Mizan

Privacy Policy

Last updated: August 2026

Mizan is an AI spend management platform. This policy explains what we collect, why we collect it, and how long we keep it. The short version: we store the metadata needed to run the product — account details, aggregated usage, billing records, and receipts — and we never store the prompts or completions that flow through our gateway.

Overview

Mizan operates in two ways. On the dashboard, you connect your provider accounts (OpenAI, Anthropic, Google, AWS, and more) and Mizan pulls usage data from their billing APIs to show your spend. On the gateway, you route model requests through a single endpoint (/v1/chat/completions) and Mizan forwards them to the provider of your choice. Each mode touches different data, and this policy describes both.

What we collect

Account information

Your name, email address, and profile image, provided through Clerk when you sign up. For organizations: the organization name, slug, and avatar. If you create an organization, we store the identity of members and the roles assigned to them.

Provider credentials

When you connect a provider account, we store the API key required to read your usage. Keys are encrypted at rest (AES-256-GCM) and are never displayed again after setup. When you route traffic through the gateway using your own credentials (BYOK), those credentials are used to serve your requests and are stored encrypted as well.

Usage data

From provider billing APIs we collect daily aggregates: tokens consumed, cost in USD, model, provider, and (where the provider reports it) project or workspace. For gateway requests we record per-request metadata — model, provider, input/output token counts, cost, latency, status code, and a truncated error message on failure. See Data Retention for how long this is kept.

Receipts & subscriptions

When you upload a receipt, scan your email (Gmail or Outlook, only after you connect and authorize it), or forward a bill, we collect the amount, currency, billing period, provider, and invoice identifier. To parse receipts from email, the raw message text is transmitted to a parsing model; we retain a truncated copy for review. Email scanning never runs without your explicit authorization.

Billing & wallet

When you top up your wallet, payment details (card number, CVV, and bank details) are processed by Stripe and never pass through or touch our servers. We store the resulting transaction metadata: the amount credited, any service fee, the balance after the transaction, and a reference to the Stripe payment intent. We do not store full card numbers.

Khabir chat

If you use Khabir, our in-dashboard spend assistant, we store the conversation history so the thread persists across visits. Messages are sent to OpenRouter, which routes them to the model you have configured for Khabir. Do not paste secrets or personal data you would not want a third-party model to see.

Settings & preferences

Your saved preferences: budgets and alerts, cost centers, projects, subscription entries, notification settings, weekly digest preferences, and locale.

How we use it

  • To provide the dashboard, the gateway, and Khabir.
  • To calculate and display your spend, and to bill your wallet or pass through BYOK costs.
  • To send transactional emails: budget alerts, weekly digests, and connection-error notices.
  • To maintain, secure, and debug the service, and to prevent abuse and fraud.
  • To comply with legal, tax, and accounting obligations (for example, keeping billing records).

We do not sell your personal data. We do not use your data to train models. We do not use the prompts or completions that flow through the gateway for any purpose other than serving them to the provider you chose.

Prompts & completions

When you make a gateway request, your prompt and the resulting completion are forwarded to the provider you selected and returned to you. Mizan does not log or store prompt or completion content. For every request we record only the metadata described above (model, token counts, cost, latency, status). If you route through your own connected account (BYOK), the provider's own privacy and data-use policies — the ones you already have a contract with — apply to that content.

Who we share with

We share data only with the subprocessors required to operate the service, and only as needed: Clerk (identity), Vercel and Railway (hosting), Neon (database), Redis (caching and queues), Stripe (payments), Resend (email), and the model providers you route traffic to. When you connect a provider or scan your email, we also share the minimal data with that provider or with Google/Microsoft that the integration requires. The full, current list is published in our Subprocessors page, which we update at least 30 days before adding a material processor.

Retention & deletion

We keep your data only as long as needed to run the service and meet legal obligations. Usage records, gateway request metadata, and wallet history are kept while your account is active; billing and tax records are retained for the period required by applicable law after that. Deleting a connection, key, or account removes the associated data where possible. Full details, including how to delete your account, are in our Data Retention policy.

Your rights

Depending on where you are, you may have the right to access, correct, export, delete, or object to the processing of your personal data, and to withdraw consent. Many of these are available directly in the product (e.g. deleting connections, keys, and conversations). For anything else, email us at naim@app-mizan.com and we'll respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

Security

Provider credentials are encrypted at rest with AES-256-GCM. Gateway keys are stored only as one-way hashes. All data is transmitted over TLS. Every record in our database is scoped to its owner, and every API request authenticates via Clerk-issued JWTs. Details are on our Security page.

Changes to this policy

We may update this policy from time to time. Material changes will be announced via email to the address on your account and by updating the date at the top of this page. Continued use of the service after changes take effect constitutes acceptance.

Contact

Questions about this policy or your data: naim@app-mizan.com. Support and account deletion requests: naim@app-mizan.com.