Privacy policy

Your financial history belongs in your spreadsheet.

Montley moves financial data from Plaid to a Google Sheet you control. If you opt in to chat notifications, we also keep an encrypted delivery copy for no more than 24 hours while sending newly synced transactions and later amount changes.

Effective and last updated: September 1, 2026

Privacy at a glance

Transaction rows and balances

Sheet is the durable source

Not logged or ordinarily stored. Optional chat delivery uses an encrypted buffer for no more than 24 hours.

Telegram notifications

Optional

Newly synced transactions and later amount changes are sent only after you connect a group. Every group member may see them, and Telegram retains delivered messages under its terms.

Google account and access

Stored securely

Profile details and encrypted OAuth tokens let you sign in and keep your Sheet connected.

Bank connection metadata

Stored securely

Encrypted Plaid tokens, account labels, identifiers, and sync state keep automatic updates working.

Billing information

Handled by Stripe

Montley keeps billing status and Stripe identifiers, not your full card number.

Product usage analytics

Pseudonymous events

PostHog receives sanitized page paths, setup milestones, and aggregate sync counts, never financial details.

About this policy

This Privacy Policy explains how Montley ("Montley," "we," "us," or "our") collects, uses, discloses, and protects information when you visit montley.app or use the Montley service. It also explains the important boundary between financial data that passes through our systems and the limited account, connection, and operational data we retain to provide the service.

This policy does not govern the independent practices of Google, Plaid, Telegram, Stripe, your financial institution, or anyone with access to a Google Sheet or chat you own or share. Their privacy terms apply to the information they process.

Information we process

Financial data processed in transit

When you connect a financial institution, Montley receives transaction and account-balance information from Plaid and sends it to the Google Sheet you selected. This can include transaction dates, descriptions, merchant names, categories, amounts, pending status, check numbers, account names and masks, institution names, account identifiers, current and available balances, currency, and timestamps. Montley may also read existing data in the connected Sheet to identify prior transactions, apply updates, repair the expected structure, and avoid duplicates.

Montley ordinarily holds this data only in application memory while a sync or maintenance operation runs. We do not put transaction details or balance amounts in application logs, analytics systems, or task-queue messages. The durable source of record is the Google Sheet you control. If you opt in to a chat notification, the limited exception described below applies to the transaction and amount-change details selected for delivery.

Optional chat notification data

If you connect the Montley Telegram bot to a group, Montley creates encrypted delivery payloads for newly synced transactions and later amount changes. A transaction payload can contain the date, description, current amount, currency code, account name and mask, and institution name. An amount-change payload also contains the previous amount. Connection, settings, and test messages may contain the connected Sheet title and link. The active database holds each encrypted payload only while delivery is pending. Montley clears it after successful delivery, permanent failure, disconnection, or expiration, and always within 24 hours. Task-queue messages contain only an internal delivery-job identifier. Protected database backups may contain an encrypted copy until the backup expires under our backup-retention schedule.

We also retain the Telegram group identifier and title in encrypted form, a one-way lookup value, destination status, provider message identifier, delivery timestamps and status codes, and replay-prevention metadata. We do not retain the text of your bot commands. Telegram receives and stores messages delivered to your group under Telegram's own practices. Montley does not support direct chats, channels, or Telegram Secret Chats. Telegram may retain a delivered message until it is deleted in Telegram, and every current or future group member may be able to see it.

Product analytics receives only aggregate counts of rows added, updated, or removed during a completed sync. Those counts do not include transaction descriptions, merchants, categories, dates, amounts, balances, account details, or Sheet contents.

Google account and spreadsheet information

When you sign in with Google, we receive and retain your Google account identifier, email address, name, profile image URL, OAuth access and refresh tokens, and token expiration. We also retain limited information about connected spreadsheets, such as the Google file identifier, URL, title, relevant tab identifiers, ownership, and collaborator permissions. OAuth tokens are encrypted at rest.

Bank connection and account metadata

To keep automatic syncing active, we retain an encrypted Plaid access token and limited connection metadata. That metadata can include Plaid Item and account identifiers, institution name, account name and official name, the last four digits or other account mask, account type and subtype, holder category, sync cursor, connection status, error state, and sync timestamps. We retain when a balance was last delivered, but not the balance amount itself.

Billing information

Stripe collects and processes your payment method, billing address, and any tax information requested during checkout. To create and reconcile a subscription, Montley sends Stripe your account email and an internal Montley Sheet record reference. We do not send Stripe the Google Sheet file identifier, title, URL, or contents. Montley receives and retains your email address, Stripe customer, checkout, and subscription identifiers, subscription status, trial and billing dates, payment status, and related billing metadata. Montley does not receive or store your full payment card number.

Invitations, communications, and support

If you invite someone to a Sheet, we process the invitee's email address, the inviter's name or email, the spreadsheet title, the invitation status, Google Drive permission identifiers, delivery timestamps, and a hashed invitation token. We send invitation emails through Postmark. If you contact us, we process the information in your message and any details needed to respond.

Technical information and local storage

Our hosting, security, and delivery systems may process standard technical information such as an IP address, request URL, browser or device type, timestamps, service errors, and security events. Montley uses a strictly necessary, signed session cookie to keep you authenticated. It expires after 30 days unless you sign out sooner. Your theme preference is stored locally in your browser.

We use PostHog Cloud for product analytics. PostHog receives pseudonymous browser and device identifiers, browser type, page paths with query strings and fragments removed, sanitized referrer paths, product setup and billing milestones, internal Montley user and workspace references, and aggregate sync counts. We do not send PostHog names, email addresses, Google Sheet file identifiers, titles, URLs, contents, bank or institution details, account identifiers, transaction details, amounts, or balances. We disable automatic interaction capture, session replay, surveys, heatmaps, performance capture, exception capture, device-model collection, and GeoIP enrichment. PostHog uses first-party browser storage to relate anonymous visits to a signed-in pseudonymous profile. We do not use third-party advertising cookies or behavioral advertising trackers.

How we use information

We use information only as reasonably necessary to:

  • authenticate your account and maintain your session;
  • connect the Google Sheet you select and keep its expected structure working;
  • connect financial accounts through Plaid and deliver transaction and balance updates to your Sheet;
  • send newly synced transaction and later amount-change notifications to a chat service you connect;
  • manage collaborators and send invitations you request;
  • process subscriptions, trials, refunds, and account billing;
  • operate, secure, troubleshoot, and improve the reliability of Montley;
  • understand signup, setup, activation, and retained product use so we can improve Montley;
  • prevent fraud, abuse, and unauthorized access;
  • respond to support and privacy requests; and
  • comply with law and enforce our agreements.

We may use operational statistics such as counts of completed or failed syncs to maintain the service. Those statistics do not include transaction details or balance amounts. We do not sell personal information, use it for targeted advertising, determine creditworthiness, make lending decisions, or use Google or financial data to train artificial intelligence models.

Google user data

Montley requests access to your basic Google profile and to Google Drive files that you create with Montley or explicitly open or select for use with Montley. We use that access to sign you in, create or connect the selected spreadsheet, read and update its relevant contents, manage Sheet collaborators at your direction, and maintain automatic syncing. Montley does not request general access to every file in your Google Drive.

Montley's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, sell it to data brokers, or allow humans to read it except with your affirmative permission for support, when necessary for security, or when required by law.

We provide your Google account email to Stripe solely to create and manage the subscription you request. We do not provide Stripe with the Google Sheet file identifier, title, URL, or contents. If you connect Telegram notifications, we send the selected Sheet title and link to the Telegram chat at your direction. Other disclosures of Google user data are described in the disclosure section below.

You can revoke Montley's Google access at any time from your Google Account connections. Revoking access stops Montley from accessing the Sheet but does not delete the Sheet or the information already in it. Contact us if you also want us to delete the related Montley account or connection records.

Plaid and financial data

Montley uses Plaid to connect supported United States financial institutions and requests the Transactions product, including up to two years of transaction history. Depending on your institution, Plaid may ask for credentials or other authentication information. Those credentials are submitted to Plaid or your financial institution and are not received or stored by Montley.

Plaid independently collects, uses, and retains information under its End User Privacy Policy. You can review or manage connections recognized by Plaid through Plaid Portal where available.

Disconnecting an institution in Montley stops future syncs, asks Plaid to remove the connection, and deletes the related Plaid token, account metadata, and sync-job metadata from Montley's active database. Financial rows already written to your Google Sheet remain there until you change or delete them in Google Sheets.

Online tracking and browser signals

Montley does not collect personal information about your browsing activities over time and across unaffiliated websites or online services for advertising. We do not use advertising pixels, sell personal information, or share personal information for cross-context behavioral advertising. Our browser-based PostHog integration respects a browser's Do Not Track setting. Server-generated milestones about completed service operations, such as a successful sync, may still be recorded when Do Not Track is enabled. We recognize browser-based opt-out signals, including Global Privacy Control, when applicable law requires it. There is currently no sale or advertising-related sharing to opt out of.

Third-party components used to provide Montley may collect technical and interaction information. Plaid instruments activity inside Plaid Link for security, support, and analytics and typically uses Google reCAPTCHA. Google may process information through its sign-in and file-picker components. Plaid, Google, Telegram, Stripe, and your financial institution may also collect information when you interact with their embedded or hosted services, and they may be able to recognize your browser or device across services according to their own policies. Montley uses these components to provide the functionality you request, not for advertising, and does not receive third-party advertising profiles from them. Their privacy policies describe their practices and how they respond to browser signals.

How we disclose information

We disclose information only in the following circumstances:

  • At your direction. We send financial data to the Google Sheet you select, share access with collaborators you invite, and send newly synced transaction details and later amount changes to a Telegram group you connect. Anyone with access to that Sheet or any current or future member of that group may be able to see its contents according to the permissions you set.
  • Service providers. We use Google for sign-in, Drive and Sheets access, and cloud hosting; Plaid for financial account connectivity; Telegram for optional chat delivery; Stripe for payments and billing; Postmark for transactional email; and PostHog for the limited product analytics described above. They process information for these functions under their agreements and privacy terms.
  • Legal and safety reasons. We may disclose information when reasonably necessary to comply with law or legal process, investigate fraud or abuse, protect a person's safety, or protect the rights and security of Montley, our users, or others.
  • Business changes. Information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to this policy and applicable law. We will obtain explicit prior consent before transferring Google user data when Google's policy requires it.

The relevant provider policies include the Google Privacy Policy, Plaid End User Privacy Policy, Telegram Privacy Policy, Stripe Privacy Policy, Postmark privacy terms, and PostHog Privacy Policy.

Retention and deletion

Transaction rows and balance amounts are not ordinarily retained by Montley. They remain in your Google Sheet under your control and Google's retention practices. If you opt in to chat notifications, encrypted payloads for newly synced transactions and amount changes are cleared from the active database after delivery or within 24 hours. Encrypted copies in protected backups age out under the backup-retention schedule. Telegram separately retains delivered messages under its practices and your controls in Telegram.

We retain account, spreadsheet, connection, invitation, billing, and operational records for as long as reasonably necessary to provide Montley, maintain security, resolve disputes, meet legal and accounting obligations, and enforce our agreements. Invitation delivery-attempt records used to prevent abuse are deleted after 30 days. A signed login session expires after 30 days unless you sign out sooner.

We retain pseudonymous product analytics only while it is reasonably needed for product improvement, security, or operational analysis. A verified account-deletion request includes the associated identified PostHog profile and events unless retention is required or permitted by law.

When you disconnect a bank connection, we delete its active Montley connection records as described above. When you ask us to delete your Montley account, we use a documented manual process to verify the request, identify any Sheets or subscriptions that need your direction, disconnect provider access, and delete or de-identify personal information that we are not required or permitted to retain. Deleting your Montley account does not delete your Google Sheet or the financial data in it. Limited information may remain in protected backups until those backups expire, and Stripe or other providers may retain records under their own legal obligations and policies.

Security

Montley uses administrative, technical, and organizational safeguards designed to protect personal information. Google OAuth tokens, Plaid access tokens, Telegram group identifiers and titles, and temporary notification payloads are encrypted at rest. Data is encrypted in transit, access to production systems is restricted, task queues contain delivery identifiers rather than message content, and application logging is designed to contain operational metadata rather than financial transaction details.

No method of transmission or storage is completely secure. You are responsible for protecting your Google account and for choosing who can access the Google Sheets that contain your financial data.

Your choices and rights

You can:

  • view, edit, export, share, or delete financial data directly in your Google Sheet;
  • manage or revoke Google access from your Google Account;
  • disconnect a financial institution from the Montley dashboard;
  • send a Do Not Track signal through a supported browser or clear Montley's browser storage to limit product analytics;
  • disconnect Telegram notifications from the Montley dashboard;
  • manage payments and cancel a subscription through the Stripe-hosted billing portal; and
  • ask us to access, correct, delete, or provide a portable copy of personal information associated with your Montley account.

Depending on where you live, you may have additional rights to know about, access, correct, delete, or obtain a copy of personal information, or to appeal a decision about a request. Montley does not sell personal information or share it for cross-context behavioral advertising. To submit a request, email hello@montley.app from the email address associated with your account and state the type of request. We will confirm receipt within 10 business days and respond within 45 calendar days. If applicable law permits more time, we will notify you and explain the extension. We may verify your identity through your existing account or account email before completing the request. A portable copy covers information retained by Montley; your transaction rows and balances remain available from the Google Sheet you control. We will not discriminate against you for exercising an applicable privacy right.

Other information

United States service

Montley is designed for users of supported United States financial institutions. Montley's application and database infrastructure is hosted in the United States. If you access Montley from another country, your information may be transferred to and processed in the United States, where privacy laws may differ from those where you live.

Children

Montley is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided personal information to Montley, contact us so we can take appropriate action.

Changes to this policy

We may update this policy as Montley or applicable requirements change. We will post the updated policy here and change the date above. If a change materially affects how we use or disclose information, we will provide additional notice as required by law. If we materially change how we use Google user data, we will obtain consent when required by Google's policies.

Contact us

For privacy questions or requests, email hello@montley.app.