Privacy notice.
This summary describes the product's current data flows and request process. A counsel-reviewed privacy policy is required before paid self-service launch.
Data you provide
BudgetR stores account profile data and the financial records needed to render the app surfaces you use.
Connected accounts
Bank credential collection is handled by Plaid. BudgetR receives tokens and data needed to sync supported accounts; it does not ask for bank passwords.
Third-party processors
Cloudflare hosts the app and data services. Plaid provides supported bank connections and Schwab provides the optional brokerage connection. Stripe processes subscription payments when paid billing is enabled. Resend delivers account emails when email delivery is configured. Cloudflare AI is used by features that invoke it. These integrations do not all run when you visit a public page.
Household sharing
Sharing a cash account makes that account's balance and transaction activity visible to current household members. Members also see the joint monthly plan and shared review changes. Other personal models stay private. Revoking access stops further reads; it cannot erase information someone already viewed or saved.
Cookies and tracking
BudgetR sets an HTTP-only account session cookie and stores display preferences in the browser. Its first-party marketing funnel uses a random browser-tab session identifier, stores only its SHA-256 hash with fixed demo and access-request event labels, and excludes financial values, free text, email, username, and raw IP addresses. BudgetR does not install advertising trackers; Cloudflare may still process platform, security, and request telemetry as the hosting provider.
Retention
Subscription expiry does not automatically delete financial records. Verified accounts can download a financial archive from Your data. Anonymous first-party funnel events are retained for up to 180 days and pruned by production maintenance. A reviewed retention policy remains required before paid launch.
Account closure
Eligible accounts can request closure from Account exit. Product access stops during an isolation period of at least 24 hours. Erasure waits for billing and provider checks; closure does not cancel subscriptions or promise completion within 24 hours. Limited billing, security, audit and closure-receipt records remain. Closure does not erase records held by banks, Stripe or backup providers.
Demo mode
Demo accounts use synthetic data and are read-only. They cannot import Plaid or Schwab data.
Your rights and requests
Verified contact details will appear below when configured. A contact address and a reliable process for copy, correction and deletion requests are required before paid launch. This page does not submit requests or promise that an unconfigured mailbox is monitored.