Budget Privacy Policy
Last updated: 29 July 2026
Budget is a local-first personal budgeting app. Entries, categories, notes, limits, preferences, imported files, and locally generated statistics stay on the device unless the user deliberately uses an online feature described below.
Budget does not sell personal data, show third-party advertising, or use financial information for advertising.
Data processed by feature
Account
Firebase Authentication processes the email address, sign-in provider, provider profile name (when supplied), and Firebase account identifier needed to sign in. A free signed-in account does not by itself upload the local budget to Firestore.
Google Play subscriptions
Google Play processes payment details. Budget receives the product identifier, purchase token, subscription state, and expiry needed to verify Premium access. Budget does not receive full payment-card details. Purchase records are kept in client-inaccessible Firestore so missed subscription events can be reconciled with Google Play.
Premium cloud sync and Shared expenses
If cloud sync is enabled, the user's budget records and synchronization metadata are stored in Cloud Firestore. Shared expenses additionally store the Shared profile, random Shared ID, group membership, invitations, participants, expenses, payer and split information, and the display names needed by group members.
These features can contain financial information such as dates, descriptions, categories, amounts, notes, limits, and balances. They are sent only when the user enables cloud sync, joins or creates a Shared group, or performs another explicit cloud action.
Firebase Cloud Messaging processes an installation push token when notifications are enabled for Shared activity.
Premium AI
When a Premium user deliberately uses Assistant, AI Charts, screenshot import, voice input, voice output, or category icon creation, the Publish app sends the request through the Budget Cloudflare Worker. The Worker verifies Firebase Authentication, Firebase App Check, and the current Premium entitlement, then sends the necessary request to OpenRouter and the selected model provider.
Depending on the chosen AI feature, the transient request can contain:
- the question and recent assistant conversation needed to answer it;
- category, merchant, or entry labels needed for the requested task;
- locally computed totals, counts, date ranges, filters, and other aggregate financial results;
- a screenshot selected for entry extraction;
- a voice recording selected for transcription; or
- text selected for spoken output; or
- the chosen category name and expense/income type, or a custom icon prompt, plus the generated icon returned to the device.
Budget's Worker does not persist screenshots, audio, tool arguments/results, or request/response bodies in application logs. While Share Assistant diagnostics is enabled in AI Settings, Budget stores Assistant questions or recognized transcripts, model replies/text sent to speech, model, locale, prompt revision, random request references, and tool names for owner debugging for no more than 30 days. This text can contain amounts, categories, merchants, or notes that appeared in the interaction. Users can stop future collection at any time by unchecking the setting.
OpenRouter prompt/response logging is not enabled by Budget. Chat, screenshot, transcription, and category icon calls require a zero-data-retention route and deny providers that declare data collection. If no compatible route exists, the request fails. The current speech-output route also denies data-collecting/training providers, but it cannot currently require a compatible zero-data-retention endpoint. OpenRouter and the selected model provider may therefore process limited speech request metadata or retain speech content for their documented operational period. Users can leave voice output disabled.
Necessary AI accounting and diagnostics
Cloudflare keeps bounded data needed to enforce allowances, control provider cost, support subscribers, investigate reliability, and understand aggregate AI-feature use:
- a one-way pseudonymous account reference derived from the Firebase account identifier;
- daily feature request and quota-unit counts;
- the monthly category-icon generation count and remaining 5-icon allowance;
- monthly actual or conservatively estimated provider cost and remaining allowance; and
- content-free diagnostics: random request reference, feature, request kind, model identifier, prompt revision, locale, fixed result code, latency range, provider cost when supplied, and timestamp; and
- an owner-only operations directory containing verified sign-in email, optional provider display name, subscription product/source/expiry, the one-way account reference, cost/allowance summary, daily feature counters, models recently used by feature, latest result, and last activity.
The private One Ring owner tool can list and search these bounded records and open the content-free diagnostic history. The directory is not included in the Publish APK and every endpoint requires a high-entropy owner token.
Cloudflare does not store the raw Firebase identifier, Shared ID, purchase token, tool arguments/results, screenshot, audio, category-icon prompt, or generated icon in AI accounting, diagnostics, or the owner directory. Assistant questions and replies collected under the user's diagnostics setting are stored in that account's pseudonymous support record, not the owner directory. Other AI request/response content remains excluded.
Security and operational metadata
Firebase App Check with Play Integrity helps confirm that protected calls come from a genuine app installation. Google processes the associated integrity signals. Firebase, Cloudflare, OpenRouter, the selected model provider, and Google Play can also process ordinary network and security metadata such as IP address, timestamps, request size, status, and device/app information under their own terms.
Budget does not currently include a Firebase Analytics product-usage SDK, Crashlytics, or Firebase Performance Monitoring. Google Play and Android Vitals may still provide the developer with aggregated store and technical-quality information.
Retention
- Local data remains until the user edits it, clears it, uninstalls without restoring a backup, or otherwise removes it.
- Account, sync, Shared, notification, and billing-link data remains while needed for the account and is removed or anonymized through account deletion as described below.
- Pseudonymous per-account AI usage and provider-cost records are retained for no more than 90 days after their last update.
- Owner-directory email/name, entitlement and AI-operations summaries are retained for no more than 90 days after the account's last AI update.
- Content-free AI request diagnostics are retained for no more than 30 days and are also bounded to the latest 500 records per pseudonymous account.
- Assistant interactions collected while diagnostics sharing is enabled are retained for no more than 30 days and bounded to the latest 200 per pseudonymous account. Users can stop future collection in AI Settings.
- A deletion tombstone containing the Firebase account identifier, cleanup state, and timestamps is retained for no more than seven days.
- Content-free Cloudflare deletion blockers containing only an expiry are retained for no more than seven days so an already-running AI request cannot recreate deleted quota or diagnostic state.
- Budget does not archive other AI feature content. If a user voluntarily sends other support material through a separate channel, that channel's retention terms must be provided at submission.
- Files explicitly exported by the user are controlled by the user and can contain sensitive financial information.
Account and data deletion
The in-app Account → Delete account and data action asks Google Play to cancel future renewal, deletes the Firebase Authentication account, private cloud-sync data, Shared profile and invitations, billing links, push tokens, Firebase AI counters, and Cloudflare quota, cost, diagnostic, Assistant interaction, and owner-directory state.
Groups owned by the deleted account are deleted for all participants. In a group owned by another person, historical expenses are retained for the other participants but the deleted identity is replaced with a non-identifying deleted-user label. Local data on the device is not deleted by the cloud account action. Payments already made are not refunded. If subscription cancellation or required cloud cleanup cannot be confirmed, Budget does not claim that deletion succeeded and leaves the account available for a retry.
A seven-day Firebase deletion tombstone and content-free Cloudflare deletion blockers prevent old signed-in devices, in-flight AI requests, or delayed billing notifications from recreating deleted cloud data. They are then scheduled for automatic deletion.
Users who no longer have the app can use the public account-deletion page listed in Budget's Google Play store entry. That page must be published with a working support request route before public release.
Service providers
Budget uses:
- Google Play Billing and the Google Play Developer API;
- Google Firebase Authentication, App Check/Play Integrity, Cloud Firestore, Cloud Functions, Cloud Messaging, and related Google Cloud services;
- Cloudflare Workers and Durable Objects;
- OpenRouter; and
- the model provider selected for the requested AI feature.
These processors handle data under their own terms and privacy notices.
Security
Online traffic uses HTTPS. Firebase rules, server-side entitlement checks, App Check, client-inaccessible billing collections, bounded inputs, rate limits, and restricted owner endpoints reduce unauthorized access. No online service can be guaranteed completely secure, so Budget minimizes stored backend data and does not retain normal AI content.
Contact and changes
Privacy and support questions can be sent to hello.aisstudios@outlook.com. Users can review the current Privacy Policy and Account Deletion instructions at this legal centre.
Material changes to this policy will be published with a new effective date.