Privacy Policy

This page explains what data Mari Yangu stores, which providers process it, and the controls you have over your account and workspace data.

Last updated: February 2026

What we collect

We collect only the account and expense data needed to sign you in, read your receipts, and keep your workspace working across devices.

  • Account info: email address and name when you sign up via Clerk.
  • Expense images: photos you capture or upload, stored in private cloud storage.
  • Extracted data: merchant names, dates, amounts, and line items read from your receipts.
  • Device token: a hashed identifier for anonymous or guest users.
  • IP hash: a one-way hash of your IP address used to prevent abuse. We do not store your raw IP.

How we store your data

Storage depends on the data type, but the same rule applies everywhere: keep it private and limited to the right workspace.

  • Database: stored securely in a cloud database.
  • Images: stored in private cloud storage and shared only through temporary secure links.
  • Local storage: cached on your device so the app works offline.

Third-party services

A small set of providers supports sign-in, receipt reading, search, email delivery, and hosting.

  • Google Gemini: reads your expense images, and turns expense text such as merchant names, line items, and notes into search data. We send this data to Google only to provide those features. Google processes it under its own API terms.
  • Clerk: handles sign-in. See Clerk's Privacy Policy.
  • Resend: sends emails such as workspace invitations. See Resend's Privacy Policy.
  • Cloudflare: provides hosting, storage, and delivery infrastructure. See Cloudflare's Privacy Policy.

Data retention

How long we keep data depends on your account type and workspace settings.

  • Anonymous users: data is deleted after 30 days with no expenses, or 90 days with expenses.
  • Authenticated users: data stays until you delete it or close your account.
  • Workspace retention: admins can set a retention policy, such as 365 days. After that, expenses are soft-deleted automatically.
  • Soft-deleted expenses: removed for good after a 30-day grace period.

Your rights

Data controls live inside the product, so you can manage your information without filing a support ticket first.

  • Export: download your data as JSON from Settings.
  • Delete: remove your account and its data from Settings.
  • Access: review your data in the app at any time.

Contact

For privacy questions or data requests, email privacy@mariyangu.com.