Budget Guide
PrivacyTermsSupportReturn to app

PRIVATE APP PRIVACY

Your financial plan is sensitive. We treat it that way.

This notice covers the account-based app at app.budgetguide.org. The public calculator has a separate session-only policy.

Effective August 16, 2026 · Invite-only US beta

What we keep

We keep your account profile, household permissions, confirmed budget facts, normalized monthly snapshots, goals, plans, check-ins, review history, subscription status, and limited security and operational records. These records are tied to your login so your plan is available when you return.

Statements and images

Uploaded statement files, page images, extracted text, and raw transaction descriptions are temporary processing inputs. They are processed in the active browser session and are not saved as account records. Only the normalized facts you review and confirm can enter your saved plan.

Connected accounts

If you choose Plaid, your institution and Plaid process the accounts and Transactions data you authorize. Budget Guide keeps an application-encrypted Plaid connection token, its sync cursor and health, opaque provider identifiers, and the minimum normalized transaction evidence needed for later reviews. We do not receive or keep your bank password, full account or routing numbers, or raw Plaid response bodies.

Future check-ins request changes since the last successful sync. You may disconnect from the app at any time; Budget Guide then asks Plaid to revoke access before marking the connection disconnected. Deleting your account also attempts remote revocation first and stops rather than claiming success if revocation fails.

Households

Every adult uses a separate login. Personal records stay visible only to their owner. A member sees a row only after its owner marks it Shared; contribution-only rows share a total without exposing the underlying personal lines. Supporters are view-only. Household owners can remove access, and invitations expire and work once.

Service providers

Supabase provides account identity and protected database storage. Plaid provides optional financial-account connectivity. RevenueCat and Stripe support subscriptions and payment processing. Resend supports account email. Google supports optional sign-in. Paper Boy Studios receives privacy-minimized product telemetry that excludes names, email, account IDs, financial values, descriptions, filenames, and typed text.

Deletion, retention, and security

You can export your data and request self-service account deletion inside Household and account controls. Shared-household owners must transfer or delete the household first. Confirmed records remain while the account is active; operational rate-limit records are short-lived, and provider event records contain no financial payload. Encrypted transport, row-level authorization, server-only provider credentials, rate limits, and redacted operations records reduce risk, but no online service can promise zero risk.

Your choices

Manual entry and statements remain alternatives to connected accounts. You can decline account linking, choose which accounts to authorize, correct categories, keep facts Personal, disconnect an institution, cancel a subscription, export your data, or delete the account. Contact paperboystudiosco@gmail.com for a privacy or security request. Do not email statements, passwords, Social Security numbers, account numbers, or access tokens.

Age and advice boundary

The invite-only beta is for adults in the United States. Budget Guide provides educational planning tools, not individualized financial, legal, tax, credit, investment, or benefits advice.