← Back

Privacy Policy

Last updated: August 2026

1. Introduction and Who We Are

This Privacy Policy explains how Rune Labs SAS, a company registered in France, collects and processes your personal data when you use Monquiro, our AI-powered personal assistant.

Rune Labs SAS acts as the data controller for the processing activities described in this policy, unless stated otherwise for specific integrations.

This policy applies to the Monquiro web and mobile applications, related support interactions, and connected features such as Google sign-in, Gmail invoice scanning, Google Calendar synchronization, push notifications, Pennylane synchronization, and billing.

We process data under Regulation (EU) 2016/679 (GDPR) and applicable French law, including the Loi Informatique et Libertes.

2. Definitions

For this policy, the following terms have these meanings:

  • Personal Data: any information relating to an identified or identifiable natural person.
  • Processing: any operation performed on personal data, including collection, storage, use, transmission, or deletion.
  • Data Controller: the entity that determines why and how personal data is processed. For Monquiro, this is Rune Labs SAS.
  • Data Processor: a third party that processes personal data on behalf of the data controller.
  • Data Subject: the individual whose personal data is processed.
  • GDPR: Regulation (EU) 2016/679.
  • Service: the Monquiro application and related features operated by Rune Labs SAS.
  • User: any person who creates an account, connects integrations, or otherwise uses the Service.
  • Cookies: small text files placed on your device to support session and product functionality.

3. Data We Collect

We collect the following categories of personal data depending on how you use Monquiro:

  • Account Data: name and email address, received through Google OAuth or provided when you sign up with email and password.
  • Notes and Journal Data: the content of your notes and daily journals, together with their tags and links.
  • Note Attachment Data: files you share into the app or attach to notes (such as PDFs and images), including text extracted from them, stored in our database until you delete the file, the note, or your account.
  • Task Data: tasks, reminders, and recurring routines you create or that the assistant creates for you.
  • Calendar Data: events in your Monquiro calendar and, if you connect Google Calendar, events synchronized from and written to your Google calendars (read/write access).
  • People and Project Data: names, aliases, contact details, relationships, and notes about the people and projects you record. This can include personal data about third parties that you choose to enter; you are responsible for having a legitimate reason to record it.
  • Contact Import Data: if you use the Android app's contact sync, the names, phone numbers, and email addresses of your phone contacts, imported only on your explicit action and stored as people entries you control (edit or delete at any time); they are never shared onward beyond the processors documented in this policy.
  • AI-Derived Memory: facts the assistant extracts from your notes, journals, and conversations, stored with validity dates — corrected facts are marked invalidated and kept for history until your account is deleted — plus AI-generated annotations and daily briefs, and numerical embeddings (1024-dimension vectors) of note, fact, and person text used for search and retrieval.
  • Chat Data: prompts and responses exchanged with the Monquiro assistant.
  • Email Data: email metadata and attachments identified as invoices, accessed in read-only mode through the Gmail API when authorized by you.
  • Financial Document Data: vendor names, invoice totals, dates, categories, and tax information extracted by AI from uploaded files or Gmail attachments.
  • Notification Data: push device tokens for your registered devices, and the content and history of the notifications we send you (kept for 90 days).
  • Integration Credentials: encrypted OAuth tokens and API keys, such as Google tokens and Pennylane API keys.
  • Billing Data: subscription plan details and payment status or dates. Full payment card numbers are processed by Stripe or your mobile app store and are not stored by us.
  • Technical Data: IP address, browser type, and device metadata processed transiently for secure operation. We run no analytics or tracking and keep no usage-tracking logs.

4. How We Collect Your Data

We collect personal data directly from you when you create an account, write notes and journals, create tasks and events, send chat messages, upload documents, configure integrations, or contact support.

Some data is derived by the Service itself: the AI assistant produces new data — remembered facts, annotations, daily briefs, embeddings, and suggestions — from the content you provide.

We also receive data from third parties you choose to connect, such as profile information, email, and calendar data from Google, and payment confirmations from Stripe or RevenueCat. We do not use third-party analytics or advertising data sources.

5. Legal Bases for Processing (GDPR Article 6)

We process personal data only when a valid legal basis applies under Article 6 GDPR:

  • Contract performance: account provisioning, authentication, notes, journals, tasks, calendar, people and project records, chat assistance, invoice scanning, document analysis, and requested integrations.
  • Legitimate interests: service security, abuse detection, fraud prevention, and proactive assistant suggestions based on your activity in the app (see section 7 — you can object at any time).
  • Consent: Google access scopes granted via OAuth (Gmail read-only, Calendar read/write), push notifications, and any optional communications that require consent. You can withdraw consent at any time.
  • Legal obligation: compliance with accounting, tax, and record-keeping requirements under applicable law.

6. How We Use Your Data

We use personal data to deliver and operate Monquiro, including to:

  • Authenticate users and maintain account security.
  • Provide the notes, daily journal, task, calendar, and people/project features.
  • Provide AI chat assistance and organize your content using AI models.
  • Build and maintain the assistant's memory — extracted facts, annotations, daily briefs, and embeddings — so the assistant stays useful over time.
  • Synchronize events with Google Calendar, including creating and updating events you ask for.
  • Send push notifications: reminders, and proactive suggestions and questions from the assistant.
  • Scan invoices and receipts from authorized Gmail sources or uploaded files and extract accounting data.
  • Synchronize invoice and accounting information with Pennylane when you connect it.
  • Manage subscriptions, invoicing, and billing administration.
  • Comply with legal and regulatory obligations.

7. AI Processing, Memory, and Proactive Suggestions

Monquiro's assistant builds a memory from your content: it extracts facts from your notes, journals, and conversations, annotates notes, prepares daily briefs, and computes embeddings so it can retrieve relevant context when you talk to it. When a remembered fact is wrong or outdated, it is corrected by invalidation — the old fact is marked no longer valid and kept for history — and all facts, including invalidated ones, are permanently erased when you delete your account. You can ask the assistant in chat to forget a specific fact at any time.

The assistant also analyzes your usage patterns — for example task completion, project activity, and periods of inactivity — to decide when to send you proactive suggestions and questions. This is a form of profiling under the GDPR. It is used solely to operate the assistant for you: it is never used for advertising, is not shared with third parties for their own purposes, and produces no legal or similarly significant effects on you.

You can object to or adjust this behavior at any time (Article 21 GDPR): change your notification settings in the app, or simply tell the assistant — for example “notify me less” or “stop suggestions about this project”. The assistant also automatically backs off when you ignore its notifications.

8. Google API Services User Data Disclosure

Monquiro connects to Google services only after you explicitly authorize OAuth permissions. We request read-only Gmail access (gmail.readonly) and full Google Calendar access (read/write), which the app uses to synchronize your events and to create or update events you ask for.

Monquiro's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We use Gmail data only to detect and process invoices at your explicit request, and Calendar data only to provide the calendar features you use.
  • We do not use Google user data for advertising purposes.
  • We do not sell Google user data to third parties.
  • We do not allow humans to read Google user data except with your explicit consent, when necessary for security or abuse investigations, or when required by law.
  • We do not transfer Google user data except as needed to provide the service you requested.

9. Data Sharing and Third-Party Processors

We share personal data only with processors needed to provide Monquiro and only under appropriate contractual and legal safeguards.

We require all processors to comply with GDPR and we maintain data processing agreements with relevant providers.

  • Google LLC (United States): OAuth authentication, Gmail read-only access, Google Calendar read/write synchronization, and push notification delivery through Firebase Cloud Messaging — notification titles and bodies transit through FCM. Transfers are protected by the EU-US Data Privacy Framework and Standard Contractual Clauses.
  • Mistral AI (France): AI processing. Mistral receives your chat history, note and journal content submitted for organizing and memory extraction, snippets retrieved as context for the assistant, invoice text and images, and text submitted for embedding computation. Processing is limited to service delivery.
  • Pennylane SAS (France): accounting synchronization, only when you connect your Pennylane account.
  • Stripe Inc. (United States): payment processing and subscription administration for web subscriptions. Transfers are protected by the EU-US Data Privacy Framework and Standard Contractual Clauses.
  • RevenueCat Inc. (United States): mobile subscription management. Receives your user identifier and purchase data.
  • Infomaniak Network SA (Switzerland): application hosting and data storage. Switzerland is covered by a European Commission adequacy decision.

10. International Data Transfers

Monquiro is hosted by Infomaniak Network SA in Switzerland, a country recognized by the European Commission as providing an adequate level of data protection, so hosting does not require additional transfer safeguards.

When data is transferred to United States based providers — Google, Stripe, and RevenueCat — we rely on recognized transfer mechanisms such as the EU-US Data Privacy Framework where available and Standard Contractual Clauses.

Mistral AI and Pennylane are based in France, so their standard processing for Monquiro stays within the European Union.

11. Data Retention

We apply the following retention periods, which match how the product actually behaves:

  • Account data: kept while your account is active; removed when you delete your account.
  • Notes, journals, tasks, people and project records, and calendar events: kept until you delete them or delete your account.
  • Chat history: kept until you clear it or delete your account.
  • AI memory facts: corrected facts are invalidated (marked no longer valid) rather than deleted, to preserve history; all facts, including invalidated ones, are permanently erased when you delete your account.
  • AI daily briefs: deleted after 14 days.
  • Abandoned empty notes: archived after 24 hours, then permanently deleted 7 days later.
  • Notification history: deleted after 90 days.
  • Sign-in sessions: expire after 30 days.
  • Integration credentials: deleted immediately when you disconnect the integration.
  • Billing and accounting records: retained for 10 years to satisfy French legal obligations.
  • When you delete your account, your data is removed from our active systems immediately, except records we are legally required to keep (such as billing records). We keep no analytics or usage-tracking logs.

12. Data Security

We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction.

If a personal data breach occurs, we notify CNIL within 72 hours when required under GDPR Article 33 and notify affected users without undue delay when Article 34 applies.

  • Encryption in transit using HTTPS and TLS 1.2 or higher.
  • Encryption at rest for sensitive credentials — OAuth tokens and API keys — using AES-256-GCM.
  • Authenticated, expiring session cookies for sign-in.
  • Access control mechanisms and authenticated administrative access.
  • Secure development and deployment practices.
  • Incident response procedures.

13. Your Rights Under GDPR (Articles 15-22)

Subject to applicable conditions, you have the rights listed below. You can exercise most of them directly in the app, or by contacting contact@monquiro.com.

In-app: download a full copy of your data from Settings (data export — Articles 15 and 20); delete your account and all associated data from Settings, confirmed by typing your email address (Article 17); ask the assistant in chat to forget or correct a specific remembered fact (Articles 16 and 17); and adjust or turn off proactive notifications in your notification settings or by telling the assistant (Article 21).

For requests made by email, we respond within 30 days unless a lawful extension applies, and we may request reasonable identity verification before fulfilling a request.

  • Access your personal data (Article 15).
  • Rectify inaccurate or incomplete data (Article 16).
  • Request erasure of your data (Article 17).
  • Restrict processing in certain situations (Article 18).
  • Receive your data in portable form (Article 20).
  • Object to specific processing activities, including proactive suggestions based on your usage patterns (Article 21).
  • Not be subject to decisions based solely on automated processing with legal or similarly significant effects (Article 22).
  • Withdraw consent at any time where processing relies on consent (Article 7).
  • Lodge a complaint with CNIL.

14. Cookies and Tracking

Monquiro uses essential session cookies required for authentication and secure operation of the service.

We also use localStorage for product preferences such as selected language or interface settings.

We do not use advertising cookies, third-party analytics trackers, or cross-site behavioral profiling. Because only essential cookies are used, no cookie consent is required. Cookie practices are aligned with the ePrivacy framework and applicable French (CNIL) guidance.

15. Children's Privacy

Monquiro is not intended for children under 16 years of age.

We do not knowingly collect personal data from children under 16. If we become aware that such data has been collected, we will delete it promptly.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect legal, technical, or business changes.

When we make material changes, we will update the Last updated date and provide notice by email or in-app notification at least 30 days before the changes take effect where required.

17. Supervisory Authority

You have the right to lodge a complaint with the French supervisory authority: Commission Nationale de l'Informatique et des Libertes (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.

Website: www.cnil.fr.

18. Contact Us

For any privacy or data protection request, contact: contact@monquiro.com.

Data Controller: Rune Labs SAS, 254 rue Vendôme, 69003 Lyon, France.