Privacy Policy

How Munibee collects, uses and protects your data. In plain language, no fine print.

Last updated: 17.07.2026

At Munibee, your financial life is personal, and we treat it that way. This page explains, in plain language, what we collect, why, and the choices you have. No fine print, no surprises. If anything here is unclear, just email us at privacy@munibee.com and a real person will answer.

Munibee AS (org.nr. 835 660 052), Petroleumsveien 6, 4031 Stavanger, is the data controller for your personal data.

The short version

  • We only collect what we need to run Munibee for you.
  • We never sell your data, and we never use your bank data for marketing.
  • We don’t use advertising trackers or third-party analytics.
  • Your data is stored within the EU.
  • You’re in control. You can access, export, or delete your data any time.

What we collect, and why

Account info: your name, email, phone number and settings. We use these to create and look after your account.

Bank data: when you connect a bank through PSD2 (the EU’s secure open-banking standard), we retrieve your account overview, balance and transaction history so we can give you a clear picture of your finances. We never see your bank login or password. Your bank data is encrypted, no Munibee employee can read it, and it’s never used for marketing or sold to anyone.

Shared Hives: only the transactions you choose to share become visible to your Hive members. Members who join later do not see what was shared before they joined — a Hive must always be settled and stand at zero before new members can be invited. Your private transactions stay private, always.

Shared projects: the same applies to a shared project. Only what you choose to share is visible to the others, the rest stays private.

Shared-account marking in a Hive: you can mark an account as a shared account for a Hive. The marking is a piece of information you register yourself, and it is visible to whoever is a member of the Hive at any given time — including members who join later — together with the account’s display name. It does not give the members access to your account or your transactions. Transactions are only shared when you add them to the Hive yourself. The legal basis is our agreement with you (GDPR Art. 6(1)(b)). The marking is deleted when you remove it, leave the Hive or delete the account.

Receipts: if you scan a receipt, the text recognition happens right on your device. The image isn’t uploaded to us or anyone else.

Usage data: basic technical logs that help us fix bugs and improve the app. We don’t use third-party analytics or advertising trackers.

Marketing: only if you say yes. You can change your mind any time, in the app or via the unsubscribe link.

What we use your data for

  • Running Munibee and keeping it working well for you
  • Showing your overview and balances, and helping you plan, predict and understand your finances
  • Sending you important service messages (and notifications you’ve opted into)
  • Keeping your account and data secure, and fixing bugs
  • Improving the product using anonymised statistics
  • Marketing, only with your consent
  • Meeting our legal obligations as a Norwegian company

The GDPR requires us to have a legal basis for everything we do with your personal data. These are the bases we rely on:

  • Our agreement with you (GDPR Art. 6(1)(b)): most of the service — running your account, retrieving the bank data you connect yourself, showing what you choose to share in Hives and projects, shared-account markings and settlements.
  • Your consent (Art. 6(1)(a)): marketing and the optional sharing of anonymous statistics. You can withdraw your consent at any time.
  • Legitimate interest (Art. 6(1)(f)): keeping the service safe — fixing bugs, security logs and preventing misuse. Our interest is protecting you, the other users and the service.
  • Legal obligation (Art. 6(1)(c)): retention Norwegian law requires of us, for example under the Bookkeeping Act.

Who we work with

To run Munibee, we rely on a small number of trusted partners who process data on our behalf. Each is bound by a data-processing agreement, and all of them are based in the EU:

PartnerWhat they help withWhere
Enable Banking OySecurely connecting to your bank (PSD2)Finland 🇫🇮
ScalewayHosting, database and secure storageNetherlands 🇳🇱 (French company)
BrevoSending emails and SMS (e.g. verification codes, notifications)France 🇫🇷

All your data is stored within the EU. As soon as Scaleway offers server hosting in Norway, we plan to move your data there.

How long we keep your data

  • Account data: deleted within 30 days after you close your account.
  • Financial records: some may be kept for up to 5 years where Norwegian bookkeeping law requires it.
  • Technical logs: deleted after 6 to 24 months.
  • Bank data: transactions already retrieved are kept as part of your overview even if you disconnect a bank — they are deleted when you delete them yourself or close your account.
  • Shared transactions: when you close your account, the other members of shared Hives and projects can still see the date, title and amount of transactions you shared there, but they are anonymised so they can no longer be linked to you.

Your rights

You have the right to access, correct, delete, restrict the processing of, and export (port) your data, and to object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time. Just email privacy@munibee.com and we’ll respond within 30 days.

You can also contact Datatilsynet, the Norwegian Data Protection Authority (datatilsynet.no), if you’d like to raise a concern.

No automated decisions

We make no automated decisions that have legal effects or a similarly significant impact on you. Categorisation and insights are suggestions — you always decide.

Keeping your data safe

Security is at the heart of how we build Munibee. Your data is encrypted both in transit and at rest, access is tightly restricted, and your bank data is protected so that no Munibee employee can read it. In the unlikely event of a data breach, we’ll notify Datatilsynet within 72 hours and let you know as soon as possible.

Cookies

We only use cookies that are necessary to keep you signed in and secure. No advertising cookies, ever.

Age

Munibee is intended for adults (18+). We don’t knowingly collect data from anyone under 18, and if we learn that we have, we’ll delete it.

Changes to this policy

If we make a significant change, we’ll let you know by email and in the app at least 30 days before it takes effect.

Questions? We’re happy to help. Email privacy@munibee.com.