Security isn't a feature. It's the model.
We never ask for your bank login, so there is nothing of yours for us to leak. Here is exactly what we hold, who else sees it, and how to take it back.
You upload it. MintValt reads it. That is the entire list.
MintValt never asks for your bank login. You upload a statement when you want to, so you decide what comes in and when.
One outside service reads your financial data: Anthropic, whose models turn your statements into transactions and answer your questions. None of it trains a model, and none of it is sold. The other providers we rely on, for sign-in, payments, email and error monitoring, are named in the privacy policy along with exactly what reaches them.
You upload a statement
A PDF or a spreadsheet, from any bank, with no login
MintValt reads it
The transactions are pulled out for you, and nothing is trained on them
The transactions are yours
Stored against your account, nothing else kept
You can take them back
Download them as a spreadsheet, or delete the lot, any time
Collect less, and there is less to protect.
Every design decision starts with the same question: do we really need this data? Usually the answer is no.
No bank credentials
We never ask for your bank login, so there is no password of yours for us to lose. You upload statements yourself.
Uploads are never stored
Statements and receipts are read in memory and never written to disk. We keep the transactions, not the file they came from.
No card details
Your card never reaches our servers. Checkout runs through a payment provider certified to handle them.
No tracking, no selling
No advertisers, no data brokers, no analytics built on your spending. You pay for the product, not with your data.
Encrypted in transit
Your data is encrypted the moment it leaves your device, and again in our backups.
Built around the standards that matter.
MintValt is designed around the principles behind the major data-protection regimes, and card payments run through a certified provider.
GDPR principles
Designed around GDPR: access, correction, deletion and portability of your data on request.
CCPA principles
Built with CCPA in mind, the right to know, delete and opt out.
PDPA principles
Aligned with Sri Lanka's Personal Data Protection Act, the law that governs us, for access and correction.
PCI DSS
Card payments are handled by a certified provider. Your card details never reach us.
Data minimization
We collect only what we need to run the app, and never your bank credentials.
You're in control. Here's how.
Access your data
Ask for a copy of everything we hold and we will send it.
Correct inaccuracies
Update or fix any personal information you believe is wrong.
Delete your data
Request full deletion and we'll remove your data from our systems.
Export your data
Download your transactions and your net worth history as a spreadsheet, any time.
Restrict processing
Ask us to limit how we use your data while concerns are reviewed.
Withdraw consent
Change your mind any time. Analytics cookies are yours to turn off from the footer, and anything else you can ask us to stop.
To exercise any of these rights, email us at privacy@mintvalt.com
Trust, through transparency.
You should know what happens to your financial data before you upload any. Now you do. Try MintValt free for 14 days.