Legal

Privacy Policy

Last updated August 30, 2026 privacy@manilo.app

Summary

The short version: Manilo (formerly Ledgy) is local-first — your transactions live on your device. If you turn on Cloud, a copy syncs to our servers on Google Cloud (United States) so your other devices, people you share with, and AI assistants you choose to connect can work with it. We never sell your data, never show ads, and never use your data to train AI models.

This Privacy Policy explains what data Manilo ("we", "us") collects when you use the Manilo iOS app (including the Apple Watch app), the Manilo web dashboard at dashboard.manilo.app, the Manilo Telegram bot, our AI-assistant integrations (ChatGPT, Claude, and other MCP-compatible clients), and any related services (collectively, the "Service"). Some service endpoints operate under our legacy ledgy.app domain. This policy is written in plain English and aligned with the GDPR (EU 2016/679) and Apple App Store requirements.

What we collect

Account data (when you sign up for Cloud)

  • Email address — identifies your account and receives service email. If you sign in with Apple or Google, we receive the email and basic profile they share; if you sign up with email and password, we store your email and a hash of your password (never the password itself).
  • Authentication data — sign-in tokens issued by Apple, Google, or our own auth flow. Personal access tokens you create for API/MCP access are stored as SHA-256 hashes only.
  • Subscription status — whether you have an active entitlement or trial, supplied by RevenueCat and Apple. Payments are processed by Apple (in-app) or RevenueCat's checkout (web); card details never reach our servers.

Application data (when you use Cloud)

  • Your ledger — transactions (amount, currency, date, category, account, free-text notes, merchant/payee), accounts and balances, categories, tags, budgets, recurring rules, spending groups (including the display names of people you share with), and profile settings (primary currency, language, date and number format, timezone, week start).
  • Receipt files you attach — photos or PDFs.
  • Voice input. Dictation in the iPhone app is transcribed on your device by Apple's speech framework — only the resulting text reaches us. Voice entries made on Apple Watch and voice notes sent to the Telegram bot are transcribed on our servers by our AI provider (Groq); the audio is processed transiently and is not stored by us.
  • For Telegram users: your Telegram user ID (the join key to your Manilo account) and the messages, photos, and voice notes you send the bot.
  • For Apple Wallet users: transaction notifications you choose to forward — merchant, amount, currency, and timestamp. We never receive card numbers.
  • Content you hand to a connected AI assistant to import (for example a bank statement or a receipt) — it is processed by that assistant's platform first, then stored in your ledger like any other entry.

Diagnostic and usage data

  • Crash reports — anonymized, sent through Apple's standard crash reporting (which you can opt out of in iOS Settings).
  • Usage analytics — we use Google Analytics (Firebase) across the app, the website, and our API to measure feature usage: screens viewed, features used, tool calls made by connected assistants, and timings. For signed-in users these events are linked to your account identifier, and a copy of the raw events is exported to Google BigQuery in our own project so we can analyze product usage per account. We do not send transaction amounts, merchant names, notes, or receipt contents to analytics. On our websites, Google Analytics sets cookies only after you accept them in the cookie banner; declining keeps the site fully functional.
  • Install attribution — if you installed Manilo from an Apple Search Ads ad, Apple's privacy-preserving AdServices framework provides an attribution token that our subscription provider RevenueCat exchanges for the campaign, ad group, and keyword the install came from. No device identifier (IDFA) is involved and no tracking permission is requested; we use it only to measure which ads work.
  • Security data — IP addresses are processed transiently for rate limiting and abuse protection. Server logs (which reference your account identifier and actions, never your email) are retained for up to 30 days.

What we never collect

  • Your bank credentials, card numbers, or banking sessions. Manilo does not connect to bank accounts.
  • Your contacts, calendar, photo library, or location. We only receive the photos you explicitly attach.
  • Identifiers For Advertisers (IDFA). Manilo does not show ads.
  • Stored voice recordings. Audio is transcribed and discarded; iPhone dictation never leaves your device.
  • Anything we don't strictly need to deliver the features above.

How we use it

We use the data above only to:

  • Sync your ledger across your devices and with people you have explicitly invited to shared groups or accounts.
  • Parse your text, photos, voice transcripts, and forwarded notifications into transactions (AI processing).
  • Answer questions and perform actions you ask a connected AI assistant to do.
  • Manage your subscription and trial.
  • Send transactional, onboarding, and offer email — sign-in codes, security notices, account changes, getting-started tips, and occasional messages about your trial or plan. Every non-essential email has an unsubscribe link.
  • Deliver push notifications you enable. Their text can include amounts and merchant names, appears on your lock screen, and transits Apple's and Google's push services.
  • Diagnose crashes, measure usage, and prevent abuse.
  • Measure which App Store ads bring people to Manilo (see install attribution above).

We do not sell your data, share it for advertising, or use it to train our own or third-party AI models.

  • Performance of our contract with you (Art. 6(1)(b)) — syncing your ledger, parsing your entries with AI, serving connected assistants, managing your subscription, and sending transactional email.
  • Our legitimate interests (Art. 6(1)(f)) — usage analytics, install attribution, abuse prevention and security, and onboarding and offer email. You can object at any time: unsubscribe from email via the link in every message, and contact us to opt out of analytics for your account.
  • Your consent (Art. 6(1)(a)) — cookies on our websites, and optional features you switch on yourself (Cloud, Telegram bot, Apple Wallet forwarding, connecting an AI assistant). Withdraw it by turning the feature off or declining cookies.

AI Assistants & Model Context Protocol (MCP)

If you connect Manilo to an AI assistant — ChatGPT (OpenAI), Claude (Anthropic), or another MCP-compatible client — via our integrations page, the assistant can, on your instruction, read and change your data through Manilo's tools. We never push your ledger to an assistant on connection — data moves only when the assistant calls a tool on your behalf.

What the assistant can read: your transactions (including notes and merchant names), accounts and balances (including income/expense/transfer breakdowns), budgets, categories, tags, recurring rules, spending groups including member display names, your profile settings, aggregated totals, and receipt files via short-lived signed download links whose URL contains your account identifier. Tool responses also include record identifiers (so the assistant can reference entries in follow-up actions) and service state such as your trial or subscription status and occasional usage tips.

What the assistant can write: create, update, and delete transactions, transfers, balance adjustments, accounts, categories, tags, budgets, recurring rules, and groups; update your profile settings; and attach receipt files to transactions.

Data the tools return is transmitted to the assistant's platform and handled there under that platform's own privacy terms (OpenAI's for ChatGPT, Anthropic's for Claude). Content you upload to an assistant is processed by that platform before Manilo receives what you asked to import. You can disconnect the assistant at any time from its settings, and revoke personal access tokens in the dashboard; server-side access ends immediately.

Subprocessors

To deliver the Service we rely on the following providers. Each processes data only on our instructions under a data-processing agreement.

  • Google Cloud Platform — hosting and storage: our backend runs on Google Cloud Run, with Google Firestore (database) and Google Cloud Storage (receipt files) in the United States; push delivery via Firebase Cloud Messaging.
  • Groq — primary AI parsing of transaction text and receipt images, and transcription of Apple Watch and Telegram voice input. Requests carry your account identifier for abuse prevention; content is not used to train their models per their API terms.
  • OpenAI — fallback AI parsing of transaction text and receipt images, under the same account-identifier and no-training API terms. OpenAI is also the assistant platform that receives your queried data when you connect Manilo to ChatGPT.
  • Anthropic — the assistant platform that receives your queried data when you connect Manilo to Claude; API data is not used for model training per their terms.
  • Apple — Sign in with Apple, in-app subscription payments, push notifications, and crash reporting.
  • Google — Sign in with Google, Google Analytics (Firebase) for usage measurement (sets cookies on our websites with your consent), and Google BigQuery for our analytics export.
  • RevenueCat — subscription state, web checkout, and install attribution; receives your account identifier and Apple Search Ads attribution data, never your ledger.
  • Microsoft 365 — transactional and onboarding email delivery.
  • Upstash — encrypted, short-lived server-side cache; entries expire within 24 hours.
  • Telegram — message relay for users who opt into the Telegram bot. Your conversation with the bot (including transaction confirmations it sends) stays in your Telegram chat history under Telegram's own privacy policy.

Where data is transferred out of the EU or UK, we rely on our providers' recognized safeguards (EU-U.S. Data Privacy Framework or Standard Contractual Clauses). For DPA copies or subprocessor sub-locations, write to privacy@manilo.app.

Retention & deletion

  • Your ledger and receipts are kept for as long as your account exists — until you delete individual entries or your whole account.
  • If your Cloud subscription ends, your synced data remains stored so it is there if you return; your local copy stays on your device. You can remove the server copy at any time by deleting your account.
  • Account deletion: Settings → Account → Delete account. Your data is deleted from our production database immediately — a hard delete, not a deactivation. Receipt files become permanently inaccessible at the same moment. Encrypted database backups expire within 30 days; server-side caches within 24 hours; server logs within 30 days.
  • AI providers (Groq, OpenAI, Anthropic) process parsing and assistant requests transiently under their API data-retention terms and do not train on them. Google Analytics retains usage events for up to 14 months, and our BigQuery copy is deleted on the same 14-month schedule.

Your rights

If you're in the EU, UK, or California you have rights to access, correct, port, delete, or object to the processing of your personal data. Most of them you can exercise directly in the product, or by emailing privacy@manilo.app. We respond within 30 days.

  • Delete everything: Settings → Account → Delete account.
  • Export your ledger as CSV from the app.
  • Disconnect an AI assistant from the assistant's own settings; revoke personal access tokens in the dashboard — both cut off server-side access immediately.
  • Unsubscribe from non-essential email via the link in every message.
  • Opt out of crash reports in iOS Settings.

You also have the right to lodge a complaint with your local data protection supervisory authority.

Children

Manilo is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect data from minors. If you believe a child has signed up, contact us and we'll delete the account.

Changes

If we change this policy in a way that affects how we handle your data, we'll notify you in-app and by email at least 14 days before the change takes effect. Continued use of the Service after the change constitutes acceptance.

Contact

Email: privacy@manilo.app

The data controller is Borys Harholinskyi, an individual entrepreneur (autónomo) registered in Spain, trading as Manilo. Contact: privacy@manilo.app.