly collect data from children.

9. Changes to This Policy

We may update this policy occasionally.

10. Contact Us

Questions about privacy? Contact support@moniquid.co.uk.