Data controller
The controller of your personal data is:
monni acts as the data controller for the data it collects from its users, including the banking data it receives through Open Banking. The providers that help us deliver the service — Yapily for the bank connection and Anthropic for the AI models, among others — act as data processors under our instructions (see sections 05, 06 and 09).
We have not appointed a Data Protection Officer (DPO), as the conditions of art. 37 GDPR do not currently apply. For any privacy matter, the contact channel is sacurio@vaultitech.com. We will review this decision before the general launch of the service.
Data we collect
We collect only the data needed to provide the service:
Data you give us
- Account and sign-up: name, email and password (stored with bcrypt hashing, never in plain text).
- Waitlist: email, language and details of your sign-up request. To evidence your consent we store the version of the text you accepted, the date, your browser and a hash of your IP address (never the IP itself), along with the campaign parameters you arrived with.
- Settings and corrections: categories, budgets, subscriptions and any correction you make to what monni detects automatically.
- Communications: messages you send us by email or support, and the messages you write in the financial chat.
Banking and financial data (Open Banking)
- Account information: IBAN, ownership, account type, currency, available balance and book balance.
- Transaction history: amounts, dates, descriptions, merchants and any counterparty data your bank provides.
- Account holder identity data provided by your bank.
Automatically generated data
- Technical and server log data: IP address, device type, operating system, app version and the requests made to our API with their timestamp.
- Error logs for diagnostics and service improvement.
- Data derived from the analysis: assigned categories, detected subscriptions, spending patterns and monthly financial profile (see section 06).
Data we do NOT collect
- Banking credentials (your bank username and password). We never ask for them and they can never reach us.
- Special categories of data under art. 9 GDPR: racial or ethnic origin, health, sexual orientation, beliefs, trade union or political affiliation. If a bank description were to indirectly reveal such data, we treat it as any other financial data and never use it to segment you.
- Geolocation data.
- Data of persons under 18 (see section 12).
- We do not build creditworthiness profiles, nor do we query or feed debtor registries (ASNEF, Experian, Badexcug or others).
Legal basis for processing
In accordance with the GDPR and Spanish Organic Law 3/2018 (LOPD-GDD), we process your data on the following bases:
Where processing is based on your consent, you can withdraw it at any time without affecting the lawfulness of processing carried out beforehand.
Where we rely on legitimate interest, we have carried out the corresponding balancing test between that interest and your rights. You can request a copy of that assessment at sacurio@vaultitech.com.
Purposes of processing
We use your data to:
- Deliver the service: connect your accounts, categorise transactions, detect subscriptions, generate your budget and show you your financial position in real time.
- Answer your questions: the financial chat uses your economic context to give you answers about your own situation.
- Personalise the experience: tailor analysis, alerts and suggestions to your real situation.
- Tell you about important changes: service notifications, security and changes to this policy.
- Marketing (only with your consent): news, financial tips and early access to features.
- Prevent fraud: detect unauthorised access and protect the integrity of your account.
- Improve the service: technical diagnostics and aggregate analysis to optimise the experience.
- Meet legal obligations: respond to requests from competent authorities.
We do not use your data for third-party advertising, we never sell it, and we do not disclose it to financial institutions, insurers, employers or credit scoring registries.
Open Banking and Yapily
To connect your bank accounts, monni uses Yapily Ltd., an Account Information Service Provider (AISP) authorised and regulated under the PSD2 Directive. Yapily acts as a data processor under our instructions, through the contract required by art. 28 GDPR.
How the connection works
- monni redirects you to your bank’s authentication portal.
- You authenticate directly with your bank (monni never sees your credentials).
- Your bank issues an authorisation token with the scope you approved.
- Yapily uses that token to retrieve the data, which it transmits to us encrypted.
Scope of access
- Read-only: monni cannot initiate payments or move money.
- Bank consent lasts a maximum of 90 days under PSD2, and renewing it requires you to authenticate with your bank again.
- You can revoke access at any time from monni or directly at your bank. Once revoked, we immediately stop receiving new data.
Manual statement import
As an alternative to the automatic connection, monni lets you import a statement you have downloaded from your bank. In that case the data reaches our servers directly, without Yapily being involved, and is treated exactly like data obtained via Open Banking.
Data held by Yapily
Yapily keeps its own records of the access in line with its regulatory obligations as a supervised entity. If you want to exercise your rights directly against Yapily you can do so through their privacy policy; you can also channel the request through us at sacurio@vaultitech.com.
Artificial intelligence and profiling
monni uses large language models (LLMs) from Anthropic PBC (Claude) to make sense of your transactions. This section explains exactly what data leaves our servers for the model, under what safeguards, and which decisions are made automatically.
What we send to the model
Safeguards with the model provider
- Anthropic acts as a data processor, subject to the data processing agreement (DPA) required by art. 28 GDPR.
- Data sent through their API is not used to train their models. This is a contractual obligation in their commercial terms, not a setting that depends on a checkbox.
- API operational logs are retained for a short, limited period and deleted automatically.
- Processing takes place on servers located in the United States, covered by Standard Contractual Clauses (see section 09).
- Anthropic may rely on infrastructure sub-processors, bound by the same obligations.
Profiling and automated decisions
Analysing your transactions builds a financial profile — dominant categories, spending patterns, recurring charges and saving capacity — through automated processing. This constitutes profiling within the meaning of art. 4.4 GDPR, and its only purpose is to show you your situation and suggest adjustments.
We do not make automated decisions producing legal effects or similarly significantly affecting you within the meaning of art. 22 GDPR. monni does not grant or deny credit, does not compute a creditworthiness score, does not set prices based on your profile and does not share your profile with financial institutions, insurers or employers.
Every suggestion from the model is an editable proposal: you can correct any category, amount or detected subscription, and your correction overrides the model’s and shapes the ones that follow.
Limits of the AI and your control
- The AI can be wrong. Its output is indicative and does not constitute regulated financial, tax or investment advice.
- Do not type passwords, credentials, health data or other sensitive data into the chat: we do not need them and they would be sent to the model along with your question.
- AI categorisation is a core function of monni and cannot be switched off on its own without emptying the service of its purpose. You can, however, manually correct any result, stop using the chat whenever you want, and delete your account at any time.
- If you have questions about how a specific result was produced, write to sacurio@vaultitech.com and we will explain it.
Data retention
We keep your data only for as long as each purpose requires:
Once these periods elapse, data is securely deleted or irreversibly anonymised for aggregate statistical use.
While a claim, dispute or legal request is ongoing, we may block the strictly necessary data for the duration of the proceedings, in accordance with art. 32 LOPD-GDD.
Recipients and transfers
Service providers
We share your data only with the providers that allow us to deliver the service, all of them bound by the data processing agreement required by art. 28 GDPR:
These providers may in turn rely on sub-processors — for example, cloud infrastructure providers — contractually bound by the same obligations. You can request the up-to-date list of sub-processors at sacurio@vaultitech.com.
We may also disclose data to public authorities, courts or law enforcement where there is a legal obligation or a valid request.
International transfers
Transfers to the United Kingdom rely on the European Commission adequacy decision, renewed on 19 December 2025 (art. 45 GDPR): no additional safeguards are required.
Transfers to the United States are made under the Standard Contractual Clauses approved by the European Commission (art. 46.2.c GDPR), supplemented by the technical measures described in sections 06 and 11 — in particular, the fact that we send no direct identifiers to the AI models. You can request a copy of these safeguards.
We do not sell your data to third parties, we do not share it with advertisers, and we do not disclose it for creditworthiness assessment.
Your rights
As a user in the EU, the GDPR grants you the following rights:
- Access (art. 15): request a copy of the data we process about you.
- Rectification (art. 16): correct inaccurate or incomplete data.
- Erasure (art. 17): have your data deleted when it is no longer necessary.
- Portability (art. 20): receive your data in a structured, machine-readable format.
- Objection (art. 21): object to processing based on legitimate interest.
- Restriction (art. 18): restrict processing while a dispute is resolved.
- Not to be subject to automated decisions (art. 22): monni makes no such decisions (see section 06), but you can ask us at any time for a human explanation of any result of the analysis.
- Withdraw consent: at any time, without retroactive effect.
How to exercise your rights
Write to sacurio@vaultitech.com stating the right you wish to exercise. We may ask you to prove your identity if we have reasonable doubts about who is making the request. We will respond within one month, extendable by two further months for particularly complex requests, in which case we will tell you why.
Deleting your account
You can delete your account from within the app. When you do, we immediately revoke access to your bank accounts and disable access to your data; final erasure or anonymisation completes within a maximum of 30 days, except for data we must retain by legal obligation (see section 08).
Complaints to the AEPD
If you believe we have infringed your rights, you can lodge a complaint with the Spanish Data Protection Agency (AEPD). We would appreciate the chance to resolve it first.
Security
We apply technical and organisational measures to protect your data against unauthorised access, loss or accidental destruction:
- Encryption in transit via TLS across all communications between the app, our API and our providers.
- Encryption at rest of the database (AES-256), managed at infrastructure level by our hosting provider.
- Passwords stored with bcrypt hashing: never kept in plain text and not recoverable, not even by us.
- Authentication via short-lived tokens with refresh; on your device they are kept in the operating system’s secure store (Keychain on iOS, Keystore on Android).
- Counterparty IBANs are stored as a cryptographic hash rather than in plain text, so we can recognise a recurring destination without keeping the account number.
- HTTP security headers, strict input validation and rate limiting to stop automated attacks.
- Access to production data restricted to strictly necessary personnel under the principle of least privilege.
- Notification to the AEPD within 72 hours, and to you without undue delay, in the event of a breach posing a risk to your rights.
No measure offers absolute security. If you find a vulnerability, please disclose it responsibly to sacurio@vaultitech.com and we will treat it as a priority.
Minors
monni is intended exclusively for people over 18 years old, since using it requires holding a bank account and entering into a service contract. We do not knowingly collect data from minors. If you believe a minor has provided their data, contact us at sacurio@vaultitech.com and we will delete it immediately.
Changes to this policy
We may update this policy to reflect changes in the service, the law or our practices. When we do:
- We will update the “Last updated” date at the top.
- We will notify you by email with reasonable notice if the changes are substantial.
- If the changes require fresh consent — for example, a new AI processing activity or a new recipient — we will ask for it explicitly before applying them.
Contact
For any question about this policy or how we process your data:
We reply within 72 hours on business days.