Last updated: June 25, 2026
This Privacy Policy describes how MoneIT collects, uses, stores and protects users' personal data in compliance with Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003.
Contents
1. Data controller and DPO2. Data collected3. Purposes and legal bases4. Retention5. Data processors6. Aggregated sharing with partners (with consent)7. International transfers8. Cookies and technical tracking9. User rights2b. Life Simulator data (with consent)10. Minors11. Security12. ChangesThe data controller is Salvatore Patti, a private individual, residing at Via Ercole 30, 98077 Santo Stefano di Camastra (ME), Italy, Italian tax code PTTSVT82S06D643E.
Privacy contact: moneyoshelp@gmail.com
As a private individual who does not carry out large-scale processing or systematic processing of special categories of data, the appointment of a DPO is not mandatory under Article 37 GDPR.
Collected on a voluntary basis via a post-registration popup. These are aggregated ranges, not exact values:
You can skip the questionnaire or request its deletion at any time.
We automatically log significant actions of authenticated users who have given the relevant consent:
Logs are append-only (an integrity measure) and are fully deleted upon account cancellation or after 24 months.
Accessible exclusively to the authenticated user:
Budget Tool entries are also extracted in anonymous, structured form into the internal budget_snapshot table for the aggregated analysis described in §3.c. This extraction happens automatically on every save.
Users with a Premium subscription can use the "Import from bank statement" feature in the Budget Tool. When the user voluntarily uploads a document (a PDF or image of a bank statement, receipt or transaction list), the following applies:
Legal basis: Performance of a contract — Article 6(1)(b) GDPR (the feature is activated by the user as part of the Premium service). Uploading the document is always voluntary and never automatic.
Handled entirely by Stripe Inc. (PCI-DSS Level 1). We only store the Stripe customer ID and subscription status. No card or bank account data is stored on our servers.
Email addresses entered in the newsletter form are stored together with the acquisition source and the IP address at the time of sign-up. Activation requires double opt-in via an email link.
Through the Life Simulator tool, the user can voluntarily enter precise personal financial data. This data is saved only after explicit consent via a dedicated checkbox, and is never collected implicitly:
This data is used to: personalize suggested Clubs, show anonymous aggregated benchmarks ("users similar to you invest on average €X/month"), and to generate the personalized monthly MoneIT Report.
The derived investment tier (low / mid / high) is used exclusively in aggregated form in reports. Consent can be withdrawn at any time by writing to moneyoshelp@gmail.com; in that case, Simulator data is deleted within 30 days.
Legal basis: Explicit consent — Article 6(1)(a) GDPR, documented with a timestamp and IP address in the gdpr_consent table.
| Purpose | Data (§) | Legal basis — Art. 6 GDPR |
|---|---|---|
| a) Provision of the service (account, tools, Clubs) | 2.1, 2.4, 2.5 | Performance of a contract — point (b) |
| b) Managing payments and subscriptions | 2.6 | Performance of a contract — point (b) |
| c) Anonymous aggregated analysis for product improvement | 2.3, 2.4 (agg.) | Consent — point (a) (revocable) |
| d) Personalizing the in-app experience | 2.2, 2.3 | Consent — point (a) (revocable) |
| e) Aggregated sharing with financial partners (see §6) | 2.2, 2.4 (anon. agg.) | Explicit consent — point (a) (revocable) |
| f) Marketing communications and newsletter | 2.1, 2.7 | Consent — point (a) (revocable) |
| g) Operational service communications | 2.1 | Performance of a contract — point (b) |
| j) AI processing of bank statements (Premium feature, only on explicit action) | 2.4b | Performance of a contract — point (b) |
| h) Security and fraud prevention | 2.8 | Legitimate interest — point (f) |
| i) Tax and regulatory obligations | 2.1, 2.6 | Legal obligation — point (c) |
Purposes based on consent are optional and can be withdrawn at any time from the account settings, with no effect on access to the service.
| Data category | Retention period |
|---|---|
| Account and tool financial data | For the lifetime of the account + 30 days after cancellation |
| Demographic data | Same as account data; can be deleted earlier upon request |
| Behavioral logs | 24 months from the event; fully deleted upon account cancellation |
| Structured budget snapshot | Replaced on every save; deleted upon account cancellation |
| Life Simulator data (with consent) | Until consent is withdrawn or the account is cancelled; deleted within 30 days of the request |
| GDPR consent audit log | 10 years (record of processing — Art. 5 GDPR) |
| Email list / leads | Until unsubscription or a deletion request |
| Tax and accounting data | 10 years (Italian Presidential Decrees 633/1972 and 600/1973) |
We do not sell or transfer personal data to third parties for their own purposes. Data is shared exclusively with the following technical providers, appointed as Data Processors under Article 28 GDPR:
With explicit, separate consent, MoneIT may share with financial partners (banks, asset managers, funds, insurers) exclusively aggregated, anonymized datasets from which it is impossible to trace back to an individual user's identity.
Examples of shareable aggregated data:
Never shared: individual data, emails, names, exact amounts, personal portfolios, or any information that would allow direct or indirect identification.
Consent can be withdrawn at any time. Aggregated datasets already delivered, since they contain no individual data, cannot technically be "withdrawn".
Supabase, Stripe, Vercel and Anthropic may process data outside the EU (mainly the USA). Transfers are based on the Standard Contractual Clauses (SCCs) — EC Decision 2021/914/EU — or applicable adequacy decisions. For Anthropic, the transfer covers exclusively the content of the document voluntarily uploaded by the user for the bank statement import feature (§2.4b), and is limited to the time strictly necessary for processing.
MoneIT uses only strictly necessary technical cookies required for the service to function (authentication session management). We do not use profiling cookies, third-party cookies or advertising pixels.
Internal behavioral tracking (§2.3) happens via direct API calls to our servers, applies only to authenticated users with active consent, and does not involve third parties.
Under Articles 15–22 GDPR you have the right to:
Write to moneyoshelp@gmail.com. We will respond within 30 days. You can lodge a complaint with the Italian Data Protection Authority, the Garante Privacy (garanteprivacy.it).
You can delete your account directly from the app at any time:
Upon cancellation, the following are deleted immediately: account data, tool financial data, demographic data, behavioral logs, Life Simulator data. Only tax data required by law (10 years) and the GDPR consent audit log are retained.
Alternatively, you can request deletion by writing to moneyoshelp@gmail.com.
The service is intended for users at least 18 years old. We do not knowingly collect data from minors. If we become aware of a minor's data, we delete it immediately. Reports can be sent to moneyoshelp@gmail.com.
In the event of a data breach that poses a risk to your rights, we will notify you within 72 hours of discovery (Art. 33 GDPR).
In the event of substantial changes, registered users will be notified by email with at least 30 days' notice. The updated version is always available at this address. Continued use of the service after notification constitutes acceptance for purposes not based on consent.