NeatlyMoney
Start free

Privacy Policy

Effective date: September 17, 2026

Here's the short version:

  • Your data is encrypted in transit and at rest, and stored on servers in the EU.
  • We don't sell, rent, or share your data. Ever. Your financial data is encrypted on your device, so no one else can read it, not even us.
  • No trackers, no analytics on what you spend.
  • Export or delete everything, anytime.

Full policy below.

Who we are

Neatly Money is a personal finance tracking application operated by Igor Stepanov, entrepreneur individuel (EI) under the French micro-entreprise scheme, registered in France under RCS Nantes 103 095 501, with a registered address at 105 Boulevard Michelet, 44300 Nantes, France ("we", "us", "our", or the "Publisher").

We act as the data controller for the personal data we process about you in connection with your use of the Neatly Money application available at neatly.money (the "Service"). For any privacy-related question or request, please contact us at privacy@neatly.money.

We have not appointed a Data Protection Officer (DPO) because the scale and nature of our processing do not require one under Article 37 of the General Data Protection Regulation ("GDPR").

What personal data we collect

We collect and process the following categories of personal data when you use the Service:

Account data: your email address, a hashed form of the password you choose, and (if you choose to provide them) optional profile details such as your display name, theme preference, and preferred display language. If you sign in using Google, we also receive your Google account email address and (if available) your name and profile picture.

Financial data: the personal-finance information you enter into the Service, including the names and types of your accounts, transactions, categories, budgets, and balances. This data is provided by you and is not collected from any third party. We do not connect to your bank, and we do not import your bank statements.

Technical data: strictly limited to what is necessary to operate the Service securely. This includes your IP address (used to operate and deliver the Service, including for security and abuse-detection purposes, and never for analytics), and the essential cookies described in our Cookie Policy. We do not use any analytics, advertising, or tracking cookies.

Notification data: your notification settings, such as which alerts are turned on and whether details are hidden (by default, alerts are on and details are shown). To send you security alerts, we also keep short records of when a new device starts syncing with your account and when you turn security alerts back on. These records contain no financial data and are kept while your account exists.

Push subscription data: if you turn on push notifications for a device, we store what your browser gives us to deliver them to that device: its delivery address and the technical keys your browser creates so that only that device can open our notifications (these keys cannot be used to read your financial data). We also store a time of day and your approximate time zone, so reminders arrive at a reasonable hour, and dates such as when notifications were turned on and last sent. None of this includes your financial data.

While push notifications are on, a notification can briefly wake the app on your device in the background, even when it is closed. The device then checks that you are still signed in and downloads your data in its encrypted form, so it can prepare the notification text itself. That text never leaves your device. Like any connection, these requests include your IP address and browser information.

Is providing data mandatory?

Providing your email address and a password (or signing in with Google) is required to create and use a Neatly Money account. The legal basis for processing this data is the performance of the contract between you and us (Article 6(1)(b) GDPR). If you do not provide this information, we cannot create or maintain your account.

A few things are simply needed for the app to work and stay secure, so they are not optional: your notification settings, the security records described above, your IP address, and the essential cookies described in our Cookie Policy. Everything else is up to you. You can use the Service without providing a display name, choosing a theme, or changing your language, and you decide what financial information to enter and whether to turn on push notifications on a device.

Why we collect your data and on what legal basis (Article 6 GDPR)

We process your personal data on the following legal bases:

  • Performance of a contract (Article 6(1)(b) GDPR): to create and maintain your account, store and display the financial information you enter, deliver the core features of the Service, including the notifications you choose to turn on, and respond to your support requests.
  • Our legitimate interests (Article 6(1)(f) GDPR) — to keep the Service secure, detect and prevent abuse and fraud, debug technical errors, and improve the reliability of the Service. We balance these interests against your rights and freedoms; you may object to this processing as described below.
  • Compliance with a legal obligation (Article 6(1)(c) GDPR) — to respond to lawful requests from competent authorities and to comply with our obligations under applicable French and EU law.
  • Your consent (Article 6(1)(a) GDPR) — for any future processing that requires consent (for example, if we later introduce optional features such as marketing emails or non-essential analytics). At present, we do not rely on consent because we do not perform any such optional processing.

How long we keep your data

We keep your personal data for as long as your account is active. You can delete your account at any time from your settings. To protect you, we confirm the request by email: we do not delete anything until you click the confirmation link, which stays valid for 7 days. When you confirm, we permanently delete your account and all associated data from our active systems immediately, except for a few limited technical records described below, which contain no financial data. There is no grace period, and the deletion cannot be undone.

Encrypted backups of our database may retain a copy of your data for up to approximately one week after deletion, after which they rotate out and the data is no longer recoverable. Backups are used only for disaster recovery and are never accessed for any other purpose.

If you turn on push notifications for a device, we keep that device's subscription until you turn notifications off on it, until the push service tells us it is no longer valid, or until 90 days pass without the app being opened on that device and without us sending it a notification. If a removal request, for example when you sign out, does not reach us, the subscription stays until one of the other conditions applies. A notification that is waiting to be delivered is discarded by the push service within 7 days. When you change or reset your password, or delete your account, we keep a short technical record of the sessions that were ended, with no financial data, for up to about five weeks.

We may retain a minimal record, such as a security-log entry noting that an account was deleted and a short-lived record of the deletion request itself, for a limited time when required to comply with a legal obligation, defend a legal claim, or prevent fraud and abuse. Alongside it we keep a one-way fingerprint of the deleted account's identifiers for up to one year, so that a device that had not finished erasing its local copy can prove the deletion was its own and finish the job. The fingerprint cannot be turned back into an identifier, and it is deleted after one year at the latest. These records do not contain any of your financial data.

Who we share your data with (sub-processors)

We do not sell your personal data, and we do not share it with third parties for their own marketing or advertising purposes.

To operate the Service we rely on a small number of carefully selected sub-processors. Each sub-processor processes personal data only on our documented instructions, under a written data-processing agreement, and with appropriate technical and organisational safeguards in place.

ProcessorPurposeLocationSafeguard
Supabase, Inc.Authentication (email/password, Google OAuth) and session managementIreland (eu-west-1)EU GDPR + Standard Contractual Clauses + EU-US Data Privacy Framework
Neon, Inc.Managed PostgreSQL database hosting (your account, transactions, budgets, and other application data)Germany (eu-central-1, Frankfurt)EU GDPR + Standard Contractual Clauses + EU-US Data Privacy Framework
Vercel Inc.Web application hosting and serverless function executionEU regionStandard Contractual Clauses + EU-US Data Privacy Framework
Google Ireland LimitedGoogle Sign-In (only if you choose to sign in with Google)Ireland / United StatesEU-US Data Privacy Framework

We will update this list when we add or change a sub-processor. An error-tracking service (Sentry) will be added to this list when we deploy it; until then, no error-tracking provider receives your data.

Push notifications: if you turn them on, push notifications are delivered through the push service provided by your browser or device maker (Apple, Google, Mozilla, or Microsoft); we only send to those known services. They receive the delivery address, the sending time, and an encrypted message, from which they can tell that a message comes from Neatly Money and whether it is a daily reminder, a security alert, or a notice sent after an account deletion, but not what it says. Every message our server sends is a short coded signal, not readable text: the text shown in a notification, including any names or amounts, is composed on your own device and is never sent to our servers or to the push service; like any notification, your device's operating system may also show it in its notification history or on connected devices such as a watch. By default, notifications such as budget alerts can show names and amounts on your lock screen and in your notification history; turning on Hide details in Settings stops this. These push services may process this data outside the European Union, under their own terms.

International transfers of your data

Your personal data is stored within the European Union. Some of our sub-processors are companies incorporated in the United States (Supabase, Neon, Vercel, and Google). These sub-processors keep your data on EU-based infrastructure for our use of their services, and they have committed to lawful international-transfer mechanisms — namely the European Commission Standard Contractual Clauses ("SCCs") and, where applicable, certification under the EU-US Data Privacy Framework.

In addition to the storage described above, if you turn on push notifications for a device, the push service provided by your browser or device maker may process the delivery information described in the "Who we share your data with" section outside the European Union, under its own terms.

You may request a copy of these safeguards by writing to privacy@neatly.money.

Your rights

Subject to the conditions set out in the GDPR, you have the following rights regarding your personal data:

  • Right of access — to obtain confirmation of whether we process your personal data, and a copy of that data.
  • Right to rectification — to ask us to correct inaccurate or incomplete personal data.
  • Right to erasure ("right to be forgotten") — to ask us to delete your personal data in the cases set out in Article 17 GDPR.
  • Right to data portability — to receive a structured, commonly used and machine-readable copy of the personal data you have provided to us, and to ask us to transmit it to another controller where technically feasible.
  • Right to restriction of processing — to ask us to limit the processing of your personal data in the cases set out in Article 18 GDPR.
  • Right to object — to object, on grounds relating to your particular situation, to processing that is based on our legitimate interests.
  • Right to withdraw consent — where processing is based on your consent, to withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

You also have the right to lodge a complaint with the French data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), or with the supervisory authority of the EU member state where you reside or work. The CNIL complaint form is available online.

Submit a complaint to the CNIL

How to exercise your rights

To exercise any of the rights described above, please write to us at privacy@neatly.money. We will respond within one month of receiving your request, as required by Article 12(3) GDPR. We may extend this period by up to two further months for complex or numerous requests, in which case we will inform you of the extension and the reasons for it within the first month.

We may need to verify your identity before acting on your request, in particular by asking you to confirm the email address associated with your account.

You can export all of your data, and delete your account and all associated data, directly from your settings. For any other request, please write to us at privacy@neatly.money.

Cookies

We use only a small number of essential cookies, which are necessary to provide the Service. We do not use any analytics, advertising, or tracking cookies. For full details, please read our Cookie Policy at /legal/cookies.

Read our Cookie Policy

Automated decision-making

We do not carry out any automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. We do not profile you for advertising purposes, and we do not use your personal data or your financial data to train any machine-learning or artificial-intelligence model.

Children's data

The Service is intended for adults aged 18 or older. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us at privacy@neatly.money and we will take appropriate steps to delete it.

Data security

We take the security of your personal data seriously and apply appropriate technical and organisational measures to protect it, including:

  • Encryption in transit — all communication between your device and the Service uses HTTPS (TLS).
  • Password hashing — passwords are never stored in plain text; they are hashed using industry-standard algorithms managed by our authentication provider.
  • Access controls — only the Publisher has administrative access to the production systems, and access is granted on the principle of least privilege.
  • Regular dependency updates and security reviews of the application code.
  • EU-based infrastructure with the safeguards described in the sections above.

No method of transmission or storage is completely secure. While we work hard to protect your personal data, we cannot guarantee absolute security.

Changes to this Privacy Policy

We may update this page from time to time. The Effective Date at the top of the page reflects the latest version. We encourage you to review this page periodically. Continued use of the Service after the new Effective Date constitutes acceptance of the changes.

Contact, language, and effective date

If you have any question about this Privacy Policy or about how we process your personal data, please contact us at privacy@neatly.money.

This document is issued in English. A French translation is provided for convenience and ease of reading; in case of discrepancy, the English version prevails.

Effective date: September 17, 2026.

NeatlyMoney

Built calmly by a small team that answers its own emails. Slowly, on purpose.

Legal
Privacy PolicyTerms of ServiceCookie PolicyLegal Notice
Company
AboutContact
© 2026 Neatly Money. Made with care.

Friendly notes, monthly

No spam, no noise.