Privacy Policy
Last updated: 18 July 2026
1. Who we are
BudgetAIze (budgetaize.com) is operated by Kristiyan Kiryakov ("we", "us"). We are the data controller for the personal data described in this policy. You can reach us at contact@budgetaize.com for any privacy question or request.
This policy explains what personal data the BudgetAIze mobile app collects, why, who it is shared with, and the rights available to you under the EU/UK General Data Protection Regulation (GDPR).
2. Data we collect
We collect only what the app needs to function. We do not use advertising or analytics tracking.
- Account data: first name, last name, and email address, created when you register.
- Financial data you enter: transactions, budgets, categories, recurring items, debts, assets, and financial-plan progress. This data is the core content of the app and is stored so the app can work.
- Receipt images: when you scan a receipt, the photo is sent to our server and forwarded to a third-party service for text recognition (see Section 4), and the extracted text is returned to the app. The image itself is not saved to a database or storage bucket by us.
- Voice recordings: when you use a voice-input feature, the audio clip is forwarded to a third-party service for transcription (see Section 4) and is not retained by us after the transcript is returned.
- Household data:if you use shared households, we process the email addresses you invite, invitation status and expiry, and each member's role and contributions.
- Subscription and billing data: your subscription status and entitlements, managed through a third-party subscription platform (see Section 4) and the Apple App Store or Google Play. We do not receive or store your payment card details.
- Support communications: anything you send us directly, such as an email to contact@budgetaize.com.
3. Why we process your data, and our legal basis
- Providing the service (contract): storing and displaying your transactions and budgets, computing your health score and forecasts, and running household sharing.
- AI features (contract, at your request): AI-assisted analysis and content generation, each triggered by an action you take.
- Billing (contract): processing your subscription through the app stores and RevenueCat.
- Security and abuse prevention (legitimate interest): rate limiting and the shared monthly AI usage budget.
- Support (legitimate interest / consent): responding to messages you send us.
4. Who we share data with
We use a small number of processors to run the app. Each only receives the data it needs to perform its function:
- Supabase — hosts our database, authentication, and server-side functions. All of your account and financial data is stored here. (Supabase Privacy Policy)
- OpenAI — provides AI-assisted analysis, chat, transcription, and content-generation capabilities used by certain features in the app. It receives the financial summaries and questions needed to generate a response, not raw bank data (we never collect bank credentials). (OpenAI Privacy Policy)
- Google Cloud Vision — provides optical character recognition (text extraction) for images processed by the app. (Google Cloud Privacy Notice)
- RevenueCat — manages subscription status and entitlements together with the Apple App Store and Google Play. (RevenueCat Privacy Policy)
We do not sell personal data, and we do not share it with data brokers or advertisers.
5. International transfers
Supabase, OpenAI, Google Cloud Vision, and RevenueCat may process data outside the European Economic Area, including in the United States. Where this happens, we rely on the EU-U.S. Data Privacy Framework and/or the European Commission's Standard Contractual Clauses as the transfer safeguard with each processor.
6. AI features: what they do and do not do
- AI features reason over the financial summaries the app has already computed from your own data, not the open internet and not your bank accounts.
- We access OpenAI and Google Cloud Vision through their business/API products, not their consumer chat products. Under each provider's API data-processing terms, data we send them is not used to train their general AI models.
- The data we send to OpenAI never includes your name or email address. Depending on the feature, it consists of a pseudonymous account identifier, your financial figures and category names, and any free text you type (chat messages, transaction notes). We do not apply an anonymization step, because that identifier is still linkable back to your account in our own database and therefore remains personal data under GDPR even without your name attached.
- AI features share one capped monthly usage budget per household. When the cap is reached, affected features pause with a visible notice rather than failing silently or charging extra.
- AI-generated output, such as scores, forecasts, and written suggestions, is an estimate, not financial advice, and is never the system of record for your data.
7. How long we keep your data
We keep your account and financial data for as long as your account is active. Receipt images and voice audio are not retained once processed. If you delete your account, see Section 8 for what happens to your data.
8. Account deletion and shared households
You can delete your account at any time from Settings in the app. What happens next depends on your role:
- Individual account, or a household member:your authentication record is deleted, your AI caches and usage logs are removed, and your profile is anonymized (your name is replaced and your email is set to a non-identifying placeholder). Shared household transactions you contributed remain, attributed to the anonymized profile, so other members' shared history and totals are preserved.
- Household owner: deleting your account deletes the entire household, including the accounts of every member you invited. The app asks you to confirm this explicitly before proceeding.
9. Your rights under GDPR
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data (directly editable in the app for most fields).
- Erase your data (account deletion, described in Section 8).
- Receive a portable copy of your data in a common format (available from Settings in the app).
- Object to or restrict certain processing based on our legitimate interests.
- Withdraw consent at any time where processing is based on consent, without affecting prior processing.
- Lodge a complaint with your local data protection supervisory authority, or the Bulgarian Commission for Personal Data Protection (CPDP).
To exercise any of these rights, use the in-app controls where available, or email contact@budgetaize.com.
10. Security
- All traffic between the app and our servers, and between our servers and Supabase, OpenAI, Google Cloud Vision, and RevenueCat, is encrypted with TLS/HTTPS.
- Financial data is isolated per household using database-level Row Level Security, enabled on every table in our database.
- Your password is never stored by us in plain text; authentication is handled by Supabase Auth using industry-standard hashing.
- On your device, your session is stored in the platform's secure credential store (iOS Keychain / Android Keystore) rather than in a plain, unencrypted file.
- Server-side API keys for our processors are never exposed to the app or to any client device.
- AI features and other sensitive endpoints are rate-limited to reduce the impact of abuse or a compromised account.
- No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
11. Children
BudgetAIze is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the product changes. If we make a material change, we will update the "Last updated" date above and, where appropriate, notify you in the app.
13. Contact
Questions about this policy or your data: contact@budgetaize.com