Privacy PolicyUU PDP No. 27/2022 Compliant

Privacy Policy

Full compliance with Indonesia's Personal Data Protection Law (UU PDP No. 27/2022). Your financial confidentiality is non-negotiable.

Last Updated: September 5, 2026
Version: Version 2.4
Jurisdiction: Republic of Indonesia
Reading Time: ~5 min

Key Transparency Highlights (30-Second Summary)

MoneFin operates on a strict Zero Data Brokering standard: we NEVER sell, rent, or trade your financial transactions to third parties or advertising networks.

AI processing is fully isolated: your prompts and transactions are NEVER used to train public third-party AI models.

You possess complete Data Subject Rights under Indonesian law (access, export, rectification, and instantaneous permanent deletion of your data).

01

Privacy Commitment & Regulatory Framework (UU PDP)

At MoneFin, we view financial privacy as a fundamental individual right. This Privacy Policy is constructed under comprehensive compliance with Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection ('UU PDP') and modern global data privacy standards.

This policy outlines the categories of data we collect, our lawful bases for processing, the technical safeguards we enforce, and your enforceable rights as a Data Subject within MoneFin.

02

Categories of Personal Data We Collect

We collect only data that is strictly proportionate and necessary to power your personal finance management:

Account Identity Data: Full name or nickname, active email address, securely hashed password (using industry-standard adaptive cryptography), and profile avatar if voluntarily uploaded.

User-Entered Financial Records: Custom account/wallet labels (e.g., 'BCA Savings', 'Jago Pocket', 'Cash Wallet'), recorded starting balances, income and expense entries, budget categories, monthly thresholds, savings goals, and split bill participant lists.

Device & Security Telemetry: Anonymized IP addresses, browser User-Agent strings, operating system identifiers, and active login session timestamps used for multi-device management.

AI Assistant Interaction Logs: Financial queries submitted to the MoneFin AI assistant, stored in an encrypted state bound exclusively to your user account.

03

Zero Data Brokering Principle

We make an unyielding commitment: MoneFin has never and will never sell, rent, lease, or distribute your personal financial records to advertising networks, commercial data brokers, or marketing syndicates.

Our corporate revenue model is entirely independent of targeted advertising. We are funded strictly to engineer robust, private, and secure personal finance management tools.

100% Data Integrity Guarantee

MoneFin does not monetize user data via ad exchanges. Your financial balances and transactions belong solely to you, never to advertisers.

04

Lawful Purposes of Data Processing

Pursuant to Article 20 of the UU PDP, MoneFin processes data under your explicit consent and for contract fulfillment, strictly to:

Aggregate, calculate, and present your cash flow, account balances, and net worth summaries.

Render comparative expense analytics, category breakdowns, and goal tracking charts.

Compute automated mathematical allocations for group split bills.

Dispatch transactional security One-Time Passwords (OTP) to your verified email.

Detect unauthorized login attempts and enable remote session termination.

Generate contextual AI analytics responses upon your active request.

05

Isolated AI Processing & Zero Public Model Training

The AI Assistant in MoneFin operates via dedicated enterprise API channels bound by zero data retention agreements with upstream AI model providers.

Your telemetry and queries are encrypted in transit via TLS 1.3 and processed instantaneously in ephemeral memory. Upstream providers are contractually prohibited from using MoneFin customer data to train or fine-tune public models.

Strict AI Isolation

Your prompts and financial queries are strictly shielded and NEVER utilized to train public large language models.

06

Data Storage, Retention, & Cryptographic Protection

Data is hosted within cloud data centers maintaining ISO 27001 and SOC 2 certifications. All client-to-server traffic is shielded by Transport Layer Security (TLS 1.3 / HTTPS).

Passwords are irreversibly hashed using Bcrypt/Argon2id algorithms with unique cryptographic salts. Sanctum session tokens are stored as cryptographic SHA-256 hashes in our database.

Your financial data is retained for the lifespan of your account. When you delete your account, your profile, wallets, transactions, split bills, and session records are permanently and irrecoverably purged from production databases.

07

Your Rights as a Data Subject Under UU PDP

In compliance with Chapter IV of the Indonesian PDP Law, you enjoy the following enforceable rights, operable directly within the app:

Right of Access & Data Portability: You may view all stored transaction history at any time and export your records into standard formats (CSV/Excel/PDF).

Right to Rectification: You may update your display name, wallet labels, transaction entries, and category allocations at will.

Right to Erasure ('Right to be Forgotten'): You hold the absolute right to permanently delete your account and all associated financial history via Profile Settings, validated with password re-confirmation.

Right to Revocation: You may terminate active remote sessions on any other device with a single click.

Right to Withdraw Consent: You may cease using the platform and request immediate closure of your account without penalty.

Access & Data Portability

Download transaction logs in CSV/Excel formats whenever required.

Rectification & Updates

Edit wallet labels, amounts, and category mappings freely.

Permanent Erasure

Irreversibly purge account and data via Profile Settings.

Device Session Revocation

Remotely terminate active logins across older devices.

08

Cookie Policy & Session Token Architecture

MoneFin does not employ third-party cross-site advertising cookies.

We utilize securely configured Sanctum authentication tokens bearing the 'mnf_' prefix to manage authorized session states.

Browser local storage (localStorage) is reserved strictly for non-sensitive presentation preferences such as language (ID/EN) and the Balance Privacy toggle.

09

Data Protection Officer (DPO) Contact

MoneFin has appointed dedicated data compliance personnel to oversee and guarantee alignment with personal data protection regulations.

For inquiries, subject access requests, or regulatory questions, please contact our Data Protection Officer at:

Email: privacy@monefin.com

Was this document clear and helpful?

We are dedicated to presenting terms transparently with zero hidden fine print.