SMS messages you choose to paste
MoneyKai processes only the message you paste, offline on your phone, to suggest transaction details. Unrelated messages and security codes are ignored. Pasted text is discarded after parsing and no inbox permission is needed. Only details you review and confirm enter your local financial records. SMS-derived transactions, raw SMS, OTPs, PINs and passwords are not uploaded or included in cloud backups.
Optional automatic bank SMS
Default public builds do not request SMS inbox access. A distribution configured for SMS capture presents a separate prominent disclosure and obtains affirmative consent before Android SMS permission. When enabled, MoneyKai filters incoming bank and payment SMS offline, including while the app is closed. It ignores unrelated messages, security codes, offers and failed payments. Redacted drafts, masked account hints and confirmed SMS-derived transactions remain on-device. Decline, stop capture or revoke access in Android Settings without losing manual tracking. Automatic access is subject to Google Play permission review; this policy does not imply approval.
Before You Buy and Price Memory
Before You Buy estimates budget impact from confirmed spending and commitments you enter; scenario inputs are not saved. Price Memory stores the prices, quantities, variants, shops, dates and optional transaction links you enter on your phone, separated by account. Price history is not currently cloud-synced or included in MoneyKai backups. Neither tool infers item prices from SMS totals or retrieves live shop prices. Delete entries in Price Memory; clearing storage or uninstalling may remove the local history.
Encryption and control
HTTPS protects transfer of non-SMS records to services, but is not end-to-end encryption; authorized services can process synced records. Android transaction records, capture drafts, app notifications and Price Memory use authenticated encryption with a device Keystore key. Other preferences may use ordinary private storage. Turning capture off stops future reading, not the OS permission or existing records: revoke access and clear drafts separately. Signing out clears capture consent and drafts; account-separated price history remains. Confirmed in-app deletion also removes this account’s price history on this device. Other devices and exported files must be cleared separately. Never enter credentials in record fields.
Scope
This policy covers the MoneyKai React Native Android app, package com.moneykai.mobile, and the MoneyKai services it uses to provide authenticated cloud sync. It applies to the public Play release, not separate internal research builds.
Developer and contact
MoneyKai is the app name and developer identity used for this release. Privacy questions or deletion requests can be sent to support@moneykai.app.
Information we process
To provide the service, MoneyKai processes account identifiers supplied through sign-in, user-entered profile details, transactions, budgets, savings goals, group and split-expense data, app settings, and backup snapshots. If you use the optional People picker, the selected contact identifiers, names, and amount allocations are attached to your transaction and may be included in sync and backups. The full address book is not uploaded. The app also keeps a local working copy on your device so it can remain useful when your connection is interrupted.
How cloud sync works
When you sign in, MoneyKai sends the information needed for your account, sync, Firebase cloud backup, and shared-expense features to MoneyKai services. Firebase is used for authentication and MoneyKai backend services process synced application data for the authenticated account. We use this information to provide the features you request, restore your data, keep your signed-in devices consistent, and maintain service security.
Optional device notifications
If you enable app notifications, MoneyKai may show reminders or app alerts on your device and handle your response to those alerts. The public Play release does not request notification-listener access and does not read notifications from other apps.
Optional contacts access
MoneyKai asks for contacts permission only when you open the People picker in a transaction. You can select one or more people or add a name manually; declining permission does not prevent you from recording a transaction. MoneyKai reads the device contact list for the picker but saves only the contacts you select with that transaction.
What the public Play release does not access
The default public build does not read the SMS inbox, capture other apps’ notifications, or request camera, microphone, location or broad storage permissions. Pasted-message parsing processes only the message you choose to paste. Automatic SMS access is limited to specially configured distributions with separate disclosure, consent and permission. Notification capture, Gmail sync, PDF statement parsing, wealth integrations, Financial AI, advertising, payment processing and bank-account aggregation are not included in the default public build.
Diagnostics and selling data
The public Play release disables remote Sentry reporting and diagnostic-event uploads. Optional local diagnostics remain on the device for troubleshooting and are not uploaded in this release. MoneyKai does not sell personal or sensitive user data, and it does not use financial data for advertising.
Retention and deletion
Data stored on your device remains until you delete it, clear app storage, or uninstall the app. Account and synced data are retained while your account is active so the service can provide sync and backups. To delete your account and associated data, use Profile → Security & data → Delete account in the Android app, or visit https://moneykai.com/account-deletion to request deletion without the app. We verify requests made through support before completing them.
Sharing
MoneyKai shares data only with the service providers needed to authenticate you and operate the cloud-sync service, or when you intentionally use a sharing feature such as a group expense or exported file. We do not sell this data.
Cookies and local storage
This public website may use necessary browser storage for sign-in, preferences, security, and page behavior. The Android app does not use web cookies.
Optional diagnostics and performance telemetry
Optional website diagnostics and performance telemetry run only after you accept analytics consent. MoneyKai uses this information to find broken routes and performance regressions without collecting financial document contents.
Changes
If a future release adds a new data source, permission, processor, or purpose, MoneyKai will update this policy and the corresponding Google Play Data Safety disclosures before that release is distributed.
Last reviewed
This policy was last reviewed on September 30, 2026 for message parsing and purchase tools. Public SMS inbox access remains subject to separate permission review.