Privacy Policy
Last updated August 2026
Ureta, operated by MirrorMagic Games Ltd (Cyprus) ("we", "us"), turns the payout reports from app stores and ad networks into the VAT invoices a developer has to issue. This policy explains what we hold, why, and what you can ask us to do with it.
What we hold
- Account data - your email address and a hashed password.
- Your business identity - the legal name, address, registration and VAT numbers and bank details of the entity you invoice from. We hold these because they are printed on the invoices you issue; an invoice without them is not valid.
- Connected payout credentials - the App Store key, Google Play service account, or OAuth grant you give us so we can read your earnings. Encrypted at rest. They are read-only where the platform offers a read-only scope, and you can disconnect any of them at any time.
- Your revenue figures and the invoices built from them, including the reports we fetched and the exchange rates applied, so that every number on a document can be traced to where it came from.
- Operational logs - what was fetched and when, what failed, what was sent. Needed to run the service and to tell a broken connection from a quiet month.
What we do with it
- Fetch your earnings from the platforms you connect, and only those.
- Prepare, check and issue your invoices, and keep them for you.
- Send you what you ask us to send: your monthly packet, deadline reminders, and a warning when a connected platform has gone quiet.
- Take payment for your subscription, and keep the service running and secure.
We do not use your data to train any model, and we do not sell it. Your figures are not aggregated into any product we sell to anyone else.
Who else sees it
Only the services needed to run Ureta, each receiving only what its job needs:
- The platforms you connect - we call their reporting APIs with the credentials you gave us.
- Our hosting and database, in the EU.
- Our payment provider, which handles your subscription and is the merchant of record for it. We never see your card.
- Our email provider, to deliver the messages listed above.
- Our contract reader - when you upload a contract to be read, the file is sent to Anthropic. It is used to read that document and nothing else, and it is not used to train any model.
- The people you name as recipients of your monthly packet - in Settings you set one required address for yourself and, optionally, your accountant's. A packet goes to those addresses and nowhere else. You can change or remove the accountant's address at any time, and nothing is sent to anyone until you issue the month's invoices. Never otherwise.
Naming an address here is you asking us to send that person your revenue figures and invoices. That is the whole of what it authorises: we do not share your data with them for any other purpose, and we do not add recipients of our own.
How long we keep it, and the part that is unusual
Most of what we hold is deleted when you ask: credentials, contact details, logs.
Platform keys. When you connect a store or ad network we keep that key, encrypted, until you delete your workspace or ask us to remove it - including if you stop paying or never subscribed at all. We do this so that coming back does not mean redoing the connection work. Ask us at any time and it goes.
Issued invoices are different, and it matters. They are statutory records. The law in the countries Ureta serves requires them to be retained for between six and ten years, and that obligation is yours, as the business that issued them. So we do not erase them on request while that period is running. What we do instead is hand them over first: you get every invoice and the ledger behind it, in a form your accountant can open, and after that you are responsible for keeping them.
Your archive stays readable to you even if you stop paying us. A lapsed subscription turns off new invoicing, never access to what you already issued.
Your rights
You can do two of them yourself, in the app, without asking us. Sign in as the workspace owner and open Settings: Download your data builds one ZIP containing everything we hold about your workspace - your records as JSON and CSV, and the actual PDF of every document you ever issued - and Delete workspace erases all of it. We ask you to take the download before the deletion, because your issued invoices are records the law requires you to keep, and once we delete them we no longer have them.
You can also write to [email protected] from the address you signed up with to ask for a copy, a correction or a deletion, and we will do it for you. See Deleting your data for what happens in practice. If you are in the EU, the EEA or the UK, these rights are yours under the GDPR and you may also complain to your national supervisory authority.
Security
Payout credentials are encrypted at rest, passwords are hashed, and everything is served over TLS. No other customer can see your records, and Ureta has no feature that lets one workspace view another. Our own staff can technically reach the underlying database and document storage, because the service has to read your figures to produce your invoices while you are asleep; we access them only to operate the service or to fix a fault you have reported. No system is perfect, and we would rather say that than claim otherwise.
Changes
If we change this policy we will update the date above, and tell you if the change is material.
Contact
The data controller is MirrorMagic Games Ltd, Cyprus. Questions, or a request about your data: [email protected].