Privacy policy

Who operates Metaji

CFV Tech operates Metaji, a bookkeeping app for adults aged 18 and older. This policy explains how we handle information when you use the app, its supporting services and metajiapp.com. For privacy questions or requests, contact [email protected].

Your account

We process your email address, account identifier, display name and language preferences to create and manage your account. If you sign in with Google, we verify the sign-in information Google provides. Sign-in records can include your device name, session identifiers, request times, IP address and verification-code records. These help us authenticate you and prevent misuse.

Your books and backups

Metaji keeps a working copy of your books on your device. Records can include income and expenses, amounts, balances, dates, descriptions, people and organisations you enter, categories, projects, budgets and notes. Cloud backups send your application data to our server so it can be restored. Backups can also include photos you attach to entries. We keep a current backup and a previous version for recovery.

Backups are associated with your account and travel over an encrypted connection. They are not end-to-end encrypted. The AI service does not read the backup archive, but relevant information from your books is sent separately when you use AI features.

Conversations and AI processing

When you use Metaji's AI features, we process the text, photos or recordings you submit and relevant bookkeeping context. This can include recent conversation history, descriptions, names, categories, amounts and financial information needed to understand a request and answer it. Our server and AI service providers process this information to prepare entries, answer questions and generate conversation titles.

Metaji uses OpenRouter to route AI requests to model providers. The current service configuration includes DeepSeek for text capture, Google Gemini for media, Qwen for conversation titles, and OpenAI models for questions about your records and fallback processing. Requests use OpenRouter's data-collection-denied routing setting. This setting does not mean that no operational or security records are retained by us or our providers. Provider handling is governed by their applicable service terms and privacy practices.

We keep AI request and response records for service reliability, retry recovery, usage limits, troubleshooting and cost accounting. These records can contain your submitted text, extracted information, financial amounts, generated replies and entry proposals, along with model and request metadata. Media is processed for the request; photos attached to entries may separately be retained in cloud backups.

Optional SMS and voice features

On supported Android devices, you can enable SMS access to help record payment transactions. The feature processes payment-message information such as transaction amount, date, merchant, sender information and direction. Incoming payment messages may create entries automatically; check those entries and complete any missing details. Financial information derived from messages can become part of your books and backups. When you review and submit a message, the saved record can also include its sender, received time and a source identifier in your cloud backup. The reviewed payment text and any notes you add are sent through the AI capture flow described above. Automatic payment posting does not send the original SMS body to AI; information from saved entries may later be included when you ask about your books. You can turn SMS access off and use manual entry instead.

Microphone access is used when you choose voice input. Speech recognition may run on your device or use the operating system's speech service, depending on your device and language. Submitted recordings or transcripts may also be processed by Metaji's AI providers. Camera or photo access is used when you choose to add a receipt or other image. You can manage these permissions in your device settings.

Service providers and other disclosures

We use Railway to host application services and the database, OpenRouter and its model providers for AI processing, Resend for account emails, Cloudflare for the website and email routing, and Google services where you choose Google sign-in or use Android speech recognition. These services may process data outside your country.

We also process messages and information you send to support. Hosting and security services may process technical information such as IP addresses, request times, errors and device or browser details to deliver and protect the service. Metaji does not display advertising or sell your personal data. We may disclose information when required by law or necessary to investigate abuse and protect the service.

Retention and deletion

We keep your account information and current and previous application backups while your account is active, unless you ask us to delete them. AI request and response records are eligible for cleanup after 90 days. Verification-code records are eligible after 24 hours; a code expires sooner and cannot be used simply because its record remains. These cleanup jobs run when the service starts, so eligible records can remain longer until cleanup runs.

Deleting your account removes its profile and sign-in contacts, signed-in device sessions, current and previous application backups, associated AI records, verification-code records and referral links from the active service database. Requests that are already being processed by an external provider may finish there. Deletion prevents their results from being saved back to your deleted account.

We retain a minimal deletion record indefinitely: your internal account identifier and deletion timestamp. It allows retries and other devices to recognise deletion and prevents deleted account data from being restored. It does not include your email address, books, photos or conversations.

Account deletion cannot immediately erase copies on an offline device, exports you keep elsewhere, or records held separately by service providers. The app removes data it can identify as belonging to the deleted account when it processes deletion. Older cached media whose owner cannot be identified safely may remain on a device. Support correspondence and operational security records are retained separately for handling requests, preventing abuse and meeting applicable obligations. Service-provider records follow the provider’s applicable retention practices; we do not promise immediate erasure from every provider system.

For instructions and an independent email request route, see Delete your Metaji account. Signing out or uninstalling the app does not delete the server account.

Your choices

You can manage optional app permissions through your device settings and contact [email protected] to request access, correction or deletion of your information. We may need to verify that you own the account before acting. Export any records you need to keep before requesting deletion. Your available privacy rights depend on the laws that apply to you.

Children and policy changes

Metaji is intended for adults aged 18 and older, and is not directed to children. Contact [email protected] if you believe a child has provided us with personal information. We will update this policy when our practices change and display the revised date on the published page.