Privacy Policy
Effective date: September 16, 2026 · Last updated: October 5, 2026 · Pending legal review · Versión en español
1. Who we are
Mega Apps Ventures, LLC is a Delaware limited liability company with its registered office at 131 Continental Dr, Suite 305, Newark, DE 19713, United States, and mailing address 8 The Green, Suite #27141, Dover, DE 19901, United States (the "Company", "we", "us"). We publish and operate consumer apps for iOS, Android and the web, and we are the controller of the personal data described in this policy. For any question about this policy or your data, write to support@megaappsventures.com.
2. What this policy covers
This policy covers:
- this website, megaappsventures.com;
- your communications with the Company by email;
- the processing the Company runs for all of its apps: web payments, purchases made through the Apple App Store and Google Play, and the portfolio admin we use to operate the apps (section 3.4).
Each app has its own privacy policy that describes the data processed inside that app (section 12). Where this policy and an app's policy differ for data inside that app, the app's policy prevails.
3. Information we collect
3.1 This website
megaappsventures.com is a static information site. It has no forms, sets no cookies, runs no analytics or advertising scripts and loads nothing from third-party servers (fonts are served from our own domain). We do not collect personal data through it.
Our hosting provider records standard web-server access logs (IP address, requested URL, date and time, browser identification) for the security and operation of the server. We use them only to investigate abuse or technical problems.
3.2 Email
If you write to one of our @megaappsventures.com addresses we receive your email
address, the content of your message and the technical headers your mail provider adds. We do
not add you to any mailing list.
3.3 Payments
Web purchases (Stripe). When you buy a membership in the web version of one of our apps, the payment is made on a checkout page hosted by Stripe. Stripe collects your card details, the cardholder name and the billing country (and further billing details where Stripe requires them). We never see or store your card number. On our side we keep: the email address of your app account, an internal user identifier, the app and plan you bought, the amount, the currency, the date, the payment status and the Stripe customer, subscription and invoice references, together with the record of the payment events Stripe sends us (payments, refunds, subscription changes and cancellations).
Store purchases (Apple App Store, Google Play). When you buy inside one of our iOS or Android apps, Apple or Google bills you under their own terms and privacy policies. We receive the confirmation of the purchase and the status of the subscription (product, price, currency, renewal and expiry dates) linked to the internal identifier of your app account, not your payment details. We use RevenueCat to process these store confirmations (section 5).
3.4 The portfolio admin (operating our apps)
To operate all of our apps from one place, the Company runs an internal admin at
admin.megaappsventures.com / api.megaappsventures.com. Once an hour it
copies from each app the following data about each user account: email address, display name,
account status, plan, purchase source, entitlement dates, registration and last-activity
dates, whether the email was verified, and the app's payment records (provider, plan, amount,
currency, date, reference). It also stores aggregate counts (users, active users, memberships,
revenue) per app and per day.
Only the Company's operators can sign in to the admin. Operators use it to view these records, to grant memberships, to suspend or unsuspend an account, and, for support and troubleshooting, to open the app as that user. Every such action is written to an audit log (which operator, which action, which account, when, and the result).
4. How we use the information and on what basis
- Answering your messages and handling support requests: our legitimate interest in responding to you, or the steps needed before entering into a contract.
- Providing, billing and renewing memberships, sending payment confirmations and handling refunds and chargebacks: performance of the contract with you, and our legitimate interest in preventing fraud and payment abuse.
- Operating, securing and supporting our apps across the portfolio, including the admin described in section 3.4: our legitimate interest in running the services we publish, in detecting abuse and in giving support.
- Legal, tax and accounting obligations: compliance with the laws that apply to a US company (for example, keeping records of sales).
We do not sell personal data, we do not show third-party advertising on this website and we do not use your data for advertising profiling.
5. Who we disclose it to
We share personal data only with the service providers we need to run the Company and its apps, each for the purpose stated here:
- Hosting provider (hostrd.com). Hosts this website, the portfolio admin,
the app servers and databases and our
@megaappsventures.commailboxes, and keeps the server access logs. The provider states that the server is located in Finland; we have not independently verified the physical location of the data centre. The provider's daily backups are stored on a separate backup server in Helsinki, Finland (section 7). - Stripe, Inc. (United States). Processes web payments. Receives the email address of your app account, an internal user identifier, the app and plan, and, on its own checkout page, your card and billing details. Stripe emails you a receipt for each payment and refund.
- Apple Inc. (App Store) and Google LLC (Google Play). Process purchases made inside our iOS and Android apps and pay the proceeds to the Company. They receive your payment details under their own terms; we receive the purchase confirmation.
- RevenueCat, Inc. (United States). Manages the status of subscriptions bought inside our iOS and Android apps. Receives the internal identifier of your app account (not your name or email), the purchase information Apple or Google hand over, and the technical device and app data its software kit needs. It is not involved in web payments.
- Google LLC (Gmail). Messages sent to our
@megaappsventures.comaddresses arrive on our hosting provider's mail server and are forwarded to a Google mailbox used by the Company's owner. - Email delivery and AI providers used inside an app are listed in that app's own policy. MyFinances360, for example, sends its account and payment emails through Brevo and uses the Claude API of Anthropic PBC for document extraction; see section 12.
We may also disclose personal data to public authorities where a law or a binding order requires it; to professional advisers (accountants, tax representatives, lawyers) bound by confidentiality, to the extent they need it; and to a buyer or successor of the Company or of one of its apps, in which case this policy continues to apply to the transferred data. We do not sell or rent personal data.
6. How data is disclosed
- Data is transmitted to our providers over encrypted connections (HTTPS/TLS for the APIs of Stripe, RevenueCat, Apple and Google; TLS for the email relays our apps use). Card details are entered directly on pages operated by Stripe, Apple or Google and never pass through our servers.
- Each provider receives only the fields its service needs, as listed in section 5. We do not export, share or sell lists of users.
- Disclosures to authorities are made only on a written legal request, limited to the data the request covers.
7. How we protect it
We use the following measures:
- All traffic to this website, the admin and our apps is encrypted (HTTPS with HTTP Strict Transport Security).
- Server access is by SSH key only; password login to the server is disabled. Two-factor authentication is enabled on the server management console, the hosting control panel and the backup system.
- Card data never touches our servers (Stripe, Apple, Google).
- Account passwords, in our apps and in the admin, are stored as salted hashes and cannot be recovered.
- API keys, webhook secrets and database credentials are kept on the server, outside the source code repositories.
- Access to production systems is limited to the person operating the Company. Admin operator accounts cannot be self-registered; they are created by the operator only.
Known limits, stated plainly. Most data is not encrypted at rest: databases and stored files are protected by the server's access controls and file-system permissions, not by encryption (individual apps encrypt specific items, as their policies state). Our hosting provider backs up the hosting accounts every day, incrementally, to a backup server in Helsinki, Finland, keeps each backup for 90 days and keeps weekly snapshots of the backup storage for four weeks; these backups are encrypted. The admin's operator login has a strong password and short-lived sessions but no second factor yet. We have not undergone third-party security audits, certifications or penetration tests. No method of transmission or storage is completely secure; if we learn of a breach affecting your data we will inform you as the applicable law requires.
8. How long we keep it
- Server access logs: for the limited period our hosting provider keeps them for the operation and security of the server.
- Email: for as long as needed to answer you and, afterwards, as a record for as long as legal record-keeping obligations require.
- Payment records: for as long as tax and accounting law requires the Company to keep records of its sales.
- Data inside an app: as that app's policy states. When you delete your account in an app, its data is removed according to that app's policy.
- Copies in the portfolio admin: removed automatically within about one hour after your account has been permanently deleted in the app. The audit log of operator actions is kept as a record of what was done to which account.
- Backups: a deleted item can survive in the hosting provider's backups for up to about four months (90 days of daily backups plus four weekly snapshots).
9. Your rights
Depending on where you live, data-protection law (for example the EU General Data Protection Regulation, Dominican Republic Law No. 172-13, or a US state privacy law) may give you rights over your personal data. Whether or not a particular law applies to the Company, we honour the following for everyone:
- to access the personal data we hold about you and receive a copy;
- to correct inaccurate or incomplete data;
- to delete your data (within an app, by deleting your account);
- to receive your data in a portable, commonly used format;
- to object to, or ask us to restrict, processing based on our legitimate interests;
- to withdraw consent where processing is based on it;
- to complain to the supervisory authority competent for you.
To exercise a right, write to support@megaappsventures.com from the email address linked to your account, or tell us how we can verify your identity. We answer within 30 days, or within the shorter period the applicable law sets. We will never treat you differently for exercising your rights.
10. Children
This website and our services are not directed to children under 13, and each app sets its own minimum age (MyFinances360 requires users to be 18 or older). We do not knowingly collect personal data from children. If we learn that a child has provided personal data to us, we delete it.
11. Where your data is processed
The Company is established in the United States and its owner operates it from the Dominican Republic. Our hosting provider states that the servers are in Finland (European Union), and our other providers process data in the United States and the European Union. Your data may therefore be processed in any of those countries. As of this version we have no specific data-processing or transfer agreements (for example, standard contractual clauses) signed with our providers; the terms and privacy policies each provider publishes apply. This point is under legal review.
12. Privacy policies of our apps
Each app keeps its own privacy policy, which prevails for the data processed inside that app:
- MyFinances360: myfinances360.com/en/privacy.php (English) · myfinances360.com/privacidad.php (Spanish)
Apps that have not yet been released will publish their policy before launch, and we will list it here.
13. Changes to this policy
We may update this policy to reflect changes in our services, our providers or the law. The effective date and the last-updated date at the top show the current version. If a change is material, we announce it on this page and, for users of an app, in the app or by email as that app's policy provides.
14. Contact
Mega Apps Ventures, LLC
131 Continental Dr, Suite 305
Newark, DE 19713, United States
Mailing address: 8 The Green, Suite #27141, Dover, DE 19901, United States
support@megaappsventures.com