Privacy Policy
Monerise — Privacy-First Personal Finance
Effective date: July 31, 2026 Last updated: July 31, 2026
1. Who We Are
Monerise is developed and operated by ICI Tech Teknoloji A.Ş. ("Company", "we", "us", or "our"), a technology company registered in Turkey.
| Company | ICI Tech Teknoloji A.Ş. |
| Website | https://monerise.app/ |
| app@icitech.com.tr |
What Monerise is: Monerise is a personal finance tracking app designed to help you manage wallets, transactions, budgets, and multi-currency balances. It is not a bank, broker, payment service provider, tax advisor, or investment product. It does not transfer money between bank accounts, connect to bank accounts, or provide financial advice.
2. Our Privacy Architecture — Read This First
Monerise is built around a privacy-first, offline-first design. Understanding how data flows in the app is important.
Your financial data stays on your device by default. Transactions, wallet balances, categories, budgets, and reports are stored in local storage on your device. Daily use does not require a cloud account or internet connection.
On-device encryption. Data on your device is protected with AES-256 encryption at rest.
App lock. Access to the app is protected by biometric authentication (fingerprint/face) or PIN.
When does data leave your device?
| Scenario | Does data leave? | What is sent? |
|---|---|---|
| Daily tracking (add transactions, budgets, reports) | No | Nothing |
| Optional live exchange rate update | Yes — read only | Rate request only — no financial data |
| Optional cloud account (backup/sync) | Yes — if you enable it | Encrypted financial data |
| Optional export/backup | Yes — if you initiate | Encrypted or formatted file you control |
| Crash reports | Yes — anonymized | Technical error data only |
| Purchase verification | Yes | App Store/Google Play receipt |
No bank connection. Monerise does not link to any bank or financial institution. We never request or store bank credentials, card numbers, or account login details.
3. Data We Collect
Account Information (Optional): If you choose to create an account for optional cloud backup or sync, we collect your email address and password (one-way hash). An account is not required to use Monerise's core features.
Financial Tracking Data (Device-local): Transaction records (amount, date, category, note, wallet), wallet names and balances, category and tag configurations, budget limits and progress. This data is stored locally on your device. It is sent to our servers only if you enable optional cloud backup.
Exchange Rate Data: When you request an optional live rate update, we fetch current rates from an exchange rate provider. We send no financial data to this provider — only a request for rates. You can also edit rates manually without any network request.
Backup and Export Data: If you use optional backup or export features, your financial data leaves your device in an encrypted or formatted file that you control.
Purchase Data: App Store or Google Play purchase receipt for one-time purchase verification. We never receive your payment card details.
Technical Data: App version, device type and OS version, anonymized crash logs and error reports.
Communications Data: Email and message content from support contacts.
Financial data — income, expenses, balances, and budgets — is among the most sensitive categories of personal data. Monerise's core design commitment is to keep this data on your device. We do not use it for advertising, profiling, or any commercial purpose.
4. Exchange Rate Provider
When you request optional live exchange rates, we call a third-party exchange rate API. This call contains only a request for rates — no transaction data, wallet balances, or personal identifiers are included. The exchange rate provider receives no information about your financial situation. You can use Monerise's full feature set with manually entered rates, with no network calls at all.
5. Optional Cloud Account and Backup
If you create an account, your encrypted financial data may be synced to our cloud servers for backup purposes. This is entirely optional — core tracking features work without an account. When cloud backup is enabled, your data is transmitted using TLS 1.2+ and stored encrypted at rest.
6. Legal Bases for Processing
| Purpose | Legal Basis |
|---|---|
| Account creation (optional) | Performance of contract |
| Providing core tracking features | Performance of contract |
| Exchange rate fetch (optional) | Performance of contract / Legitimate interest |
| Optional cloud backup/sync | Performance of contract |
| Crash analysis and app quality | Legitimate interest |
| Purchase verification | Performance of contract |
| Legal obligations | Legal obligation |
| Marketing communications | Consent |
7. What We Do Not Do
We do not sell financial data or personal data. We do not share financial data with advertising networks. We do not connect to your bank accounts or request banking credentials. We do not use advertising identifiers (IDFA/GAID). We do not use your financial data to train AI models. We do not provide investment advice or financial recommendations. We do not store payment card details. We do not knowingly collect data from children under 18.
8. Third-Party Services
| Service | Purpose | Privacy Policy |
|---|---|---|
| Exchange rate provider | Optional live rate data | Available on request |
| Apple App Store | iOS distribution and purchase | https://www.apple.com/legal/privacy/ |
| Google Play | Android distribution and purchase | https://policies.google.com/privacy |
| Cloud infrastructure | Optional backup storage | Available on request |
We do not integrate advertising SDKs or third-party AI services.
9. Data Sharing and Disclosure
We share data only as necessary: with Apple or Google (purchase receipt verification); with exchange rate provider (rate request — no financial data); with cloud infrastructure providers if you use cloud backup (encrypted financial data, under strict data processing agreements); with financial and legal advisors (compliance); with courts and regulators (lawful requests); with potential acquirers under strict confidentiality. We never share financial data with advertising networks.
10. International Data Transfers
ICI Tech Teknoloji A.Ş. is based in Turkey. Infrastructure providers may operate internationally. All transfers of cloud backup data are subject to appropriate safeguards per KVKK Article 9. Exchange rate requests carry no personal data.
11. Data Retention
Device-local financial data is retained until you delete it in-app or uninstall the app. Cloud backup data is retained for the duration of your account plus 30 days after account deletion. Purchase records are retained for 10 years per Turkish commercial law. Crash logs are deleted after 12 months. Support communications are retained for 3 years.
12. Security
- AES-256 encryption for data at rest on device
- Biometric or PIN app lock
- TLS 1.2+ for all data in transit (when network is used)
- No financial data transmitted during core tracking use
- Cloud backup data encrypted in transit and at rest
- Regular security assessments
13. Children's Privacy
Monerise is intended for users aged 18 and older. We do not knowingly collect data from minors. Contact app@icitech.com.tr if you believe a child has submitted data.
14. Your Privacy Rights
Access, correct, or delete account data by contacting app@icitech.com.tr. Delete financial data directly in-app (Settings → Data → Delete All Data). Delete account via Settings → Account → Delete Account. Export your data via the in-app export feature. Withdraw marketing consent via Settings → Privacy → Marketing Preferences. We respond within 30 days, free of charge.
15. EEA and UK Users
If you are in the EEA or UK, GDPR applies. Read our GDPR Privacy Notice at https://monerise.app/en/privacy/gdpr for full details.
16. Changes
Material changes notified at least 14 days in advance. Current version at https://monerise.app/en/privacy.
17. Contact Us
Email: app@icitech.com.tr Website: https://monerise.app/ Subject: "Privacy Request — Monerise"
We acknowledge enquiries within 5 business days.
18. Governing Law
This Policy is governed by the laws of the Republic of Turkey, including KVKK No. 6698. Disputes are subject to Turkish court jurisdiction.