Monito LogoMonito
About Features AI Architecture Contact Get Monito →
Monito LogoMonito
🏠Home 📖About ✨Features 🤖AI Architecture 💬Contact
⚡ Get Monito Free →
100% Offline SQLCipher AES-256 11 AI Models
🛡️ Privacy Policy

Your Privacy is Our Core Architecture.

Last Updated: August 2026 • Version 1.7.0 • Compliant with GDPR, CCPA, and Global Financial Privacy Standards

Contents

  • 1. Executive Summary
  • 2. 100% Offline-First AI
  • 3. Information We Process
  • 4. SQLCipher AES-256 Security
  • 5. SMS, Voice & OCR Policies
  • 6. Cloud Sync & SSL Pinning
  • 7. GDPR & CCPA Rights
  • 8. Account Erasure & Export
  • 9. Contact Our DPO

1. Executive Summary

Monito ("we," "our," or "us," operated by Digitekki) was founded on an uncompromising principle: your financial life is private and belongs exclusively to you. Unlike traditional fintech applications that monetize your transaction history, track your spending habits, or sell behavioral dossiers to credit aggregators and advertisers, Monito is engineered from the ground up as an offline-first, encrypted personal intelligence application.

All machine learning computations, entity extraction, receipt scanning, and budget simulations execute locally on your physical device processor. Zero financial data leaves your phone unless you explicitly enable optional multi-device cloud synchronization.

2. 100% Offline-First AI Architecture

Monito embeds a proprietary stack of 11 lightweight machine learning models (799.1 KB total footprint) directly into the app binary:

  • Local TFLite Inference: Transaction classification, spending anomaly detection, and bill recognition run on Google AI Edge LiteRT 1.4.0 without sending tokens to cloud APIs.
  • Zero Telemetry Harvesting: We do not embed third-party advertising SDKs, behavioral analytics trackers (e.g., Facebook Pixel, AppsFlyer, Adjust), or cross-app tracking beacons.

3. Information We Process

Depending on your use of Monito’s features, the following data points are created and stored strictly on your local device:

  • Financial Records: Ledger amounts, transaction timestamps, merchant names, categories, custom tags, budgets, and savings milestones.
  • Bank SMS & Push Notifications (Android): Transactional alerts from whitelisted banking apps are parsed in a transient background isolate. Non-financial messages are ignored, and raw SMS payloads are never stored on disk or sent over any network.
  • Voice Recordings: Spoken audio is streamed directly to the on-device BiLSTM intent model in RAM. Audio recordings are immediately purged from memory once the transaction entity is extracted.
  • Receipt Images: Physical bill photos are analyzed locally by Google ML Kit OCR and 4-channel image quality filters before being saved exclusively inside your encrypted app-private directory.

4. SQLCipher 256-bit AES Security

All local database tables are protected with SQLCipher AES-256-CBC database-at-rest encryption. Cryptographically random 256-bit keys are generated on first launch and sealed inside your operating system’s hardware security module (Android Keystore / iOS Apple Secure Enclave).

🔒
Zero Plaintext Exposure: Even if your device is backed up or unencrypted file system access is attempted, the underlying SQLite database file is completely unreadable without the hardware-bound key.

5. SMS, Voice & Camera Device Permissions

Monito requests minimal device permissions strictly required for user-initiated features:

  • SMS / Notification Listener: Used exclusively to parse real-time transaction debit/credit alerts from whitelisted financial institutions. Personal OTPs, passwords, and private chats are never accessed.
  • Microphone: Activated solely when you hold the Voice Entry button to speak a transaction.
  • Camera & Storage: Used solely to capture or import receipt photos for line-item OCR processing.
  • Biometrics (FaceID / Fingerprint): Used solely for app-lock verification. Biometric templates remain inside the OS Secure Enclave and are never accessible to Monito.

6. Optional Cloud Synchronization & SSL Pinning

If you create an optional Supabase cloud sync account to back up or sync data across multiple devices, all payload transmissions are protected with Subject Public Key Info (SPKI) SSL Pinning (SHA-256 certificate hashes). This completely prevents Man-in-the-Middle (MITM) inspection on untrusted Wi-Fi networks.

Remote tables enforce PostgreSQL Row-Level Security (RLS) policies with security_invoker = on, ensuring that only your authenticated UUID can read, write, or delete your encrypted cloud records.

7. GDPR & CCPA User Rights

Regardless of your geographic location, Monito affords all users full compliance with the European General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA):

  • Right to Access (GDPR Art. 15): You have direct access to all data stored in the app at any time.
  • Right to Data Portability (GDPR Art. 20): One-tap export of your complete financial database into an open JSON/CSV format.
  • Right to Erasure / Forgotten (GDPR Art. 17): Permanent, irreversible deletion of all local and cloud data.
  • Non-Discrimination (CCPA): Monito provides the exact same high-tier features without requiring personal data monetization.

8. Account Erasure & Data Portability

You can permanently delete your entire account and all associated records directly inside the app under Settings ➔ Security & Privacy ➔ Delete Account. Upon entering "DELETE" to confirm:

  1. All remote Supabase database rows and authentication credentials are wiped permanently via cascade execution.
  2. All local SQLite tables are truncated and zero-filled.
  3. The 256-bit SQLCipher encryption key is permanently destroyed from the Hardware Keystore / Secure Enclave.
  4. All local cached tokens, receipts, and configurations are erased.

9. Contact Our Data Protection Officer (DPO)

If you have questions regarding this Privacy Policy, your rights under GDPR/CCPA, or security audits, please contact our Data Protection team:

Digitekki Technologies — Monito Privacy Team

Email: privacy@monito.in

Security Vulnerability Reports: security@monito.in

Website: https://monito.in

Monito LogoMonito

The enterprise AI-powered personal wealth and money management system. 100% offline-first privacy with SQLCipher 256-bit AES encryption.

Product
Features AI Architecture Privacy & Security Download v1.7.0
Pages
About Contact Privacy Policy Terms of Service
Built with 💜 in India • Powered by Flutter, Dart & Jaspr
© 2026 Digitekki. All rights reserved. • monito.in