Skip to main content
MONEDASH
HomeAboutProPrivacyTerms
MONEDASH
Data stewardship

Privacy Policy

How MoneDash handles account, portfolio, property, billing, market-data, and optional AI assessment information.

July 6, 2026EffectiveJuly 30, 2026Last updated

Development Notice

MoneDash is currently in active development and should not be treated as a live, production, commercially launched service. If you find this page or access the app during this development period, you should not upgrade to Pro, rely on the Service, or use it as the basis for any financial, tax, legal, investment, or operational decision.

Any access during this stage is at your own risk. Features, calculations, subscriptions, billing flows, data, displays, legal text, and security controls may be incomplete, experimental, inaccurate, unavailable, or changed without notice. You should not submit sensitive or real-world financial information unless you understand and accept those risks. Stareway Films does not accept responsibility for losses, errors, reliance, data issues, or other consequences arising from use of this development version, except where applicable law does not allow that responsibility to be excluded.


Privacy at a Glance

This Privacy Policy explains how Stareway Films ("Company," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information through MoneDash, its website, web application, interfaces, support channels, and related services.

MoneDash is a portfolio-tracking and analytics aid. It is not a broker, custodian, trading platform, bank, investment adviser, tax adviser, accountant, or legal service. Portfolio and linked-account information can be highly sensitive. We do not sell personal information, use it for targeted advertising, or disclose it except as described in this Policy.


Information We Collect

The information we collect depends on the features you use, the plan you purchase, the integrations you activate, your location, and applicable market-data requirements.

  • Account information, such as name, email, username, authentication identifier, profile settings, role, plan, and account ID.
  • Subscription and billing information, such as plan, price, payment status, invoices, refunds, disputes, billing metadata, and Stripe customer or subscription identifiers.
  • Portfolio information, such as holdings, balances, transactions, cost basis, quantities, currencies, dividends, coupon behavior, fees, taxes, cash interest, allocations, notes, and performance calculations.
  • Property information, such as exact addresses, coordinates, property descriptions, ownership percentages, physical dimensions, acquisition and sale records, valuations, income, expenses, improvements, and uploaded property images or captions.
  • Institution and integration information, such as bank, broker, account labels, connection status, masked account information, permissions, and synchronization timestamps when applicable.
  • Market-data entitlement information, such as country, intended use, professional or non-professional status, declarations, and related compliance records where required.
  • Support and communications information, such as messages, feedback, attachments, survey responses, troubleshooting details, email preferences and consent history, and delivery, bounce, complaint, or unsubscribe status.
  • Legal acceptance information, such as the Terms and Privacy Policy versions and document hashes presented, acceptance date and time, acceptance-screen version, application release, and limited request metadata used to evidence the action.
  • Device, usage, and security information, such as IP address, browser, operating system, pages used, session events, crash records, API activity, authentication events, and approximate location inferred from IP.
  • Cookies, local storage, and preferences, such as session identifiers, authentication cookies, display preferences, historical-mode state, selected portfolio, and consent choices where applicable.

Information We Do Not Want You to Submit

Unless a specific feature clearly asks for it, do not submit Social Security numbers, government identification numbers, health information, biometric information, private keys, seed phrases, full payment-card numbers, plaintext brokerage passwords, or unrelated confidential information. Do not place unnecessary secrets in support messages, notes, imports, or free-text fields.


How We Collect Information

  • Directly from you when you create an account, subscribe, add transactions, configure settings, create portfolios, request support, or submit feedback.
  • Automatically from your device and browser when you visit or use MoneDash.
  • From service providers such as Auth0 for authentication, Stripe for payments, Resend for customer email delivery and preference synchronization, Heroku and database providers for hosting and storage, and monitoring or security providers used to operate the Service.
  • From Google Maps and Places when you choose an address suggestion or display a property map, and from Amazon Web Services when optional property images or profile photos are uploaded, stored, or delivered.
  • From integrations or financial institutions if you authorize a future linked-account feature.
  • From market-data providers such as EOD Historical Data (EODHD) and other vendors that supply prices, fundamentals, quotes, exchange rates, and reference data.
  • From OpenAI and public web sources when you enable or request an AI portfolio assessment.

How We Use Information

  • Create, authenticate, secure, and administer accounts.
  • Process subscriptions, invoices, payment status, cancellations, refunds, and billing records.
  • Store, calculate, display, export, and synchronize portfolio data and related analytics.
  • Calculate current value, initial investment, gains and losses, exchange-rate impact, fees, taxes, allocations, dividends, coupons, cash interest, and historical views.
  • Generate an optional, consented AI portfolio assessment and research public news relevant to the privacy-filtered portfolio report.
  • Operate market-data access, licensing, professional or non-professional classifications, and provider compliance where required.
  • Protect MoneDash against unauthorized access, fraud, scraping, abuse, attacks, and other security risks.
  • Communicate with users about accounts, billing, security, legal notices, product updates, support, and service operations.
  • Improve reliability, debug issues, understand feature use, test improvements, and plan capacity.
  • Comply with legal, tax, accounting, consumer-protection, privacy, market-data, and security obligations.

How We Disclose Information

We disclose personal information only as needed to operate MoneDash, at your direction, or when legally required. We do not disclose more information than reasonably necessary for the relevant purpose.

  • Cloud, hosting, database, backup, and infrastructure providers that help run MoneDash.
  • Mapping, address-search, and durable media-storage providers used for optional Property maps and images.
  • Authentication and security providers that support login, account protection, abuse detection, logging, and incident response.
  • Stripe and related payment providers that process subscriptions, invoices, disputes, taxes, and billing status.
  • Market-data vendors and exchanges that provide quotes, reference data, exchange rates, fundamentals, entitlement checks, and required licensing or usage compliance.
  • OpenAI when you enable or request an AI portfolio assessment; MoneDash sends the privacy-filtered report and any investor context you explicitly include.
  • Support, communications, analytics, and error-monitoring providers used to communicate with users, diagnose problems, and improve reliability.
  • Professional advisers, insurers, government authorities, or legal recipients when reasonably necessary for compliance, disputes, security, or legal obligations.
  • Corporate transaction participants if Stareway Films evaluates or completes a merger, financing, acquisition, restructuring, or asset transfer.

Current Service Providers and Data Recipients

The following list names the current providers that receive personal information, portfolio-derived information, uploaded content, communications, or technical data from MoneDash or directly from your browser. A provider receives data only when needed for its stated purpose or when you use the corresponding optional feature.

  • Salesforce / Heroku (Core infrastructure). Heroku hosts the MoneDash server and managed PostgreSQL database. Because the application runs there, Heroku can process account identifiers, portfolio and transaction records, property records, subscription state, request and IP metadata, operational logs, backups, and other information stored or transmitted through MoneDash. Heroku regions may run on Amazon Web Services infrastructure; Salesforce/Heroku remains MoneDash's contracted platform provider for that hosting path. Provider privacy information.
  • Amazon Web Services (AWS) (Media storage and delivery). MoneDash directly uses Amazon S3 and CloudFront for profile photos, property media, brand assets, and authenticated digital-product files. AWS receives the uploaded files, object and delivery metadata, and network information needed to store or deliver them. AWS may also supply underlying infrastructure to Heroku, depending on the Heroku region. Provider privacy information.
  • Okta / Auth0 (Authentication and account security). Auth0 handles sign-in, access tokens, email verification, password-reset workflows, and authentication security events. It can receive account name and email, authentication identifiers and credentials, and login metadata such as time, IP address, browser, device, and approximate location. MoneDash does not receive or store the plaintext password entered into Auth0. Provider privacy information.
  • Stripe (Subscriptions and billing). When you open checkout or billing management, Stripe receives your email, MoneDash account and authentication identifiers used as billing metadata, plan, customer and subscription identifiers, and transaction status. Stripe collects payment-card, billing, fraud-prevention, and payment-network information directly. MoneDash does not intend to receive or store your full card number. Provider privacy information.
  • EOD Historical Data (EODHD) (Market and reference data). The MoneDash server sends instrument symbols, bond or crypto identifiers, exchange-rate pairs, requested dates or ranges, and search terms needed to retrieve quotes, fundamentals, exchange rates, earnings, and reference data. MoneDash does not intentionally send your name, email, Auth0 identifier, or complete portfolio to EODHD, although the requested instruments can reflect assets or searches associated with use of the Service. Provider privacy information.
  • Google Maps Platform and Places (Optional Property maps and address search). When you load a Property map or search for an address, your browser communicates directly with Google. Google can receive address search terms, selected place and address information, latitude and longitude, IP address, browser and device metadata, and map interactions required to provide the feature. Provider privacy information.
  • OpenAI (Optional AI portfolio assessment). Only after the AI assessment is enabled or manually requested, MoneDash sends a privacy-filtered portfolio report containing holdings, values, gains, allocations, currency exposure, performance, and any investor context you choose to provide. Exact property addresses and coordinates, account numbers, authentication and database identifiers, and raw provider errors are excluded by contract checks. OpenAI's web-search tools may generate searches containing instrument names or portfolio-related topics and retrieve information from public publishers. Provider privacy information.
  • Google Workspace / Gmail (Human customer support). Messages sent to support@monedash.com are delivered to the Stareway Films Google Workspace inbox. Google can process sender and recipient addresses, email headers, message content, attachments, and related security and delivery metadata. Feedback submitted inside MoneDash may also be copied to this support inbox. Google Workspace is not used as the application-email sender. Provider privacy information.
  • Resend (Application and marketing email when enabled). When MoneDash application email is activated, Resend receives recipient and sender addresses, names, message content and attachments, consent and topic preferences, provider identifiers, delivery events, bounces, complaints, suppressions, and unsubscribe state. Open or click information is processed only if that tracking is intentionally enabled. Auth0 may also use a separately scoped Resend credential for account emails. Provider privacy information.
  • Sentry (Optional error monitoring). If Sentry monitoring is configured, MoneDash sends scrubbed error and performance diagnostics such as stack traces, route paths without query strings, browser or device information, release and environment labels, and network metadata needed to deliver the event. MoneDash removes the event user, request body, query string, authorization headers, and cookies before sending; an error message can still contain information supplied by the failing code. Provider privacy information.
  • Cloudinary (Legacy media compatibility). New MoneDash uploads use AWS, but the server retains compatibility for profile or property media created under the former Cloudinary storage path. If a legacy asset remains, Cloudinary can process the image, asset metadata, deletion request, and browser delivery metadata until that asset is migrated or deleted. Provider privacy information.
  • Google Fonts (Web typography). MoneDash currently loads font styles and files from the Google Fonts Web API. A visitor's browser sends Google the IP address, requested font URLs, browser and operating-system user agent, and referring MoneDash page. Google states that Google Fonts does not set cookies or use this information to create end-user profiles or serve targeted advertising. Provider privacy information.
  • GoDaddy (Domain, DNS, forwarding, and email-authentication reporting). GoDaddy provides the monedash.com registration and authoritative DNS, and may handle apex-domain forwarding and aggregate DMARC reports. It can receive domain or DNS request metadata, resolver or network information, redirect request headers, and aggregate email-authentication results. MoneDash does not intentionally send portfolio or account records to GoDaddy. Provider privacy information.

These providers may use affiliates and subprocessors to deliver their services. Those downstream lists can change and are maintained by the relevant provider. Examples include AWS infrastructure beneath parts of Heroku, payment networks and financial partners used by Stripe, email-delivery infrastructure used by Resend, and public publishers reached through OpenAI web search. We review the direct provider inventory when integrations change and update this Policy when a change is material.

MoneDash does not currently embed an advertising network, behavioral advertising pixel, or general-purpose product analytics platform, and it does not sell personal information.


Customer Email and Marketing Preferences

Auth0 and its configured email provider handle authentication messages such as password resets and email verification. MoneDash uses Resend for essential application messages such as welcome, billing, subscription, security, and service notices. We may process your email address, account name, message template, delivery identifiers, delivery status, and sanitized failure information to send, retry, troubleshoot, and suppress those messages.

Product updates, newsletters, and promotions are separate optional preferences and begin disabled. If you opt in, we store the selected topics and consent or withdrawal timestamps and synchronize those choices to Resend. You may change them in Settings or use the unsubscribe control in a marketing message. Essential account and service notices are not marketing and remain enabled while your account is active. A hard bounce, spam complaint, or provider suppression may prevent further delivery until the address is reviewed.


Optional AI Portfolio Assessments

MoneDash does not send a portfolio report to OpenAI until you give explicit consent. Once weekly preparation is enabled, MoneDash may prepare one live assessment for the selected portfolio during each calendar week and reuse it across logins. You may disable future preparation from the Portfolio Report page.

The transmitted report excludes exact property addresses and coordinates, authentication and database identifiers, account numbers, private property descriptions, and raw provider errors. It can still contain sensitive financial information including position names, quantities, values, gains, allocation, currency exposure, and performance. Optional investor-profile fields are sent only when you explicitly generate or refresh an assessment. Public web research sources and the validated assessment may be stored with the report identifier and research period.


Market Data and EODHD

MoneDash uses market-data providers, including EOD Historical Data (EODHD), to retrieve prices, fundamentals, exchange rates, and reference information. Requests to market-data providers may reveal symbols, instruments, dates, quote requests, technical metadata, or usage information needed to supply and administer licensed data.

Market-data vendors and exchanges may impose requirements relating to professional or non-professional status, permitted use, display, audit, retention, country, location, entitlement, and usage reporting. MoneDash may request or process information needed to comply with those requirements.


Property Location and Media

A property address can identify a home, business, investment, or other sensitive location. MoneDash treats exact addresses, coordinates, valuations, cash flows, descriptions, and property media metadata as authenticated portfolio data. Avoid uploading images or notes that reveal people, access codes, security systems, legal documents, license plates, or other information that is not needed for portfolio tracking.

Address suggestions and maps may be processed by Google Maps and Places. Optional images may be stored in Amazon S3 and delivered through Amazon CloudFront; MoneDash stores their ownership-scoped metadata and durable URL in its database rather than storing image files on Heroku. Standard CloudFront delivery URLs are not a private document vault and may remain accessible to someone who obtains the URL. Deleting a property removes its active property records and media metadata, while provider deletion, backups, and cached copies may complete on their respective operational schedules.


Payment Information

Subscription payments are processed by Stripe. Stareway Films does not intend to store full payment-card numbers. We may receive and store limited payment metadata such as customer identifiers, subscription identifiers, plan, price, status, invoices, disputes, billing timestamps, and webhook records needed to administer access.


Cookies, Local Storage, and Preferences

MoneDash uses cookies, local storage, and similar technologies for authentication, session handling, security, selected portfolio, selected historical date, graph state, display preferences, entitlement behavior, and other core app functionality. If non-essential analytics or advertising technologies are added where consent is legally required, MoneDash should request consent before activating them.


Retention and Deletion

We retain information for as long as reasonably necessary to provide MoneDash, maintain accounts, process subscriptions, comply with legal and market-data obligations, resolve disputes, enforce agreements, improve security, keep audit records, and maintain operational backups. Retention periods may vary by data type, plan, account status, legal hold, backup cycle, or security need.

Deletion from backups may occur through scheduled overwriting rather than immediate removal. Until overwritten, backup data remains protected and is not restored to active use except for disaster recovery, security, or legal necessity.

Legal acceptance events are append-only account audit records. We retain them while the account remains active and may retain a minimized record afterward when reasonably necessary to resolve disputes, demonstrate agreement, enforce these Terms, or satisfy a legal obligation. Technical evidence associated with acceptance is limited to what the server observes and is not used for advertising or behavioral profiling.


Your Controls and Requests

Depending on the feature and applicable law, you may update account details, correct portfolio records, export supported records, disconnect integrations, manage preferences, cancel subscriptions, or request account deletion through the controls available in MoneDash.

You may also request access, correction, deletion, or a portable copy of covered personal information through the support, account, or privacy-request channels made available by Stareway Films. We may need to verify identity, account ownership, authority, and residence before acting on a request.


Security

We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, acquisition, use, alteration, disclosure, or destruction. These safeguards may include access controls, protected credentials and secrets, secure development practices, logging and monitoring, backup controls, incident response, and vendor oversight.

No internet transmission, cloud service, database, or security measure is completely secure. You are responsible for protecting your devices, email account, and login credentials, using strong passwords, enabling multi-factor authentication where available, and signing out of shared devices.


International Processing

Stareway Films and its providers may process personal information in the United States and other countries where they operate. Those countries may have privacy laws that differ from the laws where you live. Where required, appropriate transfer safeguards should be used for covered international transfers.


Children

MoneDash is for adults and is not directed to anyone under 18. We do not knowingly collect personal information online from children under 13. If we learn that such information was collected without legally sufficient authorization, we will take reasonable steps to delete it.


U.S. State and International Rights

Depending on where you live and whether the relevant law applies to Stareway Films, you may have rights to access, confirm, correct, delete, or obtain a portable copy of personal information; opt out of targeted advertising, sale, or certain profiling; revoke consent; or appeal a privacy-request decision.

MoneDash does not sell personal information, share it for cross- context behavioral advertising, or use it for targeted advertising under the current product assumptions. If those practices change, this Policy and the app controls should be updated before launch of the new practice.


Changes and Contact

We may update this Privacy Policy to reflect product, vendor, legal, security, or operational changes. We will post the revised version and change the "Last updated" date. If a change is material, we will provide additional notice through MoneDash, email, or another reasonable method where required.

For privacy, support, billing, or security questions, contact Stareway Films at support@monedash.com. Please do not include brokerage passwords, private keys, seed phrases, full payment-card numbers, or other unnecessary secrets in a request.