Privacy Policy
Effective Date: October 1, 2026
1. Privacy at a Glance
Majir is built to help users find and manage rewards and offers without turning private communications into a data product. This section is the short version. The sections below are the full policy, and they control if anything here reads differently.
What Majir reads: Only the promotional emails you let it scan, to pull out offers and rewards. It never sends, deletes, or moves your email.
If you use Majir inside an AI assistant: The assistant sends Majir a short product query, never your conversation. Majir sends back offers, prices, and links. If you sign in, it also sends back your own saved offers. Details in Section 6.
Who sees your offers: You, and any AI assistant you connect yourself. Never merchants, affiliate networks, or other users.
No training on your data: Majir never uses your data to train AI, including your email, your offers, and your queries.
You can leave at any time: Disconnect an inbox, disconnect an assistant, or delete your account. Section 8 explains how.
We design for:
Data Minimization: We collect and retain only what we need to deliver rewards discovery and attribution.
Purpose Limitation: Inbox data is used to detect and maintain offers and rewards, not to read personal conversations.
User Control: Inbox access, AI assistant access, notifications, and location are optional and can be turned off at any time.
No Sale of Personal Information: We do not sell your personal information.
2. What the Service Does
Email Read Access: If you connect Gmail or Microsoft Outlook, Majir processes reward and promotion-related emails from recognized senders to identify offers and rewards.
Rewards Summary: Majir surfaces a consolidated view of your offers and keeps them up to date.
Shopping Search: Majir looks up products, store prices, coupons, and promo codes when you or an assistant you connected asks about something to buy.
AI Assistant Access (Optional): You can use Majir inside an AI assistant such as ChatGPT or Claude through the Majir connector. Section 6 describes exactly what moves between the assistant and Majir.
Notifications (Optional): Alerts before rewards and offers expire.
Location (Optional): Used to match offers to real store locations and improve relevance. Majir does not send location-based alerts today.
3. Information We Collect and Process
a. Information You Provide
Account data (such as email address and preferences you set in the app) and support communications you send to us.
b. Read-Only Email Data (Only If You Connect Gmail or Microsoft Outlook)
Depending on the provider and permissions granted, we may process email metadata (sender, subject, date/time) and email content necessary to detect and extract offer and reward details (for example, merchant name, offer value, expiration date, redemption terms).
Important: Majir's intent is to avoid storing full message bodies. When feasible, we store only extracted offer attributes needed to operate your Rewards Summary.
c. Notifications
Device notification tokens and notification preferences.
d. Location
Approximate or precise location based on your device settings.
e. Device and Usage Data
IP address, device type, operating system, app version, logs, diagnostic data, and feature usage events.
f. Partner and Attribution Data
Click and referral identifiers and conversion signals used to measure offer performance and attribute outcomes.
g. Shopping Queries (App and AI Assistants)
The product words you or your assistant search for (for example "stainless sink grid 28 inch"), plus any optional store, category, condition, or price cap you add. When the query comes from an AI assistant, we also receive the name of the assistant and its software identifier, the network address the request came from, and any details the assistant adds on its own (see Section 6.a). We ask assistants to send product words only, never names, addresses, or account or order numbers, and we do not receive the rest of your conversation. Before a query is saved, its numbers are masked (Section 9).
h. Redemption Records
When you choose to use an offer, in the app or through an assistant, we record that attempt (the offer, the time, and a redemption identifier) and generate a tracked shopping link. This record shows an attempt, not a purchase.
4. How We Use Information
We use data collected to:
- Provide and operate the Service (connect inbox, detect offers, maintain the Rewards Summary, answer shopping queries from the app or a connected AI assistant).
- Improve relevance and reliability (deduplication, ranking, fraud prevention, debugging, performance).
- Deliver user controls (notifications, settings, location preferences).
- Support security and compliance (monitoring, abuse detection, audits, legal obligations).
- Partner measurement (aggregated reporting and conversion attribution).
- Apply usage limits (for example, the daily number of free lookups an assistant can make without a Majir account).
No AI training: Majir never uses your data to train AI. That includes your email content, your saved offers, and your shopping queries. The AI and search services listed in Section 5.a process data for us to provide the Service, and their own terms govern how they handle it.
5. How We Share Information
We do not sell personal information. We also do not share your private email content with merchants, affiliate partners, product-data partners, or AI assistants. We may share limited data as follows:
a. Service Providers
We use vendors for hosting, analytics, security, and support. They process data on our behalf under confidentiality and security obligations. Current categories of service providers include:
- Cloud Infrastructure: Microsoft Azure (hosting, storage, managed databases) and Azure AI Foundry (large language model inference, including DeepSeek models) for offer extraction and ranking. Cloudflare (edge hosting and storage) runs the Majir connector that AI assistants talk to.
- Product Data and Search: A live product and price search partner that receives the product words of a shopping query (never your name, email address, or conversation) and returns current listings, prices, and store links.
- Query Screening: An AI judgment service that reads the product words of a query and returns a decision on whether a live search is needed.
- Email Delivery: Transactional email providers that send account and sign-in emails (for example, a welcome email or a one-time sign-in code).
- Location Services: Google Places API for resolving the store locations shown with offers.
- Authentication and Inbox APIs: Google (Gmail API) and Microsoft (Graph API) for the optional inbox connection you authorize.
- Notifications: Firebase Cloud Messaging (Google) for push notification delivery.
- Payments: Stripe for subscription billing where applicable.
b. AI Assistants You Connect
If you use Majir inside an AI assistant, the assistant receives what Majir returns for your request: offers, prices, coupon codes, tracked shopping links, and, when you are signed in, your own saved offers and the email addresses and scan status of your connected inboxes. The assistant is run by its own provider (for example OpenAI for ChatGPT or Anthropic for Claude) under that provider's privacy policy. Section 6 has the full description.
c. Partners and Affiliate Networks (Attribution)
When you click or redeem an offer, we may share referral/click identifiers, offer or campaign identifiers, conversion signals (such as timestamp and event type), and aggregated performance metrics. We share what is reasonably necessary to operate attribution and reporting. Links may earn Majir a commission. Our picks never depend on it.
d. Legal, Safety, and Business Transfers
We may disclose information to comply with law, protect rights and safety, prevent fraud and abuse, or in connection with financing, acquisition, or asset transfers, subject to appropriate protections.
6. When You Use Majir Inside an AI Assistant
You can use Majir inside ChatGPT, Claude, or another AI assistant that supports the Majir connector. This section explains what moves between the assistant and Majir, who receives it, and how to stop. You do not need a Majir account to look up offers this way. A Majir account is only needed to see your own saved offers.
a. What the Assistant Sends Majir
- A short product query in a few words, and optionally a store, a category, a product condition, or a price cap.
- The name and software identifier of the assistant, so we know which assistant is asking.
- The network address the request came from, which we use to count free lookups when you are not signed in.
- If you signed in with Majir, a sign-in token that identifies your account. If you did not sign in, no Majir sign-in details.
- Details the assistant adds on its own. Some assistants attach a language setting, an approximate location, or a pseudonymous user ID to each request. Majir does not use or keep the language or location details. It may use a scrambled (one-way hashed) form of the pseudonymous user ID to count free lookups, and nothing else.
The assistant does not send Majir the rest of your conversation, your chat history, or your files. We ask assistants to keep names, addresses, and account or order numbers out of the query, and we do not need them to answer.
b. What Majir Returns
Without a Majir account: product listings with the store and current price, coupons and promo codes, savings amounts, expiry dates, a product photo and stated details when the store provides them, and a Majir shopping link where one exists.
Signed in with Majir: everything above, plus your own saved offers (the coupons, credits, and rewards Majir found in the inboxes you connected), the email addresses and connection status of those inboxes, when each inbox was last scanned, and how many free lookups remain. Only your own inbox data is ever returned. Majir never returns another person's offers.
When you choose to use an offer: a tracked shopping link and a record of that attempt. Majir does not buy anything, does not apply a discount, and does not hold payment details.
c. Who Receives It
- The assistant you connected. It shows you Majir's answer and may keep it as part of your conversation under its own provider's privacy policy (for example OpenAI for ChatGPT, or Anthropic for Claude). Majir does not control what the assistant keeps.
- Our product data and search partner. It receives the product words of the query to return live listings and prices. It does not receive your name, your email address, your saved offers, or anything from your inbox.
- Our query screening service. It reads the product words to decide whether a live search is needed.
- Affiliate networks and merchants. When you open a tracked link, the network and the merchant receive click and referral identifiers as described in Section 5.c. They never receive your inbox content or your saved offers.
d. What Majir Keeps
Majir keeps as little as it can from an assistant request:
- Your sign-in: a connector sign-in stays valid for 30 days after you last used it and extends each time you use it. Once you remove Majir from the assistant, that sign-in is no longer presented and it expires on its own within 30 days.
- Lookup counts: when you are not signed in, we count lookups by network address, and may also count them by a scrambled form of the assistant's pseudonymous user ID, for the current day only. Past days are cleared when the day rolls over.
- Short-lived working data: sign-in handshakes and result pages held for paging stop working within 15 minutes.
- Shopping queries: Majir does not save the words of a query an assistant sends. It saves a one-way scrambled code of the masked query, made with a secret key so it cannot be matched by guessing searches, and counts about the search (for example, how many results it found), to improve results and detect abuse. A query shaped like an email address or a web address gets no code at all. When you are signed in, some of these records are linked to your account. They are deleted after 90 days. We do not keep your conversation.
- Redemption records: links to your saved offers can keep working while the offer is available. After 13 months, personal details are removed from the attempt and click records. Deleting your account unlinks these records at once. Records without personal details stay for commission accounting.
What the assistant keeps from the conversation is governed by the assistant provider's privacy policy, not this one.
e. Your Controls
- Disconnect the assistant: remove Majir from the assistant's connector or app settings. The assistant can then no longer reach your Majir account. Your connector sign-in expires on its own within 30 days of last use.
- Revoke inbox access: disconnect an inbox in Majir settings, or revoke Majir in your Google or Microsoft account security settings. Majir stops scanning that inbox.
- Delete your account: see Section 8. Majir refuses sign-ins and stops assistant access to your account at once. Remaining stored copies are removed within 30 days.
- Stay signed out: you can look up public offers through an assistant without ever creating a Majir account, up to a daily limit.
Commission disclosure: Links may earn Majir a commission. Our picks never depend on it. Majir states this when you connect it and in the tool descriptions the assistant reads, and commission never changes which offers Majir recommends.
7. Advertising and Tracking
Majir may use analytics to understand product performance. We do not use connected inbox content to build cross-site behavioral advertising profiles from private messages.
Do Not Track Signals: Because there is no accepted standard for how to respond to Do Not Track browser signals, Majir does not currently respond to DNT signals. Majir is a mobile application and a connector for AI assistants, so browser signals are generally not applicable to our Service.
8. Your Controls and Choices
- Disconnect Gmail/Microsoft Outlook: Turn off inside the Service and/or revoke access in your Google or Microsoft account settings.
- Disconnect an AI Assistant: Remove Majir in the assistant's connector or app settings. See Section 6.e.
- Delete Your Account: In the Majir app, open Help and Support and choose Delete account, or contact us. Account access stops at once. Majir refuses sign-ins, disconnects your inboxes, and unlinks your account from shopping records. Remaining stored copies, including your profile photo, notification copies, connector sign-in records, and personal details in click records, are removed within 30 days. Section 9 explains what stays without a link to you.
- Disable Notifications: In device settings.
- Disable Location: In device settings.
- Access, Delete, or Correct Your Data: Contact us, reach out to us here.
9. Data Retention
We keep search and usage records for 90 days after collection. Account data stays while your account is open. We keep some records longer to:
- Protect against fraud and abuse,
- Meet legal, tax, accounting, or audit obligations,
- Resolve disputes or enforce agreements.
After these periods, we delete records or remove their personal details. After account deletion, access stops at once and remaining stored copies are removed within 30 days.
Some categories have their own rules:
- Email content: Majir reads a message to extract an offer. It keeps the extracted offer details (merchant, value, code, dates, link) and the message identifier, not the message body, for as long as the offer is in your Rewards Summary.
- Inbox connections: disconnected at once when you disconnect an inbox or delete your account. The inbox and its scan records are removed as part of deletion.
- AI assistant connector sign-ins: valid for 30 days after last use and extended on each use. When you delete your account, every connector sign-in stops working at once, and the sign-in records in our main database are removed within 30 days. The connector service may hold a session record until it expires, but it can no longer reach your account.
- Redemption links: shopping links from search results stop working within 24 hours to 7 days, depending on the plan that issued them. Links to your saved offers can keep working while the offer is available.
- Lookup counts and short-lived working data: lookup counts cover the current day. Sign-in handshakes and paging snapshots stop working within 15 minutes.
- Store address lookups: merchant store locations, not your location, cached for 30 days.
- In-app notifications: deleted 90 days after they are sent, together with the copy the app displays, or within 30 days when you delete your account. Some older copies on open accounts may remain until we locate and remove them.
- Server logs: our hosting provider (Microsoft Azure) keeps operational logs for the period set in our hosting account, for security and to fix problems. These logs can include your account ID and IP address.
- Shopping queries, usage events, and offer interactions: before a search is saved, every number in it is masked, and a search shaped like an email address or a web address is not saved at all. Search history, usage events, and offer interactions are deleted after 90 days. Your savings history (the offers Majir found, the ones you used, and the ones confirmed) stays with your account while it is open, because your Rewards Summary is built from it.
- Redemption and click records: personal details are removed after 13 months. Deleting your account unlinks these records at once, and any remaining personal details are removed within 30 days. The remaining records contain only limited shopping and accounting details.
- Account record after deletion: access stops at once. Remaining stored copies of your profile photo, notifications, connector sign-ins, search history, interactions, usage events, and profile details are removed within 30 days. Savings and redemption records stay without a link to you after personal details are cleared. We keep a minimal record that the account existed and was deleted, and a one-way fingerprint of each email address the account used. The fingerprint cannot be turned back into your address. It is kept to prevent abuse, under the fraud and abuse exception above, and has no set end date.
10. Data Breach Notification
In the event of a data breach affecting your personal information, we will notify you via email at the address associated with your account. The notification will include:
- A description of the breach and the types of information involved,
- Steps we are taking to address the breach,
- Recommended actions you can take to protect yourself,
- Contact information for questions or concerns.
We will provide this notification without unreasonable delay and in accordance with applicable law, including the breach notification requirements under Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") where those requirements apply. Where PIPEDA applies, we will also report breaches that pose a real risk of significant harm to the Office of the Privacy Commissioner of Canada and maintain records of breaches as required by law.
11. Security
We use safeguards designed to protect data, including access controls, encryption in transit, and secure handling of authentication tokens. We continuously improve protections.
12. Children
The Service is not intended for children under 13 (or the age required by local law). We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 13, we will delete it promptly.
13. International Users (United States, Canada, Mexico)
The Service is currently offered to residents of the United States, Canada, and Mexico. Users in other countries are not the intended audience of the Service.
a. Cross-Border Data Transfers
Majir is a United States company. Personal information collected through the Service is stored and processed in the United States on Microsoft Azure infrastructure, and may be processed by United States-based service providers listed in Section 5.a. If you access the Service from Canada or Mexico, you acknowledge that your personal information will be transferred to and processed in the United States, which may have data protection laws that differ from those in your country of residence. We rely on service provider contractual commitments and administrative, technical, and physical safeguards to protect your information during and after transfer.
b. Canadian Users (PIPEDA)
If you are a resident of Canada, Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and applicable provincial privacy laws (including Quebec's Law 25) may apply to our processing of your personal information. You may:
- Request access to, correction of, or deletion of your personal information by contacting us through our contact form with the subject "Canada Privacy Inquiry",
- Withdraw consent to specific processing at any time (for example, by disconnecting Gmail or Outlook and disabling notifications or location),
- Receive a response to a privacy request within thirty (30) days where required by law.
External Redress: If you are not satisfied with our response to a Canadian privacy request, you may contact the Office of the Privacy Commissioner of Canada ("OPC") at www.priv.gc.ca, or your applicable provincial privacy regulator.
c. Mexican Users (LFPDPPP and ARCO Rights)
If you are a resident of Mexico, the Federal Law on Protection of Personal Data Held by Private Parties ("LFPDPPP") may apply to our processing of your personal information. Under LFPDPPP you have ARCO rights, meaning the right to:
- Acceso (Access): Know what personal information we hold about you and how we use it,
- Rectificación (Rectification): Correct personal information that is inaccurate or incomplete,
- Cancelación (Cancellation): Request deletion of personal information when its processing is no longer justified,
- Oposición (Objection): Object to specific uses of your personal information.
How to Submit an ARCO Request: Contact us through our contact form with the subject "ARCO Request". Please include your name, the email address associated with your Majir account, the ARCO right(s) you wish to exercise, and any documents reasonably necessary to verify your identity. We will respond within the timeframes required by LFPDPPP (generally within twenty (20) business days to acknowledge the request).
External Redress: If you are not satisfied with our response, you may contact Mexico's National Institute of Transparency, Access to Information and Personal Data Protection ("INAI") at home.inai.org.mx.
d. Users Outside the United States, Canada, and Mexico
We do not intend the Service for users outside these three countries and we do not knowingly collect personal information from individuals who are not residents of one of them.
14. California Privacy Notice (CCPA/CPRA)
This section provides disclosures for California residents and applies to the extent the California Consumer Privacy Act, as amended by the CPRA ("CCPA/CPRA"), applies.
a. Notice at Collection
In the last 12 months, we may have collected these categories of personal information:
- Identifiers: Email address, account IDs, device identifiers.
- Commercial Information: Offer interactions, shopping queries, and redemption-related events.
- Internet or Network Activity: Usage logs, IP address, device data.
- Geolocation: Approximate or precise location (only if enabled).
- Inferences: Offer relevance signals derived from your interactions.
Sources: You, your connected email provider (only with your authorization), your device, an AI assistant you connected to Majir (only the query it sends), and our partners for attribution data.
Business Purposes: Operate the Service, maintain your Rewards Summary, improve product performance, secure the Service, and measure partner attribution.
b. Sale and Sharing
We do not sell personal information as "sell" is defined under the CPRA. We also do not "share" personal information for cross-context behavioral advertising. If our practices change, we will update this policy and provide opt-out mechanisms required by law.
c. Sensitive Personal Information
Sensitive personal information may include precise geolocation and contents of communications. Majir uses such information only as reasonably necessary to provide the Service you request (for example, detecting offers you asked us to find) and for permitted security and compliance purposes.
d. Your California Rights
Subject to verification and legal exceptions, you may have the right to:
- Know/access the personal information we collected and how we used it,
- Delete personal information,
- Correct inaccurate personal information,
- Opt out of sale or sharing (not currently applicable as described above),
- Limit the use of sensitive personal information (where applicable),
- Non-discrimination for exercising rights.
How to Submit a Request: Reach out to us here with "California Privacy Request" in the message. We will verify your request (for example, by confirming control of the account email). You may also use an authorized agent consistent with CPRA requirements.
e. Retention (California)
Section 9 describes how long each category is kept and which records stay for accounting or legal needs. Account access stops at once on deletion, and remaining stored copies are removed within 30 days.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will revise the Effective Date at the top of this document. For material changes, we will provide notice through the app or via email before the changes become effective.
16. Contact
Majir Inc.
Questions? Reach out to us here.
Appendix: Inbox Permissions and Scope Usage (Google and Microsoft)
Google Gmail Scope
Scope: https://www.googleapis.com/auth/gmail.readonly
Meaning: Read-only access to Gmail messages and metadata you authorize. Majir cannot send email, delete messages, or modify your mailbox using this scope.
How Majir Uses It: Detect and extract reward and promotion offer details; maintain your Rewards Summary and notify you before offers expire (if enabled).
Microsoft Outlook Permission
Permission: Mail.Read
Meaning: Read access to mail messages you authorize. Majir cannot send, delete, or modify mail using this permission alone.
How Majir Uses It: Detect and extract reward and promotion offer details; maintain your Rewards Summary and notify you before offers expire (if enabled).
Google API Services User Data Policy: Majir's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: Gmail data is used only to show you your offers and rewards, is never used for advertising, and is never passed to an AI assistant or a partner as raw email. Only the offers Majir extracted from your inbox are returned to an assistant you connected, and only when you sign in.
User Control: You can disconnect at any time in Majir settings and revoke permissions from Google or Microsoft account security settings.