Privacy
We never require a bank login. We don't sell your data. We don't train shared AI models on your receipts. Privacy isn't a setting at Marvin — it's the design.
Last updated: September 15, 2026
What changed
September 15, 2026 — New “Device security checks” note under Analytics describing the check the Android and iOS apps run when they open, what it reads on the phone, and what leaves it. This check has been part of the mobile apps since their first release; we should have listed it sooner. The matching “Mobile app security” partner category was added to the Trust Center. Nothing else changed. Previous version (September 14, 2026)
September 14, 2026 — New “Analytics” section naming the sign-in, usage and AI-usage records we keep and for how long. Corrected that a message which trips our abuse filter is kept in the security record. “We don’t profile you” reworded to say we keep basic analytics to improve the app and spot abuse. Previous version (August 1, 2026)
Four pledges
You upload what you want to share. You delete what you want to remove. You export everything as CSV and JSON anytime, on any plan, including Free.
Marvin never sees or stores your online-banking username or password, and we never screen-scrape. The core app needs no bank login at all. The optional bank connection (Pro+, US & Canada) signs you in through our secure bank-connection provider — those credentials go to the provider and your bank, never to Marvin. You feed Marvin what you choose: receipts, statements, manual entries.
Every receipt, statement, and entry is encrypted on disk with industry-standard AES-256. Personal fields like your name and email get an extra layer of encryption on top.
We don't sell your data to advertisers. We don't share it with brokers. And your receipts never become training data for AI models that other people use. Marvin's intelligence is built on public data, not yours.
What we never do
How your data moves
Encrypted in transit. Encrypted at rest. Never resold.
The details
To run the app for you, we need to hold a few things: your email, name, country, currency, and the entries you create or upload — receipts, statements, manual transactions, recurring bills, your salary settings. That's the working set Marvin needs to draw your timeline, calculate your forecast, and answer your questions honestly. None of it is sold, shared, or used to train shared AI models. Your numbers stay your numbers.
We don't ask for your address, phone is optional, and we never request government IDs.
To run the app for you: rendering your timeline, generating Marvin's insights, calculating forecasts, and sending you the password-reset email if you ask for one. We also keep basic analytics on how the app is used, described below, to improve it and to spot abuse. Nothing is sold, and nothing about how you use Marvin is used to advertise to you.
Alongside your entries we keep three kinds of technical records, none of which contain the contents of your receipts, statements, or conversations.
Device and sign-in records: when you sign in, on what kind of device and browser, from which IP address, and by which method. Kept for 12 months to protect your account and help you recover it.
Device security checks: each time the Marvin Money app for Android or iOS opens, it runs a security check built by a specialist mobile-security partner. The check looks at whether the phone is rooted or jailbroken, whether the app has been tampered with or is being manipulated by another program, and, on Android, whether a known malicious or hooking app is installed. To do that it reads the list of apps installed on the phone. What leaves the phone is the result of the check together with a device identifier that is not your account, the device model, and the app version; those go to the partner and to our security log. The check never touches your entries, receipts, or conversations, and it does not run in the web app. Kept in our security log for up to 2 years, like the other security records described below.
Usage records: which screens you open, for how long, and which features you use. Kept for 12 months so we can see what works and where people get stuck, and to recognise abuse.
AI usage records: how often Marvin does work for you and roughly what it costs. Kept for 2 years to run your monthly AI allowance.
If a message you send to Marvin trips our abuse filter, that message is kept as part of your security record so we can review it, as described under account deletion. Everything above is included in your data export and erased with your account, except the security records described below.
If you choose to split a planned bill with someone — your partner, a roommate, a group — the only information that crosses between your accounts is your display name and the total and each person's share of the specific bills you share. Never your other budgets, expenses, balances, or anything you haven't shared. It's opt-in on both sides: you each add the other's account email and confirm the link before anything can be shared, and every person accepts their own share before it touches their budget. Your display name is shown only to people you've linked with. Leave a shared bill, or unlink from someone, and that sharing stops.
Your account, expenses, and encrypted backups are stored on enterprise-grade cloud infrastructure located in Canada (Montréal region). Uploaded receipts and statements are read to extract your transactions and then discarded — the original files are not kept. Your data does not leave Canada at rest. When you contact us from outside Canada, requests are still routed to and stored on these Canadian servers.
Everything is encrypted at rest, and backups are encrypted too. We chose at-rest encryption rather than end-to-end-on-your-device because Marvin's AI features — reading a receipt, answering a question, drawing your forecast — need to process the actual numbers to give you a useful answer. End-to-end would mean a notebook that can't read itself. Access is restricted to a small named team, and only for defined purposes: responding to incidents, investigating abuse, reviewing analytics to improve the app, and curating merchant names and category icons so everyone's feed displays correctly. Never for marketing, never out of curiosity.
To operate Marvin securely and reliably, we work with a small number of carefully selected partners for hosting, payments, AI features, market data, communications, mobile app security, and the optional bank connection.
You can see the current list of those partners in our Trust Center. Each is bound by contract to process your data only on our instructions and only as needed to deliver services to Marvin. By contract, our partners are not permitted to sell your data, advertise to you, or train their own AI models on it. Where a partner needs to use a sub-processor of its own, or is required by law to disclose data (for example, in response to a court order), we expect them to tell us — and we vet those arrangements as part of onboarding.
Marvin works fully without a bank login, and most members never connect one. Pro+ members in the US and Canada (more countries coming) can optionally connect a bank to auto-update their balance and import recent transactions. It's a convenience, not a requirement — you can use every part of Marvin without it.
When you use it, you sign in through our secure bank-connection provider — your credentials go to the provider and your bank, and Marvin never sees or stores your banking username or password. You can disconnect anytime, and transactions already imported stay as your records. If you downgrade or cancel Pro+, the connection stays active until your current plan period ends, then is automatically disconnected at the source, so no access lingers. To use auto-import again later, you simply reconnect with a fresh sign-in.
You get 30 days to change your mind — sign back in and everything comes back. After that your data is erased for good — gone within 31 days of the request: receipts, statements, what Marvin remembers about you, all of it. Then there are no copies, no backups, no recovery. Export anything you want to keep before you press the button. Step-by-step instructions, and a line-by-line list of what goes and what stays, are on the data deletion page.
One exception, disclosed plainly: if your account was flagged for abuse — things like prompt-injection attempts or malicious uploads — we keep those security-event records for up to 2 years. Your email is replaced with a one-way fingerprint that can't be turned back into your address. We keep them so an abuser can't delete their account and start fresh with a clean slate, and to meet legal obligations. These records describe the security event itself, including a message that tripped the abuse filter. Never your expenses, receipts, or the rest of your conversations.
We also keep a one-way fingerprint of your email — not the address itself — for one job only: making sure the free trial can't be claimed twice. It can't be reversed, and it isn't used for anything else.
One more thing we keep: we used to sell prepaid AI credits, and where someone had paid for credits they hadn't spent, we keep a note of how much was left and what they paid for it. No name, no email, no account number — just the amount and the payment reference. Financial records are one of the things the law requires us to hold on to, and this is the smallest version of one we could keep. We no longer sell credits; AI Boosters replaced them, and a Booster leaves no balance to keep a record of.
You can request a copy of everything we have on you, ask us to fix anything that's wrong, or have us delete you entirely — at any time, on any plan. Email privacy@marvinmoney.com. We respond within 7 days, usually within 24 hours.
The fastest way to get your copy is self-serve: Settings → Data → Export my data. We'll email a secure, single-use download link to your account email — no waiting on us.
When we change this page in a way that matters — what we collect, how long we keep it, who we share it with, or your rights — we tell you by email and in the app before the change takes effect. If a change expands what we do with your data or removes a right, you get at least 30 days' notice and the app asks you to accept it. A dated summary of every change sits at the top of this page, with the previous version linked. Wording fixes and clarifications take effect when posted.
Write to privacy@marvinmoney.com. A real person reads everything.
Try Marvin for 7 days. We'll never ask you for anything we don't need.