Privacy Policy

MoneyMate is a local-first personal finance app. Your income, expenses, lends, debts and budgets are written to a database on your own phone. Nothing is uploaded anywhere unless you switch on a sync mode yourself.

Effective: 2 August 2026 Last updated: 2 August 2026 Applies to: MoneyMate for Android & iOS, and this website

1. The short version

At a glance
  • Local-first. Every transaction you record is written to an encrypted-at-rest SQLite database inside the app's private storage on your device, before anything else happens.
  • Cloud sync is opt-in. The app works completely offline, with no account, forever. You choose whether to connect a MoneyMate account or a Google Sheet.
  • No advertising. MoneyMate contains no ad networks and no ad identifiers.
  • No analytics or tracking SDKs in the app. There is no Firebase Analytics, no Crashlytics, no Sentry, no Meta SDK, no attribution SDK — we do not measure what you tap. Our website's home page does use Google Analytics to count visitors; see Cookies and website analytics.
  • We never sell or share your data for advertising or any other cross-context behavioural purpose.
  • You can delete everything from inside the app, or by requesting deletion on the web — no app install required.

This policy explains the whole picture in detail. It is written to be read, not to be survived. If anything here is unclear, ask us and we will explain it and, where needed, fix the wording.

2. Who is responsible for your data

MoneyMate ("MoneyMate", "the app", "we", "us") is built and operated by an independent developer based in Bangladesh, trading under the name MoneyMate. We are the data controller for the limited personal data described in this policy.

The quickest way to reach us about anything privacy-related — a question, a correction, a rights request, a complaint — is contact@texion.tech. We aim to answer within 7 days and are bound to a 30-day maximum for formal rights requests.

3. Data kept on your device

The core of MoneyMate is a database stored in the app's private sandbox on your phone. Other apps cannot read it, and neither can we. It holds:

  • Financial records you enter — amount, date, category, an optional note or reason, and whether it is income or expense.
  • Lends and debts — the amount, the direction, repayment progress, and the name or label you attach to the other person. That name is a free-text field you control; you are free to use initials or a nickname.
  • Categories you create, with their icons and colours.
  • Budgets and recurring rules you set up.
  • Preferences — chosen theme, language, currency and date format, home-screen widget configuration.
  • A local app lock — if you enable it, a PIN (stored as a hash, not as the digits you typed) and/or a flag saying biometric unlock is switched on.
  • A pending-sync queue, if a sync mode is enabled, listing changes not yet sent upstream.

If you add home-screen widgets, a small summary of the figures those widgets display (for example, this month's balance) is cached in the platform's own widget storage, because Android and iOS render widgets outside the app process. That cache never leaves the device.

Uninstalling the app deletes this database. In local-only mode that is genuinely irreversible — we hold no copy to restore from. Please export a PDF or enable a sync mode first if you want your history to survive a reinstall.

4. What leaves your device — by storage mode

MoneyMate has four storage modes. You pick one during setup and can change it later in Settings. The mode alone determines what, if anything, is transmitted.

Storage mode Account needed What leaves your device
Local only
(the default)
None Nothing. No account, no network calls carrying your financial data. The app is fully functional in airplane mode.
Google Sheet Your Google account Your financial records are written into a spreadsheet in your own Google Drive, using your own Google credentials. The data goes from your phone to Google. It does not pass through our servers.
MoneyMate account MoneyMate account Your financial records, categories, budgets and recurring rules are synced to our server so they survive a lost phone and appear on your other devices. Plus your email address and display name.
Full sync MoneyMate + Google Both of the above at once.

If you use a MoneyMate account, the personal data we hold on our server is deliberately minimal: your email address, a display name, an optional avatar image URL (supplied by your sign-in provider), your app preferences, and the financial records you chose to sync. We do not ask for your phone number, postal address, date of birth, government ID, or any bank or card credentials.

Worth stating plainly

MoneyMate never connects to your bank. There is no open-banking integration, no screen-scraping, no SMS reading, and no card linking. Every figure in the app is there because you typed it.

5. Google Sign-In and Google Sheets

If you choose to sign in with Google, or to sync to a Google Sheet, MoneyMate uses Google's official sign-in flow. We receive your email address, your name, and your profile picture URL from Google. We never see your Google password.

The permission we ask Google for

To create and update your finance spreadsheet, MoneyMate requests the https://www.googleapis.com/auth/spreadsheets scope. This is used for a single purpose: reading and writing the MoneyMate spreadsheet that holds your finance data.

Google API Services — Limited Use disclosure

MoneyMate's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: we use Google user data only to provide and improve the sync feature you asked for; we do not transfer it to others except as necessary to provide that feature, for security purposes, or to comply with applicable law; we do not use it for advertising; and no humans read your Google data except with your explicit permission, for security purposes, to comply with applicable law, or on aggregated and anonymised data for internal operations.

Your spreadsheet lives in your Google Drive, under your control. You can open it, edit it, share it, or delete it at any time without involving us, and you can revoke MoneyMate's access from your Google account permissions page. Revoking access stops future syncs; it does not delete the spreadsheet, because the spreadsheet is yours.

Note that once your data is inside Google Sheets, Google's own Privacy Policy governs Google's handling of it.

6. Device permissions we ask for

MoneyMate asks for very little, and each request is tied to a feature you chose to use.

Permission When it is asked What it is used for
Biometrics
(fingerprint / Face ID)
Only if you turn on app lock Unlocking the app. The check happens entirely inside your device's secure hardware. We never receive your fingerprint or face data — the operating system only tells the app "yes" or "no".
Photo library Only if you tap to set a profile picture Reading the one image you pick. MoneyMate does not scan, index, or upload your photo library.
Network access Always granted on install Sync (if enabled), sign-in (if used), and checking whether you are online so queued changes can be sent. In local-only mode the app makes no data calls.

MoneyMate does not request access to your location, contacts, microphone, camera roll beyond a single picked image, call logs, or SMS messages.

7. What we never do

Some commitments are easier to verify as absences. As of the effective date of this policy, the MoneyMate app ships with:

  • No advertising SDK of any kind, and no use of the Android Advertising ID or Apple's IDFA.
  • No analytics SDK — we do not know which screens you visit, how long you use the app, or which features you like. Product decisions come from what people tell us by email.
  • No crash-reporting SDK — crashes are not automatically transmitted to us.
  • No social-network or attribution SDKs.
  • No selling, renting, or licensing of personal information to anyone, and no "sharing" for cross-context behavioural advertising as that term is defined under California law.
  • No use of your financial records to train machine-learning models.
  • No profiling and no automated decision-making that produces legal or similarly significant effects.

If this ever changes, we will update this section, change the "last updated" date, and — for anything material — tell you inside the app before it takes effect.

8. Server logs and diagnostics

This section applies only if you use a MoneyMate account. In local-only and Google-Sheet modes, our servers are not involved in your data at all.

Our API records aggregate performance figures: a per-minute count of requests, a count of server errors, and response-time percentiles. These rollups contain no IP addresses, no user identifiers, and no request contents — they exist so we can tell whether the service is healthy. They are automatically deleted after 7 days.

Separately, administrative actions taken by our own operators (signing in to the admin console, looking up an account to answer a support ticket, resolving a deletion request) are recorded in an audit log with the operator's IP address, for accountability. Those entries are automatically deleted after 90 days.

Like essentially every service on the internet, our hosting provider's web server also produces short-lived operational logs that may include your IP address, the time of a request, and the endpoint called. These are used solely to keep the service running and secure, and are rotated on a short cycle.

This website is covered separately in Cookies and website analytics below.

9. Cookies and website analytics

This section is about this website — the pages you are reading right now. It has nothing to do with the app. Everything in What we never do still holds: the MoneyMate app itself contains no analytics SDK, and none of your financial records are involved here.

In one line

This website uses Google Analytics to count visitors. It records page views and approximate location — never your financial records — and any tracker blocker stops it without breaking anything here.

What runs, and where

Every page on moneymate.texion.tech — including this one — loads Google Analytics 4 (measurement ID G-FCWXR02WT7). We use it to answer basic questions we otherwise cannot: how many people find the site, which countries they come from, and whether anyone reads far enough to reach the FAQ. It tells us nothing about you as an individual, and we never try to connect it to a MoneyMate account.

This applies to every page here, including the deletion request page. If you would rather not be counted while exercising a privacy right, use one of the opt-outs below first — they work across the whole site, and nothing stops working when analytics is blocked.

What it collects

  • The pages you view on this site and roughly how long you stay.
  • Approximate location — country or city level, derived from your IP address. Google discards the full IP address and does not log it.
  • Device, browser and screen size.
  • The site or search engine that referred you, if any.
  • A randomly generated identifier stored in cookies named _ga and _ga_FCWXR02WT7, which lets Google tell a returning visitor from a new one. It contains no name, email or account reference.

Google Analytics data is retained for 14 months and is then deleted automatically. We have not enabled Google Signals, advertising features, remarketing, or data sharing with other Google products, so this data is not used to build an advertising profile of you.

The other thing stored in your browser is a single localStorage entry remembering whether you chose light or dark mode. It is not a cookie, is never sent to us, and exists purely so the page does not flash white at you. Web fonts are served by Google Fonts, which means Google receives your IP address when a page loads — the same as on most of the web.

The cookie notice, and how to switch this off

The first time you arrive, a banner tells you that analytics is in use. It is a notice rather than a question — there is one button, and dismissing it records that you have seen it. We would rather say that plainly than show you a fake choice.

In the EU/EEA, the UK and Switzerland, where local rules are strictest, the tag is loaded through Google Consent Mode in a state that cannot write cookies. If you never interact with the notice, nothing is stored and you are never counted. Elsewhere, measurement begins when the page loads.

The controls that genuinely switch this off are the ones your browser gives you, and they work on every page here whatever our banner says:

  • Block cookies for this site in your browser settings.
  • Install Google's official Analytics opt-out browser add-on.
  • Use a browser or extension that blocks trackers — we do not attempt to work around these, and nothing on the site breaks when they are active.
  • Use the app instead. MoneyMate on your phone loads none of this — everything in this section is about the website only.

You can also object to this processing outright, or ask what we hold, by writing to contact@texion.tech. We will honour it — see Your rights.

Our lawful basis is our legitimate interest in understanding whether the site works (GDPR Art. 6(1)(f)) — not consent, which is why we do not describe the banner as one. We have weighed that interest against your privacy: the data is aggregate, carries no financial information, is never linked to a MoneyMate account, and is not used for advertising or profiling. Google acts as our processor for it, and as an independent controller for its own purposes under Google's Business Data Responsibility terms. Analytics data may be processed on Google servers outside your country; see International data transfers.

10. Why we process data, and our legal bases

For users in the EU/EEA and the UK, the GDPR requires us to name a lawful basis for each purpose. Ours are:

Purpose Data used Lawful basis
Providing the app itself (recording and displaying your finances) On-device data only Performance of a contract
Syncing your data to your account so it survives a lost phone Email, display name, synced records Performance of a contract
Syncing to your Google Sheet Google profile basics, synced records Consent (given when you grant the Google permission; withdrawable at any time)
Authenticating you and keeping accounts secure Email, session tokens, IP for abuse control Legitimate interests (securing the service)
Keeping the service reliable Aggregate metrics with no identifiers Legitimate interests (service continuity)
Answering support and rights requests Your email and what you tell us Legal obligation and legitimate interests
Measuring visits to our home page Page views, approximate location, device and browser, an anonymous cookie identifier Legitimate interests (knowing whether the site works) — see section 9

11. How long we keep data

  • On-device data — until you delete it, or uninstall the app. We have no control over and no visibility into this.
  • Synced account data — for as long as your account exists. When you delete your account, it is erased as described in section 14.
  • Aggregate performance metrics — 7 days, automatically.
  • Administrative audit entries — 90 days, automatically.
  • Deletion requests — the record of the request itself (email address, date, outcome) is retained for up to 12 months after it is completed, so we can demonstrate that we honoured it. This is a legal-accountability record, not a copy of your finances.
  • Support emails — up to 24 months, so we have context if you write again.
  • Google Analytics data for our home page — 14 months, after which Google deletes it automatically.

12. Who else touches your data

We do not sell your data, and we share it only with the small number of providers needed to run the service:

Provider Role Applies when
Our hosting provider Runs the servers and database that store synced account data You use a MoneyMate account
Texion authentication service Handles sign-in, session tokens and password/OAuth flows on our behalf You create an account
Google Sign-in provider and, if you choose it, the destination for your spreadsheet You sign in with Google or use Sheets sync
Google Play / Apple App Store Distribute the app; they independently collect their own install and purchase data under their own policies You install the app
Google Analytics Counts visitors to our home page — no financial data and no account identifiers are ever sent to it You visit this website's home page

We may also disclose data if we are legally required to by a valid order from a competent authority, or where it is strictly necessary to establish, exercise, or defend legal claims, or to prevent fraud or a security threat. If we ever receive such a demand, we will notify the affected user unless the law forbids it.

If MoneyMate is ever transferred to another owner, your data may transfer with it. You will be told in advance and given the chance to delete your account first.

13. Your rights

Wherever you live, you can exercise all of the rights below by emailing contact@texion.tech. We do not charge for this and we will not make the app worse for you because you asked.

Everyone

  • Access — get a copy of the personal data we hold about you.
  • Correction — fix anything inaccurate. Most fields you can edit yourself in the app.
  • Deletion — have your account and synced data erased. See section 14.
  • Portability — receive your data in a structured, machine-readable format. Your data is already portable by design: the app exports PDF reports, and Sheets sync puts everything in a spreadsheet you own.
  • Withdraw consent — disconnect Google, or switch back to local-only mode, at any time in Settings.

EU / EEA and UK (GDPR)

You additionally have the right to restrict or object to processing based on our legitimate interests, and the right to lodge a complaint with your national data protection authority. We would appreciate the chance to put things right first.

California (CCPA / CPRA)

You have the right to know what personal information is collected and for what purpose, to request deletion or correction, and to opt out of sale or sharing — and we make that last one easy by never selling or sharing personal information at all. We do not offer financial incentives in exchange for data, and we will not discriminate against you for exercising any right.

Other jurisdictions

Users elsewhere — including under Brazil's LGPD, Canada's PIPEDA, and Australia's Privacy Act — have comparable rights, and we apply the same process to all requests regardless of where you are.

14. Deleting your data

There are two ways, and both work.

In the app

Open Settings and use the close-account option. In local-only mode this wipes the on-device database immediately and permanently. With an account, it signs you out and clears local data; use the web form below to have the server-side copy erased too.

On the web — no app needed

Go to moneymate.texion.tech/delete-account and submit the form. You can ask us to delete your entire account, or just your financial records while keeping the sign-in. You will get a reference number.

We verify that the request genuinely comes from the account holder before erasing anything — usually by replying to the email address on the account. Once verified, we complete deletion within 30 days, and normally much sooner.

What gets erased: your account record, email, display name, avatar reference, preferences, and every synced transaction, category, budget and recurring rule.

What does not: the accountability record of the deletion request itself (section 11), and anything living in your own Google Sheet — that spreadsheet is in your Drive, so only you can delete it. Backups are purged on their normal rotation, within 90 days at the outside.

15. How we protect your data

  • All network traffic between the app and our servers is encrypted with TLS.
  • Your on-device database sits in the app's private storage, unreadable by other apps.
  • Optional app lock with PIN or biometrics, so a borrowed phone does not expose your finances.
  • Sign-in tokens: short-lived access tokens (15 minutes), with the long-lived refresh token held in the platform's hardware-backed secure storage — the Android Keystore or the iOS Keychain — not in ordinary app preferences.
  • Signing out invalidates every server session for your account, not just the one on that phone.
  • Administrative access to production data is restricted, individually authenticated, and audit-logged.

No system is perfectly secure. If a breach ever affects your personal data, we will notify affected users and the relevant supervisory authority without undue delay, and within 72 hours where the GDPR requires it.

16. International data transfers

MoneyMate is operated from Bangladesh, and our servers may be located outside your country. If you are in the EU/EEA or the UK, this means your data may be transferred to a country that has not received an adequacy decision. Where that happens, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) together with the technical measures in section 15. You can request details of the safeguards in place by emailing us.

In local-only mode, no transfer happens at all — your data never leaves your device.

17. Children

MoneyMate is a general-audience personal finance tool and is not directed to children. We do not knowingly collect personal information from anyone under 13, or under the higher minimum age that applies where you live (16 in parts of the EU). If you believe a child has provided us with personal data, contact us and we will delete it promptly.

18. The Bangladesh edition

A separate edition of MoneyMate is distributed in Bangladesh through mobile-operator channels. If — and only if — you are using that edition, two additional things apply:

  • Sign-up uses your mobile number with a one-time SMS code. Your number is processed to verify you and to link your operator subscription.
  • Access is tied to a subscription billed by your mobile operator. The operator and its aggregator process your number and billing status; their own privacy terms apply to that processing, alongside this policy.

The edition published on Google Play worldwide does not use phone verification or carrier billing, and requires no account at all to get started.

19. Changes to this policy

We will update this page when the app changes. The "last updated" date at the top always reflects the current version. For material changes — a new category of data, a new recipient, a new purpose — we will give notice inside the app before the change takes effect, and where the law requires it, ask for your consent.

Continuing to use MoneyMate after a change takes effect means you accept the updated policy.

20. Contact us

Email: contact@texion.tech
Delete your data: moneymate.texion.tech/delete-account
Terms of Service: moneymate.texion.tech/terms

Write in English or বাংলা — both are fine. Please put "Privacy" in the subject line so it reaches the right place quickly.