Privacy Policy
Ming · Effective date: 22 June 2026
1. Who we are
Ming is a personal finance application that aggregates your bank account data into a single view. Ming ("we", "us", "our") is operated as a product of Ming. References to "you" mean any person who creates a Ming account.
For privacy enquiries, contact us at privacy@getming.com.ng.
2. What data we collect
2.1 Account information
When you register, we collect:
- Full name — provided by you at sign-up
- Email address — used for authentication and transactional emails
We do not collect your BVN, NIN, date of birth, or home address at registration.
2.2 Bank connection data
The Ming app connects to your bank directly from your device. Your online banking credentials (your bank username and password) are stored only on your device, encrypted in the operating system's secure storage (iOS Keychain / Android Keystore). They are used on your device to sign in to your bank and are never transmitted to, or stored on, Ming's servers, and are never shared with any third party.
Once the app has retrieved your data on your device, it uploads the following to us — never your credentials:
- Account number — stored to identify each connected account
- Account holder name — the name on the account as returned by your bank
- Current balance — updated each time your device syncs the account
- Transaction history — including amount, direction (debit/credit), date, and the narration text exactly as your bank records it
- Raw transaction data — the unprocessed transaction response from your bank is stored alongside each transaction for audit and debugging purposes; it does not contain your login credentials
Some banks require an additional device identifier as part of their authentication. For First Bank, the app generates a synthetic device identifier (not your actual device's IMEI); for Zenith Bank, the app uses the device model name (e.g. "SM-G998B"). These values are generated and held on your device alongside your credentials and are not stored on Ming's servers.
2.3 Derived and generated data
- Transaction categories — we classify your transactions into spending categories (e.g. "Food & Dining", "Transfers") using pattern matching and, optionally, AI classification via Anthropic's API. Only the transaction narration text is used for classification; no other personal information is sent.
- Merchant and sender names — extracted from transaction narrations for display purposes
- Net worth snapshots — a daily record of your total assets derived from your connected account balances
- Insights — aggregated spending summaries, cashflow data, and subscription detection computed from your transaction history
2.4 Device and session data
- Device token — a Firebase Cloud Messaging (FCM) token used to deliver push notifications to your device. Stored alongside your device type (iOS or Android).
- Session tokens — short-lived access tokens (15 minutes) and refresh tokens (14 days) used to keep you authenticated. Stored temporarily in our cache and cleared on sign-out.
- Biometric enrolment token — if you enable biometric login, a credential token (valid for 90 days, renewed each time you use it) is stored on your device and in our cache. This token does not contain your biometric data; biometrics are processed entirely on your device by your operating system.
2.5 Notification preferences
If you configure notification settings, we store seven boolean preferences: push notifications enabled, email notifications enabled, large debit alerts, unusual spend alerts, subscription detection alerts, weekly digest, and net worth change alerts.
2.6 Consent log
We maintain an audit log of bank connection events (when you connect or disconnect a bank account) for security and compliance purposes.
3. How we use your data
| Purpose | Data used |
|---|---|
| Displaying your account balances and transactions | Bank connection data, transaction history |
| Syncing balances and transactions (performed on your device; we receive only the resulting credential-free data) | Account balances and transaction history uploaded by your device |
| Generating spending insights, categories, and net worth | Transaction history, balances |
| Delivering push notifications and email alerts | Device tokens, email address, transaction data |
| Authenticating your identity | Password hash, PIN hash, session tokens |
| Detecting suspicious account activity | Session data, failed login counts |
| Sending transactional emails (alerts, weekly digest) | Email address, transaction summaries |
We do not use your data for advertising. We do not sell or rent your data to any third party.
4. Third parties we share data with
The Ming app connects directly to your bank's digital banking platform from your device. We do not use third-party financial data aggregators such as Mono, Okra, or Stitch.
We share data with the following service providers strictly to operate the platform:
| Provider | Purpose | Data shared |
|---|---|---|
| Resend (resend.com) | Transactional email delivery | Your email address and the content of alert and digest emails |
| Google Firebase (firebase.google.com) | Push notification delivery | Your device FCM token and notification content |
| Anthropic (anthropic.com) | AI-powered transaction classification (optional) | Transaction narration text only. No name, email, account number, or balance is included. Anthropic does not retain this data for training. |
All third-party providers process data under their own privacy policies and are contractually required to process data only as instructed by Ming.
5. Data retention
| Data type | Retention period |
|---|---|
| Transaction history | Retained for as long as your account is active |
| Bank credentials | Never held by us; stored only on your device and deleted from it when you disconnect the bank or uninstall the app |
| Net worth snapshots and insights | Retained for as long as your account is active |
| Session and refresh tokens | Cleared on sign-out; expire automatically (15 min / 14 days) |
| Biometric tokens | Valid for 90 days (sliding); revoked on sign-out or account deletion |
| Notification history | Retained for as long as your account is active |
| Deleted account data | Permanently and irreversibly deleted 30 days after you request account deletion |
6. Account deletion
You can delete your account at any time from Settings → Delete account. When you submit a deletion request:
- Your sessions and biometric credentials are immediately revoked — you are signed out of all devices.
- A 30-day grace period begins. You can cancel the deletion by emailing support@getming.com.ng before the deadline.
- After 30 days, all your data is permanently deleted from our systems, including your profile, all bank connection data, your full transaction history, net worth history, and notification records. This deletion is irreversible.
7. Your rights under the Nigeria Data Protection Act (NDPA) 2023
As a data subject, you have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — ask us to correct inaccurate or incomplete data
- Deletion — request deletion of your account and all associated data (see Section 6)
- Restriction — ask us to limit how we process your data in certain circumstances
- Objection — object to processing carried out on the basis of legitimate interests
To exercise any of these rights, email privacy@getming.com.ng. We will respond within 30 days.
8. Security
- Bank credentials never reach our servers — they are held only on your device, encrypted in the operating system's secure storage (iOS Keychain / Android Keystore).
- Passwords and PINs are hashed using Argon2 and never stored in plaintext.
- All connections to Ming's servers are encrypted using TLS, and the app pins its connections to Ming to guard against interception.
- The Ming app performs on-device integrity checks and protects the data it holds on your device.
- Access tokens expire after 15 minutes to limit the impact of token compromise.
- You may enable biometric login or a 6-digit PIN for an additional layer of access control.
No security measure is perfect. In the event of a data breach that affects your personal data, we will notify you in accordance with the NDPA 2023.
9. Children
Ming is not directed at or intended for use by persons under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has created a Ming account, contact us at privacy@getming.com.ng and we will delete the account.
10. Changes to this policy
We may update this policy from time to time. When we make material changes, we will notify you by email or through a notice in the app before the changes take effect. The effective date at the top of this document will always reflect the most recent version.