Skip to content
Tamoogi
Security

How we protect your business data

Your permits, filings, receipts, and documents are sensitive. This page explains, in plain language, the safeguards Tamoogi has in place today. It only describes what the application actually does.

Last updated 3 October 2026

Your files

Documents stay private to your business

  • Uploaded files are kept in private, encrypted cloud storage. They are never published at a public web address.
  • Inside the app, a file can only be opened by people you have given document access in that business. Receipts and other files attached to expenses also require access to the business’s financials.
  • Every file download is recorded in the business’s activity log, so owners can see who opened what and when.
Access

You decide who sees what

  • Each business is separate. Being part of one business gives no access to another.
  • Owners choose each collaborator’s permissions, such as viewing documents, managing expenses, or seeing financial figures, and can change or remove them at any time.
  • Owners can review an activity log of changes made in their business.
Sign-in

Protecting your account

  • Passwords are stored only in a scrambled, one-way form. No one at Tamoogi can read your password.
  • The number of sign-in attempts in a short period is limited, to make password guessing harder.
  • Everything you send to and receive from Tamoogi travels over an encrypted (HTTPS) connection.
Backups

Your records are backed up

  • We keep encrypted daily backups, stored away from our main servers.
AI features

AI that works for you, on your terms

  • The assistant only reads business records that you yourself can access.
  • AI features are provided by third-party AI model providers. Business owners can turn AI features off for a business at any time from its settings; chat, receipt scanning, and knowledge import then stop sending that business’s information to them.
  • We strip sensitive details like card numbers before records are passed to the AI model.
Payments

Card details never reach us

  • Subscription payments are handled by PayMongo. Your card details go directly from your browser to PayMongo, so Tamoogi never receives or stores your full card number.
Deletion

Deleted means deleted

  • Files you delete are permanently removed 30 days after deletion. The 30 days give you time to notice a mistake.
  • If you delete your account, 30 days later your files, AI conversations, and knowledge entries are deleted and your personal details are erased. Billing records are kept because tax rules require them.
  • See our privacy page for how long each kind of data is kept and how to download a copy of your data.
Your part

Keeping your data safe is shared work

These safeguards protect your data inside Tamoogi. Some protections depend on you and your team:

  • Keep your password private and do not share your account. Anything done while signed in as you is treated as you.
  • You choose who to invite and what they can see. Anyone you give access to can view and download those records, so review permissions and remove people who no longer need access.
  • Files you download or share outside Tamoogi are no longer protected by these safeguards. Keep your devices and email secure.
  • Only upload information you have the right to share, including details about your employees, customers, or suppliers.
  • Keep your own copies of records you are required to keep. You can download them at any time.

Read our privacy page to see what data we collect, who can see it, how long it is kept, and how to download or delete it.