Legal centrePrivacy and data

Budget Privacy Policy

Last updated: 29 July 2026

Budget is a local-first personal budgeting app. Entries, categories, notes, limits, preferences, imported files, and locally generated statistics stay on the device unless the user deliberately uses an online feature described below.

Budget does not sell personal data, show third-party advertising, or use financial information for advertising.

Data processed by feature

Account

Firebase Authentication processes the email address, sign-in provider, provider profile name (when supplied), and Firebase account identifier needed to sign in. A free signed-in account does not by itself upload the local budget to Firestore.

Google Play subscriptions

Google Play processes payment details. Budget receives the product identifier, purchase token, subscription state, and expiry needed to verify Premium access. Budget does not receive full payment-card details. Purchase records are kept in client-inaccessible Firestore so missed subscription events can be reconciled with Google Play.

Premium cloud sync and Shared expenses

If cloud sync is enabled, the user's budget records and synchronization metadata are stored in Cloud Firestore. Shared expenses additionally store the Shared profile, random Shared ID, group membership, invitations, participants, expenses, payer and split information, and the display names needed by group members.

These features can contain financial information such as dates, descriptions, categories, amounts, notes, limits, and balances. They are sent only when the user enables cloud sync, joins or creates a Shared group, or performs another explicit cloud action.

Firebase Cloud Messaging processes an installation push token when notifications are enabled for Shared activity.

Premium AI

When a Premium user deliberately uses Assistant, AI Charts, screenshot import, voice input, voice output, or category icon creation, the Publish app sends the request through the Budget Cloudflare Worker. The Worker verifies Firebase Authentication, Firebase App Check, and the current Premium entitlement, then sends the necessary request to OpenRouter and the selected model provider.

Depending on the chosen AI feature, the transient request can contain:

Budget's Worker does not persist screenshots, audio, tool arguments/results, or request/response bodies in application logs. While Share Assistant diagnostics is enabled in AI Settings, Budget stores Assistant questions or recognized transcripts, model replies/text sent to speech, model, locale, prompt revision, random request references, and tool names for owner debugging for no more than 30 days. This text can contain amounts, categories, merchants, or notes that appeared in the interaction. Users can stop future collection at any time by unchecking the setting.

OpenRouter prompt/response logging is not enabled by Budget. Chat, screenshot, transcription, and category icon calls require a zero-data-retention route and deny providers that declare data collection. If no compatible route exists, the request fails. The current speech-output route also denies data-collecting/training providers, but it cannot currently require a compatible zero-data-retention endpoint. OpenRouter and the selected model provider may therefore process limited speech request metadata or retain speech content for their documented operational period. Users can leave voice output disabled.

Necessary AI accounting and diagnostics

Cloudflare keeps bounded data needed to enforce allowances, control provider cost, support subscribers, investigate reliability, and understand aggregate AI-feature use:

The private One Ring owner tool can list and search these bounded records and open the content-free diagnostic history. The directory is not included in the Publish APK and every endpoint requires a high-entropy owner token.

Cloudflare does not store the raw Firebase identifier, Shared ID, purchase token, tool arguments/results, screenshot, audio, category-icon prompt, or generated icon in AI accounting, diagnostics, or the owner directory. Assistant questions and replies collected under the user's diagnostics setting are stored in that account's pseudonymous support record, not the owner directory. Other AI request/response content remains excluded.

Security and operational metadata

Firebase App Check with Play Integrity helps confirm that protected calls come from a genuine app installation. Google processes the associated integrity signals. Firebase, Cloudflare, OpenRouter, the selected model provider, and Google Play can also process ordinary network and security metadata such as IP address, timestamps, request size, status, and device/app information under their own terms.

Budget does not currently include a Firebase Analytics product-usage SDK, Crashlytics, or Firebase Performance Monitoring. Google Play and Android Vitals may still provide the developer with aggregated store and technical-quality information.

Retention

Account and data deletion

The in-app Account → Delete account and data action asks Google Play to cancel future renewal, deletes the Firebase Authentication account, private cloud-sync data, Shared profile and invitations, billing links, push tokens, Firebase AI counters, and Cloudflare quota, cost, diagnostic, Assistant interaction, and owner-directory state.

Groups owned by the deleted account are deleted for all participants. In a group owned by another person, historical expenses are retained for the other participants but the deleted identity is replaced with a non-identifying deleted-user label. Local data on the device is not deleted by the cloud account action. Payments already made are not refunded. If subscription cancellation or required cloud cleanup cannot be confirmed, Budget does not claim that deletion succeeded and leaves the account available for a retry.

A seven-day Firebase deletion tombstone and content-free Cloudflare deletion blockers prevent old signed-in devices, in-flight AI requests, or delayed billing notifications from recreating deleted cloud data. They are then scheduled for automatic deletion.

Users who no longer have the app can use the public account-deletion page listed in Budget's Google Play store entry. That page must be published with a working support request route before public release.

Service providers

Budget uses:

These processors handle data under their own terms and privacy notices.

Security

Online traffic uses HTTPS. Firebase rules, server-side entitlement checks, App Check, client-inaccessible billing collections, bounded inputs, rate limits, and restricted owner endpoints reduce unauthorized access. No online service can be guaranteed completely secure, so Budget minimizes stored backend data and does not retain normal AI content.

Contact and changes

Privacy and support questions can be sent to hello.aisstudios@outlook.com. Users can review the current Privacy Policy and Account Deletion instructions at this legal centre.

Material changes to this policy will be published with a new effective date.