Security Policy
Effective: September 4, 2026
Moneyly handles your personal financial records, so security is a core design requirement — not an afterthought. This page describes how your data is protected. For what data is collected, see the Privacy Policy.
1. Architecture that minimizes risk
- Offline-first. Your records live in the app's private on-device storage by default. Data that never leaves your phone cannot leak from a server.
- No passwords of ours to steal. Sign-in uses Google OAuth — we never see, handle, or store your Google password.
- No bank connections. Moneyly has no bank sync and never asks for bank logins, card numbers, or one-time codes. Every record is typed in by you, so there are no financial credentials to compromise.
- Minimal permissions. The app requests only Internet, Notifications (for your reminders), and Run-at-startup (to re-schedule reminders after reboot). No location, contacts, camera, or file access.
2. Data in transit
- All network traffic — cloud backup, feedback submission, ads, billing — uses encrypted HTTPS/TLS connections.
- Authentication uses short-lived Google ID tokens; each backup request is tied to your signed-in account.
3. Data in the cloud (only if you enable backup)
- Backups are stored in Firebase Cloud Firestore, isolated per user account by security rules: an account can only read and write its own backup document.
- Google's infrastructure provides physical security, network controls, and operational monitoring as described in Google's own security documentation.
- Crash reports and analytics are transmitted to Firebase services under Google's data protection terms.
4. Data on your device
- Records and settings are kept in the app's sandboxed private storage, inaccessible to other apps on a non-compromised device.
- Reminder times and contents never leave the device; scheduled alerts are delivered by the Android system locally.
- Uninstalling the app or clearing its data permanently removes everything stored on the device.
5. Payments and ads
- Moneyly Pro purchases are processed entirely by Google Play Billing — your payment details go to Google, never to us.
- Ads in the free version are served by Google AdMob under Google's ads and consent policies.
6. What we will never ask for
Moneyly support will never ask for your passwords, bank logins,
card numbers, OTP codes, or full backup files. Anyone asking for these while
claiming to be us is not us — please report it immediately.
7. Your part in staying secure
- Keep your device locked (PIN, fingerprint, or face) and install system updates.
- Only install Moneyly from Google Play; builds from other sources may be tampered with.
- Review which Google account you use for backup, and sign out on devices you no longer own.
8. Reporting a vulnerability
If you discover a security issue, please email support.moneylyapp@gmail.com with details and steps to reproduce. Do not disclose it publicly until we have had a reasonable time to fix it. We will acknowledge reports and keep you updated on the fix.
Found a security issue?
Contact us privately — please do not post vulnerabilities publicly.