Privacy policy
Last updated: 19 September 2026
Introduction
Dashboard X is a personal-finance app for Android made by Mugu Labs ("Mugu Labs", "we", "us", "our"). This policy explains what data the app collects, why, where it is kept, and what you can do about it. It is written from what the app actually does — if something here is unclear, ask us at support@mugu-labs.com.
If you are in the UK or the EU, Mugu Labs is the data controller for the personal data described here.
1. What we collect
Your account
- Your email address and a password (stored only as a hash, never in plain text), or — if you choose Sign in with Google — the name, email address and profile photo that Google shares with us. We never see your Google password.
- The name you enter on your profile (optional) and a profile photo if you add one.
- Your device's timezone (for example "Africa/Nairobi"), stored once so that the dates on your transactions are your local calendar dates. It is not a location.
The financial data you enter
Dashboard X is built around data you type in or import yourself: accounts and their opening balances, transactions (amount, date, category, description and notes), transfers between accounts, categories, budgets, scheduled and recurring transactions, and the rows of any bank-statement CSV you choose to import. We do not connect to your bank and we never pull transactions automatically.
When you contact us
- Support requests sent from the app's Help Center: the email address you give, your message, and any screenshots you choose to attach from your gallery.
- Feedback sent from "Share feedback": your rating and any comment, together with the app version and build number, the Android version, your locale, the screen you were on, and two coarse buckets — how long you have had the account (under 7 days, 7–30, 30–90, over 90) and roughly how many transactions you have (under 10, 10–100, over 100). This helps us understand feedback in context.
- If you delete your account, an anonymous reason (a short code and an optional comment). It is not linked to you or your account.
What we do not collect
The app asks for no permission other than internet access. It does not use your camera or photo library except through the Android picker when you choose a photo. It does not read your contacts, your location, your files or your other apps. It uses no advertising identifiers, no analytics or crash-reporting SDKs, and no cookies. Nothing tracks you across apps or websites.
2. Why we use it
- To run the app — sign you in, keep your data in sync between your devices, and show you your balances, budgets and analytics.
- To keep it working — the app and Android version attached to feedback tell us where a problem happens.
- To answer you when you write to support or send feedback.
- To improve Dashboard X using what people tell us.
We show no advertising. We do not sell your data, share it for marketing, build profiles from it, or use your financial data for anything other than showing it back to you.
3. Where it is stored and who processes it
Your data is stored in a database hosted by Supabase in the European Union (Frankfurt), which also handles sign-in and stores profile photos and support screenshots. A few other companies process data on our behalf, only as far as needed to run the service:
| Processor | What for |
|---|---|
| Supabase | Hosting, database, authentication, file storage (EU region) |
| Resend | Sending the emails the app needs: verification codes and password-reset links |
| Only if you choose Sign in with Google — Google acts as your identity provider | |
| Google Play | Distributing the app; Play's own privacy policy applies to the store |
These providers may not use your data for their own purposes. We do not otherwise share personal data with anyone, unless the law requires it or it is needed to protect the service from abuse.
4. How long we keep it
- While your account exists, we keep what you have entered so the app can show it to you.
- Transactions you delete in the app are kept for 30 days so they can be undone, then permanently removed. Imported statements you roll back follow the same 30-day rule.
- Deleting your account (Settings → Delete account) removes your profile, your financial data, your photos and your support attachments immediately and permanently. We keep only the email address of the deleted account on a block-list for 30 days, used for one thing: stopping that address from being signed up again by accident. After 30 days it is purged too.
- Support and feedback records are kept while they are useful for resolving the request and improving the app, then deleted.
5. Your rights
Wherever you are, you can:
- See and correct your data — it is all in the app, and your profile is editable.
- Export it — Transactions → Export writes your transactions to a CSV file you can keep or move elsewhere.
- Delete it — Settings → Delete account, or email us and we will do it for you.
- Object to a use of your data, or ask us anything about it: support@mugu-labs.com. We aim to reply within a few days, and at the latest within 30 days where the law requires it.
If you are in the UK or the EU you also have the right to complain to your data-protection authority. We would rather hear from you first.
6. Security
Everything the app sends travels over HTTPS (TLS). In the database, access rules ensure each account can only reach its own rows — no other Dashboard X user can see your data, and we do not look at it except to answer a support request you have made. Passwords are hashed. No system is perfectly secure, and we cannot promise that yours will never be breached; if it were, we would tell you.
7. Children
Dashboard X is for adults: you must be 18 or older to use it, and we do not knowingly collect data from anyone younger. If you believe someone under 18 has created an account, email us and we will delete it.
8. Changes to this policy
If we change how the app handles your data, we will update this page and the "Last updated" date above. For material changes we will also tell you in the app before they take effect.
9. Contact
Mugu Labs — support@mugu-labs.com