Legal

Privacy Policy

Last updated: 21 June 2026

Mary is a household-management assistant that reads your email inbox and quietly keeps track of the subscriptions, bills, renewals and documents that run a home. Because that means handling personal information — including data from your Google account — we want to be plain about what we collect, why, where it lives, and the control you keep over it.

1. Who we are

This service (“Mary”, “we”, “us”, “our”) is operated by Ausfit Torsion Bars Pty Ltd, 24 Legge Street, Roselands 2196, NSW. For any privacy question or request, contact us at hello@meet-mary.com.

We handle personal information in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Where you access Mary from outside Australia, additional local rights may apply (see “Your rights”).

2. The information we collect

a. Account information

b. Google user data (read-only Gmail access)

When you connect a Gmail account, you grant Mary the scopes email, profile and https://www.googleapis.com/auth/gmail.readonly. Using these, Mary reads message metadata, content and attachments only to detect and organise household items — subscriptions, bills, renewals, documents and related tasks. From your mail we may derive and store:

Mary's Gmail access is read-only. We never send, delete, modify or draft email on your behalf.

c. OAuth tokens

To keep your inbox in sync, we store a Google refresh token. It is encrypted at rest (AES-GCM) and is used solely to obtain short-lived access tokens for syncing.

d. Technical & usage data

What Mary does not do

We do not sell your data. We do not use your Gmail content to build advertising profiles. We do not use your email content to train generalised AI/ML models. We do not transfer your Google user data to others except as described in “How we share data” below.

3. How we use your information

4. Google API Services — Limited Use

Mary's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, data obtained through Gmail read-only access is used only to provide and improve the user-facing features described in this policy; is not transferred to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition; is not used for advertising; and is not read by humans unless you give explicit consent for specific messages, it is necessary for security or to comply with law, or the data is aggregated and anonymised for internal operations.

5. AI processing

To classify emails and extract details, relevant message content and attachments are sent to a third-party AI provider (currently OpenAI) for processing. This processing is performed under the provider's API terms, which do not permit using API-submitted content to train their general models. We send only what is needed to classify a given email, and we use the result to populate your household items.

6. How we share data (sub-processors)

We share data only with service providers that help us run Mary, each bound to protect it:

ProviderPurposeData involved
GoogleAuthentication & Gmail syncProfile, OAuth tokens, mail content
SupabaseDatabase, file storage, backend functions, hostingAll stored account, household and document data
OpenAIAI classification & extractionRelevant email content and attachments
NetlifyWebsite & app hostingTechnical request data
logo.devDisplaying brand/merchant logosMerchant domain names (no personal content)

We may also disclose information where required by law, to enforce our terms, to protect the rights and safety of users or the public, or in connection with a business transfer (merger, acquisition or sale of assets), subject to the Limited Use commitments above.

7. Where your data is stored

Your data is stored with the providers listed above and may be processed on servers located outside Australia (including in the United States). Where we transfer personal information overseas, we take reasonable steps to ensure it is handled consistently with the APPs.

8. How long we keep it

9. Security

We use industry-standard safeguards: encryption in transit (TLS), encryption of OAuth refresh tokens at rest, row-level access controls scoping data to your household, and restricted server-side access to sensitive operations. No system is perfectly secure, but we work to protect your information and will notify you of an eligible data breach as required by law.

10. Your rights and choices

To exercise any of these, email hello@meet-mary.com.

11. Children

Mary is not directed at, and is not intended for use by, anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. We'll revise the “Last updated” date above and, for material changes, provide a more prominent notice. Continued use of Mary after a change means you accept the updated policy.

13. Contact

Questions, requests or concerns about privacy: hello@meet-mary.com.