Last updated: 2 October 2026
Pack Money is provided by Loup / Dataloup, operated by Luc Mathery. Contact [email protected] about your information or this policy.
Pack Money cannot log into your bank or initiate a payment. It does store financial information you choose to record. Manual entry works without bank SMS. Telegram, AI and The Mental Load are optional features with the data flows described below.
Your household records
Pack Money stores transactions, amounts and currencies, merchant or payee descriptions, categories, dates, person labels, notes, bills, yearly costs, planned pay, savings records, goals and settings. It also stores import records, accepted bank-message text, corrections and audit history needed to maintain the ledger.
These records are held in a Cloudflare D1 database for your household. The application runs on Cloudflare Workers. In the current deployment model, each household has its own Worker and financial database; this does not make its data inaccessible to the service operator or hosting provider. Authorised operators may access records when needed to provide support, maintain the service, investigate abuse or fulfil a verified request.
Members signed in to the same household can access and manage its records. The current product does not offer a separate viewer-only role. Do not enter information that other approved household members should not see.
Manual entries, statements and SMS
- Manual entries: the fields you submit are sent to your household service and stored with the record.
- PDF statements: the browser reads the selected PDF and sends extracted statement entries for matching and confirmation. The original PDF is not uploaded by that importer. It remains wherever you saved it.
- CSV imports: the selected CSV contents and filename are sent for staging and import. Imported entries and import metadata are stored.
- Bank SMS: if you set up a collector, it sends selected transaction text, an event ID and a receipt time to your household service. The accepted raw text can contain amounts, a card suffix, merchant details or a balance included by your bank. Configure the collector to reject verification codes and authorisation requests before sending.
The app does not have direct access to your banking account, your full message inbox or your card credentials. A Shortcut only sends what its installed actions and automation pass to it. Its saved outbox may live on the phone or in your iCloud account; remove those files when no longer needed.
Sign-in and service security
The service uses credentials, login-attempt records and session information to authenticate household members and prevent abuse. Passwords are checked against stored hashes; service credentials are held as Worker secrets. Browser sessions use Secure, HttpOnly cookies. Sessions expire after 60 days and recognised-device cookies after 365 days, unless invalidated sooner.
Cloudflare receives normal connection information, such as IP addresses and request metadata, when serving the website and API. The application includes error logging for reliability, security and troubleshooting. See Cloudflare’s privacy policy.
HTTPS, authenticated requests and scoped credentials reduce risk; they do not make any online service completely safe. Keep your login, collector token and connection tokens private. Someone with a valid credential may be able to use the access it grants, even though Pack Money itself has no bank-payment capability.
Optional AI
AI can be disabled for your household deployment. When enabled, requests go to its configured Anthropic or OpenAI API provider. AI can run for questions, instruction interpretation, automatic categorisation and scheduled reports, not only when you manually ask a question.
Depending on the feature, requests include your question or instruction, budget settings, spending summaries, category names, merchant names, dates, amounts, person labels and selected recent purchases or outgoing account movements. Automatic categorisation can send a sanitised shop name, amount and allowed categories. Text you type into a question is part of the request; avoid adding secrets.
Ordinary answers are not saved as a chat history by Pack Money. Command jobs, proposed changes, delivery caches and audit records can nevertheless retain related content. Replies sent to Telegram remain there too. Provider processing and retention follow the applicable provider’s terms; this policy does not promise zero provider retention. See Anthropic’s commercial terms and OpenAI’s privacy policy.
Optional Telegram
Pairing stores your Telegram user ID, available name and username, group ID and title, household/member association and connection status. A separate shared gateway stores routing, pairing and delivery metadata. It routes command and reply content to the correct household without storing message bodies in its routing database. Your household database stores command jobs and delivery state for reliable processing.
Telegram receives messages and replies delivered through the bot. Everyone in the connected group can read them, including group members who cannot issue Pack Money commands. Use a private group with people you trust. Telegram group messages are not Secret Chats. See Telegram’s privacy policy.
Disconnecting an account or group prevents future authorised use after the access check; an already authorised request may finish. It does not erase delivered messages, remove group members or delete Telegram’s records. Manage group membership and message history in Telegram separately.
Optional connection to The Mental Load
You choose what to share: bill, yearly-cost and payday reminders; optionally their names and amounts; and separately spending, savings or category-limit summaries. Overview permissions start off. The feed excludes raw transactions, bank-message text, notes, spender names and bank-account identifiers.
The Mental Load reads this information directly from your household service using a separate access token. Tokens are stored hashed on the Pack Money side. You choose an expiry of 30 days, 90 days or one year and can revoke access earlier. Connection labels, permissions, dates and security audit events are stored with the household.
The supported Mental Load client keeps the token in device-only Keychain storage and excludes imported financial reminders and summaries from its AI requests. Imported reminders and your local notes can enter its optional iCloud backup; access tokens and the Family money summary do not. Restoring a backup requires reconnection. See The Mental Load privacy policy.
Revocation stops further reads but cannot remotely erase information already copied to a phone or backup. Disconnect and remove imported data in that app if required. Completing a task in The Mental Load does not record a payment or change the Pack Money ledger.
Exchange rates
For automatic currency estimates, the household service requests a currency pair and date from Frankfurter. It does not send the purchase amount, merchant, bank text, household identity or access token to the rate provider. The provider still receives the usual technical connection metadata. Returned rates and dates are cached with the household.
Estimates are reference conversions, not bank-confirmed amounts. A matched statement can replace the estimated home-currency amount while retaining the original foreign amount.
Why we process information
We use records to provide the household service you request, maintain its accuracy, authenticate access, deliver chosen integrations and help with support or recovery. We use necessary technical information to secure and operate the service and may retain information required by law. Where applicable, these purposes rely on providing the service, legitimate interests in security and maintenance, legal obligations or consent for an optional feature.
We do not sell personal information or use it for advertising. Service providers process information to operate the features above. Information may be processed outside your country, under those providers’ applicable data-protection terms and transfer arrangements. We may disclose information when legally required or necessary to protect the service and its users.
Retention, exports and deletion
Financial records, accepted SMS text, imports, settings and audit history remain with your household until corrected, removed through supported controls or deleted as part of a verified household request. They do not all have a rolling 30- or 90-day expiry.
Scheduled cleanup is configured to remove sent or skipped household Telegram jobs after 90 days; failed jobs and financial records are not covered by that rule. Shared-gateway cleanup is configured to prune pairing records a day after expiry, incoming delivery IDs after seven days and sent-message/delivery bindings after 90 days. Cleanup depends on the service running successfully. Connection metadata and other records can remain until removed.
A spending CSV is a partial export, not a complete recovery backup. Database backups and recovery copies may retain deleted information for their applicable recovery period. Copies you download, Shortcuts outbox files, Telegram history and AI-provider records have separate storage and deletion rules.
For access, correction, export, deletion or another privacy request, contact [email protected]. We will verify your authority over the household and explain what can be removed, what must be retained and any recovery-copy limitations. Depending on where you live, you may also have rights to restrict or object to processing, withdraw consent or complain to your local data-protection authority. Turning off an integration does not by itself delete the household database.
Children and changes
Pack Money is for adults managing household finances. It is not directed at children; avoid entering unnecessary information about them. When the service or its data practices change, we will update this policy and its date, and give additional notice where required.