Munrir ("Munrir", "we", "us", or "our") is operated by Dil Eight LLC, a Florida limited liability company. This Privacy Policy explains what the Munrir mobile application, the website at https://munrir.com, and related services (together, the "Service") collect, why, and what happens to it.
Munrir is a planning tool. You tell it what you owe; it calculates repayment scenarios and explains a next step. It does not connect to your bank accounts, and it moves no money.
1. What we collect
1.1 Account information
- Your email address.
- Your password, stored only as a cryptographic hash. We never store the password itself.
- If you sign in with Google, the account identifier and email address Google returns to us.
1.2 What you tell us about your debts
The Service exists to work with figures you enter yourself: balances, interest rates, minimum and actual payments, income, and the transactions or budget entries you choose to record.
Before you create an account, the app may ask a few questions to shape a first example — how pressing your debt feels, whether you usually pay minimums or more, what kinds of debt you hold, and how you would describe your credit standing. Those answers are your own description of your situation, not data obtained from anyone else.
1.3 What the Service calculates
Repayment plans, projections, the actions a plan proposes, and which proposed actions you accepted or declined. These are derived from the figures above and are stored so a plan survives closing the app.
1.4 Payments
If you buy a paid feature, we do not receive or store your card number. On the website the payment is taken by Stripe; in the app it is taken by Apple or Google. What reaches us is the fact that a purchase or subscription exists, its identifier and status, and when it renews or ends — not your payment details.
1.5 What stays on your device
A PIN code, if you set one, and the biometric unlock setting are kept on your device and are never sent to us. Biometric matching is performed by your operating system; fingerprints and face data never reach Munrir.
Before you create an account, the app keeps an identifier on the device so your answers and a draft plan are still there when you come back. In the browser version this identifier is currently derived from characteristics of the browser; we are replacing that with a randomly generated value.
1.6 What we do not collect
- We do not connect to your bank and do not import your accounts or statements.
- On the website, we use basic cookieless analytics to understand which pages and links are useful. If you select "Accept all" in the cookie banner, PostHog may also use analytics cookies or local storage to remember the browser across visits. Selecting "Only necessary" keeps analytics cookies and analytics local storage off; the only thing the website then keeps on your device is the choice itself, so that we do not ask again. We do not send the debt figures you enter to analytics tools, and the app does not embed third-party analytics.
- We do not build advertising profiles and do not sell personal information.
- We do not ask for government identifiers, and we do not take payment card numbers.
2. Why we use it
- To operate your account and keep you signed in.
- To calculate repayment scenarios, plans, and the projections you asked for.
- To send messages the Service itself requires: email verification, password resets, and notices about these documents.
- To take payment for paid features and to keep a subscription active.
- To keep the Service working and secure, including diagnosing failures from our own server logs, measuring basic website usage without cookies, and, where you choose "Accept all," measuring website usage with analytics cookies or local storage.
- To show offers that fit the plan calculated from your figures, and to be paid when someone takes one up.
We do not use your financial data for advertising, and we do not share it for cross-context behavioural advertising.
3. Legal bases for users in the EEA and the UK
Where the GDPR or UK GDPR applies, we rely on: performance of a contract for operating your account and producing the plans you request; legitimate interests for security, fraud prevention, and keeping the Service reliable; consent where consent is required; and compliance with legal obligations. On the website, the basic cookieless measurement described above rests on our legitimate interest in knowing which pages and links are useful; analytics cookies and local storage are used only with your consent, given in the cookie banner.
4. Who else processes it
We use a small number of providers that process data on our behalf under contract, and only for the purposes above:
- Google, to verify a Google sign-in when you choose that method.
- Resend, to deliver transactional email such as verification and password-reset messages.
- Stripe, to take card payments made on the website.
- Apple and Google, to take purchases and subscriptions made inside the app, under their own terms.
- DigitalOcean, which hosts the servers and the database where the data described here is stored.
- PostHog, to measure website analytics such as page views, language changes, theme changes, viewport size, link or call-to-action clicks, and cookie banner choices. The website uses PostHog in cookieless mode by default. If you select "Accept all," PostHog may use analytics cookies or local storage for persistent analytics.
We do not sell personal information, and we do not disclose it to anyone else except where the law requires it.
5. Offers and affiliate links
The Service may show offers from card issuers and lenders, and where it does, we are paid a commission when someone takes one up through us. The Terms of Use explain that arrangement; this section is about what happens to data.
If you follow an offer, you leave Munrir. The affiliate network that carries the link and the provider receive the click and an identifier that lets them attribute it, and they may set their own cookies or device identifiers. From that point they decide for themselves what to collect and why: they are independent controllers, not processors acting for us, and their own privacy notices apply.
What comes back to us is whether an application was completed and became payable, so the commission can be settled. We do not receive what you put in the provider's application.
6. How long we keep it
Account data and the figures you entered are kept while your account exists. You can ask us to delete your account at any time by writing to [email protected]; personal data is removed within 30 days unless the law requires us to keep it longer.
One record survives deletion, deliberately and in minimised form: that a given user accepted a specific version of these documents at a specific time. It contains an identifier, the document, the version, and the timestamp — nothing else. It is the only proof of what was agreed, which is why it cannot be erased along with everything else.
Server logs that record errors and requests are kept for a limited period for security and debugging, and are not used to build a profile of you.
7. Security
Traffic is encrypted in transit. Passwords are stored only as hashes. Sign-in tokens are held in your device's secure storage — the system keychain on iOS and Android — rather than in ordinary application storage. Access to production systems is restricted.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal data, we will notify you and the relevant authority where the law requires it.
8. Where it is processed
Your data may be processed and stored in the United States and in other countries where our providers operate. For transfers out of the EEA or the UK we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses.
9. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, and receive a copy in a portable form. Write to [email protected] and we will answer within the period the applicable law allows.
If you are in the EEA or the UK you also have the right to complain to your data protection authority.
You can choose whether to allow analytics cookies in the website's cookie banner, and you can change that choice at any time: "Cookie settings" in the website footer reopens the banner, and selecting "Only necessary" withdraws consent and clears the analytics cookies and local storage that were set. Withdrawing consent does not affect measurement that already happened while it was given.
10. Age
The Service is intended for adults: you must be at least 18 to use it. We do not knowingly collect personal information from children. If you believe a child has given us personal information, write to [email protected] and we will delete it.
11. Changes to this policy
Every version of this policy has a permanent address and stays published, so it is always possible to read exactly what applied at a given time. The current version is listed at https://munrir.com/legal.
When a new version takes effect, the app asks you to accept it before you continue. We do not treat silence as agreement.
12. Contact
| Company | Dil Eight LLC |
|---|---|
| Product | Munrir |
| Website | https://munrir.com |
| [email protected] | |
| Location | Florida, United States |
Version 2026-09-14sha256 56167fc094c640b6e01e89118970c1a1e76dee0be0ac020c383414c5286dd5ad