Privacy Policy

Your data, your business.

Last updated: July 2026 · Operated by Rafflexchange Inc.

Seven specific commitments about how we handle your financial data. Plain language, no dark patterns, no vague promises. Monthcloser is a document-first personal finance platform operated by Rafflexchange Inc. You hand us your payslip, bank statement, and credit card statement once a month; we process them, close your month, and give you a verified picture of your financial life. We don't connect to your bank accounts, we don't follow you around the web, and we don't sell your individual data. This policy complies with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission (NPC).

Who we are

For the purposes of the Data Privacy Act, the Personal Information Controller (PIC) responsible for your personal data is Rafflexchange Inc. (“Rafflexchange”, “Monthcloser”, “we”, “us”), a company registered in the Republic of the Philippines and the operator of monthcloser.com. Contact us about any privacy matter at support@monthcloser.com.

Monthcloser does not look at your financial data. Here is exactly what that means.

01
Your documents are deleted immediately after processing.
02
Your financial data is encrypted in our database.
03
Our team accesses your data only to support you, with your permission.
04
Access to your financial data is restricted and logged.
05
Your employer cannot see your individual financial data.
06
Your data is never sold. To anyone. Ever.
07
Deleting your account permanently deletes your data.

The seven privacy commitments

These are the specific, named commitments that constitute Monthcloser's privacy stance. Each is backed by a technical or operational measure.

1. Your documents are deleted immediately after processing.
We keep the numbers. We do not keep the documents.
How it works: Uploaded files are processed entirely in memory and are never written to our disks or database. Once we extract the figures and you confirm them, the file is permanently discarded. If a document is password-protected, the password is used only to open the file during processing and is never stored or logged.
2. Your financial data is encrypted at rest.
Your records are stored in a managed database that encrypts data at rest at the storage layer.
How it works: Financial line items, closed-month records, Closer Reports, and Financial Health Scores are stored in MongoDB Atlas, which encrypts data at rest at the storage layer. Access is limited to the application serving you.
3. Our team does not browse your financial records.
No Monthcloser employee looks at your financial data in the normal course of their work.
How it works: Access to financial records is restricted to the application serving the authenticated user. If resolving a support issue you raise requires someone to look at your data, we do so only with your permission.
4. Access to your data is restricted and logged.
Access to your financial data is limited by role and recorded for security.
How it works: Financial data is partitioned per user, access is restricted by role, and server activity is logged for security and accountability. We are working toward surfacing a plain-language access summary to you directly in the app.
5. Your employer cannot see your individual financial data.
If your employer sponsors Monthcloser, any reporting to them uses only anonymized group metrics.
How it works: Under our enterprise program, any employer-facing reporting uses only anonymized, aggregated group metrics — never individual records. Your salary, balances, spending, and personal Financial Health Score are never shared with your employer.
6. Your data is never sold. To anyone. Ever.
We never sell your individual financial data.
How it works: We do not currently operate any data-licensing or benchmark product. If we ever offer anonymized, aggregated benchmarks, participation would be strictly opt-in — and your exact income, transactions, and score would never be shared with any third party in identifiable form.
7. Deleting your account permanently deletes your data.
Not archived. Not anonymized and retained. Gone.
How it works: Account deletion triggers permanent deletion of all financial line items, closed-month records, Close Reports, Financial Health Scores, and document metadata; residual copies in encrypted backups are purged in the ordinary backup rotation. Billing records required by law are retained only as long as legally required.

What we collect

Account and profile information

When you sign up, we store your email address, your name (optional), and a hashed password. We never see your password in plain text — it's hashed with a per-user salt before it touches our database. If you choose to complete your profile, we may also store optional details you provide, such as a phone number, employment type, or employer industry. These are entirely optional and used only to personalize your Monthcloser experience and improve the relevance of your benchmark comparisons.

Your monthly close data

To close a month, you upload your statements (PDF) and confirm them. We then store the structured result of that close:

  • Bank transactions (date, description, amount, category, and the classification you confirm) from the statement you uploaded
  • Credit-card line items from your statement
  • Payslip earnings and deductions you confirmed during the close
  • Financial account summaries (for example SSS, Pag-IBIG, PhilHealth, loans, insurance, or investment accounts) and their latest balances
  • Your Financial Health Score and its four component scores for each closed month
  • Your Close Reports
  • Category rules you create to help us classify future merchants
  • Milestone badges earned and your streak count

This data lives in a per-user space in our MongoDB Atlas database. No other user can see your data, and we don't share it with anyone outside what's strictly required to run the service (see “Who has access” below).

Your original documents are never stored

This is central to how Monthcloser works. When you upload a statement or payslip, the original file is processed entirely in memory and is never written to our disks or database. Once we extract the figures and you confirm them, the file is discarded. We keep only the structured result — not the source document. If a document is password-protected, the password you enter is used only to open the file during processing and is never stored or logged.

The Close Report™ and AI processing

You receive The Close Report™ — an automatic AI-generated monthly financial health report delivered after every close. We want to be fully transparent about how this works.

The honest disclosure To generate your Close Report, your monthly financial summary for that month is sent to our AI provider (Anthropic) over a secure (HTTPS) connection to produce your report. Under Anthropic's commercial API terms, data submitted through the API is not used to train their models. We store only the resulting report — we do not keep a separate copy of the summary.

The Close Report and Ask AI use your verified closed-month data to generate these features automatically. If you prefer that your data is never processed by AI, contact us to disable Close Report and Ask AI generation — you keep full access to your monthly close either way. The two Ask AI questions available after each close use your data only to answer your specific question and are not retained beyond the session.

Enterprise program employees

If your employer provides Monthcloser as an employee benefit, your account is sponsored by your employer but your data remains entirely yours:

  • Your employer cannot see your individual data. Any report your employer receives contains only anonymized group metrics for the cohort as a whole — no individual salary, balance, spending, or Financial Health Score.
  • Your account belongs to you, not your employer. Your financial history, closed months, Close Reports, and score trajectory are yours permanently. If you leave the company, your account continues under an individual subscription.
  • Your coach sees only what you share. A Monthcloser Certified Coach™ sees aggregated cohort information only; your individual data is visible to them solely if you explicitly grant Shared Close View access in the app, which you can revoke anytime.

Billing information

If you subscribe, payments are handled entirely by Stripe. We never see or store your full card number, CVV, or bank account details. From Stripe we receive and store:

  • Your Stripe customer ID and subscription ID
  • Payment status (paid / failed) and amount per invoice
  • Plan code and subscription period dates

This is what powers the “Billing” tab in your account.

Logs and basic operations

Our server logs standard things like request paths, response status codes, and timestamps so we can keep the service healthy and secure. We don't run third-party analytics, ad pixels, or session recorders.

Why we process your data (legal bases)

Under the Data Privacy Act, we process your personal data only where we have a lawful basis to do so:

  • Your consent — given when you sign up and when you upload and confirm documents for processing.
  • Performance of a contract — to provide the Monthcloser service you signed up for, including closing your months and managing your subscription.
  • Compliance with legal obligations — for example, retaining billing records required by tax and accounting laws.
  • Our legitimate interests — to keep the service secure, prevent fraud and abuse, and improve reliability, balanced against your rights and freedoms.

If we introduce an anonymized benchmark dataset in the future, we would rely on your explicit opt-in consent, which you could withdraw at any time.

What we don't do

  • We don't connect to your bank. No Plaid, no Open Banking, no read-only credentials. Your bank account stays your bank account.
  • We don't sell your individual data. Ever — not your specific transactions, not your salary, not your Financial Health Score. We do not currently operate any data-licensing or benchmark product; if we ever offer anonymized aggregate benchmarks, it would be strictly opt-in and your individual data would never be sold.
  • We don't track you across the web. No ad networks, no marketing pixels, no cross-site cookies.
  • We don't use your data to train AI models. Under Anthropic's commercial API terms, data submitted through their API is not used to train their models.
  • We don't share your data with your employer in individual form. Your employer receives only anonymized cohort metrics.

Who has access

Your data is processed by a small set of vetted infrastructure providers acting as our Personal Information Processors, each with a narrow, specific role and bound by their standard terms and applicable data-protection commitments:

ProviderRoleData processed
MongoDB AtlasDatabase hostingAccount data, close records, and Close Reports (encrypted at rest at the storage layer)
HerokuApplication hostingRuns the Monthcloser application servers
AnthropicAI for the Close ReportMonthly close financial summary — per report only; under Anthropic's API terms, not used for training
StripePayment processingBilling records only — no financial health data

The Monthcloser team accesses your data only to run the application that serves you and to help with a specific support request you raise — the latter only with your permission. Access is restricted by role and logged for security.

Employer-sponsored accounts

If your employer has entered into a service agreement with Rafflexchange Inc. to offer Monthcloser as an employee benefit, the following applies in addition to the rest of this policy.

Your employer's role. Your employer is a Personal Information Controller under the Data Privacy Act, sponsoring your participation in the program. That sponsorship covers the cost of your access and enables the program within your organization. It does not give your employer access to your personal data.

What your employer sees. Your employer — and no one at your employer — ever sees your individual closes, your Financial Health Score, your Close Report, your uploaded documents, or any figure attributable to you personally. The only information available to your employer is anonymized, aggregated cohort metrics for the group as a whole (for example, the cohort's average savings rate or the percentage of employees who completed a close this month), provided in a quarterly report. To prevent identification of any individual, we only report a metric if the cohort it describes has at least 10 participating employees; smaller cohorts are combined with a broader group or withheld until that threshold is met.

Access logging. Any access to your individual data by Monthcloser staff — which occurs only when strictly necessary to investigate a bug or respond to a support request — is logged. Such access never occurs without your consent for support matters.

AI and automated processing. Your Close Report and Financial Health Score are generated by automated systems from your verified closed data. No Monthcloser staff member reviews your data to produce these outputs. Aggregated cohort reports for your employer are similarly computed by automated systems from anonymized data and are not reviewed at the individual level.

When your employer's program ends. If your employer's service agreement with Rafflexchange Inc. ends — for any reason, including your own departure from the company — your account does not disappear. You will be notified and offered the option to continue on a personal subscription. Your complete close history, your Financial Health Score history, your Close Reports, and your Annual Forecast (if unlocked) remain yours permanently. Your employer has no role in that continuation and receives no data about it.

If you decline to continue. If you do not take up a personal subscription after your employer's program ends, your account enters read-only access. Your data is retained under the standard retention terms in this policy and is not shared with your employer or any third party. You may request deletion at any time by contacting support@monthcloser.com.

Your rights are unchanged. Employer sponsorship does not affect your rights under the Data Privacy Act. You retain the right to access, correct, object to, and request erasure of your personal data regardless of how your account was created or who is paying for it.

Where your data is processed

Some of our processors — including MongoDB Atlas, Heroku, and Anthropic — may store or process data on servers located outside the Philippines. Where personal data is transferred across borders, we take steps to ensure it remains protected to a standard consistent with the Data Privacy Act and applicable NPC issuances, and that our processors are bound by appropriate contractual and security safeguards.

For subscribers in Singapore, Australia, the United Kingdom, and the European Union, additional protections apply under the respective applicable privacy laws (PDPA, Privacy Act 1988, UK GDPR, and GDPR). Contact us if you have questions about the protections applicable to your jurisdiction.

How we protect your data

We apply organizational, physical, and technical security measures appropriate to the sensitivity of your financial data, including:

  • Encryption in transit — all traffic between your browser and our servers is protected with TLS (HTTPS), with HTTP automatically upgraded to HTTPS.
  • Encryption at rest — data is encrypted at rest at the storage layer by our database provider (MongoDB Atlas).
  • Password protection — passwords are hashed with a per-user salt and never stored in plain text.
  • Document minimization — original documents are never persisted; we keep only the structured figures you confirm.
  • Access controls — data is partitioned per user and internal access is limited by role.
  • Access logging — access to financial records is logged for security.
  • AI processing — Close Report generation sends only a per-month financial summary to Anthropic over HTTPS and does not log your financial content.
Honest security statement No system is 100% secure, and we do not make absolute security claims. What we commit to is applying appropriate technical and organizational measures, maintaining an incident-response procedure, and being transparent with you if something goes wrong.

How long we keep your data

Data typeRetention period
Original documents (payslips, bank & CC statements)Not retained. Discarded immediately after processing; never written to disk.
Account & close data (transactions, Financial Health Scores, Close Reports)Kept while your account is active. Permanently deleted on account closure.
Billing recordsKept as long as required by applicable tax, accounting, and anti-fraud laws. Stripe retains billing records under its own policies.
Operational logsKept for a limited period for security and reliability, then rotated out. Financial content is never in operational logs.
Anonymized benchmark data (if introduced)Would be retained only as anonymized aggregate statistics; the opt-in disclosure would explain that individual contributions cannot be removed from historical aggregates.
Access logsRetained for security for a limited period, then rotated out.

Your rights

Under the Data Privacy Act, you have the right to be informed, to access, to object, to rectify, to erasure or blocking, to data portability, and to be indemnified for damages. In practice, within Monthcloser you can:

  • Access & export — view and download your monthly closes as CSV or similar
  • Correct — edit any line, category, or rule directly in the app
  • Delete — remove individual months, or request full account deletion
  • Object — withdraw consent to specific processing by contacting us to disable Close Report generation
  • Cancel — end your subscription anytime from Account → Subscription

To exercise any of these rights, contact us at support@monthcloser.com. You also have the right to lodge a complaint with the National Privacy Commission (NPC) if you believe your data privacy rights have been violated — see privacy.gov.ph.

Data breach notification

We maintain safeguards to prevent unauthorized access to your data. In the event of a personal data breach that may pose a real risk of serious harm, we will:

  • Notify the National Privacy Commission within 72 hours of knowledge of the breach;
  • Notify affected users within a reasonable time with specific information about what occurred and what data was involved; and
  • Take immediate steps to contain the breach and prevent further unauthorized access.

Our database provider encrypts data at rest at the storage layer, which adds a layer of protection against certain forms of infrastructure compromise.

Cookies

We use one essential mechanism: a token stored in your browser's localStorage so you stay signed in. That's it. No tracking cookies, no third-party cookies, no consent banner drama because there's nothing tracking you.

Children

Monthcloser is intended for salaried professionals and is not designed for users under 18. We don't knowingly collect personal data from children. If you believe a minor has created an account, contact us at support@monthcloser.com and we will delete it promptly.

Changes to this policy

If we change how we handle data, we'll update this page and the “Last updated” date at the top. Significant changes — to the seven commitments, to what we collect, or to who has access — will be announced in-app with at least 30 days' notice before taking effect. We will never reduce the protections described in the seven commitments without explicit notice and the opportunity for you to export your data and close your account first.

Data Protection Officer & contact

Questions, deletion requests, access requests, or anything privacy-related — including matters for the attention of our Data Protection Officer — can be sent to support@monthcloser.com. We will respond within a reasonable period consistent with the Data Privacy Act. For complaints about how we have handled your personal data, you may also contact the National Privacy Commission directly at privacy.gov.ph.

The bottom line Monthcloser is built on the principle that your financial data belongs to you. We need to see it to serve you — to close your month, generate your Close Report, and show your Financial Health Score. We do those things. We do not do anything else with it.