Last updated: 2026-08-18
This policy describes how Moneyflowr processes personal data. It reflects what the application actually does; no processing is listed here that does not take place.
The controller within the meaning of Art. 4(7) GDPR is the operator named in the legal notice. Contact details are listed there.
Account data: name, email address, password (stored only as a bcrypt hash), Google account ID and Telegram ID or username where you sign in with those, plus your language, time zone, base currency and plan.
Content you enter: expenses, accounts and balances, investments, savings goals, recurring payments, debts, categories and budgets.
Company mode (Pro): your company details and the client records you create, including client name, email address, phone number, postal address and notes, along with the invoices you issue.
AI assistant: the messages you send and any image you attach, stored with your chat history so you can read it again later.
Issue reports: if you report a problem from within the app, the message you write is stored with your account and deleted together with it.
Technical data: your IP address is evaluated in memory to rate-limit sign-in and admin PIN attempts. It is not written to any database or log file and is discarded when the time window expires.
Providing the account and every feature you use is processing for the performance of a contract, Art. 6(1)(b) GDPR. Without this data the service cannot be provided.
Rate limiting sign-in and admin attempts protects accounts against brute-force attacks and rests on our legitimate interest, Art. 6(1)(f) GDPR.
Optional features you switch on yourself rest on your consent, Art. 6(1)(a) GDPR: loading the Telegram login widget, linking a Telegram account, the notification messages you enable in settings, and the AI assistant. You can withdraw consent at any time with effect for the future.
Moneyflowr uses two cookies. Both are strictly necessary to deliver the service you requested and are therefore exempt from consent under §165(3) Austrian Telecommunications Act 2021. There is no consent banner because there is nothing optional to consent to.
ft_session — keeps you signed in. Encrypted, HttpOnly, SameSite=Lax, valid for up to one year. It contains only a session identifier that can be revoked server-side.
google_oauth_state — a random value that protects the Google sign-in flow against cross-site request forgery. HttpOnly, valid for 10 minutes, deleted as soon as sign-in completes.
No analytics, advertising, tracking or profiling cookies are set. The application does not use localStorage or sessionStorage, and no analytics or tracking service is embedded anywhere in it.
The Inter typeface is downloaded at build time and served from our own server. Your browser makes no request to Google when a page loads, and no IP address is transmitted to Google for fonts.
Hetzner Online GmbH, Nuremberg, Germany — hosting of the application and the database. Data stays within the EU.
OpenRouter, Inc. (USA) and, through it, Google as the model provider — used only when you use the AI assistant or send an expense to the bot in free text. For the assistant, a snapshot of your financial context is transmitted: account balances, budgets, recent expenses, goals, upcoming recurring payments and debts, plus any image you attach. In Company mode the snapshot adds invoice numbers, amounts, due dates and status; client names and contact details are deliberately excluded, so no data identifying your clients is sent.
Resend (USA) — delivers password reset emails. Receives your email address and the reset link.
Telegram — if you use the bot, the login widget or the Mini App. Receives the messages you exchange with the bot and, when the widget or Mini App loads, your IP address and browser details.
Google — only if you choose to sign in with Google. We receive your Google ID, email address and name.
Exchange rates and market prices are fetched by our server, which sends only a currency code or a ticker symbol. No personal data of yours reaches those services, and your browser never contacts them.
Using the AI assistant transfers data to the USA (OpenRouter and the model provider). Password reset emails are delivered via a provider in the USA. Telegram processes data outside the EU. These transfers only happen for the features named above; if you do not use them, no such transfer takes place.
Account and content data is kept until you delete your account, which removes it permanently along with everything linked to it: finances, company and client records, invoices, chat history and issue reports. Password reset tokens expire after one hour, pending bot entries after their short timeout, and expired sessions are cleared automatically every hour. Two records outlive the account by design: usage counters for the AI features keep only token totals, with your user ID stripped out on deletion, and if an administrator ever changed your plan, that change stays in an audit record identified by the ID of the now-deleted account.
You have the right to access, rectification, erasure, restriction of processing, data portability and objection under Art. 15 to 21 GDPR. Two of these you can exercise yourself at any time: Settings offers a CSV export of your data, and the same page deletes your account and all associated data. For anything else, contact us at the address in the legal notice.
If you believe your data is being processed unlawfully, you can lodge a complaint with the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, dsb@dsb.gv.at, +43 1 52 152-0.
If you use Company mode to store client records and issue invoices, you decide what is stored about those people. For that data you are the controller and we act as your processor. The agreement Art. 28 GDPR requires is the one you accept when activating Company mode; you can read it at any time.
There is no automated decision-making or profiling with legal effect within the meaning of Art. 22 GDPR. The AI assistant produces suggestions and summaries; it makes no decisions about you.