Privacy & security

Your information is yours.

Mont only works if you trust it with the details of your money. This page explains, in plain language, what we collect, how it's protected, and what we can and can't see.

Last updated August 3, 2026

The short version

  • We collect only what Mont needs to run, and you can export or delete it at any time.
  • Connecting a bank is optional, off until you turn it on, and your banking credentials never reach us.
  • Your amounts and connected-account tokens are encrypted at rest with a key unique to your account.
  • Everything travels over encrypted connections (TLS).
  • We use limited product analytics and crash diagnostics to improve Mont. PostHog does not receive exact amounts or balances, assistant conversation text, receipts, statements or banking credentials.
  • We do not sell your data or use it to advertise to you.

What we collect

Account information. Your email and name, so you can sign in and we can reach you about your account. If you sign in with Google or Apple, we receive your name and email from them to create your account. We never see your password for those services.

What you put into Mont. The expenses, receipts, statements, budgets and notes you create or upload. This is your content; we store it to show it back to you and reason across it.

Subscription details. If you subscribe to Mont Premium, Apple processes the payment. We receive only your subscription status and transaction identifiers, never your card numbers.

Bank account data (optional). If you choose to connect a bank, we receive from our aggregation provider the identifiers, names and types of the accounts you select, their balances, and their transaction history: dates, amounts and descriptions. We never receive or store your online banking credentials. This is off until you turn it on, and only what you choose gets connected.

Product analytics and diagnostics. We record limited events such as whether account creation, onboarding, paywall and subscription actions, briefings, notifications, assistant requests, imports and selected financial workflows succeed or fail. These events use controlled categories and counts, not the values or content you enter.

Technical context. PostHog may add the app version and build, device model and type, operating-system version, locale, time zone, network type, TestFlight or simulator status, and anonymous session and installation identifiers. After you sign in, we associate events with Mont's internal account identifier, not your name or email. For crashes, we send the error type and technical stack trace after filtering free-form error messages and interaction steps.

How we use it

To run the app, categorize your expenses, generate your insights, sync what you connect, secure your account, understand which product flows work or fail, diagnose crashes, and respond when you contact us. We do not sell your personal data or use it for third-party advertising.

Product analytics and diagnostics

What we measure. We use PostHog to understand broad product behavior, such as account and onboarding completion, paywall outcomes, subscription-status changes, briefing and notification opens, whether the assistant completed a request, and whether selected financial workflows were completed. Import events contain counts only. Assistant events contain controlled execution details such as outcome, provider, model, response type, and safe action categories.

What PostHog never receives. We do not send exact financial amounts or balances; transaction, account, budget, debt or savings-goal names; bank account numbers or credentials; user prompts or assistant response text; receipt or statement images or extracted text; statement rows; or action parameters. Automatic screen views, element autocapture, repeated-tap detection and session replay are disabled.

Purpose and location. We use these data only to improve Mont, measure whether features work, and diagnose technical failures. PostHog processes them on our behalf in its United States cloud region. We do not use PostHog for advertising, data brokerage, or tracking you across other companies' apps or websites. PostHog's privacy policy: https://posthog.com/privacy

Who we share it with

Service providers. Trusted providers host our servers and databases under agreements that limit them to working for us. PostHog processes limited product analytics and diagnostics for us in its United States cloud region. Your AI assistant is powered by our AI providers, Anthropic or OpenAI, who are bound to protect your data to a standard at least equal to this policy (described below). If you connect a bank, our aggregation provider, Paybook S.A.P.I. de C.V. (Syncfy), handles that connection as a data processor acting on our behalf, under the same obligation (described below). Subscriptions are processed by Apple.

Your partner, if you choose. If you link up with a partner on Mont, only what you explicitly share (shared accounts and budgets) is visible to them. Everything else stays private to you.

Nobody else. We don't sell your personal data, share it with advertisers, or hand it to anyone beyond what this notice describes, unless the law requires it.

How your information is protected

In transit. All traffic between the app and our servers is encrypted with TLS.

At rest. Your most sensitive fields (amounts and account tokens) are encrypted with AES-256-GCM using a key unique to your account.

Honest scope. This is application-layer encryption, not zero-knowledge end-to-end encryption: to generate your insights, our servers can decrypt your data while they process it. We tell you this plainly rather than promising more than we deliver.

AI and insights

Your AI assistant and daily briefing are powered by Anthropic (Claude) or OpenAI. To answer you and reason across your money, we send the active AI provider the context needed: your account names and balances, your budgets, your savings-goal names and amounts, and your transaction titles and amounts.

Your data is not used to train any AI models, and it is not sold. Our AI providers are contractually bound, and their own privacy policies commit them, to protect your data to a standard at least equal to this policy: they process it only to generate your response and retain it only for a limited period. Their privacy policies: https://www.anthropic.com/legal/privacy and https://openai.com/policies/privacy-policy

Scanning improvements are separate, and opt-in. If you turn on “Share scanned receipts” or “Share scanned statements” in Settings › Privacy & security, those images and their parsed text help us make our own receipt and statement scanner more accurate. This never goes to Anthropic or OpenAI and never touches your AI assistant. Scanning works whether or not you turn this on, and you can turn it off any time.

You can turn AI off any time in Settings › General › AI & Data. With AI off, nothing is sent to Anthropic or OpenAI and you receive the standard briefing.

Connected services

Bank sync is optional, and off until you turn it on. No bank is connected until you go to Settings, choose your bank, and give your explicit consent inside the app. We record the date and time of that consent, so there's a clear record of when you agreed. If you never turn it on, none of this section applies to you.

Your credentials never reach us. You enter your online banking username and password directly into a secure widget operated by our aggregation provider, Paybook S.A.P.I. de C.V. (Syncfy). Those credentials travel encrypted to Syncfy and are never transmitted to or stored on Mont's servers. Syncfy's use of data is governed by their Privacy Policy: https://help.paybook.com/en/article/privacy-and-security-policy-k33bgf/

What we receive. For the accounts you choose to connect, Syncfy sends us the account identifier, its name and type, its balance, and its transaction history: dates, amounts and descriptions. We receive nothing from accounts you didn't select.

What we do with it. We use that data inside the app only: to show you your accounts and movements, keep your balances current, feed your budgets, and generate your insights. Amounts that arrive from your bank are encrypted at rest with the key unique to your account, exactly like every other amount in Mont.

Disconnecting. You can disconnect a bank, switch an account back to manual entry, or disconnect any other service, any time in Settings. Collection stops and the stored credential is deleted at the provider. Transactions already imported stay in your account so your history stays intact; you can delete them whenever you want, or delete your account to remove everything.

How long we keep it

While your account is active. Your data stays in Mont for as long as you have an account, so the app can keep working for you.

When you leave. Delete your account and we remove your core account and financial data from our systems; copies in encrypted backups are purged as those backups rotate. Product analytics and diagnostic records already stored by PostHog may remain until its configured retention period expires. We may also keep minimal records where the law or security needs require it.

Your rights

Export. Download everything you put into Mont, any time, in a portable format.

Delete. Delete your account and we remove your data.

Access & correction. See and fix the information we hold about you.

Object. Ask us to stop a specific use of your data, like emails from us, and we will.

Changes & contact

Mont is in active development, so this notice will evolve before public launch. We'll update the date above when it changes.

Questions about privacy or security? Email patovw@gmail.com.