Menudo App

Privacy Policy

We value your privacy. Below is a clear and transparent explanation of how we handle and protect your personal information in Menudo.

1. Data Controller

Menudo App is developed and operated by Miguel Cruz, based in the Dominican Republic. We are committed to protecting your privacy and treating your personal data in accordance with the highest standards of transparency and security. For any inquiries regarding this policy, please contact us at: soporte@menudoapp.com.

2. Information We Collect

To provide our personal and shared expense tracking features, we process: • Account Data: Email, unique user ID, profile name, and optional profile picture provided during registration. • Financial Data: Transaction details you log manually or automatically (amount, concept/description, category, date, currency, and uniqueness/idempotency keys). • Collaboration Data: Emails of users you invite to your shared expense lists.

3. Email Connection (Banking feature)

Banking is optional: it only turns on if you connect it, and you can disconnect it at any time from Settings › Connect bank. • Which email: you can connect Gmail (Google) or Outlook, Hotmail and Live (Microsoft). • Permission we request: one only and READ-ONLY in both cases — "gmail.readonly" on Google and "Mail.Read" on Microsoft. Menudo cannot write, reply, forward or delete anything in your email, and cannot modify your account. • What we read: only the emails sent by the bank addresses you connect. The query we send — to Gmail or to Microsoft, depending on which you connected — is limited to those senders, so the rest of your inbox is never read or downloaded. • What we store: from each bank email we extract the amount, the currency, the merchant or person, the date, the last four digits of the card when the bank includes them, and the type of movement. We also keep the email text for 30 days so we can investigate a recent problem; after that it is deleted automatically. We never store your email or bank password: we do not have them and we do not ask for them. • What we use it for: only to suggest movements in the app's review tray. Nothing is recorded in your accounts until you accept it. • What we never do: we do not sell or share this data, we do not use it for advertising or profiling, and we do not use it to assess creditworthiness or for lending. No person at Menudo reads your email: the process is automated. We would only access a specific email if you asked us to in order to resolve your own support case, if it were strictly necessary to investigate a security abuse, or if required by law. • Limited Use: Menudo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. • How to remove it: Settings › Connect bank › Disconnect. Movements you already accepted remain yours, like any expense you typed in by hand. – If you connected Gmail, disconnecting revokes the permission with Google and deletes the token. You can also revoke it yourself at https://myaccount.google.com/permissions. – If you connected Outlook, we delete the token from our servers, which stops us reading anything. Microsoft gives applications no way to revoke the permission on their own, so the entry stays listed in your Microsoft account until you remove it at https://account.live.com/consent/Manage. We show you this when you disconnect. If you delete your Menudo account, everything related to Banking is deleted, and for Google we also revoke the permission. • Where it is stored: in our database at Supabase (United States), encrypted in transit and at rest. Your email access token is additionally encrypted separately with AES-256-GCM.

4. AI Processing and Categorization

When you log a transaction via voice, text, or Siri Shortcut, the expense description and your custom category list are processed using Groq's LPU hardware and the Llama 3 model to automatically categorize the entry. We do not transmit personally identifiable information (such as your name or email) to Groq's AI services.

5. Providers and Storage

Your data is stored and processed securely using industry-leading technology providers: • Supabase: For secure, encrypted database hosting, user authentication, and cloud storage. • RevenueCat & Apple App Store: For secure management of premium subscription status and billing. We never store or handle your credit/debit card details. • Apple APNs: For sending clean, real-time push notifications regarding collaborative list activities. • Sentry: For application stability monitoring and capturing system and server errors. • PostHog: For product analytics and tracking user interactions inside the mobile app and website.

6. Data Retention and Security

• Extreme Idempotency: Every transaction contains a unique "idempotency_key" generated by the mobile client. If your connection drops and transmits multiple times, our backend prevents duplicate logs. • Retention: We keep your data only as long as your account remains active. If you choose to delete your account in the app settings, all your personal info and transaction history will be permanently and immediately deleted from our active databases.

7. Your Rights and Governing Law

You retain the right to access, correct, export, or permanently delete your data at any time. Operated by Miguel Cruz, this agreement is governed by the laws of the Dominican Republic, while incorporating global compliance standards (including GDPR rights) for all users.

Have questions about your data?

We are committed to absolute transparency. You can reach out to support or email us directly.