budge
Home

Privacy Policy

Effective and last updated: September 5, 2026

This policy explains what budge collects, why it is used, who processes it, and the choices available to you.

Who we are and how to contact us

This policy applies to the budge mobile application, website, and related services (collectively, “budge”). For privacy questions or requests, email privacy@budgemoney.com. For general support, email support@budgemoney.com.

Information we collect

  • Identity and contact information: an Auth0 account identifier and, depending on the sign-in method and information you provide, email address, name, phone number, verification status, and authentication records.
  • Connected-account information: institution and account names, account type, partial account number or mask, currency, balances, and connection status.
  • Financial activity: transaction dates, merchant or statement descriptions, amounts, categories, income inferred from deposits or identified by you, refunds, recurring status, pending or posted status, and the account associated with a transaction.
  • Credit and statement information: credit-card balances, limits, APR information, statement balances, minimum payments, payment dates, due dates, and available statement metadata and documents when supported and requested.
  • Information you create or choose: free-spending budgets, manual account details, category corrections, recurring selections, transaction rules, connected-account choices, Lock Screen privacy settings, and other preferences.
  • Security and technical information: App Attest key identifiers, public keys, assertion counters, encrypted attestation receipts, app version and environment, DeviceCheck token digests and risk signals, request identifiers, IP-derived abuse controls, security events, and encrypted Live Activity or Wallet tokens when those optional features are used.
  • Communications: the contents and contact details of messages you send to our support or privacy addresses.

How we collect and use information

  • We receive identity information when you create an account or sign in through Auth0.
  • We receive financial information from Plaid only after you choose an institution and authorize the requested connection in Plaid Link.
  • We receive preferences and corrections directly from you and security signals from the app, Apple, and our service infrastructure.
  • We use this information to authenticate you; connect and maintain accounts; calculate budgets, transaction-derived income, spending, and recurring activity; organize transactions; display cached balances and retrieve current balances when you request a refresh; display liabilities and statements; provide optional Live Activity and Wallet features; respond to requests; prevent fraud and abuse; secure, debug, and operate the service; and comply with law.

Plaid and financial account connections

budge uses Plaid Link to let you authorize access to supported financial accounts. budge requests Transactions, including the account-and-balance and transaction data scopes needed for budgeting and transaction-derived income features; requests consent for Liabilities; and requests Statements when supported. When you tap the balance refresh control, budge asks Plaid to retrieve current balance information from your institution. Plaid handles the institution login experience; budge does not receive or store your bank username or password.

When you request an available statement, budge retrieves it from Plaid and streams it to your device. budge does not use statement PDF contents for categorization, analytics, or ordinary application logging. You can disconnect an institution in Quick Settings; budge then requests revocation of that Plaid connection and deletes data imported for that connection from active budge systems.

Plaid End User Privacy Policy

Service providers and disclosures

We may also disclose information when you direct us to, to protect users or the service, in a properly structured business transaction, or when required by valid legal process. We require service providers to handle data consistently with their role and applicable agreements.

  • Plaid processes authorized financial connections and financial data.
  • Auth0 processes identity, authentication, account, and session information.
  • Amazon Web Services hosts the service and provides databases, encrypted storage, key management, operational logging, and support-email delivery.
  • Apple processes App Attest and DeviceCheck security requests and, if you opt in, APNs Live Activity delivery and Apple Wallet pass installation.

Auth0 Privacy · AWS Privacy · Apple Privacy

No sale, advertising, or cross-app tracking

budge does not sell personal information, serve third-party advertising, share financial information for targeted advertising, or track you across apps or websites owned by other companies. The website does not use advertising cookies or tracking scripts.

Retention and deletion

While your account is active, budge retains imported transaction history for up to 730 days and keeps other account data for as long as needed to provide the features you use. Short-lived authentication and rate-limit records expire automatically. Security, support, and operational records are retained only as long as reasonably necessary for security, support, dispute resolution, and legal obligations. Encrypted backup copies expire under the applicable backup lifecycle and are not restored to active use after deletion.

You may disconnect one institution without affecting others. You may also initiate full account deletion in Quick Settings. Full deletion revokes Plaid connections, deletes the Auth0 identity, invalidates sessions and integrity keys, and deletes user-scoped active data, including transactions, budgets, rules, connected accounts, statement references, Live Activity tokens, and Wallet records. A provider may retain limited records when independently required for security, fraud prevention, legal compliance, or dispute resolution.

Your choices and privacy rights

  • Disconnect an institution or revoke its consent in Quick Settings.
  • Choose transaction classifications, recurring status, budgets, and other account preferences.
  • Opt in to or turn off Live Activity and choose whether amounts are hidden.
  • Initiate account deletion in Quick Settings.
  • Request access, correction, a portable copy, deletion, restriction, or an appeal where applicable by emailing privacy@budgemoney.com. We may need to verify your identity, but we will never ask for your bank password.

Security and international processing

budge uses encryption in transit, Keychain storage on device, encrypted server records, access controls, managed encryption keys, request-integrity checks, and operational monitoring. Face ID is evaluated by iOS; budge does not receive your biometric template. No security measure can guarantee absolute protection. Providers may process information in countries other than your own, subject to applicable safeguards.

Children

budge is intended only for people age 18 or older who can authorize the financial accounts they connect. We do not knowingly collect personal information from children. If you believe a child provided information, email privacy@budgemoney.com.

Changes to this policy

We will update the date above when this policy changes and provide additional notice when a change materially affects how information is used or when consent is required.