+
+
Last updated: June 2026

Privacy Policy

Gasti.pro — Operated by MoneyLabs LLC

1. Introduction

At Gasti.pro, the privacy of our users is a priority. This Privacy Policy describes what data we collect, how we use it, with whom we share it, and what rights you have over your information.
This policy is an integral part of our Terms and Conditions of Use. By using the service, you accept the practices described in this document. If you have any questions, you can contact us at hello@gasti.pro.

2. Data Controller

MoneyLabs LLCEntity registered in Delaware, United StatesContact: hello@gasti.pro

3. Data We Collect

3.1 Data provided directly by the user

  • Name and email address (account registration)
  • Manually entered financial data (expenses, income, categories)
  • Information provided during interactions with the chatbot

3.2 Automatically collected data

  • IP address and approximate geolocation data
  • Device type, operating system, and browser
  • Usage and browsing logs within the application
  • Cookies and similar tracking technologies (see section 7)

3.3 Data from third-party integrations

When the user authorizes integrations, we may receive data from:
  • Digital wallets and payment services
  • Email accounts (only for invoice and receipt analysis)
  • Financial and banking institutions
  • E-commerce platforms and other financial providers

These integrations always require express authorization from the user and can be revoked at any time from the account settings.

4. How We Use Your Data

We use the collected information for the following purposes:
  • Service provision: process, organize, and display the user's financial information.
  • Personalization: adapt the experience, the chatbot, and analyses to each user's profile.
  • Product improvement: identify errors, analyze usage patterns, and develop new features.
  • Service communications: send account-related notifications, important updates, and security alerts.
  • Security and fraud prevention: detect unauthorized access and suspicious activities.
  • Legal compliance: address requirements from competent authorities when applicable.

We do not use your data for advertising purposes nor do we sell it to third parties.

5. Aggregated and Anonymized Data

To improve the service and generate insights on financial patterns, we may use completely anonymous and aggregated data to:
  • Calculate general market statistics (e.g., average rent expense per city)
  • Publish economic trend reports without identifying individual users
  • Improve the service's analysis and artificial intelligence models

Guarantees on aggregate use:

  • No aggregate data allows the identification of an individual user.
  • Strict anonymization protocols are applied before any analysis.
  • Statistics are only generated when there is a minimum volume of data that guarantees anonymity.
  • Results are never shared with third parties in a way that allows re-identification.

6. Sharing Information with Third Parties

Gasti does not sell, rent or market your personal data. We only share information in the following circumstances:
  • Service providers: companies that help us operate the platform (hosting, infrastructure, technical support), subject to confidentiality and data processing agreements.
  • Legal requirement: when required by law, court order or competent authority request.
  • Protection of rights: to prevent fraud, protect the security of the service or defend the rights of Gasti.
  • Merger or acquisition: in the event of a corporate restructuring, users will be notified a reasonable time in advance, and the data will be subject to an equivalent or more protective privacy policy.

7. Cookies and Similar Technologies

Gasti uses cookies and tracking technologies to:
  • Keep the user session active
  • Remember configuration preferences
  • Analyze usage behavior within the platform (analytics)
  • Detect suspicious or fraudulent activities

The user can manage or disable cookies from their browser settings, although this may affect the operation of some parts of the service.

8. Data Security

We implement enterprise-grade technical and organizational measures to protect your information:
  • Data encryption at rest and in transit (TLS/SSL)
  • End-to-end encryption for sensitive financial information
  • Multi-factor authentication and role-based access control
  • Storage in ISO 27001 certified data centers
  • Regular security audits and continuous monitoring
  • Detailed logs of access and modifications to data
  • Regular backups with disaster recovery procedures

Despite these measures, no system is completely infallible. In the event of a security breach affecting your data, we will notify affected users as soon as possible, in accordance with applicable regulations.

9. Data Retention

We keep your data for as long as your account is active and for the additional period necessary to comply with legal obligations or resolve disputes.
When a user requests the deletion of their account, identifiable personal data is deleted within a maximum period of 30 days, unless the law requires its conservation for a longer period.
Aggregated and anonymized data can be kept indefinitely, as they do not allow the identification of individuals.

10. User Rights

You have the following rights over your personal data:
  • Access: request a copy of the data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Deletion: request the deletion of your personal data ("right to be forgotten").
  • Portability: export your data in a readable and structured format.
  • Revocation of consent: withdraw your consent for data processing at any time, without affecting the lawfulness of the prior processing.
  • Opposition: object to the use of your data for certain purposes.

To exercise any of these rights, write to us at hello@gasti.pro. We will respond to your request within a maximum period of 30 business days.

11. International Data Transfers

MoneyLabs LLC operates from the United States. By using the service, your data may be processed and stored on servers located outside your country of residence. We guarantee that any international transfer is carried out under mechanisms that ensure an adequate level of protection.

12. Minors

Gasti allows the use of the service by minors. If the user is under 13 years of age, access and use of the service must be carried out under the supervision and with the express consent of a parent or legal guardian, who assumes responsibility for the use of the service on behalf of the minor.
Parents or guardians can contact us at hello@gasti.pro to request the deletion of data associated with the account of a minor under their guardianship.

13. Changes to this Policy

We may update this Privacy Policy periodically. When changes are material, we will notify users with reasonable advance notice through the platform or by email. continued use of the service following the notification constitutes acceptance of the new policy.

14. Third-Party Integrations (Google and Notion)

Gasti offers optional integrations that the user explicitly enables and can revoke at any time. We only access the data strictly necessary for the chosen feature; we never sell it or use it for advertising.

14.1 Google (Google Sheets)

When you connect your Google account, Gasti requests access to your email address and the Google spreadsheets you choose. We use that access solely to export and keep your transactions in sync in the spreadsheet you connect. Sync is one-way (Gasti → Google Sheets): we never read or modify other files in your Google Drive. The access token is stored encrypted (AES-256-GCM), never in plain text. You can disconnect the integration at any time from the app; when you do, we revoke the token at Google and delete it from our database.

14.2 Limited Use — Google API Services User Data Policy

Gasti's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. More information at https://developers.google.com/terms/api-services-user-data-policy.

14.3 Notion

When you connect Notion, Gasti accesses only the pages or databases you explicitly share during authorization. We write the transactions you choose to export (one-way sync, Gasti → Notion) and never read or modify the rest of your workspace. The access token is stored encrypted. You can revoke access from Notion (Settings → Connections) and disconnect the integration from Gasti, which deletes the stored token.

14.4 Data processors (sub-processors)

To provide the service we rely on providers that may process data on our behalf, under confidentiality agreements: hosting and database (Supabase), background job execution (Trigger.dev), product analytics (PostHog), AI receipt parsing (Anthropic), and the platforms the user connects (Google, Notion).

Integrations are exclusive to the Pro and Premium plans. If the subscription is no longer active, syncing stops and the connection is automatically deleted.

15. Contact

For inquiries, requests or complaints related to this Privacy Policy:
Email: hello@gasti.proData Controller: MoneyLabs LLC, Delaware, United States