Last updated: August 30, 2026
The short version: your business data belongs to you. We use it only to run your workspace, we never sell it, and you can export or delete it whenever you choose. This policy explains exactly what we collect, why, and the rights you have, whether you are a customer of our US company or our India company.
MyCG.AI (the website at mycg.ai and the application at app.mycg.ai, together the Service) is operated by two affiliated companies:
In this policy, we, us, and our refer to both companies. You can reach either of them at team@mycg.ai.
We do not collect data from your device beyond what the Service needs, and the marketing website sets no advertising trackers.
We do not sell your data. We do not share it with advertisers. We do not use your business records for marketing.
When you connect a bank account through Plaid Inc., you provide your credentials directly to Plaid inside Plaid Link. We never see or store your banking username or password. Plaid gives us read-only access to account details and transactions, which we use only to keep your books current.
Plaid's handling of your data is described in the Plaid End User Privacy Policy at plaid.com/legal. Disconnecting a bank inside the Service revokes the connection with Plaid immediately.
Connections to Mercury and Wise work through tokens you paste in yourself. Those tokens are sealed with an additional AES-256-GCM encryption layer before they are stored.
Your data is stored with Supabase (database and encrypted file storage, hosted on AWS) and served through Vercel. Both are SOC 2 audited infrastructure providers.
All traffic is encrypted in transit with TLS. Data is encrypted at rest. Documents live in private buckets and are served through short-lived signed links.
Access inside MyCG.AI is scoped per workspace with database row-level security: only members of your workspace, and the MyCG.AI staff who serve your requests, can see your data.
If you pay for a plan, card processing is handled by Stripe. Your card number never touches our servers. Stripe's privacy policy applies to the payment details you give them.
Your records stay in your workspace for as long as your account is active, because the product's job is to hold your books.
When you delete your account, we complete deletion within 30 days, except records we must keep longer for legal, tax, or accounting obligations, which are kept only as long as those obligations require and then deleted.
Server logs are kept for a short rolling window for security and then discarded.
TLS on every connection, AES-256 at rest, an extra AES-256-GCM layer on bank tokens, row-level workspace isolation, passwordless sign-in with single-use email links, and two-factor authentication on all staff infrastructure accounts.
If a breach ever affects your personal data, we will notify you within 72 hours of confirming it, with what we know and what we are doing.
Wherever you live, you can access, export, correct, and delete your data:
If you are in the United States, you may have additional rights under your state's privacy law, including the right to know what we hold and the right to non-discrimination for exercising your rights. We honor these requests regardless of state.
If you are in India, the Digital Personal Data Protection Act, 2023 gives you rights to access, correction, erasure, grievance redressal, and nomination. The India entity is the data fiduciary, and its grievance officer can be reached at team@mycg.ai. We respond to grievances within the timelines the law sets.
If you are in a region with other data protection laws (for example the EEA or UK), we honor access, portability, rectification, erasure, restriction, and objection requests, and you may lodge a complaint with your local supervisory authority.
The Service is hosted in the United States. If you use it from outside the United States, your data is transferred to and processed in the United States by the providers listed above, under contracts that require them to protect it. Both of our companies apply this same policy wherever the data is processed.
The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, email team@mycg.ai and we will delete it.
If this policy changes materially, we will email account holders before the change takes effect and note the new date at the top of this page.
Privacy questions, requests, and grievances: team@mycg.ai. Please include the email address on your account so we can verify you.