Effective date: 2026-09-24. Mezgeb is operated by Madstar studios. Contact us about this policy or your information at support@madstarstudio.tech.
Information you enter and keep on your device
Mezgeb stores your expense and income records, account names, balances, categories, notes, dates, transfers, account groupings and balance adjustments on your device. If you add account numbers or other source identifiers to help match transactions, the app stores them locally and uses masked versions in relevant displays and structured backups.
You can use the local ledger without creating a Mezgeb cloud account. Recording a transfer in Mezgeb records movement between your ledger accounts; it does not instruct a bank or wallet to move money.
Google sign-in and your Mezgeb account
If you choose Google sign-in, Google and our authentication provider, Supabase, process the information needed to authenticate you. Your Mezgeb identity may include your email address, user identifier, display name and profile-photo URL. The app may request the profile image from its host to display it.
We use this identity for account access, optional cloud backup and recovery of an app lock linked to that account. Mezgeb requests basic email and profile access; the app does not ask you to enter your Google or bank password into it.
Optional bank-message features
On supported Android builds, you can enable bank-message capture after the app's disclosure and Android permission request. Setup can read sender addresses to help you choose senders. Ongoing capture processes messages from senders you link and stores transaction drafts and supporting message text locally for review. Android's SMS permission is broader than the linked-sender filter; platform callbacks can transiently deliver other messages before filtering.
Historical balance lookup has a separate choice and disclosure. It reads messages for confirmed senders within the preceding 90 days, up to 1,000 messages. The historical review does not save the original message bodies. Balances and ledger corrections are saved only after your confirmation.
Turning capture off stops further app capture but keeps existing drafts. You can also revoke Android SMS permission. The app's structured ZIP backup excludes raw SMS records, sender authorizations and full structured account identifiers. Information you put into notes, labels or receipt images is not automatically removed from those fields when you back them up or export them.
Receipts, photos and statement imports
Mezgeb processes selected images, pasted text and supported PDF statements to help you create records. The app's text-recognition and statement-parsing flows process their input on your device. Original PDF documents are not automatically uploaded by these flows. Receipt images you attach are copied into the app's local storage and can be included when you choose cloud backup. This applies unless you choose to read a document with Tsehafi (see below).
Mezgeb uses Google's ML Kit for image text recognition. Google documents collection of device/app information, installation identifiers and operational information such as performance, configuration, event and error information for diagnostics and usage analytics. Local image processing therefore does not mean that the SDK makes no network requests. See Google's ML Kit data disclosure.
Reading statements with Tsehafi
When you choose to read a statement with Tsehafi, the photo or PDF is sent through Mezgeb's server function to Google's Gemini API under paid terms that do not allow training on your data. Supabase hosts that function; it does not store the document. Nothing is stored after reading. It is off until you turn it on, and you can turn it off in Settings. When your account is deleted, your Tsehafi daily usage count is kept only as an anonymous total with no link to you.
Cloud backup and export
Cloud backup is manual. When you choose to back up, Mezgeb sends a ZIP containing your ledger and relevant settings, grouped-account information, masked source identifiers, balance checkpoints and attached receipts to Supabase Storage for your signed-in account. A subsequent upload replaces the current backup object. The app does not provide a cloud backup history browser.
App-lock settings and PIN hashes, raw SMS records, sender authorization and full structured source identifiers are excluded from this ZIP. Android OS backup and device-transfer rules in the current release exclude app data; copies made by older releases or exports you created separately may still exist.
Cloud requests use HTTPS. ZIP exports are not protected by a separate ZIP password, and the cloud-backup feature does not provide end-to-end encryption. Protect exported files and share them only with destinations you choose to trust.
When you export a CSV or ZIP, you choose the destination using your device's sharing facilities. The recipient or service then handles that copy under its own practices.
App lock and notifications
The optional app lock stores a salted PIN hash locally. Biometric authentication is handled by your device; Mezgeb receives the authentication result rather than your fingerprint or face template. Capture notifications use generic text, with financial details shown inside the app. App lock does not encrypt an exported ZIP.
Service providers and contact information
Supabase provides authentication and cloud-backup storage. Google provides sign-in, ML Kit and, when you opt in, Tsehafi statement reading through the Gemini API under paid terms. Network services receive connection information necessary to handle requests, such as IP addresses, and may maintain service/security logs.
This site is hosted on GitHub Pages. Support email is handled through a mailbox at the madstarstudio.tech domain, support@madstarstudio.tech. Madstar studios is based in Ethiopia; Mezgeb is built for Ethiopia and available worldwide, and your information may be processed by our service providers in the regions where they operate.
If you contact support, we receive your email address and the contents of your message to answer your question, verify a deletion request or resolve a problem. Please avoid sending passwords, PINs, one-time codes or full financial statements.
We do not sell your data and do not share it for advertising. The current app contains no advertising placement or app-owned advertising SDK.
Retention and deletion
Local records remain in the app until you remove or replace them or clear the app's data. Removing a receipt reference may leave an unreferenced local image until the app's next startup cleanup. Uninstalling or clearing app storage does not delete a cloud backup or a separate export.
Your Mezgeb cloud identity and current backup remain until account deletion is completed, or the backup is replaced. Signing out alone does not delete them.
Open Settings, tap Support, then Delete account to delete your Mezgeb cloud identity and backup, and clear all Mezgeb records on the phone, immediately. You can also request deletion of your Mezgeb account and associated cloud data by emailing support@madstarstudio.tech; we complete email requests within 30 days of confirming you own the account, with an email confirmation when it is done. See the Mezgeb account-deletion page for the full process.
Nothing is retained after deletion; infrastructure backups expire within 30 days after deletion.
Deleting the Mezgeb cloud identity removes its associated cloud backup through the deletion process. It does not delete your Google account. Copies on your devices and exports held by you or recipients require separate removal; a web request cannot remotely erase an offline device. A later sign-in can create a new Mezgeb identity and does not restore a deleted cloud backup.
Audience and changes
Mezgeb is intended for adults. It is built for Ethiopia and available worldwide.
We will update this policy when our data practices change and identify the effective date above. Contact support@madstarstudio.tech with privacy questions.