Transparency first

Privacy Policy

Your data is yours. We never sell it, trade it, or share it without your consent.

Last updated: September 10, 2026

No bank loginsEncrypted in transitYou control your data

1. Introduction

MintValt ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our financial-management application (the "Service").

Core privacy principle: We do not and will never store your bank credentials, ask for bank login information, or request access to your bank accounts. You maintain complete control over your financial data at all times.

2. Information We Collect

2.1 Information you provide directly

  • Account information: your name, email address and account preferences. Not your password . Sign-in is handled by Firebase Authentication, so a password you type goes to Google and never reaches us. We do not receive it, hash it, or store it in any form.
  • Financial data: the bank statements you choose to upload, the transactions and account balances they contain or that you enter yourself, and the budgets, goals and categories you set. A statement you upload is read by AI to pull the transactions out of it, and section 4 sets out exactly what that sends and to whom.
  • Receipt data: receipt images you choose to scan. The image is sent to our AI provider, read, and discarded in the same request. We never write it to disk or to a database, so there is no receipt image for us to keep, lose, or hand over.
  • Profile information: currency preferences, notification settings, and dashboard customizations.
  • Communication: messages, feedback, and correspondence through our chat feature or support channels.

2.2 Information collected automatically

  • Marketing-site analytics: pages visited on mintvalt.com, via Google Analytics, and only if you accept the cookie banner. Decline and no analytics script loads at all. This runs on our public marketing pages only. There is no analytics SDK inside the app itself , on the web app or in the mobile apps. Nothing tracks which budgets you open or what you spend on.
  • Device information: browser type, operating system, and IP address.
  • Push notification token: if you turn on notifications in a mobile app, we store the token your device gives us so we can send them. It identifies an app installation, not you, and deleting the app or signing out removes it.
  • Crash reports: when the app or the website fails, the error and where it happened, with your account ID attached so we can tell "this breaks for one person" from "this breaks for everyone". Off in development builds.
  • Cookies: analytics cookies on the marketing site if you accept them, and nothing else. Signing in does not set a cookie: your session is a token your browser or phone holds, so there is no session cookie here for us to describe.
  • Logs: request metadata for security and performance monitoring.

2.3 Information we do NOT collect

  • Bank login credentials or passwords
  • Full credit card numbers (payments are processed securely by Creem)
  • Biometric data
  • Your location. The apps never ask for it, on any platform.
  • Your contacts, or your photo library. The receipt scanner opens a picker and receives the one image you choose; nothing else in your library is read, and we never browse it.
  • Anything else on your device that you have not handed to a specific feature
  • Advertising identifiers. There is no ad SDK in any MintValt app, so there is nothing to build an advertising profile from.
  • Information from third-party financial institutions without your explicit upload

3. How We Use Your Information

We use the information we collect to:

  • Deliver the service: process your uploads, maintain your account, and provide support.
  • Read what you upload: a statement or a receipt is sent to our AI provider to extract the transactions from it, and a payment we have not seen before is sorted into a category the same way. You can correct any of it, and a correction is remembered.
  • Answer your questions: when you ask the assistant something, it reads the figures it needs to answer you.
  • Work out your figures: budgets, spending breakdowns, projections, observations about your spending and your financial health score are calculated from your own data, on our servers. No model is involved in any of them.
  • Communicate: send account notifications, service updates, and respond to inquiries.
  • Improve the app: understand usage patterns to improve features and experience.
  • Keep it secure: detect and prevent unauthorized access or misuse.

4. Data Sharing & Disclosure

4.1 We share data with

  • People you invite: a household lets you share chosen parts of your finances with the people you live with. Only what you pick crosses: an account you share (its balance, and its transactions from the date you shared it onwards), a category you share, and a budget you share. Members also see your name, the address an invitation was sent to, and how much each member has spent on shared accounts. Nothing else moves. Your other accounts, your private transactions, your savings goals and your conversations with the assistant stay yours alone. You keep control of anything you share: only you can rename, delete or unshare it, and unsharing, leaving the household or being removed from it ends the other the access of other members immediately.
  • Creem: our Merchant of Record, which handles checkout, billing and tax (PCI-DSS compliant). Your card details go to Creem and never reach us.
  • Firebase (Google): sign-in, crash reporting, and delivering push notifications. Your email address and account identifier reach Firebase; your financial data does not.
  • Anthropic: the AI behind the assistant, transaction categorization, receipt scanning and statement parsing. Worth being specific about, because it is the one that touches your financial data. When a transaction is categorized, its description and merchant name are sent. When you scan a receipt, the image is. When you upload a bank statement, the text of that statement is, meaning every transaction on it and whatever else the document happens to contain. And when you ask the assistant a question, it reads the transactions, balances, budgets, goals and categories it needs to answer you, and those reach Anthropic too. All of it is sent to get an answer back, none of it is used to train models.
  • Resend: carries our email, in both directions. Outbound: sign-up, budget alerts, weekly summaries and billing notices, so your address and the contents of those messages reach Resend. Inbound: if you forward a bank statement to your personal import address, or reply to a support thread, that message reaches us through Resend. Forwarded statements are parsed into transactions; support replies are kept as the conversation thread.
  • Rollbar: error tracking, on our servers and in your browser. When something fails, the error, where it happened and your account identifier go there, so a failure reaches us rather than only you. A browser report can carry the request that caused it, so financial data can appear in one; passwords, tokens, cookies and authorization headers are stripped before it is sent.
  • Google Analytics: on the marketing site only, as described above.
  • Infrastructure providers: that host and run the application.
  • Our own staff: a small number of administrators can look up an account to answer a support request or investigate a fault. What the console shows them is your name, email, plan and subscription status, and counts of how many accounts, transactions, budgets and goals you have. It does not show them the transactions themselves.
  • Legal authorities: only when required by law or valid legal process.

4.2 We do NOT share

  • Your financial data with advertisers
  • Your transaction history with marketing companies
  • Your data with data brokers for commercial purposes
  • Your information without your consent, except as required by law

5. Data Retention

  • Active accounts: your data is retained while your account is active.
  • Closing your account: you can do it yourself, from Settings on the web or in either mobile app. You do not have to email anyone and wait. Your account is then erased after seven days. The delay exists so that a tap made in anger or by accident can be undone: sign in during that week and cancel, and nothing is lost. After it, your profile, accounts, transactions, budgets, goals, categories, notifications and saved devices are deleted permanently and cannot be recovered.
  • What survives that deletion: two things. First, records of payments: what our payment provider sent us, when, and whether it was genuine. These are financial records and we are required to keep them, so they outlive the account they belonged to, and they contain no transaction data, no budgets and no balances. Second, support correspondence: an email thread with us is filed under the address that sent it rather than under your account, so closing the account does not sweep it up. Ask us and we will delete it.
  • Backups: routine backups are rotated on a rolling basis, so a copy of deleted data can persist in a backup for a short period before it ages out.
  • Receipt images: never stored in the first place. The image is read and discarded within the request that uploaded it.
  • Legal hold: data may be retained longer where required for legal compliance.

6. Your Data Rights

MintValt is designed around the principles of the major data-protection regimes (GDPR, CCPA and PDPA). Wherever you are, you can ask us to honor the following:

6.1 GDPR principles (EU users)

  • Access: request a copy of your personal data.
  • Rectification: correct inaccurate information.
  • Erasure: request deletion of your data.
  • Portability: download your transactions and your net worth history as a spreadsheet from your settings, or ask us for a copy of anything else we hold.
  • Restriction & objection: limit or object to certain processing.

6.2 CCPA principles (California users)

  • Know what personal information we collect
  • Request deletion of that information
  • Opt out of the sale or sharing of personal information (we don't sell it)
  • Non-discrimination for exercising your privacy choices

6.3 PDPA principles (Sri Lanka's Personal Data Protection Act)

  • Request access to your personal data
  • Request correction of inaccurate data
  • Opt out of marketing communications

To exercise any of these, email us at privacy@mintvalt.com with "Data Request" in the subject line.

7. Security

  • Encryption in transit: all connections use TLS 1.2+, served over HTTPS with HSTS.
  • Encrypted backups: database backups are encrypted before they leave the server, and stored separately from it.
  • Scoped access: every request is scoped to your account, so your data is isolated from other users.
  • Protected secrets: API keys and secrets are kept in environment configuration, separate from application code.
  • No bank credentials: since we never store bank logins, there's no such credential to breach.

No system is ever 100% secure, but we take protecting your data seriously and will notify affected users promptly if we become aware of a breach that puts their data at risk.

8. International Data Transfers

MintValt is operated from Sri Lanka. If you use the Service from elsewhere, your data is processed in Sri Lanka and by the providers named in section 4, which operate in other countries including the United States and the European Union.

Each of those providers is bound by a data processing agreement with us that incorporates the Standard Contractual Clauses published by the European Commission, which is the safeguard the GDPR provides for transfers to a country without an adequacy decision. They may process your data only on our instructions and only to provide the service they are there for.

Accepting our Terms of Service when you create an account is your agreement to the contract, not a substitute for that safeguard. If you are in the UK, the EU or Switzerland and want to know what applies to a particular transfer, ask us at privacy@mintvalt.com and we will tell you.

9. Third-Party Links

Our Service may link to third-party websites and services. We're not responsible for their privacy practices, we recommend reviewing their policies before sharing information.

10. Children's Privacy

The Service is not intended for anyone under 18, which is the minimum age set out in our Terms of Service. We do not knowingly collect information from children, and will delete it if we become aware of it.

11. Cookies & Tracking

  • Sign-in uses no cookie: your session is a token your browser or phone holds and sends with each request. There is nothing to clear from your cookie settings to sign out, and no session cookie exists to be stolen from one.
  • Analytics cookies: set by Google Analytics on the public pages of mintvalt.com, and only after you accept them. Nothing is set before you answer, declining costs you nothing because no page here needs them to work, and the app does not set them at all. You can change your answer at any time from Cookie choices at the foot of this page.
  • Do Not Track: we do not act on Do Not Track or Global Privacy Control signals. Browsers send them inconsistently and no agreed standard says what honoring them means, so rather than claim a behaviour we have not built, we would rather point at the ones that do work: decline the banner, change your answer later from the footer, or block the cookies in your browser.

You can change your answer at any time from Cookie choices at the foot of this page, or manage cookies through your browser settings. Nothing on the marketing site depends on them, and the app itself does not use cookies.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable laws. We'll note material changes here and update the date above. Continued use of the Service means you accept the updated policy.

Contact us

Questions about this policy or your data? Reach us at privacy@mintvalt.com. We aim to reply within 1-2 business days.