The short version: it's yours.
miya.life holds your cycle, your money, your journal, your grades and your documents. Here is exactly what happens to all of it, in plain language.
No ads. No trackers. No data sold, ever, not to advertisers, not to brokers, not to model trainers.
What is collected
- Your account: a username, an email address, and a hashed password. Nothing else is required.
- What you put in: the records you create in each system. They are stored against your account and isolated from every other account.
- Files you upload: stored in an access-denied directory and streamed only through an authenticated endpoint, there is no public URL anyone could guess.
- Operational logs: ordinary web server logs, plus a change log of saves on your own account (what changed and when) so you can audit your own history.
What is not collected
- No third-party analytics, no advertising pixels, no session recording, no fingerprinting.
- No bank credentials. Finance imports read an OFX or CSV file you download yourself, your bank login never touches miya.life.
- No location tracking. Weather, world clocks and the map use only the places you name or save yourself.
- No voice recordings. Speech recognition and speech output run in your browser's own engines, on your device's side of the connection. What reaches miya.life is the text of what you asked, the same as if you'd typed it. Nothing listens until you tap the mic, and ending the conversation ends it.
Sensitive systems
Vault, the emergency card, cycle data and anything you mark yourself are flagged sensitive: masked in the interface until you deliberately reveal them, excluded from every shared group, and never surfaced in digests or notifications.
Family sharing
Sharing is off until you turn it on, per person and per group. A grant covers exactly the group named, one of sixteen, and nothing else. Revoking is immediate. Attachments are excluded from shares by design.
The AI assistant
When you ask the assistant something, typed or spoken, the relevant slice of your data for that system is sent to the model provider to produce the answer, and the answer comes back to you. It is not used to train models, and nothing is sent unless you press the button or ask the question.
Billing
Payments are processed by Stripe. Your card number goes to Stripe and only to Stripe; miya.life keeps your plan and its renewal date, nothing more. The billing portal you manage everything in is Stripe's own.
Your data, leaving
Deleting your account. Settings, Account, Delete my account removes the whole account on your own say-so: every record, every file, the login and the plan, after your password and the word DELETE. A confirmation letter goes to your address first, and then nothing of yours remains on the server.
- Export everything, whenever you want, from Settings. The export is the guarantee.
- A full backup is emailed to you automatically once a week.
- Delete your account and the records go with it.
Security posture, honestly stated
Everything runs over HTTPS. Accounts are isolated at the database level; every read and write is checked against the logged-in user, and shared reads are checked against the specific grant. Writes are rate-limited. Passwords are hashed, never stored in readable form.
Where it is kept, and for how long
- Where: on managed hosting in the United States. Your records live in the site database against your user id; your files sit outside the public web root.
- In transit: every request runs over HTTPS. The app refuses to load over a plain connection.
- How long: for as long as your account exists. Records you delete are recoverable by you for a short window through undo and the change log, and are then gone.
- After you leave: deleting your account deletes your records, your files and your history. Backups roll off on their own cycle, so a copy may persist in a backup for a short period before it is overwritten.
The services this depends on
Almost nothing leaves the system, and where something must, it is named here.
- Hosting: the servers that run the site and hold the database.
- Email: confirmation, password resets and any digest you switch on.
- Calls: when a voice or video call cannot connect directly between two devices, a relay carries the encrypted stream. The relay passes traffic through, it does not record calls, and calls are never stored.
- The assistant: covered in its own section above. When you use your own key, your question goes to the provider you chose, not through us.
- Payments: handled by the payment processor. Card numbers never reach this system.
There is no analytics service, no advertising network, no session recorder and no third-party font or script loading in the app.
Cookies
Only what signing in requires: a session cookie so the app knows it is you, and a preference or two remembered on your own device. No advertising cookies, no cross-site tracking, and nothing shared with anyone.
What you can ask for, and how
- See it: everything you have put in is visible to you inside the app, by definition.
- Take it: export hands you ordinary files, any time, without asking permission.
- Correct it: every record is editable by you.
- Delete it: individual records from their own screens, or the whole account from Settings, which removes it and everything in it.
If you are covered by the GDPR, the UK GDPR, or a state privacy law such as the CCPA, those rights are yours and the routes above are how they are exercised. Ask by email if you would rather have a person do it.
Children
Accounts are for adults. The system is not directed at children under 13 and is not designed for them to hold accounts of their own. A parent may of course record a child's appointments, school dates or medications inside their own account, which is ordinary family organisation.
If something goes wrong
If your data is ever exposed, you will be told what happened, what was involved and what to do, without spin and without delay while a story is prepared.
Changes to this policy
If this policy changes in a way that affects what happens to your data, the change is announced in the app rather than quietly published. The date below tells you when it was last revised.
Questions
Email support@miya.life. A person answers.
Last updated August 2026.
The finance app, in full
money.miya.life is a separate application, a product of miya.life operated by Bespoke Business Development. Effective 16 August 2026. It holds financial information, so it gets its own account of what happens to that information, in full, rather than a line in somebody else's policy.
Your data exists only to show you your own finances. We never sell it, never share it for advertising, never store your bank username or password, cannot move your money, and you can erase everything yourself, in the app, at any time.
Jump to: What is collected · Your bank · How it is used · Who receives it · Protection · Retention and deletion · Your rights · Cookies · Where it is processed · Children · Changes · Contact
1. What is collected, and where it comes from
| Category | Examples | Source |
|---|---|---|
| Identifiers | Name, email address, login | You, when you create your miya.life account |
| What you enter | Incomes, expenses, debts, budgets, goals, assets, notes, tags, an optional self reported credit score | You, typed into the app |
| Imported statements | Whatever is inside an OFX or CSV file you choose to import | You, from a file you downloaded from your own bank |
| Documents | Statements, receipts and other files you upload | You |
| Technical data | Login session cookies; standard web server logs, meaning IP address and request time | Automatic, required to run any website |
Deliberately not collected: your bank username and password, which we have no way to receive because no bank connection exists; precise location; contacts; advertising identifiers; anything bought from a data broker. We do not track you across other sites and we serve no advertising.
2. Your bank, and why we never touch it
miya.life has no connection to any bank. Bank linking is an optional paid add-on, off unless you switch it on: it uses Plaid, and Plaid holds the credentials, never this site. What this site stores is an access token, encrypted, on the server; it is used to read transactions and balances and nothing else, it can never move money, and unlinking deletes it here and at Plaid the same day. With the add-on off there is no bank linking, no stored token, and no technical route to your accounts.
- Nothing is fetched on your behalf. Figures are there because you typed them, or imported a file you downloaded yourself from your own bank, in your own browser.
- No credentials exist to lose. We never had your bank username or password, and now there is not even a third party holding one on our behalf.
- OFX and CSV imports become ordinary records you own, edit and delete like anything else.
- We cannot move money. True before by policy, true now by construction: no path to an account exists at all.
3. How your data is used
| Purpose | What that means concretely |
|---|---|
| Running the app for you | Categorising transactions, and computing budgets, cash flow, the calendar, payoff plans, subscriptions, alerts, reports and net worth |
| The optional AI advisor | If you use it, we send aggregated category totals and your first name. Individual transactions, account numbers, balance history and documents are never sent, and the app shows you the exact summary before it goes |
| Security and abuse prevention | Authenticating you, protecting accounts, investigating incidents |
| Legal compliance | Honouring privacy requests and legal obligations |
That is the whole list: no profiling for third parties, no marketing lists, no training models on your data, and no purposes hidden behind vague words like "improving our services".
4. Who receives data
| Recipient | Why | What they get |
|---|---|---|
| Our hosting provider | Running the application, database and backups | Stores our database and files; the financial payloads and bank tokens inside are encrypted |
| Anthropic | The optional AI advisor | Aggregated category totals and a first name, only when you use it |
No one else. We do not sell personal information and have not in the preceding twelve months, we do not share it for cross-context behavioural advertising, and we go beyond this table only where the law compels it, disclosing the minimum required.
5. How your data is protected
- Traffic is encrypted in transit with TLS 1.2 or better.
- Financial records and bank tokens are encrypted at rest with AES-256, so a copy of the database is not a copy of your finances.
- Uploaded documents sit behind your login, are never publicly reachable, and download only through an authenticated request.
- Every request is checked server side, so an account can only ever reach its own data.
- Administrative access requires multi-factor authentication.
We work to a written information security policy and an incident response plan. If a breach ever affects your data we will tell you promptly and plainly, within 72 hours of confirming it.
6. How long data is kept, and how deletion works
Your data stays while your account is active, and you hold the delete button.
| What | How | When it is gone |
|---|---|---|
| One record or document | Delete it in the app | Its content is discarded at once; documents leave storage that moment |
| Everything | Settings, then Delete everything, with a typed confirmation | Records, documents and advisor usage are erased, immediately and irreversibly |
| By email | Write to security@miya.life | Completed within 30 days, with confirmation |
| An account nobody opens | Nothing, it happens on its own | An unpaid account that has not been opened for three months is written to three times over five weeks, then closed and its files deleted. Opening it once stops the process |
Deleted data also ages out of routine disaster-recovery backups within about thirty days, and the markers left behind by a deletion are purged after ninety. Session cookies expire with your session, server logs rotate after 90 days, and privacy-request correspondence is kept 24 months as evidence of compliance, then deleted.
7. Your rights
Wherever you live, you get access (everything the app holds is shown in the app), portability (CSV export is built in), correction (every record is editable) and deletion (self service, above). In California and other states with a consumer privacy law, those same mechanisms are how we honour your statutory rights to know, access, correct and delete, and to opt out of sale or sharing. Since we do not sell or share personal information for advertising, there is nothing to opt out of, and we do not use or disclose sensitive personal information beyond what this policy describes. We will never treat you differently for exercising a right.
For anything you cannot reach in the app, email security@miya.life. We verify through your registered email address, or by in-app confirmation if there is any doubt. An authorised agent may act for you with your written permission. We answer within 30 days; if a request is unusually complex we may take up to 15 more, and will tell you first.
8. Cookies and tracking
| Cookie | Purpose | Lifetime |
|---|---|---|
| Login session | Keeping you signed in securely; strictly necessary | Your session |
| Theme preference | Remembering light or dark on that device | Until you clear it |
That is all of them. No analytics, no advertising cookies, no fingerprinting, no cross-site tracking. Because we track nothing, browser signals such as Do Not Track and Global Privacy Control are already satisfied by default.
9. Where data is processed
Our systems are hosted in the United States and your data is processed there. Using the app from elsewhere means sending your data to the United States under this policy.
10. Children
Miya Money is not directed to anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us data, email us and we will delete it.
11. Changes to this policy
If this policy changes materially we will post the new version here with a new effective date, and note the change in the app before it takes effect. The date at the top of this section always tells you which version you are reading.
12. Contact
Lewis De La Paz, Owner
Miya Money, a product of miya.life
security@miya.life
Looking for the policy covering the main app rather than Money? It is above.