Product draft updated: August 22, 2026 · Counsel review required before public launch
This beta privacy policy explains how Mizan handles financial data for the MVP. It is written for clarity before scale and should be reviewed by counsel before a larger public launch.
Mizan stores the account, transaction, bill, goal, asset, profile, product interaction, notification, and settings data you enter or sync into the app. If receipt scanning is enabled, receipt images are sent for extraction and the extracted fields are saved only when you choose to save them.
Your data powers budgeting, ledger views, goals, product matching, Mizan Score explanations, notifications, and AI-assisted tips. Mizan Score is an educational trust-readiness signal, not a regulated credit score.
Financial records are private by default. A shared profile is visible only under the privacy setting you choose. Published reviews show the name and image attached to the review.
Android SMS import is disabled in production builds unless explicitly enabled for an internal or approved build. Mizan does not need SMS inbox access for the core web MVP. Receipt scanning requires an AI provider key and may be unavailable in environments where that key is not configured.
You can export your app data from Settings. Account deletion is available at /account/delete. Confirmed deletion locks the account immediately and schedules final purge after the configured retention hold.
Mizan uses the following services to operate the web app and provide optional features. Availability depends on the deployment configuration and the choices you make in the app.
Purpose: Authentication and hosted PostgreSQL database services.
Data: Account credentials, user profile data, financial records, settings, and other data you store in Mizan.
When: Core service for registered accounts.
Purpose: Web hosting and product analytics.
Data: Technical request data and analytics events such as page views and product interactions.
When: Hosting is required for the deployed web app; analytics follows the deployment configuration.
Purpose: Error and performance diagnostics.
Data: Sanitized technical error and performance events. Default personal-identifying data collection is disabled in the current configuration.
When: Only when a Sentry DSN is configured.
Purpose: Optional AI-assisted tips, budget forecasts, and receipt extraction.
Data: Coarse financial status context for tips and forecasts; a receipt image and extraction instructions when you explicitly scan a receipt. Exact account names, balances, and transaction identifiers are not sent by the guarded tip and forecast routes.
When: Only when AI is enabled and the required consent and provider configuration checks pass; receipt extraction also requires your explicit scan action.
Purpose: Support email and optional reminder email delivery.
Data: Support messages, contact details, reminder titles and subtitles, and links needed to deliver the email.
When: Only when email delivery is configured and you submit support or enable email reminders.
Purpose: Optional mobile push reminder delivery.
Data: Your Expo push token, notification title, subtitle, and in-app destination.
When: Only when push reminders are enabled and a push token is registered.
Purpose: Optional currency-rate snapshots for multi-currency views.
Data: The base currency code ETB; no account or user identifier is included in the rate request.
When: Only when the scheduled or explicit FX refresh runs.
Purpose: Optional product analytics event capture.
Data: Product event names and the limited event properties supplied by the browser analytics wrapper.
When: Only if a PostHog client is supplied by the deployment; Mizan does not load one from the web bundle itself.