mark5 logo mark5.ai

Privacy Policy

Version 1.0 · Effective Date: January 30, 2026 · Last Updated: January 30, 2026

This Privacy Policy describes how Arctan Engineering Inc., d/b/a mark5.ai ("mark5.ai," "we," "us," or "our"), collects, uses, and protects your personal information when you use our websites and services (collectively, the "Service").

By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, do not use the Service.

1. Information We Collect

1.1 Information You Provide

CategoryData
Account informationEmail address, password (hashed, never stored in plain text)
Profile informationDisplay name (optional)
Receipt imagesPhotos of receipts you upload
Expense dataVendor, date, amount, category, account assignments, notes
Payment informationProcessed by Stripe; we do not store credit card numbers
2FA credentialsEncrypted TOTP secrets for two-factor authentication
Support communicationsEmails or messages you send to us

1.2 Information Collected Automatically

CategoryData
Device informationBrowser type, operating system, device type
Usage dataPages visited, features used, timestamps
IP addressCollected by Firebase for authentication and security

1.3 Information from Third Parties

If you sign in using a third-party provider (e.g., Google), we may receive your name and email address from that provider, subject to their privacy policies and your account settings.

2. How We Use Your Information

We use your information to:

  • Provide the Service — store and process receipts, generate reports, manage your account
  • Process payments — manage subscriptions and billing through Stripe
  • Extract receipt data — send receipt images to Google Cloud Document AI for automated data extraction
  • Secure your account — authenticate logins, verify email addresses, enable two-factor authentication
  • Communicate with you — send account-related emails (verification, password reset, subscription changes)
  • Improve the Service — analyze usage patterns to fix bugs and improve features
  • Improve data extraction — use aggregated, anonymized data (such as extracted text and user corrections) to improve our receipt processing accuracy. This data is stripped of all personally identifiable information and receipt images. See our Terms of Service Section 6.5 for details.
  • Comply with law — respond to legal requests and prevent fraud

We do not use your data for advertising. We do not sell your personal information.

3. Third-Party Service Providers

We use the following third-party services to operate mark5.ai. Each provider receives only the data necessary to perform its function:

ProviderPurposeData Shared
Google Firebase Authentication, database, file storage, hosting Email, password hash, receipt images, expense data, IP address
Google Cloud Document AI Receipt data extraction (OCR) Receipt images
Stripe Payment processing Email, payment method details (card info goes directly to Stripe)

These providers are bound by their own privacy policies and data processing agreements. We do not share your data with any other third parties except as required by law.

4. Data Storage and Security

4.1 Infrastructure

Your data is stored on Google Cloud Platform (Firebase) infrastructure located in the United States. Google Cloud provides enterprise-grade security including physical security, network protection, and encryption.

4.2 Encryption

  • In transit: All data is transmitted over HTTPS/TLS
  • At rest: Data is encrypted at rest using Google Cloud's default encryption (AES-256)
  • 2FA secrets: TOTP secrets are encrypted with AES-256-GCM using a dedicated encryption key before storage
  • Passwords: Handled by Firebase Authentication; passwords are hashed and never stored in plain text
  • Payment data: Credit card information is sent directly to Stripe and never touches our servers

4.3 Access Controls

  • Firestore security rules enforce strict user isolation — you can only access your own data
  • Storage rules ensure receipt images are accessible only to the uploading user
  • Cloud Functions require authentication for all sensitive operations

4.4 No Guarantee

While we implement industry-standard security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

5. Data Retention

ScenarioRetention Period
Active accountData is retained as long as your account is active
Account deletionAccount data, receipt images, and expense records are deleted within 30 days of account deletion
BackupsBackup copies may persist for up to 90 days after deletion, after which they are purged
Stripe recordsPayment records are retained by Stripe in accordance with their data retention policy and applicable financial regulations
Anonymized dataAggregated, anonymized data (with all personal identifiers removed) may be retained indefinitely to improve the Service
Legal obligationsWe may retain data longer if required by law or to resolve disputes

Before deleting your account, you will be prompted to download your data.

6. Your Rights

6.1 All Users

Regardless of your location, you may:

  • Access your data through the Service interface at any time
  • Correct your information via account settings
  • Export your data using the report and download features
  • Delete your account and all associated data from the account management page

6.2 California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information we have collected about you in the past 12 months
  • Right to delete your personal information
  • Right to non-discrimination for exercising your privacy rights

We do not sell personal information, including information of persons under 16 years old. Because we do not sell personal information, the CCPA right to opt out of sale does not apply.

To exercise your rights, email support@mark5.ai. We will verify your identity before processing requests.

6.3 European Economic Area Residents (GDPR)

If you are in the EEA, UK, or Switzerland, you have rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict processing, data portability, and object to processing.

Our lawful bases for processing are:

  • Contract performance — processing necessary to provide the Service
  • Legitimate interest — improving and securing the Service
  • Consent — where you have given explicit consent (e.g., marketing emails)
  • Legal obligation — complying with applicable laws

To exercise your GDPR rights, contact us at support@mark5.ai.

7. Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided personal information, we will take steps to delete that information. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at support@mark5.ai.

8. Cookies and Tracking

mark5.ai uses minimal cookies and tracking:

  • Authentication cookies — Firebase uses session cookies to keep you logged in. These are strictly necessary for the Service to function.
  • Google Analytics — We use Google Analytics (GA4) to understand how visitors use our site. This collects anonymized usage data such as pages visited, time on site, and general location (country/region). Google Analytics uses cookies to distinguish unique users. You can opt out by installing the Google Analytics Opt-out Browser Add-on. See Google's Privacy Policy for details on how Google processes this data.
  • No advertising cookies — We do not serve ads or use advertising trackers.

9. International Data Transfers

Your data is stored and processed in the United States on Google Cloud infrastructure. If you are accessing the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your jurisdiction.

By using the Service, you consent to this transfer. We rely on Google Cloud's data processing agreements and security measures to protect data in transit and at rest.

10. Data Breach Notification

In the event of a data breach that affects your personal information, we will:

  • Notify affected users by email within 72 hours of becoming aware of the breach
  • Describe the nature of the breach and the data involved
  • Describe the measures taken or proposed to address the breach
  • Notify relevant authorities as required by applicable law

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the Service at least 30 days before the changes take effect.

We will update the version number and "Last Updated" date at the top of this page. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or your data, contact us at:

mark5.ai
Email: support@mark5.ai

© 2025 mark5.ai · Home · Terms · Privacy · support@mark5.ai