Privacy Policy

Last Updated: 10/03/2026

This Privacy Policy for KOMP BG LTD ("we", "us", "our", "the Service") tells you how we collect, use, and share your information when you use the web application at my-money.report and the My Money Report mobile application. We appreciate your trust and seek to explain our privacy practices as clearly as possible. We encourage you to read this document carefully before using the Service. If you do not agree with any part of it, please do not use the Service, or discontinue use immediately. By using the Service, you accept the practices described in this Privacy Policy.

Contact for all privacy matters: [email protected] or the contact form on our website.

1. What information do we collect about you?

When we collect information, we do so to let you use the Service seamlessly. We collect the following categories of information.

Account data - name, email address, password (stored only as a secure hash), language and formatting preferences, plan type and plan history.

Financial data you enter - expenses, incomes, budget plans and scheduled items, savings and savings buckets, money transfers, and the categories, tags, and locations you create. This data exists so the Service can work for you; we do not use the content of your individual financial records for any other purpose.

Sharing data - your sharing connections, the permissions you configure, and the data you choose to make visible to connected users. Money transfers you record with a connected user are stored as part of both participants' records.

Payment data - payments are processed by our payment provider (Viva Wallet); we never receive or store your card number. We store your subscription status, plan history, and billing events (dates, amounts, invoice references) as required for accounting.

Security and account-history data - sign-in sessions, consent events (terms and Free-plan consent, with the accepted document version), plan changes, and security-relevant events. We keep this log to protect your account and to be able to demonstrate consent.

Technical data - server logs and error reports needed to run and secure the Service. Sign-up and similar public forms are protected by Google reCAPTCHA, which processes technical signals to distinguish humans from bots.

Notification data - your notification preferences, email delivery data, and (on mobile, if you enable push notifications) a device push token.

Cookies and similar technologies - see our Cookie Policy. Essential cookies (for example your sign-in session) are always active; analytics and advertising cookies are used only according to the choice you make in the cookie consent banner.

2. How do we collect such information?

We obtain information about you in the following ways.

a. Information that you give us - when you create an account and use the Service, you provide information such as your name and email address, and the financial records you choose to enter.

b. Information we collect automatically - when you access the Service from a device, we automatically collect technical information such as server logs, error reports, and cookie data (see the Cookies section below).

c. Information we receive from third parties - our payment provider (Viva Wallet) returns your subscription and billing status so we can keep your plan up to date, and a user you are connected with may record a money transfer that becomes part of your records. We do not buy personal information about you from data brokers, aggregators, or marketplaces.

3. Cookies and similar technologies

Cookies are small packets of information placed on your device so that we can recognise you and remember information such as your sign-in session and your choices on the Service. Essential cookies are always active; analytics and advertising cookies are used only according to the choice you make in the cookie consent banner. For full details, please see our Cookie Policy.

4. Do not track requests

You can control non-essential tracking directly on the Service: through the cookie consent banner (reachable any time via the "Cookie settings" link) you may disable any cookie that is not strictly necessary, and on mobile you can change your advertising choice under "Privacy options".

5. Why do we collect information about you? (purposes and legal bases)

  • Providing the Service (contract): storing and displaying your financial data, sharing it according to your settings, sending transactional emails (verification, password reset, sharing invitations), and syncing between web and mobile.
  • Billing (contract, legal obligation): processing subscriptions and refunds via Viva Wallet and keeping accounting records.
  • Security (legitimate interest, legal obligation): session management, fraud prevention, rate limiting, and the account-history log described above.
  • Optional notifications (consent / your settings): period report emails and other optional notifications you enable; you can turn them off in your settings.
  • Advertising on the Free plan (see Section 9): the Free plan is ad-supported.
  • Service improvement (legitimate interest): aggregated, anonymized usage statistics.

We do not sell your personal data, and we do not use the content of your individual financial records for advertising.

6. How long do we retain your information?

  • Your data is kept for as long as your account is active.
  • If you cancel a paid plan, your account reverts to the Free plan and your data is kept, subject to the Free plan limitations.
  • If your account is deleted (by you, or terminated by us in accordance with our Terms and Conditions), your data (personal details, financial data, generated reports etc.) is permanently removed within 30 days, except for data we must keep longer to meet legal obligations (for example billing records, which are held for the statutory periods required by Bulgarian law).
  • Technical security logs, authentication information, IP-address records and similar security data are normally retained for no longer than 12 months, unless a longer period is reasonably necessary to investigate a security incident, suspected fraud, misuse of the Service or a legal claim.
  • Data shared with a connected user stops being visible to them when you revoke the sharing connection; transfers remain part of both participants' own records.
  • Consent and account-history records are kept as long as needed to demonstrate compliance.
  • If we become aware of a dispute, complaint, investigation, threatened claim or legal proceeding, we may temporarily suspend the ordinary deletion schedule for information that is reasonably necessary to establish, exercise or defend legal claims or to comply with a legal obligation.

When we no longer have a legitimate business need to process your personal information, we delete or anonymise it, or - if that is not immediately possible (for example because it is held in backup archives) - securely store and isolate it from further processing until deletion is possible.

7. Who receives your data (processors and partners)

We use the following categories of service providers, bound by data-processing agreements:

  • Hosting: Vercel (application hosting and delivery)
  • Database: MongoDB Atlas (data storage)
  • Payments: Viva Wallet (payment processing - they act as an independent controller for the payment transaction itself)
  • Email delivery: our own mail server ([email protected])
  • Push notifications (mobile): Google Firebase Cloud Messaging
  • Consent management (web): CookieYes (cookie consent banner and consent records)
  • Bot protection: Google reCAPTCHA
  • Advertising (Free plan): Google (see Section 9)

We may also disclose your information in the following situations:

  • With your consent: when you give consent, we may share your information for the purposes described in the consent notification.
  • Legal obligations: where we are legally required to do so to comply with applicable law, a governmental request, a judicial proceeding, court order, or legal process.
  • Business transfers: in connection with, or during negotiations of, a merger, sale of business assets, financing, or acquisition of all or part of our business by another entity.

Some providers may process data outside the EU/EEA; where they do, transfers are covered by an adequacy decision or EU Standard Contractual Clauses.

8. Sale or sharing of information

We do not sell or share the personal information we collect from our users for cross-context behavioural advertising, and we do not use the content of your individual financial records for advertising.

9. Advertising (Free plan)

The Free plan is supported by advertising provided by Google (web advertising on the website; Google AdMob in the mobile application, where available).

  • Your personalization choice: whether advertising may be personalized is controlled by you - via the cookie consent banner on the web (changeable any time through the "Cookie settings" link) and via the ad-consent dialog on mobile (changeable in the app under "Privacy options"). If you decline, ads are shown in non-personalized form.
  • With your consent, Google may use cookies or device identifiers to personalize ads; the details are in Google's own privacy documentation and our Cookie Policy.
  • We may use anonymized, aggregated usage information (such as general feature usage and expense-category statistics) to improve ad relevance. The content of your individual financial records is never shared with or sold to advertisers.
  • Paid plans do not display advertising.

10. The mobile application and offline mode

  • The mobile application keeps a local copy of parts of your data on your device (for example your shopping list, lookup lists, sharing partners' names, and expenses you record while offline) so the app can work without a connection. This local copy is stored in the app's storage on your device and is removed when you sign out. It is protected by your device's own screen lock and encryption - please secure your device.
  • Expenses you record while offline are transmitted to our servers when the app next has a connection.
  • Push notifications are delivered through Google Firebase; if you disable them, no push token is kept.

11. GDPR disclosures

Automated processing - we use limited automated processing of the information you enter (for example categorising and aggregating your records) to provide the Service's reports and statistics to you. We do not make decisions producing legal or similarly significant effects about you solely by automated means.

Legal basis for the collection - the legal bases on which we process your personal data (contract, legal obligation, legitimate interest, and consent) are set out for each purpose in Section 5.

Consequences of non-consent - some information is required to provide the Service. You may refuse consent, but doing so may limit your access to the Service or reduce available features.

12. Your rights

If you are in the EU/EEA (and in many other jurisdictions), and in accordance with Articles 12 to 23 of the General Data Protection Regulation, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data (most data can be edited directly in the app)
  • Erase your data (delete your account in account settings, or contact us)
  • Restrict or object to certain processing
  • Data portability (receive your data in a structured, machine-readable format)
  • Withdraw consent at any time where processing is based on consent (for example cookie/ads consent via the banner or the app's privacy options), without affecting the lawfulness of processing before withdrawal
  • Complain to your local data-protection supervisory authority

To exercise any of these rights, contact us at [email protected] or via the contact form.

As a controller established in Bulgaria, our principal data-protection supervisory authority is the Bulgarian Commission for Personal Data Protection ("CPDP" / "КЗЛД"):

  • Name: Commission for Personal Data Protection
  • Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
  • Email: [email protected]
  • Website: www.cpdp.bg

13. Privacy of children

The Service is intended for users who are at least 18 years old or have parental consent. We do not knowingly collect data from children. If you are a parent or legal guardian and believe your child has provided us with information without your consent, please contact us; upon verification we will remove the information from our database.

14. Security of your personal information

We take reasonable measures to keep the information we collect secure - passwords are stored only as a secure hash, and data is transmitted over encrypted connections. However, no method of internet transmission or digital storage is completely secure. While we use commercially reasonable and appropriate security measures to protect your information, we cannot guarantee absolute security.

15. Links to other websites or apps

The Service may contain links to external websites, apps, or services that we do not operate and that are not governed by this Privacy Policy. We recommend that you review the privacy policies of those websites or services before providing any personal information to them.

16. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in the law or in our privacy practices. New versions are published with an updated date and previous versions are retained. We will notify you of material changes by email or in-app notification, and we recommend that you review this Policy periodically.

17. Contact us

For any questions or concerns regarding your privacy, or to exercise any of your rights, you may contact us:

  • Company: KOMP BG LTD
  • Address: Mladost bl.459, Sofia, Bulgaria
  • Email: [email protected]
  • Contact page: https://my-money.report/en/contacts