Privacy Policy

Last updated: August 15, 2026

Introduction

Welcome to BudgetLabs ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our budgeting application and related services.

Important Notice: BudgetLabs is not designed to store highly sensitive personal information such as financial account numbers, credit card details, or login credentials for banks or other institutions. Please do not enter such information into the application.

Information We Collect

Account Information

When you create an account, we may collect:

  • Email address
  • Name (optional)
  • Account credentials (securely hashed)
  • Email communication preferences — whether you have opted out of marketing email, and when that choice was made. Used solely to suppress marketing messages; does not affect transactional email (password reset, signup confirmation, family invites).
  • Legal acceptances — which version of these Terms and this Privacy Policy you accepted or declined, and when. We keep every response rather than only the most recent one, so there is an accurate history of what you agreed to. It is used to know whether to ask you again, and to evidence which version you agreed to if that is ever in question. It is deleted with your account.
  • How you found us — if you arrive at signup from one of our own campaign links (e.g. a blog post or a comparison page on our site), we record the short campaign tag from that link with your account so we know which page or campaign brought you to signup. This is an internal page/campaign identifier only — it contains no browsing history and is never shared with third parties.

Financial Data

To provide budgeting and tracking features, we collect user-entered data such as:

  • Budget categories and amounts
  • Your budget's currency and number/date format — a currency code and a language tag (e.g. SEK and sv-SE) chosen in Settings. Stored in plain text because they describe how figures are displayed, never an amount; used only for formatting. We do not convert between currencies and hold no exchange-rate data.
  • Transaction descriptions, dates, and amounts
  • Income and expense information
  • Savings goals and targets
  • Asset and debt account balances, including optional loan terms, recurring contribution amounts, and employer-match amounts you choose to record
  • Investment holdings you choose to record inside brokerage, retirement, HSA, 529, and crypto accounts — ticker symbols and market values, plus optional fund names, share counts, and cost basis. Encrypted at rest with AES-256; never shared with third parties.
  • Target allocation percentages you optionally set per asset class (US equity, international, bonds, real estate, crypto, cash) to compare against your actual holdings mix on the Allocation page. Encrypted at rest with AES-256; never shared with third parties.
  • Optional gross annual salary you choose to enter in Profile, used only to auto-convert between contribution percent and dollar amount in the savings modal — encrypted at rest, never shared with third parties
  • Health Savings Account (HSA) limit-tracking details, if you record an HSA as an asset: the coverage tier you select (family or self-only), whether you mark an account holder as age 55 or older (which changes the IRS catch-up allowance), and an optional amount you enter for contributions already made this calendar year that aren't logged as transactions, together with the year that amount applies to. The contribution amount is encrypted at rest with AES-256; the coverage tier, the age-55 flag, and the year are stored as plaintext. We collect no diagnoses, claims, providers, or any other medical information — these values are used solely to show your progress against the published IRS annual limit inside the app, and are never shared with third parties, used for advertising, or supplied to any insurer.
  • Reimbursable expense notes — free-text memos you add when marking part of a transaction as expected to be paid back by a third party (e.g. a friend, employer, or insurance). Encrypted at rest with AES-256; never shared with third parties.
  • Amount adjustment reasons — optional free-text notes you supply when you manually override the amount on an imported transaction (e.g. “added $10 cash tip”). Encrypted at rest with AES-256; never shared with third parties. The original bank-reported amount is also retained internally so duplicate detection keeps working after an override.
  • Dedup feedback — your confirmations of fuzzy-duplicate matches in the import preview, along with the incoming row's date, description, and amount at the time of confirmation. Encrypted at rest with AES-256; used solely to improve our duplicate-detection logic and never shared with third parties.
  • Subscription cancellation reason and optional comment — if you cancel your subscription in-app, we record which reason you selected from the cancellation survey (e.g. “Too expensive”, “Not using it enough”) and, if you choose to provide one, a free-text comment. The reason is stored as plaintext; the free-text comment is encrypted at rest with AES-256. This information is used solely to understand churn and improve the product — it is never shared with third parties.
  • In-app satisfaction feedback — an optional 1–5 star rating and an optional free-text comment you submit through the in-app feedback prompt. The comment may contain whatever you choose to write. Encrypted at rest with AES-256; used solely to improve BudgetLabs and never shared with third parties or published as a public review.
  • Receipts and source artifacts you choose to attach to a transaction — receipt photos, dropped emails (raw .eml, HTML body, or plain text), or uploaded statement PDFs / images. Stored in your private receipts bucket on Supabase Storage, scoped to your account by row-level security, served only via short-lived signed URLs you request, never shared with third parties. You can remove a receipt at any time by clearing it from the transaction.
  • Peer-debt loan records — if you lend to or borrow from another BudgetLabs member on a different budget (for example, a family loan), we store the loan's principal amount, a description, and its payment history, encrypted at rest with AES-256. If you propose a loan, we also collect the invitee's email address (encrypted at rest, plus a one-way hash used only to match their sign-in to the invitation) to send a one-time invitation link. See “Sharing Your Data with a Peer-Debt Counterparty” below for who can see this information.

Note: We do not collect, store, or process actual bank account numbers, credit card numbers, or login credentials for financial institutions.

Newsletter Subscription (no account required)

You can subscribe to our email newsletter from our blog or the site footer without creating an account. If you do, we collect:

  • Your email address, encrypted at rest with AES-256.
  • Which page you subscribed from — an internal tag such as blog-<article> or site-footer, so we know which article brought you in. It contains no browsing history.
  • The dates you subscribed, confirmed, and (if applicable) unsubscribed, and your current subscription status.

Subscribing is double opt-in: after you submit the form we email you a single-use confirmation link, and you are not added to the list until you click it. If you never click it, we send you nothing further — the only way another confirmation email is sent is if the form is submitted with your address again, and even then we will not send one within 15 minutes of the last. We use your address for one purpose only — sending the newsletter — and every newsletter email carries a one-click unsubscribe link. We do not sell or share this list, and subscribing does not create a BudgetLabs account.

If you also hold a BudgetLabs account, your newsletter subscription is tracked separately from your account's email preferences: unsubscribing from one does not unsubscribe you from the other, and each email tells you which list it came from.

Usage and Device Data

We may collect limited usage data (e.g., device type, browser, IP address) and use cookies or similar technologies for analytics and performance. You can manage cookie preferences through your browser settings.

We also record in-app interaction events tied to your account — specifically, which feature-discovery tips and What's New announcements we show you (e.g. a suggestion to try Smart Import or ask Hank a question) and whether you dismissed or acted on them — solely to improve how we surface features you haven't tried yet.

Separately, we record which features you open and which actions you take while signed in — for example, that you visited the Debt page, or that you added a transaction — so we can see which parts of BudgetLabs are actually used and which aren't, and improve the product accordingly. This is product analytics: it is tied to your account internally, but it is never shared with third parties, shown to other users, or used for advertising.

Cookies and Browser Storage

We keep the browser-storage footprint small and first-party. What we store falls into two groups:

  • Essential (required for the service to work):your sign-in session (so you stay logged in), an optional trusted-device token if you choose to skip two-factor prompts on a device for 30 days, a cached copy of your subscription status so the app can render without re-checking on every page, how you found us (the referral tag from a link you clicked), and your interface preferences (e.g. which dashboard view you last used, and your budget's currency and number format so amounts render correctly on first paint).
  • Analytics: Google Analytics cookies, used to understand which pages and articles people find useful. These are not required for the app to function. Separately, while you are signed in, opening a feature writes a sessionStoragekey holding a timestamp — one per feature — so we don't record the same feature-view event (see “Usage and Device Data” above) more than once every 30 minutes in that browser tab. It holds no content beyond the timestamp and clears when the tab session ends.

We do not use advertising or cross-site tracking cookies, and we do not sell or share this data. We do not set Google Analytics, or any other third-party or advertising analytics storage, for visitors in the EEA, UK, or Switzerland. The first-party feature-view timestamp described above is written the same for those visitors as for everyone else — it is not a cookie and carries no advertising or cross-site purpose. See Service Providers below for who processes analytics on our behalf.

How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our budgeting services
  • Track budgets, process transactions you enter, and show your progress
  • Send service-related notifications and account updates
  • Occasionally email you product updates, a short note from the founder asking for feedback, or an automated message based on your in-app activity (for example, a reminder to finish setting up, or a check-in if you've gone quiet). These are marketing messages — every one includes a one-click unsubscribe link, and you can opt out at any time without affecting your account or any transactional email.
  • Send our email newsletter, if you subscribed to it and confirmed that subscription. We use a newsletter subscriber's address for that and nothing else — it is not used for advertising, not combined with account data to profile you, and not shared with anyone.
  • Respond to your requests and provide customer support
  • Collect and review optional in-app ratings and feedback you submit, to understand satisfaction and improve the product
  • Detect, prevent, and investigate fraud or abuse
  • Analyze usage to enhance features and performance

Data Storage and Security

We implement commercially reasonable technical, administrative, and physical safeguards to protect your information, including:

  • Encryption in transit: All connections to BudgetLabs use HTTPS/TLS.
  • Encryption at rest: Sensitive financial fields are encrypted with AES-256 at the column level inside our database, so the stored values are unreadable without the encryption key. The key is held in a managed secrets vault — never in application code or source control.
  • Row-level security: Every record is access-scoped to its owning user at the database layer; users cannot read or modify other users’ data even by direct database query.
  • Optional two-factor authentication (TOTP): You can enable 2FA in Settings → Security to require a 6-digit code on each sign-in.
  • Trusted-device tokens: If you opt to trust a device for 30 days, we store a one-way hash of a per-device token (not the token itself), the device’s user-agent string, and the IP address used at the time of opt-in, so you can review and revoke trust later.

Important: No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

You are responsible for keeping your account credentials confidential and for all activities that occur under your account.

AI Features and Third-Party Processing

BudgetLabs includes optional AI-assisted features (collectively, "Hank" — the in-app chat assistant, AI-powered transaction import, AI-powered receipt scanning, AI-powered bill scanning (for upcoming-bill scheduling), and an MCP server for connecting external AI agents). When you use these features, certain inputs and the relevant context required to answer your question are sent to third-party AI providers for processing.

Specifically:

  • The in-app chat assistant routes your messages, plus a limited slice of your budget data needed to answer them (for example: requested category names, transaction details, or spending summaries), to xAI (Grok) via the Vercel AI SDK.
  • AI-powered import (pasted text, CSV / spreadsheet, uploaded bank-statement PDFs, and uploaded statement images), receipt scanning, and bill scanning (photos of upcoming-bill invoices, PDF bills, or emails / pasted text dropped into the “Add bill” modal, for extracting vendor / amount / due-date / supporting notes) send the file contents, email body, or image you submit to xAI for parsing into structured transaction or bill fields. Uploaded files are processed in memory and are not retained by BudgetLabs after parsing.
  • AI-powered investment statement scanning (brokerage, retirement, or crypto account statements you drop onto an asset account's Holdings section, as a PDF or an image) sends the file contents to xAI for parsing into structured holdings fields — ticker symbol, security name, asset class, market value, share count, cost basis — plus the account's stated total value and statement date. Nothing is saved to your account until you review the extracted holdings and press Save. The uploaded file is processed in memory and is not retained by BudgetLabs after parsing.
  • If you connect an external AI agent (Claude, ChatGPT, etc.) to BudgetLabs via our MCP server, the queries you make through that agent and the responses we return travel through that third-party agent’s provider; their privacy policy governs their handling of those exchanges.
  • When you submit the support form, the contents of your message and the subject you chose are sent to xAI so it can draft suggested replies for our support team. The drafts are only ever read by a human, who writes and sends the actual reply — no automated response is sent to you.

We do not use your data to train third-party AI models. We do not share AI inputs or outputs with advertisers.

Separately from these in-app features, we use Anthropic (Claude) to generate our public blog content. That pipeline contains no user data — nothing you enter in BudgetLabs is ever sent to Anthropic.

These AI features are optional. You can avoid sending data to xAI by not using the chat assistant, AI import, receipt scanning, bill scanning, investment statement scanning, or the support form. You can revoke external MCP integrations at any time from Settings → API & Integrations.

Data Sharing and Disclosure

We do not sell your personal information. We may share information in these limited circumstances:

  • Service Providers (subprocessors): With trusted third parties who help us run the Service, including:
    • Microsoft Azure — application hosting (Azure Web App) and email delivery via Azure Communication Services, covering both transactional email (e.g. password reset, sign-up confirmation, family invites) and product / marketing email.
    • Supabase — managed Postgres database, authentication, and file storage.
    • xAI (via the Vercel AI SDK) — large-language-model processing for the in-app chat assistant, AI-powered import (pasted text, CSV / spreadsheet, PDF, and image uploads), receipt scanning, bill scanning, investment statement scanning, and drafting suggested replies to support requests. See "AI Features and Third-Party Processing" above.
    • Anthropic (Claude) — generates our public blog content; no user data is ever sent to it.
    • Stripe — payment processing for web subscriptions. We do not store full payment-card numbers.
    • RevenueCat, in conjunction with the Apple App Store and Google Play — in-app purchase processing on mobile. Payment-card and billing details are handled by Apple or Google directly under their privacy policies.
    • Google Analytics and Google Search Console (Google) — aggregate usage, performance, and search-traffic analytics for our marketing site and app, read server-side via Google's Data APIs to power internal dashboards.
    • YouTube (Google) — embedded product-demo video on the marketing site, served from the privacy-enhanced youtube-nocookie.com domain. No cookies are set until you play a video; once you play one, YouTube receives your IP address and may set cookies under Google's privacy policy.
    • SaaSHub — we display an “Approved on SaaSHub” badge in the footer of our public marketing and content pages, loaded from SaaSHub's image CDN. Because your browser fetches that image, SaaSHub receives your IP address, browser user-agent, and the page you were viewing. No account or budget data is sent, and the badge is not shown on signed-in app pages.
  • Legal Requirements: When required by law, subpoena, or government request
  • Protection of Rights: To protect our rights, safety, or property, or that of our users
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

Sharing Your Data with Family Members

If you turn on Family Sharing and invite another person to join your budget, that person — once they accept — can see and modify the transactions, categories, monthly plans, debts, savings goals, and other budget data in the budget you share with them. Members of a shared budget can also see each other's name and email address, along with all financial data within the shared budget. Family Sharing is opt-in per invite; nothing is shared until you send an invite and the recipient accepts it.

You can revoke a pending invite at any time before it's accepted, and you can remove a member after they've joined. A member can also leave on their own. When someone leaves or is removed, any transactions they entered into the shared budget remain part of the budget's history so your accounting record stays intact; their personal authentication link to those records is removed.

We do not share your data with the family member's employer, advertisers, or any third party as a consequence of Family Sharing. The other party is a fellow BudgetLabs user who you have authorized to see this budget.

Sharing Your Data with a Peer-Debt Counterparty

Peer debt lets one BudgetLabs member lend money to another member on a separate, unconnected budget — for example, a parent lending an adult child. If you propose a loan, we use the invitee's email address to send a one-time invitation, to confirm the person who accepts is the one you invited, and — for as long as the loan stays open — to identify them to you on your Assets page (you will not learn their name through this feature). If you receive a proposal, both the invitation email and the in-app acceptance page tell you who is proposing it — by first name only, never their email address — and state the amount and description before you decide whether to accept. Accepting requires signing in with the exact email address the invitation was sent to; previewing those terms on the acceptance page does not — anyone signed in who has the one-time invitation link can see them, which grants no more than that same link already lets someone do by using it to accept.

Once a loan is accepted, both of you can see its principal amount, description, and payment history. Because access is granted to anyone who belongs to either linked budget rather than to one individual, so can anyone else on a shared Family Sharing budget either of you belongs to. This is inherent to the feature: a shared, honest record between two households is the whole point, and the person receiving a proposal can always decline — before accepting, the loan is not independently discoverable by anyone in the app; only the lender's household can see it as an ordinary record, and the only other way to see its terms is with the one-time link that was emailed to the invitee. BudgetLabs does not move money. The loan record only reflects that a payment happened outside the app — by cash, bank transfer, or a third-party payment service you and the other party choose.

If the lender forgives the loan, it is marked forgiven and the record is kept, not erased. If the lender's account is deleted, the loan record and its payment history are likewise kept for the borrower rather than erased, and only the connection to the lender's identity is cleared; from her Debt page, the borrower can then either keep the outstanding balance as her own personal debt record or close the loan outright, so it does not sit unresolved. If the borrower's account is deleted, no new payments can be recorded against the loan, though a payment she already submitted can still be confirmed or rejected afterward.

We do not share peer-debt data with anyone outside the accounts involved (and, where applicable, their shared-budget co-members) — never with employers, advertisers, or other third parties.

Your Rights and Choices

Depending on where you live, you may have the right to:

  • Right to know / access: request a copy of the personal information we hold about you and how we use it.
  • Right to correct: update or correct your personal information.
  • Right to delete: delete your account and associated personal information.
  • Right to portability: receive an export of your data in a machine-readable format. You can download your budget and account data anytime from Settings → Profile ("Download my data") or via /api/export while signed in — no support request needed. That export does not include the feature-usage event data described under “Usage and Device Data” above; if you'd like a copy of it, contact us using the details below and we will provide it.
  • Right to opt out of sale or sharing: we do not sell your personal information and do not share it for cross-context behavioral advertising. You may still exercise this right at any time.
  • Right to non-discrimination: we will not discriminate against you for exercising any of these rights.
  • Right to opt out of promotional communications: use the unsubscribe link in any marketing email or contact us directly.

California residents (CCPA / CPRA): you may also designate an authorized agent to make a request on your behalf, and you may appeal a denied request by contacting us at the address below.

EEA / UK / Swiss residents (GDPR / UK GDPR): our legal basis for processing your personal data is (a) the performance of our contract with you, and (b) our legitimate interests in operating and improving the Service. We do not run analytics cookies for visitors in the EEA, UK, or Switzerland — Google Analytics is disabled entirely for those visitors, so we do not rely on consent as a legal basis and you will not be asked for it. When we make a material change to this policy we will tell you in the app and ask you to confirm you have seen it — that is a notice, not a request for consent, and there is nothing for you to decline. (Our Terms of Service are a contract and are handled differently: those we do ask you to accept.) You have the right to lodge a complaint with your local data protection authority.

To exercise any of these rights, contact us at contact@budgetlabs.io. We will respond within the timeframes required by applicable law (45 days under CCPA; 30 days under GDPR, extendable by an additional 60 days for complex requests).

Data Retention

Your record of accepted or acknowledged legal documents is kept for as long as your account exists, and is deleted with it. We keep every response rather than only the most recent, because the point of the record is the history of what you agreed to.

We retain your account information (e.g., email, name) for as long as your account remains active. Financial data you enter is retained for the life of your account plus up to 90 days after deletion for backup and recovery purposes.

If you close the transaction import tool before finishing, we save your in-progress work (parsed transactions, categorizations, and similar edits) so you can resume it later. That draft is stored encrypted and is automatically deleted after 30 days, or immediately once you complete or discard the import.

When you submit the support form, your message and the email address it was sent from are also retained as business correspondence in the mailbox we use to manage support, separately from your account record, and are not subject to the periods described above.

Individual feature-view and feature-action events (see “Usage and Device Data” above) are retained for 90 days, after which they are deleted. Before deletion, each day's events are folded into a daily per-feature count with no individual timestamps — those aggregate counts are kept for as long as your account is active, the same as other usage statistics.

Newsletter subscriptions are retained until you unsubscribe. When you unsubscribe we keep your address, marked as unsubscribed, so we can honor that choice and avoid mailing you again — the record of your opt-out is the mechanism that enforces it. If you would rather we erase it entirely, email us and we will. An address that never confirms its subscription is retained as an unconfirmed request; we send it nothing further unless the form is submitted with that address again. Deleting a BudgetLabs account also removes any newsletter subscription held under the same address.

If you do not sign in or otherwise use BudgetLabs for 12 consecutive months, we treat your account as inactive and will delete it along with its data, as described above. We will email you a warning approximately 30 days before deletion and again approximately 7 days before — signing in at any point cancels the deletion and keeps your account active. Accounts with an active paid subscription are never deleted for inactivity, and we do not delete an inactive account whose shared budget is still being used by another member.

After account deletion, we will delete or irreversibly anonymize your personal data within a reasonable period, unless we are required to retain it for legal, compliance, or security reasons. When your account is deleted, we also delete your Stripe customer record and request deletion of your RevenueCat subscriber record (for mobile subscriptions).

Children’s Privacy

BudgetLabs is not directed to or intended for use by children under the age of 13. We do not knowingly collect, use, or disclose personal information from children under 13 without verifiable parental consent, in accordance with the U.S. Children’s Online Privacy Protection Act (COPPA).

If you are a parent or guardian and believe your child under 13 has provided us with personal information without your consent, please contact us immediately at contact@budgetlabs.io. We will promptly delete such information from our records.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the revised policy here and update the "Last updated" date.

For material changes, we will give at least 30 days’ notice and ask you to accept them. We will tell you in the app before the change takes effect, and once it does we will ask you to accept the updated policy. We record which version you accepted and when, so there is a clear record of what you agreed to. Minor corrections that do not change what we collect or how we use it are posted without a prompt.

If you decline, we record that as well, and you may accept later at any time. Declining never removes your access to your own information: you can view, export, and delete your data at any point, regardless of your answer. If you continue using BudgetLabs without responding to a material change after its effective date, that continued use constitutes acceptance.

Contact Us

If you have any questions about this Privacy Policy, please contact us:

Hollow Holdings, LLC

Email: contact@budgetlabs.io

Website: www.budgetlabs.io