Privacy
Last updated: 6 September 2026
The short version, if you read nothing else. Mayora stores what you type into it: what you spent, on what, what you earn, what you're saving. It stores that in Europe. It doesn't track you, carries no advertising, and sells nothing to anyone. Bank statements are read on your own device and never uploaded. And you can delete your entire account from inside the app, without asking anyone.
Who is responsible
Mayora is built and run by Filipe Martins, as an individual. For anything about your data, including access or deletion requests: [email protected].
What is stored
| What | Why |
|---|---|
| Email and password | To sign you in. The password is stored hashed and is never readable, including by me. |
| Your name, if you enter one | So others in your group know who did what. Optional. |
| Movements, bills, income, goals and budgets | They are the product. Amounts, dates, categories and any notes you write. |
| The group you belong to | To share the budget with the other people in it. |
| Receipt photos | Only if you attach one. They are shrunk on your own device before being stored, and kept in private storage reachable only by your group. |
| Notification subscription | Only if you turn them on. A device identifier, so the reminder can reach you. |
What is not stored
- Your bank statement file. When you import a PDF or a spreadsheet, the file is opened and read inside your own device. It is never sent to any server. Only the movements you confirm get saved - and nothing is saved before you press confirm.
- No usage analytics and no tracking. I don't know which screens you open, how long you stay, or where you came from.
- No advertising and no third parties watching. The app loads no trackers.
- Nothing is sold, rented or shared with anyone for commercial purposes.
Error logs
The app can send technical logs when something fails - the error message, the screen it happened on, and the browser build. These are off for everyone except my own developer account, which is how I test the app. If that ever changes, this page changes first.
Who else sees your data
The people in your group. That is the point of the app: whoever shares a group with you sees that group's movements, bills and goals. Leave the group and you stop seeing its data - and it stops being yours.
Beyond that, data passes through three services and no others:
| Service | For what | Where |
|---|---|---|
| Supabase | Database and authentication | Ireland (EU) |
| Cloudflare | Serving the app and receiving support email | Global network |
| Apple / Google | Delivering notifications to your phone, if you enable them | Per the vendor |
For how long
Your financial data stays as long as you want it to - it is a history, and deleting it for you would be ruining it. The rest has a deadline:
- Notifications you've read: deleted after 90 days.
- Resolved support requests: deleted after 30 days.
- Error logs: deleted after 7 days.
Deleting everything
In the app: Settings › Delete the account. Before you confirm, the screen tells you what happens to each group you are in:
- If you are alone in it, the group is deleted with you - movements, bills, income, goals and receipts.
- If it is shared, you leave and its data stays with the people still there. It stops recording that any of it was yours.
It is immediate and does not go through me. If you'd rather ask by email, you can.
Your rights
The GDPR gives you the right to access, correct, delete and take your data with you. Access and correction happen in the app; so does deletion. For a copy of your data, write to [email protected] and I'll send it.
If you believe your data is not being handled properly, you can complain to your national data protection authority - in Portugal, the CNPD.
Children
Mayora is not intended for children under 13 and does not knowingly collect their data. A group can list dependants, but those are just a name typed by an adult to organise expenses - they have no account and no access.
Changes
If this policy changes, the date at the top changes with it. If a change is material - for instance, if collection starts that doesn't exist today - I'll say so inside the app before it takes effect.