Privacy Policy
Last updated: 28 July 2026
MoneyBits is a budgeting app. It shows you where your money goes; it does not sell, rent or share your financial data. This page describes exactly what is collected and who touches it.
1. Data controller
Honoré Tomaka, sole trader (entreprise individuelle), 44 rue Gustave Scrive, 59110 La Madeleine, France. Contact: support@money-bits.com.
2. What is collected
a) Account data
Provided when you create an account, and handled by our authentication provider (Clerk): email address, and — if you sign in with Google — the name and email address attached to that Google account. No password is ever stored by MoneyBits itself.
b) Data you enter in the app
Accounts and their balances, transactions (amount, date, wording), categories and tags, and your monthly budget allocation. This is the content of the service.
MoneyBits performs no bank aggregation of its own: it never connects to a bank and never asks for banking credentials. If your account already holds bank-linked data, that connection was established in Cashbah — the app MoneyBits extends — and is governed by Cashbah's own policy. MoneyBits only displays it.
c) Technical data
When the app crashes or a request fails, a diagnostic report is sent to Sentry: the error message and stack trace, the app version, and the operating system and browser engine versions. When you are signed in, it carries your account identifier, so that a report you send us can be matched to it.
Sign-in is reported on the same channel, and there a report is not always the sign of a failure. MoneyBits offers several sign-in methods and falls back from one to the next when a device does not support the first: each handover sends a short technical label naming the method that stepped aside, even when the sign-in that follows succeeds. Without it, a release whose sign-in is broken for everyone looks exactly like a working one from the outside. These reports are produced before you are signed in, so they carry no account identifier.
These reports are not designed to carry the content of your budget, and several measures keep it out: session recording and performance tracing are disabled, so nothing on your screen is ever captured; your email address and username are stripped from the account record attached to the report; console output and the text you type are excluded from the diagnostic trail; and URL parameters are removed. What remains is a technical error message, which we do not deliberately populate with financial data.
This website uses PostHog to count page views and waitlist sign-ups, without cookies. The app itself contains no product analytics: nothing records which screens you open, or what you do in them. The sign-in reports described above are the only thing it sends outside of an error.
3. Purposes and legal bases
- Providing the service (account, budget, transactions) — performance of the contract.
- Authentication and account security — performance of the contract.
- Crash, error and sign-in reliability diagnostics — legitimate interest in keeping the app working, limited to the technical data described above.
- Website audience measurement — legitimate interest, cookie-free and aggregated.
4. Processors
MoneyBits has no backend of its own; it reads and writes the same database as Cashbah. The processors involved are:
| Processor | Role | Data | Location | Transfer safeguard |
|---|---|---|---|---|
| Clerk | Authentication, sessions | Name, email, IP, device, Google OAuth data | United States | Data Privacy Framework |
| Hetzner | GraphQL API hosting | Technical logs, GraphQL requests | Germany (EU) | No transfer |
| Railway | Database hosting | Application data, technical logs | European Union | Standard Contractual Clauses |
| Vercel | Web hosting | IP, user agent (technical logs) | United States | Data Privacy Framework |
| Sentry | Crash reporting | Technical logs, app version, account identifier | United States | Data Privacy Framework + SCC |
| PostHog | Website audience measurement | Cookie-free page events (this website only) | European Union | No transfer |
5. Retention
- Account and app data — for as long as the account exists, then deleted when you delete it (see deleting your account).
- Crash reports — 90 days.
- Technical server logs — up to 12 months.
6. Your rights
You have the right to access, rectify, erase, restrict and port your data, and to object to processing based on legitimate interest. Account data can be edited and the account deleted directly in the app. For anything else, write to support@money-bits.com; we answer within one month.
You may also lodge a complaint with the CNIL, the French supervisory authority (cnil.fr).
7. Security
All traffic is encrypted in transit (HTTPS/WSS). Access to your rows is enforced by database-level permissions bound to your authenticated identity, not by the app: a request cannot read another user's data even if the app asks it to.
8. Cookies
The app uses local storage only to keep you signed in and to remember your interface preferences. Neither the app nor this website uses advertising or profiling cookies.
9. Changes
This policy may change as the service evolves. The date at the top of the page always reflects the current version, and material changes are announced in the app.