Budget Assistant Privacy Policy
Effective date: August 21, 2026 Version: 2026-08-21
This Privacy Policy explains how Budget Assistant collects, uses, discloses, retains, and protects information. Contact us at support@mail.budget-assistant.com.
By continuing as a guest, creating an account, signing in, subscribing, importing or configuring Shortcuts or automations, submitting data, clicking an acceptance checkbox, or continuing to use Budget Assistant after this Privacy Policy is presented, you agree to the collection, use, and disclosure described here.
1. Layered privacy summary
- We collect guest or registered identity, installation-integrity, subscription, budget, transaction, Shortcut/setup, support, legal acceptance, and diagnostic information needed to operate Budget Assistant.
- Budget and transaction information can be sensitive because it may reveal financial habits, locations, relationships, health, religion, or other personal inferences.
- We use information to provide budgeting features, authenticate accounts, process subscriptions, secure APIs, send transactional service emails, support users, troubleshoot, and comply with legal/security obligations.
- We share information with service providers such as Apple, Google, RevenueCat, app stores, hosting/database providers, email providers, and monitoring tools as needed to operate the service.
- Budget Assistant does not currently send your personal financial data to AI or model providers. Future AI-assisted features require updated notice and fresh consent where required before launch.
- Budget Assistant is a general-audience service. A minor may use it only with the consent and supervision of a parent or legal guardian, who must manage consent on the minor's behalf when the minor cannot provide meaningful consent.
- You can request access, correction, deletion, or export by contacting support@mail.budget-assistant.com. In-app account deletion is also available where supported by the app.
2. Information we collect and why
| Category | Examples | Main purposes |
|---|---|---|
| Guest, account, and identity | Budget Assistant user ID, guest or registered status, optional email address, preferred language, OAuth provider identifiers, linked-provider state, display name or name from Apple or Google, sign-in state | Create and secure guest or registered access, authenticate you, link an optional sign-in method without merging profiles, personalize basic settings, provide support |
| Subscription and entitlement | Plan tier, billing period, product IDs, Budget Assistant user ID used with RevenueCat, entitlement state, transfer, renewal/expiration, and app store payment metadata | Process purchases, verify access, restore or transfer eligible subscription access, prevent billing abuse, send transactional subscription notices |
| Budget inputs | Income, fixed obligations, savings targets, budget periods, currencies, category names, notes | Build budgets, dashboards, calendars, reports, and cashflow summaries |
| Transactions | Amount, merchant, category, date/time, currency, notes, imported Shortcut or automation payloads, local date metadata | Record and display transactions, support Apple Pay-related review flows, calculate summaries and reports |
| Installation integrity, Shortcut, API, and security | App Attest key identifier, attestation receipt and public key, assertion counters, app/bundle/environment validation signals, restricted fallback installation ID and hashed secret, API key prefixes, hashed key material, key type/status, access timestamps, login/session timestamps, API usage events, IP address, user agent | Verify a legitimate app installation, bind guest recovery and sensitive actions, prevent replay and abuse, provision and revoke capture keys, secure APIs, troubleshoot, preserve limited audit evidence |
| App diagnostics | App version, build number, operating system, setup status, feature usage, logs, errors, timing metrics | Monitor reliability, debug issues, improve performance, support account and device-specific troubleshooting |
| Support communications | Messages, attachments, email address, request details, reply history | Respond to support, privacy, billing, and security requests |
| Legal acceptance | Terms version, Privacy Policy version, content hashes, acceptance source, IP address, user agent, app version/build | Record auditable consent evidence and determine when re-consent is required |
Do not submit unnecessary sensitive information. Budget Assistant is not designed to store highly sensitive personal information beyond what is needed for the budgeting features you choose to use.
3. How we collect information
We collect information directly from you, from your mobile app, from iOS Shortcuts and automations you configure, from backend APIs, from Apple's App Attest and Apple or Google OAuth identity signals, from RevenueCat and app store entitlement signals, from logs and diagnostics, and from support interactions.
If you use Apple Pay-related Shortcuts or automations, you control whether those automations run and what information they send. You should review Shortcut actions before importing or using them.
For guest access, the backend creates a Budget Assistant user ID after app-installation verification. Budget data is stored on the backend under that ID, while the credential needed to recover an unlinked guest remains tied to the app installation. App Attest is used for app integrity and session assurance, not as a permanent physical-device identifier or for cross-app advertising tracking.
4. Purposes, consent, and choices
For Canadian users, we aim to collect, use, and disclose personal information for reasonable purposes and with meaningful consent where required by applicable privacy law. Some processing is necessary to provide the service you request, authenticate you, process subscriptions, secure APIs, or comply with legal obligations.
Where a person cannot provide meaningful consent because of age or capacity, a parent or legal guardian must provide consent and manage the person's use of Budget Assistant on their behalf.
| Purpose | Is it required for current service? | Choice or consequence |
|---|---|---|
| Guest or registered identity, authentication, installation assurance, and security | Yes | Without this information, we cannot provide protected guest or registered service; linking Apple or Google remains optional |
| Budgeting, transaction tracking, reports, and categories | Yes for features you choose to use | You can choose what budget/transaction details to enter, but missing data may reduce accuracy |
| Subscription and entitlement verification | Yes for paid access | Without purchase/entitlement signals, paid access may not activate or restore |
| Transactional service emails and support replies | Yes when needed | These are service communications; current public features do not send marketing emails |
| Diagnostics, abuse prevention, and audit evidence | Yes where reasonably needed | You may stop use or request deletion, subject to limited retention exceptions |
| Future marketing messages | No current feature | Marketing emails require consent and unsubscribe handling where required before launch |
| Future AI-assisted processing | No current feature | Financial data will not be sent to AI/model providers unless the feature launches with updated notice and required consent |
You may withdraw consent by stopping use, deleting your account where available, or contacting us. Withdrawal may limit or prevent use of Budget Assistant.
5. Service providers and disclosures
We may disclose information to service providers that help operate Budget Assistant. We aim to limit disclosure to what is reasonably needed for the service provider's role.
| Provider or category | Role | Information involved |
|---|---|---|
| Apple | App Attest, Sign in with Apple, App Store purchases, iOS, Wallet/Shortcuts platform services, subscription management, app review | App-installation integrity and validation signals, identity signals, purchase/subscription metadata, device/platform signals, Shortcut/automation data you configure |
| Google sign-in and identity services | Identity signals such as email, provider identifiers, and display name where provided | |
| RevenueCat and app stores | Subscription purchase, entitlement, restore, cancellation, refund, and webhook workflows | Customer IDs, product IDs, entitlement state, purchase/renewal/expiration signals, account identifiers |
| Hosting, database, and storage providers | API hosting, database storage, backups, network delivery | Account, budget, transaction, support, security, diagnostic, and legal acceptance records |
| Email provider | Transactional service emails and support replies | Email address, subscription/service message content, support contact details |
| Logging, monitoring, and security tools | Reliability, troubleshooting, abuse prevention, audit logs | Logs, IP address, user agent, device/app metadata, error and timing data |
| Professional advisers, authorities, or other parties | Legal, security, accounting, tax, dispute, or compliance needs | Limited records where required or permitted by law |
These third parties may process information under their own terms and privacy policies. By using features involving those services, you also agree to applicable third-party terms.
6. Retention and deletion
We retain information for as long as reasonably needed to provide Budget Assistant, maintain security, support subscriptions, troubleshoot issues, comply with legal/tax/accounting obligations, resolve disputes, enforce terms, prevent fraud, and maintain audit records.
| Record type | Typical retention while account is active | After account deletion or request |
|---|---|---|
| Account, budget, transaction, category, and note data | Retained while needed to provide app features | Deleted or de-identified where reasonably possible, subject to backups and limited legal, security, billing, tax, dispute, anti-abuse, and audit exceptions |
| App Attest, fallback installation, API key, and usage records | Retained while installation/session/key access is active and as needed for security/audit | Revoked and deleted or de-identified where reasonably possible; App Attest receipts, key IDs, and fallback secrets are not retained in the app-owned user record after deletion, subject to limited security/audit exceptions |
| Legal acceptance records | Retained while needed to prove current acceptance and re-consent status | Deleted or retained only where required or permitted for legal/audit purposes |
| Subscription and entitlement records | Retained while needed to provide access, support billing, and resolve disputes | Some records may remain with Apple, RevenueCat, app stores, or payment providers under their own policies |
| Support communications | Retained while needed to handle the request and maintain support history | Deleted or de-identified on request where reasonably possible, subject to legal/security exceptions |
| Logs, diagnostics, and backups | Retained for operational, security, troubleshooting, and backup windows | Backup deletion may take additional time; logs may be retained in limited form for security, abuse prevention, and audit needs |
If you delete your account or guest data through available in-app deletion features or request deletion from us, we will delete or de-identify personal information where reasonably possible, subject to the exceptions above. Deletion does not cancel an Apple subscription, and Apple or RevenueCat may retain provider-side billing records under their own policies. We do not promise instant deletion of every backup, log, provider, or legally retained record.
7. International transfers
Budget Assistant and its service providers may process and store information in Canada, the United States, or other countries. Privacy laws in those countries may differ from the laws where you live. Service providers may be required to disclose information to courts, law enforcement, regulators, or government authorities in those jurisdictions where legally required.
8. Security and breach contact
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted transmission where supported, App Attest or restricted installation assurance, one-time challenges, replay counters, hashed API keys and fallback secrets, and server-side authorization checks. No system is perfectly secure. You are responsible for protecting your device, guest installation access, OAuth account, API keys, and Shortcuts.
If you believe your account, API key, Shortcut, or Budget Assistant data has been exposed or misused, contact support@mail.budget-assistant.com promptly.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, object to, or complain about processing of personal information. You can contact support@mail.budget-assistant.com to make a request. We may need to verify your identity before responding.
Canadian users may contact us with privacy questions or complaints. If unresolved, they may be able to contact the Office of the Privacy Commissioner of Canada or another applicable privacy regulator.
10. Children's privacy
Budget Assistant is a general-audience personal budgeting service and is not designed specifically for children. A person who has not reached the age of majority where they live may use Budget Assistant only with the consent and supervision of a parent or legal guardian as described in the Terms of Use.
For anyone unable to provide meaningful consent, including in most circumstances a child under 13, the parent or legal guardian must provide consent and manage use of Budget Assistant on that person's behalf. Parents and legal guardians should avoid entering unnecessary personal information about a minor and may contact us to request access, correction, or deletion. If we learn that a minor's personal information was collected without consent required by applicable law, we will take appropriate steps, which may include restricting the account or deleting the information.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we may require you to accept a new version before continuing to use Budget Assistant. Continued use after an update means you accept the updated Privacy Policy.
12. Contact
Privacy questions, requests, or complaints can be sent to support@mail.budget-assistant.com.