Privacy Policy
Last updated: 2026-05-10
1. Who we are
Mafia is operated by Premmisus Inc., incorporated in Canada. Mafia is an internal personal-finance and business-operations dashboard for the company’s founder. Access is allowlisted to a single email address — there is no public sign-up. This policy explains what data we collect, how we store it, and how the founder can control it.
2. Data we collect
We collect the minimum data needed to operate Mafia:
- Account identity: email, Google or GitHub OAuth profile, IP address at sign-in.
- Financial data via Plaid Inc. (see Section 4): bank-account names, balances, transactions, account holder names. Read-only.
- Payment data via Stripe Inc.: invoice status, customer IDs (we never see card numbers).
- Operational data you enter directly: receivables, debts, subscriptions, notes, daily reflections.
- Communication data via Telegram Bot API and Twilio: messages you send to / receive from Mafia.
3. How we use the data
- Show you your own financial state (balances, debts, cash flow).
- Generate AI assistant responses (Claude Anthropic API, Gemini API) about your data on your request.
- Send you scheduled briefings and operational alerts.
- Reconcile invoices against bank-side payments.
We never sell, rent, or share your data with advertisers, marketing platforms, or data brokers.
4. Plaid integration
Mafia uses Plaid Inc. (“Plaid”) to connect to your financial institutions. By using the bank-link feature, you authorize Plaid to access your account data on Mafia’s behalf. The data Mafia receives from Plaid is limited to the products we’ve enabled: Auth, Balance, and Transactions— all read-only. Mafia does not have any payment-initiation, transfer, or account-modification capability.
Plaid’s own privacy practices are governed by Plaid’s End User Privacy Policy. You can revoke Mafia’s Plaid access at any time from your bank’s authorization page or by contacting us at elliott@premmisus.com; on revocation we delete the linked-institution record and all derived account data.
5. How we store and secure data
- Bank-access tokens are encrypted at rest with AES-256-GCM before they touch our database. Each token has its own initialization vector and authentication tag; the encryption key is held only in environment configuration, never in code.
- Database is Postgres on Neon, accessed over TLS, scoped per user via row-level filters on every query.
- Hosting is Vercel; all traffic is HTTPS via TLS 1.2+.
- Authentication is allowlisted by email; only pre-authorized users can sign in.
- Audit log records every consequential action (financial reconciliation, bank linking, receivable updates).
- Kill Switch: a single bearer-protected endpoint (
/api/banker/killswitch) revokes all real-money and speak-on-behalf paths instantly.
6. Retention
Operational data is retained until you request deletion. Financial data pulled from Plaid is retained for as long as the link is active; deleted within 30 days of revocation. Audit log entries are retained for 7 years to satisfy financial-record obligations.
7. Your rights
You can request access to, correction of, or deletion of your data by emailing elliott@premmisus.com. Requests are honored within 30 days. If you are in the EU, EEA, UK, or California, you have additional rights under GDPR / UK GDPR / CCPA — including the right to data portability and the right to lodge a complaint with your data protection authority.
8. Children
Mafia is not directed to children under 16 and we do not knowingly collect data from them.
9. Changes
We will update this policy as needed; material changes will be announced in-product. The “Last updated” date at the top of this page tracks revisions.
10. Contact
Questions, requests, or complaints: elliott@premmisus.com.
Premmisus Inc.
Toronto, Ontario, Canada