Monvo
Data Retention and Disposal Policy
Last updated: June 24, 2026
Monvo retains consumer data only as long as necessary to provide the service and meet legal obligations. This policy defines retention periods for each data category and describes how data is securely disposed of when it is no longer needed.
1. Purpose
This policy defines how Monvo retains, manages, and disposes of consumer data and internal records. Monvo is committed to keeping data only as long as necessary for the purpose it was collected, and to disposing of it securely when it is no longer needed.
2. Scope
This policy applies to all consumer data held by Monvo, including data retrieved from the Plaid API, data extracted from uploaded financial statements, account information provided at registration, and internal operational records.
3. Data categories and retention periods
Account information (name, email): retained for the lifetime of the user's Monvo account. Deleted within 30 days of account deletion, except where a legal obligation requires otherwise.
Plaid access tokens: encrypted and stored only while the user's bank connection is active. Deleted immediately upon disconnection of the linked institution or deletion of the user account.
Transaction and balance data retrieved via Plaid: retained while the bank connection is active and the user account exists. Deleted upon institution disconnection or account deletion.
Uploaded financial statements (PDF): the original document is deleted immediately after structured transaction data is extracted. The raw file is never stored beyond the extraction process.
Extracted statement transaction data: retained while the user account is active. Deleted upon account deletion.
Authentication and session records: retained per Supabase platform defaults (authentication logs) and Vercel platform defaults (function invocation logs), typically 30 to 90 days.
Support communications: retained for 12 months after resolution, then deleted.
4. Legal hold
If Monvo becomes subject to a legal obligation, regulatory inquiry, or dispute that requires retention of specific records beyond the periods above, those records will be held until the obligation is resolved. The standard retention schedule resumes after the hold is lifted.
5. Disposal
User data is deleted from Monvo's Supabase database via API-triggered deletion routines. Plaid access tokens are revoked via the Plaid API before local deletion to ensure the connection is terminated at the source.
Deletion is permanent and non-reversible. Supabase and its underlying cloud provider (AWS) handle secure erasure of storage blocks in accordance with their SOC 2-certified data disposal practices.
Backups: Supabase maintains automated backups per its platform defaults. Deleted data is purged from backups on Supabase's standard backup rotation cycle.
6. User-initiated deletion
Users can delete their data at any time through the Monvo application. The following self-service options are available:
Disconnect institution: revokes the Plaid access token and deletes all transaction and balance data associated with that connection.
Delete all data: removes all financial data linked to the account while preserving the account itself.
Delete account: permanently deletes the user's account, all financial data, and all personal information held by Monvo, subject to any applicable legal hold.
Deletion requests submitted through the app are processed immediately.
7. Third-party data processors
Plaid, Supabase, Vercel, and Anthropic process data on Monvo's behalf. Each maintains its own data retention and disposal practices governed by their respective terms of service and privacy programs. Monvo instructs these processors to use consumer data only for the purposes described in the Monvo Privacy Policy.
8. Compliance
This policy is designed to align with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. Monvo does not currently collect data from residents of the European Union; if this changes, the policy will be updated to address GDPR requirements.
9. Policy review
This policy is reviewed annually and whenever a material change is made to Monvo's data architecture, third-party processors, or applicable law.
For questions about data retention or to submit a data subject request, contact team.monvo@gmail.com.