Privacy notice

Updated 1 month ago Version 2 — last updated: 2026-08-09

This notice explains how Moneyka processes personal data when you visit our public pages, register, and use the personal finance service. It describes what personal data we process, why, for how long, who receives it, and what rights you have under the General Data Protection Regulation (GDPR).

Read this notice together with our Cookie Policy and Terms of Service.

Who is responsible for your data

Moneyka is a personal-finance web application operated by Pavel Vlk, a self-employed sole trader registered in the Czech Republic under Business ID (IČ) 87427770 and Tax ID (DIČ) CZ8907162748, with registered address at Maršíkova 601/3, 460 06 Liberec - Liberec VI-Rochlice, Czech Republic. Use the contact address below for every privacy question or request.

Privacy contact: info@moneyka.cz.

Data protection officer

Moneyka has not appointed a statutory Data Protection Officer because, at our current scale and business model, the appointment conditions under Article 37 GDPR are not met. A designated privacy contact handles every data-protection question, request, and incident at the address above.

Personal data we process and why

The table below lists each activity for which we process personal data, the data categories involved, the purpose, and the legal basis under Article 6 GDPR.

Activity Data we process Purpose Legal basis
Registration, sign-in, and profile E-mail address, password hash, and your chosen locale, timezone, currency, and theme Create and secure your account, verify your e-mail, reset your password, and remember your preferences Performance of the contract you request when creating an account (Art. 6(1)(b)); legitimate interest in preventing account abuse (Art. 6(1)(f))
Recording your personal finances Accounts, transactions, categories, tags, descriptions, recurring templates, alarms, and statistics that you create Provide the core budgeting and finance-tracking features you use Performance of the contract (Art. 6(1)(b))
Importing bank statements Uploaded bank-export files, column mappings, import rules, import history, and deduplication identifiers Let you bulk-import transactions from your bank and avoid duplicate entries Performance of the contract (Art. 6(1)(b))
Avatars and transaction attachments Your avatar image and any receipt or attachment images you upload, including temporary copies during processing Display your profile picture and attach supporting documents to your transactions Performance of the contract (Art. 6(1)(b))
AI-assisted transaction entry and import setup (optional) Prompt text, receipt images, voice recordings, or bounded bank-export samples you submit; your finance context; the provider's response; usage and cost metadata; your own encrypted API key for the provider you selected (Anthropic, OpenAI, or Google Gemini) Let you use the optional AI feature to transcribe voice notes, analyse receipts, suggest transactions, and propose import structure and column mappings when you choose to enable it and supply your own provider API key Performance of the contract, only when you actively invoke this optional feature (Art. 6(1)(b))
Environment detection and cookies IP address (used only for a local, one-hour country/city lookup and never sent to a third party), detected locale/timezone, session identifier, "remember me" state, and your cookie-consent choice Show the app in your language and timezone, keep you signed in, and remember your cookie choices Necessary for the service you request (Art. 6(1)(b)); legitimate interest in a secure session (Art. 6(1)(f)); your consent for any non-essential storage (Art. 6(1)(a))
Transactional e-mail Your e-mail address, message subject and body, and delivery status and timestamps Send registration confirmation, password-reset, and security- or service-related messages Performance of the contract and legitimate interest in warning you about account-security events (Art. 6(1)(b) and (f))
Notifications and finance alarms Alarm thresholds you configure, generated notifications, and their read/archive status Alert you about the financial events you asked to be notified of Performance of the contract (Art. 6(1)(b))
Security, logs, and abuse prevention Server and application logs, authentication events, administrator actions, IP address, and request metadata Keep the service secure, detect and investigate abuse, and maintain accountability Legitimate interest in protecting confidentiality, integrity, and availability (Art. 6(1)(f)); legal obligation where one specifically applies (Art. 6(1)(c))
Support and exercising your rights The information you provide in your request plus what is strictly necessary to verify and answer it Respond to support requests and to requests to exercise your GDPR rights Performance of the contract, compliance with our legal obligations under GDPR, and legitimate interest in defending against unfounded claims (Art. 6(1)(b), (c), and (f))
Backups and service continuity A rolling copy of the database content described above Restore the service after a technical or security incident Legitimate interest in service resilience (Art. 6(1)(f)); a backup does not create a new purpose for the underlying data

Who receives your data

We share personal data only with the recipients below, and only to the extent necessary for the purpose stated.

Recipient Data disclosed Reason
Our hosting provider All data described in this notice, because it is stored and processed on the servers we operate through this provider Hosting and operating the service
Our transactional e-mail provider Your e-mail address, message content, and delivery metadata Sending the transactional messages described above
The AI provider handling your request — either one you select (Anthropic, OpenAI, or Google Gemini) using your own key, or, for a limited free allowance without a key, Moneyka's own OpenAI or Anthropic account Only if and when you use the optional AI feature: your prompt, receipt image, audio, bounded bank-export sample, and finance context, plus your own API key if you configured one — Moneyka's key is used instead when you have not, and is never shown to you Performing the AI analysis you requested
Authorised Moneyka personnel The minimum data necessary for the task at hand Providing support, administration, and security operations
Authorities, courts, or legal/security advisers The minimum data legally required Complying with a legal obligation or defending a legal claim

We do not sell personal data and we do not share it for advertising. Moneyka does not currently use any analytics or advertising service.

International data transfers

Some of the recipients above may process data outside the European Economic Area (EEA), depending on their own infrastructure and sub-processors. Before we enable a recipient that transfers data outside the EEA, we confirm an appropriate safeguard, such as an EU adequacy decision or Standard Contractual Clauses with supplementary measures, and we record that assessment internally. If you use the optional AI feature with your own key, the provider you choose may process your data internationally under its own terms; review the relevant provider's terms before enabling that feature. If you use the free allowance without a key, the same international-transfer considerations apply to Moneyka's own account with that provider, and we do not enable that path until the corresponding safeguard is confirmed. We keep an internal register of providers, their processing location, and the applicable safeguard, and we update it whenever a provider or its terms change.

How long we keep your data

We keep personal data only as long as necessary for the purpose it was collected for, subject to the periods below.

Data Retention period
Active account and its finance data For as long as your account is active; deleted within 30 days of a verified account-closure request
Unverified registration and password-reset tokens Unverified accounts removed 7 days after the last activation e-mail; used or expired reset data cleared within 30 days
Terms and privacy acceptance evidence Duration of your account plus 3 years after closure
Bank-import temporary files 24 hours after upload
Bank-import detailed rows and original filenames 90 days after the import run
Avatar and transaction attachment images Until you replace or delete them, or your account is closed; unattached temporary images are removed after 24 hours
AI request content (transcripts, structured output, error text) 30 days; anonymised usage and cost statistics are kept up to 12 months
Sent transactional e-mail content 30 days after sending; 90 days if delivery failed, for troubleshooting
Session, "remember me", and preference cookies See our Cookie Policy for the exact duration of every cookie
Application, security, and access logs Up to 90 days for routine logs
Administrator impersonation audit trail 12 months from the event
Database backups Rolling 7-day generations

These are the retention periods we are implementing. Some automated deletion jobs are still being rolled out, and a specific legal or contractual requirement may extend the retention of an individual record.

Your rights

Under the GDPR, you have the right to:

  • Access – request confirmation of and a copy of the personal data we hold about you
  • Rectification – ask us to correct inaccurate or incomplete data
  • Erasure – ask us to delete your data where no overriding legal ground applies
  • Restriction – ask us to limit processing in specific circumstances
  • Portability – receive certain data in a structured, machine-readable format
  • Objection – object to processing based on our legitimate interest
  • Withdraw consent – withdraw consent at any time for processing based on consent, without affecting past lawfulness
  • Complaint – lodge a complaint with a supervisory authority (see below)

To exercise any of these rights, contact us at info@moneyka.cz. We may ask you to verify your identity before acting on a request, and we will respond within the time limits set by the GDPR.

Filing a complaint with a supervisory authority

If you are in the Czech Republic, you can lodge a complaint with the Office for Personal Data Protection (Úřad pro ochranu osobních údajů): Pplk. Sochora 27, 170 00 Praha 7, Czech Republic; phone +420 234 665 111; website uoou.gov.cz. You may also complain to the supervisory authority of your own EU/EEA country of residence, place of work, or the place where the alleged infringement occurred.

Automated decision-making

Moneyka does not use your data for solely automated decisions that produce legal or similarly significant effects on you. Statistics, import rules, alarms, and AI-generated suggestions always require your review and confirmation before a transaction is created or changed.

Sensitive information

Moneyka does not intentionally ask for special categories of data, such as health, religious, political, or trade-union information. However, free-text descriptions, receipts, bank exports, or voice recordings you submit could incidentally contain such details about you or someone else. Please avoid including unnecessary sensitive information, especially about other people, in the content you submit.

Children

Moneyka is intended for adults managing their own personal finances. We do not knowingly offer the service to children. If you believe a child has provided us with personal data, contact us so we can remove it.

Changes to this notice

We may update this notice as the service, our providers, or the law change. We will update the date at the top of this page and, for material changes, provide additional notice such as an in-app message or e-mail.