SECURITY & DATA
Where your money data lives, and who can see it
You're being asked to put your bank statements into an app made by someone you've never met. That deserves a straight answer, not a badge. Here's exactly how Moniquid handles your data — including the bits most apps don't mention.
The short version
🚫
We never ask for your bank login
This is the big one. Moniquid has no Open Banking connection and no way to reach your accounts. There is no password, no card number and no banking credential of yours in our system — so there is nothing there for an attacker to steal and nothing we could misuse. You bring the data in yourself: import a statement, scan a receipt, or type it in.
📱
Your device holds the working copy
Moniquid is offline-first. Your transactions are stored in your browser on your device and the app reads from there — which is why it works with no signal. A synced copy sits on the server so you can use more than one device and don't lose everything if your phone goes in a puddle.
🔐
Encrypted in transit and at rest
Everything between you and Moniquid travels over TLS (the padlock in your browser), forced on every request. The database is Supabase managed Postgres in the EU, with AES-256 encryption at rest. Backups are encrypted too.
🇪🇺
Hosted in the EU, under UK/EU GDPR
Your data is stored in the EU, not shipped to a US data centre by default. You have the full set of GDPR rights — access, correction, export, deletion — and they're buttons in the app, not a form you have to email someone about.
🙅
No ads, no data selling, no brokers
Moniquid makes money one way: people paying £2.99/month for Premium. We don't sell or share your financial data, we don't run ad networks, and there are no third-party analytics or tracking scripts following you around the app. If we ever sold your data we'd have no product left to sell.
🗑️
Leave whenever, take everything, leave nothing
Export your full transaction history to CSV any time from You → Export Data. Delete your account from You → Delete Account and your data is removed from the live database — no "contact support to cancel" runaround.
Being straight with you about the limits
Plenty of apps imply more security than they have. Here's where Moniquid's protection actually ends, so you can make an informed choice:
⚠️
It is not end-to-end encrypted
Your data is encrypted in transit and on disk, but it is not zero-knowledge: it isn't encrypted with a key only you hold. In practice that means the server processes your data in readable form, and in principle an operator with database access could read it. Any app that categorises your spending on a server and offers AI coaching works this way — an app can't analyse what it genuinely cannot read. Access is restricted and logged, but we won't pretend it's mathematically impossible.
🤖
Statement files and merchant names go to Google Gemini
To read a PDF statement, categorise merchants, or answer an AI Coach question, Moniquid sends that content to Google Gemini and gets a result back. Our Gemini integration is configured so your data is not used to train Google's models, and files are discarded after processing. If you'd rather no AI touches your data at all: CSV imports are parsed entirely on your device, and manual entries skip AI completely.
🧾
A few named companies process data for us
Not everything can be done alone: Supabase (database, EU), Railway (app hosting), Stripe (payments — card details go straight to Stripe and never touch our servers), Resend (emails), and Google Gemini (AI). Each is listed with what it sees in the
Privacy Policy.
👤
Moniquid is a small, independent UK product
Not a bank, not FCA-regulated (we don't hold or move your money — we can't, we're not connected to your accounts), and not a financial adviser. It's a private budgeting tool built by a UK developer who uses it daily.
How to keep your side secure
Use a strong, unique password (or sign in with Google so there's no extra password to leak). Turn on biometric unlock in You → Security so your ledger is behind Face ID, Touch ID or Windows Hello on your device. And remember Moniquid will never email you asking for a password, card number or bank login — if you get a message like that, it isn't from us.
Frequently asked questions
Do you ever see my bank login or account credentials?
No. Moniquid has no Open Banking connection and never asks for banking credentials. There is no way for the app — or anyone who breached it — to access your bank accounts, because that connection simply doesn't exist.
Is my data encrypted?
Yes — TLS in transit and AES-256 at rest in an EU-hosted Supabase Postgres database, with encrypted backups. It is not end-to-end (zero-knowledge) encrypted: the server processes your data in readable form so it can categorise spending and answer AI questions.
Where is my data stored?
In the EU, in a managed Supabase Postgres database, under UK/EU GDPR. A working copy also lives locally in your browser on your own device, which is what makes the app work offline.
What happens to a bank statement I upload?
A CSV is parsed entirely on your device and the file never leaves it. A PDF is sent to Google Gemini to extract the transactions, then discarded after processing — it isn't used to train Google's models. Once transactions are extracted, the file isn't retained.
Do you sell my financial data?
No. Moniquid is funded by Premium subscriptions (£2.99/month), not advertising or data sales. There are no data brokers, no ad networks, and no third-party tracking scripts in the app.
Can I delete everything?
Yes. You → Delete Account removes your account and data from the live database, and You → Export Data gives you the full CSV of your transactions first. No support ticket needed.
Try it without linking anything
The app isn't currently available. This page is kept online for reference.