Home/Security & Encryption Policy
Security & Encryption Policy
1. Purpose
This Security & Encryption Policy ("Policy") describes the administrative, technical, and organizational measures MoniPilot™ ("MoniPilot," "we," "our," or "us") implements to help protect the confidentiality, integrity, and availability of information processed through the Services.
Security is a shared responsibility between MoniPilot and every user. While we strive to implement reasonable safeguards appropriate to our size, resources, and the nature of the Services, no security measure, software application, network, device, or transmission method can be guaranteed to be completely secure or immune from unauthorized access.
This Policy should be read together with the:
- Privacy Policy
- Terms of Service
- End User License Agreement (EULA)
- Local Data Storage & Backup Policy
- Data Retention & Deletion Policy
2. Security Philosophy
MoniPilot is designed using a privacy-first and local-first architecture.
Whenever reasonably possible:
- Financial records remain on the user's own device.
- Collection of personal information is minimized.
- Backend systems process only information necessary to provide the Services.
- Security is considered throughout software design, development, deployment, and maintenance.
Our objective is risk reduction, not the elimination of all risk.
3. Local-First Security Model
As of the Effective Date of this Policy:
Financial information such as:
- Expenses
- Income
- Budgets
- Reports
- Categories
- Financial notes
- Subscription records
- Warranty records
- Lending records
- Borrowing records
is generally stored on the user's device rather than on MoniPilot-operated servers.
Because this information is primarily under the user's control, the security of that information also depends significantly on the security of the user's device.
4. Data Encryption
Where appropriate, MoniPilot implements industry-recognized encryption technologies.
These may include:
Data in Transit
Communications between the application and MoniPilot-operated servers may be protected using encrypted protocols such as:
- HTTPS
- TLS or successor protocols
to reduce the risk of interception during transmission.
Authentication Credentials
Passwords are never intended to be stored in plain text.
Where passwords are processed by MoniPilot-operated systems, they are intended to be stored using industry-accepted one-way cryptographic hashing algorithms with appropriate salting or successor technologies.
Sensitive Backend Information
Where appropriate, certain sensitive backend information may be encrypted or otherwise protected using reasonable technical safeguards.
Local Device Storage
MoniPilot relies in part on the security features of your operating system and device.
Depending on your device and operating system, local data may benefit from:
- device encryption;
- secure hardware modules;
- secure enclaves;
- operating system sandboxing; and
- application isolation.
Availability of these protections depends on your device manufacturer, operating system version, and configuration.
5. Authentication Security
To protect user accounts, MoniPilot may implement security measures such as:
- secure authentication mechanisms;
- password hashing;
- session expiration;
- secure authentication tokens;
- login validation;
- suspicious login detection;
- rate limiting;
- account lockout after repeated failed login attempts where appropriate.
MoniPilot reserves the right to modify authentication mechanisms to improve security.
6. Google Drive Backup Security
Where Google Drive backup is enabled:
- Backup files are stored in your Google Drive account.
- Authentication with Google is handled through Google's authorization mechanisms where applicable.
- MoniPilot requests only the permissions reasonably necessary to provide backup and restore functionality.
- The security of your Google account, including your password, recovery methods, and multi-factor authentication, remains your responsibility.
MoniPilot is not responsible for unauthorized access resulting from compromise of your Google account.
7. Infrastructure Security
MoniPilot endeavors to implement reasonable security measures for backend systems, which may include:
- access controls;
- least-privilege principles;
- environment separation where appropriate;
- firewall protections;
- security monitoring;
- software updates;
- vulnerability remediation;
- encrypted communications;
- backup procedures for operational systems.
The specific technologies used may change over time without prior notice in order to improve security.
8. Secure Development Practices
MoniPilot seeks to incorporate security throughout the software development lifecycle, including where appropriate:
- secure coding practices;
- dependency management;
- code review;
- testing before release;
- vulnerability remediation;
- timely application of security updates;
- continuous improvement of development processes.
No software development process can eliminate every defect or vulnerability.
9. Third-Party Services
The Services may depend on third-party providers, including but not limited to:
- Google Play
- Apple App Store
- Google Drive
- Google AdMob
- payment processors
- cloud infrastructure providers
- analytics providers
- crash reporting providers
Although MoniPilot seeks to work with reputable providers, MoniPilot does not own, operate, or control the security practices of independent third-party services.
MoniPilot is not responsible for security incidents arising solely from the systems, networks, software, or services of independent third parties.
10. User Responsibilities
You are responsible for:
- maintaining the security of your device;
- keeping your operating system updated;
- using strong passwords;
- protecting your login credentials;
- enabling device-level security features where available;
- maintaining backups if desired;
- safeguarding your Google account where backup features are enabled;
- installing application updates promptly;
- avoiding rooted, jailbroken, or otherwise compromised devices where possible.
Failure to take reasonable security precautions may increase the risk of unauthorized access to your information.
11. Security Incident Response
MoniPilot maintains procedures intended to help identify, investigate, contain, and respond to suspected security incidents affecting MoniPilot-operated systems.
Responses may include:
- investigation;
- containment measures;
- remediation;
- security updates;
- monitoring;
- notification where required by applicable law.
The exact response will depend on the nature and severity of the incident.
12. Data Breach Notifications
If MoniPilot becomes aware of a confirmed security incident involving personal information processed on MoniPilot-operated systems, we will assess our legal obligations under applicable law.
Where notification is legally required, MoniPilot will provide notice to affected users and/or relevant authorities within the timeframe required by applicable law.
Not every cybersecurity event constitutes a reportable data breach.
13. Security Limitations
Despite reasonable efforts, MoniPilot cannot and does not guarantee that the Services will be free from:
- cyberattacks;
- hacking;
- malware;
- ransomware;
- phishing;
- denial-of-service attacks;
- hardware failures;
- software defects;
- internet outages;
- human error;
- unauthorized access;
- zero-day vulnerabilities; or
- other security threats.
Use of the Services is at your own risk, subject to your rights under applicable law.
14. Limitation of Security Liability
To the fullest extent permitted by applicable law:
- MoniPilot does not warrant that the Services are invulnerable to security incidents.
- MoniPilot shall not be liable for losses resulting from events beyond its reasonable control, including attacks against user devices, compromised user credentials, failures of third-party providers, internet infrastructure failures, or actions of malicious third parties.
- Nothing in this Policy excludes or limits liability that cannot be excluded or limited under applicable law.
Any limitation of liability is further governed by the Terms of Service.
15. Future Security Improvements
MoniPilot may introduce additional security measures, including:
- biometric authentication;
- passkeys;
- enhanced encryption;
- device attestation;
- anomaly detection;
- encrypted cloud synchronization;
- hardware-backed key management;
- additional fraud prevention technologies.
Implementation of future features is at MoniPilot's discretion and may vary by platform, device, or subscription tier.
16. Policy Updates
Technology, security threats, and legal requirements evolve over time.
MoniPilot reserves the right to modify this Policy to reflect:
- changes in technology;
- security improvements;
- regulatory requirements;
- industry standards;
- new Services or features.
Non-material updates become effective upon publication.
Where required by applicable law, MoniPilot will provide appropriate notice or obtain any required consent before material changes affecting the processing of personal information become effective.
17. Contact Information
MoniPilot Support
Email: hello@monipilot.com
Website: [https://www.monipilot.com]
If you believe you have identified a security vulnerability affecting MoniPilot, please contact us promptly using the details above.

