MyCG.AI

Privacy Policy

Last updated: August 30, 2026

The short version: your business data belongs to you. We use it only to run your workspace, we never sell it, and you can export or delete it whenever you choose. This policy explains exactly what we collect, why, and the rights you have, whether you are a customer of our US company or our India company.

1. Who we are

MyCG.AI (the website at mycg.ai and the application at app.mycg.ai, together the Service) is operated by two affiliated companies:

In this policy, we, us, and our refer to both companies. You can reach either of them at team@mycg.ai.

2. What we collect

We do not collect data from your device beyond what the Service needs, and the marketing website sets no advertising trackers.

3. How we use your data

We do not sell your data. We do not share it with advertisers. We do not use your business records for marketing.

4. Bank connections and Plaid

When you connect a bank account through Plaid Inc., you provide your credentials directly to Plaid inside Plaid Link. We never see or store your banking username or password. Plaid gives us read-only access to account details and transactions, which we use only to keep your books current.

Plaid's handling of your data is described in the Plaid End User Privacy Policy at plaid.com/legal. Disconnecting a bank inside the Service revokes the connection with Plaid immediately.

Connections to Mercury and Wise work through tokens you paste in yourself. Those tokens are sealed with an additional AES-256-GCM encryption layer before they are stored.

5. Where your data lives

Your data is stored with Supabase (database and encrypted file storage, hosted on AWS) and served through Vercel. Both are SOC 2 audited infrastructure providers.

All traffic is encrypted in transit with TLS. Data is encrypted at rest. Documents live in private buckets and are served through short-lived signed links.

Access inside MyCG.AI is scoped per workspace with database row-level security: only members of your workspace, and the MyCG.AI staff who serve your requests, can see your data.

6. Payments

If you pay for a plan, card processing is handled by Stripe. Your card number never touches our servers. Stripe's privacy policy applies to the payment details you give them.

7. When we share data

We share personal data only with the processors that make the Service work, and only what each one needs:

If you engage professional services through the Service (for example a tax filing), the qualified professionals working on your request see the records needed to complete it.

We disclose data if the law genuinely requires it, and we will tell you when we are allowed to. If our companies are ever part of a merger or acquisition, this policy continues to apply to your data.

8. How long we keep it

Your records stay in your workspace for as long as your account is active, because the product's job is to hold your books.

When you delete your account, we complete deletion within 30 days, except records we must keep longer for legal, tax, or accounting obligations, which are kept only as long as those obligations require and then deleted.

Server logs are kept for a short rolling window for security and then discarded.

9. Security

TLS on every connection, AES-256 at rest, an extra AES-256-GCM layer on bank tokens, row-level workspace isolation, passwordless sign-in with single-use email links, and two-factor authentication on all staff infrastructure accounts.

If a breach ever affects your personal data, we will notify you within 72 hours of confirming it, with what we know and what we are doing.

10. Your rights

Wherever you live, you can access, export, correct, and delete your data:

If you are in the United States, you may have additional rights under your state's privacy law, including the right to know what we hold and the right to non-discrimination for exercising your rights. We honor these requests regardless of state.

If you are in India, the Digital Personal Data Protection Act, 2023 gives you rights to access, correction, erasure, grievance redressal, and nomination. The India entity is the data fiduciary, and its grievance officer can be reached at team@mycg.ai. We respond to grievances within the timelines the law sets.

If you are in a region with other data protection laws (for example the EEA or UK), we honor access, portability, rectification, erasure, restriction, and objection requests, and you may lodge a complaint with your local supervisory authority.

11. International transfers

The Service is hosted in the United States. If you use it from outside the United States, your data is transferred to and processed in the United States by the providers listed above, under contracts that require them to protect it. Both of our companies apply this same policy wherever the data is processed.

12. Cookies and local storage

The application uses cookies only to keep you signed in and to remember your active company. Your browser's local storage remembers preferences like your theme. The marketing website sets no advertising or analytics trackers.

13. Children

The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, email team@mycg.ai and we will delete it.

14. Changes to this policy

If this policy changes materially, we will email account holders before the change takes effect and note the new date at the top of this page.

15. Contact

Privacy questions, requests, and grievances: team@mycg.ai. Please include the email address on your account so we can verify you.