Guru MoneyGuru MoneyFinance workspace

1. Data we process

  • Account: email, first and last name, and the sign-in identifier from Google, Apple or Telegram, depending on the chosen registration method.
  • Profile (optional): avatar, city, date of birth, occupation, short bio.
  • Financial data: accounts and their balances, transactions with amounts, dates, categories, descriptions and merchant names, transfers, spending limits, debts and instalments, subscriptions and their reminders.
  • Banking data: masked card number, IBAN, balance and credit limit, transaction history — only for cards the user connects themselves.
  • User-generated content: receipt photos attached to transactions, notes, and conversations with the AI assistant.
  • Technical data: IP address, User-Agent and session activity time, push notification token, device name, platform and app version.
  • Learning module: topic progress, quiz answers and interaction statistics — used to resume where the user left off and to improve the material.

2. How the data is used

  • To operate the service itself: expense tracking, bank synchronisation, analytics inside the user’s workspace.
  • To send the notifications a user has opted into: new bank transactions, subscription reminders and debt payment reminders.
  • To support users, investigate incidents and maintain security.
  • To improve the learning module based on progress statistics.
  • We do not sell data, do not share it with advertising networks or data brokers, and do not use it for cross-service tracking. The advertising identifier (IDFA) is not collected, and the app contains no third-party analytics or advertising SDKs.

3. AI assistant and third-party processing

Guru Money includes a built-in AI assistant for personal finance questions. When a user sends a message, the data needed to answer is transmitted to the selected model provider: amounts, currencies, dates, categories, transaction descriptions and merchant names (up to 200 transactions per request), configured limits, and earlier messages from that conversation.

The providers available in settings are Anthropic (Claude models), Google (Gemini models) and OpenAI (GPT models). Data is processed on their servers under each company’s own terms. Claude Haiku by Anthropic is used by default.

The AI assistant is optional. If the chat is never opened, no financial data reaches these companies. The app also supports a local model that runs directly on the device — in that mode the data never leaves the phone.

4. Who else receives data

  • Banks connected by the user (currently Monobank): we send the access token provided by the user in order to retrieve balances and transaction history. The token is stored encrypted.
  • Expo (push notification delivery): the device token and the notification text. Note that this text may contain a transaction amount and name and may appear on a locked screen — notifications can be disabled in settings.
  • Google, Apple and Telegram: only within the chosen sign-in method. We receive an identifier, email and name, and have no access to anything else in those accounts.
  • Telegram bot: if the user connects it themselves, financial summaries are delivered to their Telegram chat.
  • The hosting provider running the service infrastructure.

5. Device permissions

  • Camera and photo library — solely to attach a receipt photo to a transaction. Access is requested at the moment of use.
  • Push notifications — to deliver the alerts a user has opted into.
  • Face ID or Touch ID — for optional app lock. Biometric data is handled by the operating system, is never exposed to the app and never leaves the device.
  • Location and contacts access are not requested.

6. Storage, protection and deletion

  • Banking tokens are encrypted (AES-256-GCM) and passwords are stored only as hashes (bcrypt).
  • Receipt photos are stored privately and accessible only through a temporary signed link.
  • Internal access to data is limited to operational necessity.
  • Data is retained while the account exists. It can be deleted directly in the app: Profile → Delete account.
  • After deletion, the email, name, avatar and all sign-in identifiers are anonymised, sessions are terminated, and signing back in with the same credentials is impossible. If the user was the sole owner of a workspace with other members, ownership passes to the longest-standing active member so that shared data is not lost for those people.

7. Your rights

Users may obtain a copy of their data, correct it, restrict processing or delete their account. Deletion is available in the app; other requests can be sent to privacy@guru-money.com. We respond within 30 days.

The service is not directed at children under 13, and we do not knowingly collect their data.

8. Changes to this policy

We update this policy as the service evolves. The date of the last update is shown at the top of this page, and we announce material changes in the app.

9. Company details

ФОП Кiрiченко Iгор Леонiдович, 51200, Самар, Днiпропетровська область, registration ID: ЄДРПОУ 3680004779.

Privacy and legal requests: privacy@guru-money.com.

Operational support: support@guru-money.com.