At Montrai, we take your financial privacy seriously. This Privacy Policy describes how Montrai Inc. / j.a.t. Creativestudios ("we", "us", or "our") collects, uses, processes, and protects your information when you use our mobile and web applications.
1. Information We Collect and How We Use It
- Account Data: When you sign up via Email, Google Sign-In, or Sign In with Apple, we collect your email address and basic profile information to authenticate you and sync your data securely across devices via Google Firebase.
- Financial & Transactional Data: We store the transaction categories, amounts, dates, budgets, and savings goals you input locally and, when you use a verified account, sync them securely to Cloud Firestore.
- Collaborative Data: Data added to a "Shared Space" is accessible only to users who possess the unique alphanumeric Space ID.
2. Device Permissions & Advanced Data Processing
We utilize advanced features to streamline your financial logging. Here is exactly how your data is handled:
- Notification Access (Same-Day Transaction Parsing): On Android, granting Notification Access allows Montrai to see notification titles and text from all apps, including while Montrai is closed. Montrai processes this data locally to detect same-day bank and wallet transaction alerts. Non-transaction alerts and security codes are ignored. SMS-app notification banners are included only when you enable that source; Montrai never reads your SMS inbox or message history. Raw notification text is retained temporarily on the device for the current day and is never uploaded. Extracted transaction fields follow your normal local or cloud-sync setting.
- Microphone & Audio Data (Voice Logging): When you choose voice transaction logging, the recording is sent over an encrypted connection through a Montrai Firebase function to Google Gemini to convert it into draft transaction fields for your review. Montrai does not add the drafts to your financial records until you confirm them. The temporary audio file is removed from the app’s working storage after processing and is not intentionally retained in Montrai application logs or databases. Google processes the request as our service provider under its applicable data-processing terms.
- Biometric Data (Face ID / Touch ID / Fingerprint): Biometric locking is handled entirely through your device's native operating system APIs (iOS/Android). Montrai never accesses, collects, or stores your raw biometric templates. We only receive a "success" or "failure" message from your device.
- File Access: Local file access is used strictly when you choose a financial file (.xlsx, .xls, .csv, or .md) or submit a Google Sheets link. We do not scan background files. Canonical Montrai Markdown is validated on your device. Its content is sent for AI repair only if local validation fails and you explicitly choose Fix with Montrai AI.
3. Third-Party Services & Data Sharing
We do not sell your personal or financial data to third parties. We share data only with trusted service providers necessary to run the app:
- Google Firebase (Auth & Cloud Firestore): For secure user cloud database hosting and real-time syncing.
- Google Mobile Ads SDK / AdMob: Used for optional rewarded ads. On iOS, Montrai requests App Tracking Transparency permission before initializing AdMob. If permission is granted, AdMob may use device information across apps and websites for ad measurement and fraud prevention. Montrai requests non-personalized ads regardless of your choice, and the app remains usable if you deny permission. AdMob may also process advertising interactions, coarse location, device information, and diagnostic data for ad delivery, frequency capping, and reporting. AdMob sends a signed server-side verification callback before we grant an AI pass, data-transfer credit, or shared-space access. A data-transfer credit can unlock a reviewed formatted export or a canonical Markdown import. We do not use banner, interstitial, or app-open ads.
- Google Gemini API: Receives the voice, text, spreadsheet, or financial context that you intentionally submit for transaction parsing, spreadsheet formatting, optional Markdown repair, and tailored financial tips. Canonical Markdown validation and formatted export creation occur locally; a Markdown file is not sent to Gemini unless you explicitly request AI repair. Requests pass through an authenticated Montrai server function; they are not described as anonymous.
4. Advertising, Cookies, and Consent Choices
Before initializing optional rewarded ads on iOS, the app requests your choice through Apple’s App Tracking Transparency prompt. The mobile app also uses Google’s consent flow where required. Montrai requests non-personalized ads regardless of your ATT choice. Depending on your region and consent choices, Google may provide a non-personalized or limited ad, or no ad may be available. You can update available ad privacy choices from app settings. Declining tracking or consent, or dismissing an ad offer, does not restrict manual transaction logging, free raw-data export, or other non-reward features.
Our advertising partners may process device identifiers, coarse location, ad interaction data, and browser cookies or similar technologies for ad delivery, fraud prevention, reporting, and frequency capping. We do not sell your personal financial tracking data to advertisers.
For cost and reliability measurement, we record the AI action type, model, token counts, latency, estimated cost, ad placement, completion state, server-verified reward amount, and advertising paid-event revenue. Reward amounts and paid-event revenue are kept as separate measurements. We do not put prompts, audio, transaction amounts, categories, or file contents in monetization logs.
5. Data Security and Isolation
We implement industry-standard Firebase security rules to ensure that your financial data is completely isolated. Users can only read and write their own data, and subcollections within Shared Spaces are exclusively accessible to verified, active members of that specific Space ID.
6. International Data Transfers, Retention & User Rights (GDPR / CCPA / PIPEDA)
Montrai is accessible globally, and service providers may process data in countries other than your own. Account and synchronized financial data are retained while your account remains active or as needed to provide the service and meet legal obligations. Same-day raw Android notification text expires from local temporary storage; voice recordings are temporary processing inputs and are not intentionally retained in Montrai databases. Depending on your location, you may request access, correction, export, or deletion of personal data. A free raw JSON export is available from Profile > Account & privacy > Download my raw data; reviewed formatted Excel and Markdown reports are separate rewarded features. You can revoke microphone, notification, biometric, and Android Notification Access permissions in device settings, disable optional features in Profile, and permanently delete your account and associated cloud data from Profile.
7. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
8. Contact Information
For questions regarding this Privacy Policy or data deletion requests, please contact:
Montrai Inc. / j.a.t. Creativestudios
Email: j.a.t.creativestudios@gmail.com
Web: montraipersonalfinance.com