Privacy Policy
Last updated: May 30, 2026
Who We Are
Mohnu is a personal finance management application operated during beta by Kaue Pilger. It helps you record, categorise, and understand your spending and savings. For privacy, support, data export, or deletion requests, contact us at: support@mohnu.com
What We Collect
When you create an account and use Mohnu, we process the following personal data:
- •Email address
- •First and last name
- •A declaration that you are 18 or older when you continue or sign up
- •Financial data you voluntarily enter: transactions, categories, account balances, and payment holders
- •IP address and request metadata — used for security and rate limiting only
- •Session tokens stored as encrypted cookies, required for authentication
How We Use Your Data
Your data is used exclusively to:
- •Operate and deliver the Mohnu personal finance service
- •Authenticate your identity across sessions
- •Enforce security controls and rate-limit abusive requests
- •Process optional AI-powered actions when you choose to use them
- •Respond to support and data rights requests you send us
Legal Basis (LGPD Art. 7)
We process your data under Brazil's Lei Geral de Proteção de Dados (LGPD, Law 13,709/2018): (a) Contract performance (Art. 7, V) — to deliver the service you signed up for. (b) Legitimate interest (Art. 7, IX) — to process IP addresses and session metadata for security and abuse prevention. We do not process your data for advertising, profiling, or sale to third parties.
Service Providers (Sub-Processors)
These third-party services process your data on our behalf:
| Service | Purpose | Location |
|---|---|---|
| Neon | PostgreSQL database hosting | Germany (EU) |
| Vercel | Application server and global CDN | USA / Global edge |
| Upstash | Redis cache — rate limiting | Germany (EU) |
| Resend | Transactional email delivery | USA |
| Google Gemini | Optional AI-powered transaction parsing and category suggestions | Google infrastructure / Global |
International Data Transfers
Your account data is stored in Germany (EU) via Neon. Application requests may be processed by Vercel's global edge network, which includes nodes in the United States. Rate-limit counters are stored by Upstash in Germany (EU). Transactional emails are routed through Resend (USA). Optional AI requests may be processed by Google Gemini using Google infrastructure. These transfers are limited to what is strictly necessary to operate the service or process the optional action you requested. All listed providers maintain appropriate technical security standards.
Optional AI Features
Artificial Intelligence features are optional. You can use Mohnu without using AI and record or categorise your financial data manually. When you choose to use an AI-powered feature, Mohnu may send Google Gemini only the information needed to process that request, such as the text you provide and limited financial context needed for the feature. Depending on the feature, this context may include category names, account names, member names, transaction names, transaction types, or amounts you entered for that AI action. Mohnu does not sell your data. We aim to send only the minimum necessary data to Gemini and do not send email addresses, user IDs, tenant IDs, workspace IDs, Stripe or billing data, or authentication data as part of AI prompts. Google may process data submitted to Gemini according to its own terms, privacy rules, and data processing practices.
Data Retention
We retain your account and financial data for as long as your account remains active. We do not currently operate a general automated retention schedule for active accounts. Workspace owners can schedule deletion of the tenant/workspace account from Settings. After confirmation, deletion is scheduled with a 7-day cancellation period and then purged by an automated job. Non-owner users should contact support@mohnu.com for help with account or data requests.
Your Rights Under LGPD (Art. 18)
You have the following rights regarding your personal data:
- •Access — request a copy of the personal data we hold about you
- •Correction — request that inaccurate or incomplete data be corrected
- •Deletion — request erasure of data processed with your consent, or data no longer necessary for its original purpose
- •Portability — request a structured, portable copy of your data
- •Revoke consent — where processing is based on consent, you may withdraw it at any time
- •Information about sharing — know which entities have received your data
- •Opposition — object to processing based on legitimate interest
How to Exercise Your Rights
You may request access to, export of, or deletion of your personal data by contacting support@mohnu.com. Where self-service tools are available in the app, you may also use them. We may exclude internal, security-sensitive, or legally restricted information. For correction, non-owner requests, export help, deletion help, or any other LGPD request, send an email to support@mohnu.com with the subject line "LGPD Data Request" and describe what you need. We will respond within 5 business days.
Cookies
Mohnu uses the following cookies: (a) Essential cookies: session authentication tokens and locale preferences. These are required for the service to function and cannot be disabled. (b) Analytics cookies: we plan to introduce optional analytics before public launch. These will only be set after you provide explicit consent through an in-app cookie notice. This policy will be updated before any analytics tracking is activated.
Age Restriction
Mohnu is intended for users who are 18 years of age or older. We do not knowingly collect data from minors. Mohnu does not collect date of birth during the current beta. When you continue or create an account, you declare that you are 18 or older and agree to the Terms of Service and Privacy Policy. If you are under 18, do not create an account. If we become aware that a user is under 18, we will delete their account and associated data immediately.
Changes and Contact
We may update this policy as the service evolves. Material changes will be communicated by email to affected users before taking effect. Continued use of the service after a change constitutes acceptance. For any privacy questions or LGPD rights requests, contact us at: support@mohnu.com