Skip to main content
MONVELOP

Privacy Policy

This policy explains how MONVELOP handles account and budgeting data, optional read-only bank data and an optional read-only ChatGPT connection.

Effective: 29 August 2026support@monvelop.com

1. Who controls your data

The operator of MONVELOP is the controller of personal data processed to provide the application. Privacy and data-rights requests can be sent to support@monvelop.com.

MONVELOP is a budgeting tool. It is not a bank, payment institution or financial adviser, and it cannot initiate payments from your bank account.

2. Data we process

  • Account data: email address, preferred language, account identifiers and timestamps.
  • Authentication data: a password hash, session and password-reset token hashes, Google account identifier and login-security records. MONVELOP never receives your Google password.
  • Bank-connection data: provider, selected institution, connection and account identifiers, currency, connection status and synchronization timestamps.
  • Financial data: balances and transactions you enter manually, plus any account balances and transaction amount, date, merchant, description, category, booking status and related identifiers imported after an optional bank connection.
  • Budgeting data: income plans, envelopes, allocations, transfers, merchant rules, alerts, insights and choices made during onboarding.
  • ChatGPT connection data: the scopes you approve and OAuth authorization, access and refresh-token records needed to keep the optional connection active. MONVELOP does not receive your ChatGPT password.
  • Technical and support data: IP address and login results used for abuse prevention, plus the topic and content of messages sent to support.
  • Device-local data: language preference and unfinished onboarding choices may be stored in the browser on that device.

3. Where data comes from

Most data comes directly from you, including manual balances, income and expenses. Only when you choose to connect a bank are account balances and transaction data obtained from your financial institution through GoCardless Bank Account Data after you authorize access.

MONVELOP does not receive or store your online-banking password. Bank access is read-only and does not allow MONVELOP to make payments.

4. Why we use data and our legal bases

  • To create and operate your account, store manual entries, optionally synchronize authorized bank data, build budgets and provide requested features — performance of our service agreement.
  • To protect accounts, prevent abuse, investigate failures and maintain service reliability — our legitimate interests in security and operation.
  • To send password-reset and support messages — performance of the requested service and our legitimate interest in assisting users.
  • When you choose to connect ChatGPT, to provide the specific read-only financial information requested through the scopes you approved — your consent and performance of the feature you requested.
  • To comply with binding legal requests and applicable obligations — compliance with law.
  • Where processing relies on consent, you may withdraw it without affecting processing already carried out.

5. Who may receive data

MONVELOP does not sell personal data and does not use bank transaction data for third-party advertising.

  • GoCardless Ltd. and your financial institution, for read-only open-banking access that you authorize.
  • Google, when you choose Sign in with Google and when configured email infrastructure delivers password-reset or support email.
  • OpenAI and ChatGPT, only when you explicitly connect ChatGPT and it invokes a MONVELOP tool. The response may include balances, budget summaries, transaction details or subscription details covered by the scopes you approved.
  • Infrastructure providers used to host the application, databases and network services, acting under appropriate contractual safeguards.
  • Professional advisers, authorities or courts when disclosure is required by law or necessary to establish or defend legal claims.

6. Retention and deletion

Signed-in users can permanently delete their account in Account settings. If you cannot sign in, use the public account-deletion page and confirm the request with the one-time link sent to your email address. Limited records may be retained only where required for security, legal obligations or claims.

  • When you delete your account, MONVELOP removes the operational profile, bank connection, imported transactions and budgeting data. The GoCardless requisition is revoked before local financial data is removed.
  • Refresh sessions expire after 30 days; expired records are removed by an automated cleanup process.
  • Password-reset links expire after 30 minutes and are stored only as cryptographic hashes.
  • MONVELOP keeps ChatGPT OAuth consent and token records only while the connection is active, until they expire, or until you disconnect ChatGPT or delete your account. Data retained by OpenAI is governed by your ChatGPT plan, settings and OpenAI's policies.
  • Security logs and support correspondence are kept only as long as reasonably necessary to prevent abuse, resolve the request and meet legal obligations.
Request account deletion

7. Security, rights and choices

We may update this policy when the product, providers or legal requirements change. The effective date will be updated and material changes will be communicated where required.

  • Access tokens are short-lived; refresh sessions use an HttpOnly cookie, and stored reset/session tokens are hashed.
  • Signed-in users can download a machine-readable ZIP export from Account settings after confirming their identity.
  • You may request access, correction, deletion, restriction, portability or object to processing where GDPR provides that right.
  • You may withdraw consent and complain to your competent supervisory authority; in Poland this is the President of the Personal Data Protection Office (UODO).
  • You can review and disconnect ChatGPT in Account settings at any time. Disconnecting revokes MONVELOP OAuth authorizations and consent, but does not delete data already present in your ChatGPT conversations; manage those conversations in ChatGPT.
  • MONVELOP may generate budgeting insights and categorization suggestions, but it does not make decisions that produce legal or similarly significant effects.
  • MONVELOP is not directed to children. A parent or guardian should contact us if a child supplied personal data.

Provider privacy information