Mirato Privacy Policy
Developer name: SHIYO Lab
Responsible operator: XinYang Zhao
Contact email: [email protected]
Effective date: November 1, 2026
1. In short
Mirato is an offline ledger. The app does not request network permission, cannot connect to the internet on its own, and does not send your ledger, account information or usage data to us or any third party. We have no Mirato account system and no server that stores your data.
2. Ledgers and files
- Mirato uses the Beancount text files you choose as your ledger. The app reads them only after you grant access to a directory or choose an import file through the system file picker. This content may include accounts, dates, amounts, currencies, merchants, notes and information you add yourself.
- The app parses and searches this content on your device and writes it back to the directory you authorized when you confirm a save.
- To support safe writes and recovery after errors, the app stores working copies, ledger selection state and recovery records in app-private storage. Recovery records may contain file contents from before and after an edit.
- To make opening and querying faster, the app creates a local index database for each ledger in app-private storage. Its contents come from your ledger.
- To improve suggestions, the app stores learning records in app-private storage: recommendations you accepted, changed or rejected, as well as the input and final account selection from bookkeeping actions.
- You may also share an import template with Mirato through another app. Mirato reads the shared content only on your device.
- Rules, account aliases and import drafts may be stored in the
.mirato/folder inside your ledger directory. - Ledger files and exported backups are not additionally encrypted by Mirato. Choose their storage locations according to their sensitivity and use your device lock.
3. On-device suggestions
The app uses a local model bundled with the app, together with confirmed history and rules, to help search and recommend accounts or categories. These calculations run entirely on your device. Transaction descriptions are not submitted to a cloud model service. Search vectors are stored in the local index in app-private storage and can be regenerated from the ledger; clearing app data deletes them (clearing only the cache does not).
On some devices, the app may use on-device AI capabilities provided by the operating system. Those capabilities are provided by system components and are subject to the policies of the device manufacturer and system provider.
Suggestions may be inaccurate. Check the account, amount and transaction details before saving.
4. Network, third-party storage and system backups
- Network: The app does not request network permission, and Mirato itself does not upload any data. The app contains no advertising, behavioral analytics or crash-reporting service.
- Storage you choose: You may keep your ledger on the device or in a location accessible through the system file picker, such as a cloud drive or sync tool. Whether and how those services synchronize is determined by their own settings and privacy policies and is unrelated to Mirato.
- System backups: The app has disabled Android automatic backup and excludes cloud backup and device-to-device transfer through its data-extraction rules. App-private data is therefore not carried by system backups and is not migrated automatically when you change devices. To migrate, export a backup or copy your ledger files yourself.
5. Voice input (optional)
Voice input is optional. It starts only after you tap the microphone and grant microphone permission. The app calls the Android system speech-recognition service and places the recognized text into the bookkeeping interface.
- Mirato does not store or upload recordings. Recognized text is handled like a bookkeeping sentence that you typed yourself (see §6, Recommendation records).
- Speech recognition is performed by the system speech-recognition service on your device. Depending on the device manufacturer and system settings, the service may recognize speech on the device or send audio to its service provider. That processing is governed by the provider's privacy policy and is outside Mirato's control.
- You can revoke microphone permission at any time in system settings without affecting other features.
6. Diagnostics and recommendation records
- Diagnostic logs: The app records the app version, system version, operation name, duration, model state and error information on the device. They are stored in app-private storage, limited to the latest 200 entries, and retained after the app restarts to help investigate abnormal exits. Directory paths in the logs are replaced with “<directory>”, but filenames and context in error messages may remain.
- Recommendation records: To explain the source of each suggestion in Diagnostics, the app stores the original text, amount and recommendation result for the latest 200 bookkeeping inputs. These records also stay only in app-private storage.
- The Diagnostics “Clear” action deletes diagnostic logs and recommendation records together. This information is not sent automatically to anyone. You may copy a diagnostic report yourself; check it for anything you do not want to share before copying or sending it.
- Clearing app data or uninstalling the app deletes these records.
If you contact us by email and voluntarily attach logs or files, we receive what you send only to investigate the issue you reported. Please do not send a complete real ledger or passwords. The developer handles the email, and deletes it and its attachments within 90 days after the issue is resolved; you may also ask for immediate deletion at any time.
7. Your control and data deletion
- You can revoke Mirato's access to a directory at any time through the system file picker or device settings.
- Clearing app data or uninstalling the app deletes the app-private data on your device. It does not automatically delete copies in an authorized directory, export location or third-party sync service; manage those copies in their respective locations.
- Before clearing app data, finish any pending write recovery and keep a backup of your ledger.
8. Children
Mirato is intended for adults who manage their own finances and is not directed at children.
9. Policy updates and contact
We will update this policy and its effective date when features or data-processing practices change. If you have questions, contact us at the email address listed at the beginning of this policy.