Privacy Policy
Last updated: 22 July 2026
At Monestic we handle your data —including the financial data you choose to record— with the utmost care and solely to provide the service. This policy explains what information we process, on what legal basis, who we share it with, and the rights you have.
1. Data controller
The controller of your data is Birrastorming Ideas S.L., tax ID B98498496, with registered address at [REGISTERED ADDRESS] (hereinafter “Monestic”, “we”).
- Privacy contact: privacidad@monestic.com
- Data Protection Officer (DPO), where applicable: [DPO EMAIL]
2. What data we process
We only process the data needed to provide the service:
Data you provide
- Account and identity data: name, email address and login credentials.
- Financial data you choose to record: income, expenses, assets, net worth, debts and financing, categories, savings goals and the projections derived from them. This data is stored at your discretion: you decide what you record and can delete it at any time.
- Household data you choose to add to organise your finances. If you include third-party information, you warrant that you are entitled to do so.
- Communications: messages you send us via support or contact.
Data generated through use
- Technical and usage data: IP address, session identifier, device and browser type, and activity logs required for security and operation of the service.
- Cookies and similar technologies that are strictly necessary, and others only with your consent (see section 12).
We do not knowingly request or process special categories of data (health, beliefs, biometrics, etc.). Please do not enter such information in free-text fields.
3. Purposes of processing
- Create and manage your account and give you access to the service.
- Record your financial information and generate calculations, summaries and projections from the data you enter.
- Provide support, handle your requests and communicate with you about the service.
- Ensure security, prevent fraud and unauthorised access, and maintain backups.
- Comply with our legal obligations.
- Send you marketing communications about Monestic only with your consent, which you may withdraw at any time.
We do not sell your data, nor use it for profiling with legal effects or for third-party advertising.
4. Legal basis
- Performance of a contract (Art. 6(1)(b) GDPR): providing the service you request when you register.
- Consent (Art. 6(1)(a) GDPR): bank connection, non-essential cookies and marketing communications. It is free and revocable.
- Legitimate interest (Art. 6(1)(f) GDPR): service security and fraud prevention, balanced against your rights.
- Legal obligation (Art. 6(1)(c) GDPR): where we must retain or disclose data by law.
5. Financial data and bank connection
Financial data is especially sensitive to you, so we protect it with reinforced measures (encryption in transit and at rest, access control and data minimisation).
- We never store your online banking credentials. If you choose to connect a bank account, you do so through an authorised account-aggregation provider under PSD2 ( Enable Banking), which acts as a processor and with whom you authenticate directly.
- Bank connection is optional and requires your explicit consent. You may revoke it at any time from the app, which stops access to new information.
- We only process the account and transaction information needed for the features you enable, never for purposes unrelated to the service.
6. Recipients and processors
We do not transfer your data to third parties except where legally required. To operate the service we rely on providers acting as processors under contract pursuant to Art. 28 GDPR:
- Hosting and infrastructure: Vercel Inc.
- Database and authentication: Supabase.
- Bank aggregation (if you enable it): Enable Banking (Enable Banking Oy), authorised as an account information service provider under PSD2.
- Email and notifications: [EMAIL PROVIDER].
These providers only process data on our instructions and with the safeguards required by law.
7. International transfers
Some providers may process data outside the European Economic Area. In that case, the transfer relies on a European Commission adequacy decision or on Standard Contractual Clauses, together with additional measures ensuring a level of protection equivalent to the GDPR.
8. Retention
We keep your data while your account remains active and you retain it. If you delete specific data or your account, we erase or anonymise it, except data we must keep blocked for applicable legal periods (for example, to address potential liabilities). Backups are rotated and deleted under our internal policy.
9. Security measures
We apply technical and organisational measures appropriate to the risk, including: encryption of communications (HTTPS/TLS) and of data at rest, role-based access control and isolation per user or household, activity logs, backups and regular reviews. No system is infallible, but we work to reduce risk to a reasonable minimum. In the event of a breach affecting your rights, we will act under Arts. 33 and 34 GDPR.
10. Your rights
You may exercise at any time your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw the consents you have given, by writing to privacidad@monestic.com. We may ask you to verify your identity. We will respond within the legal deadlines.
If you believe we have not handled your rights properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or your local supervisory authority.
11. Minors
Monestic is intended for people over 18. We do not knowingly collect data from minors. If we detect such data, we will delete it.
12. Cookies
We use strictly necessary cookies for the site to work and, only with your consent, other analytics or preference cookies. You can manage them at any time. See the details in our Cookie Policy.
13. Changes to this policy
We may update this policy to reflect legal or service changes. We will publish the current version on this page, stating the last-updated date, and notify you of material changes by reasonable means.
14. Contact
For any question about this policy or the processing of your data, write to privacidad@monestic.com.