Budgetto← Back

Privacy Policy

Last updated: 16 July 2026

1. Data controller

[Your legal name or company], [Street, postcode, city, Denmark] is the data controller for personal data processed through Budgetto. Contact: support@budgetto.app.

2. What we collect

  • Account data — your email address, and authentication details managed by our login provider (Clerk). We never see your password.
  • Budget data — the category names, amounts, opening balance and reconciliation flags you enter. This is financial information about you, so we treat it carefully.
  • Sharing data — the email addresses you invite to a budget, and their access level.
  • Billing data — subscription status and plan. Card details are collected and stored by Stripe; we never receive or store them.
  • Technical data — standard server logs (IP address, timestamps) needed to operate and secure the Service.

We do not connect to your bank, and we do not import transactions. You type in only what you choose to.

3. Why we process it, and our legal basis

  • To provide the Service (your account, budgets, sharing) — performance of our contract with you (GDPR Art. 6(1)(b)).
  • To take payment and prevent fraud — contract, and our legitimate interests (Art. 6(1)(b) and (f)).
  • To keep the Service secure and working — legitimate interests (Art. 6(1)(f)).
  • To meet accounting and tax obligations — legal obligation (Art. 6(1)(c)).

We do not sell your data, and we do not use it for advertising or profiling.

4. Who processes data on our behalf

We use a small number of processors, each under a data processing agreement:

  • Clerk — authentication and account management.
  • Neon — the database storing your budgets (hosted in the EU, Frankfurt region).
  • Vercel — application hosting and delivery.
  • Stripe — payment processing and subscription billing.

Some of these are US-headquartered and may process data outside the EU/EEA. Where that happens, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework.

5. Cookies

We use only what the Service needs to function: a session cookie from our login provider, a cookie remembering your language choice, and a cookie remembering that you dismissed the onboarding tip. We do not use advertising or third-party tracking cookies, so we do not show a consent banner.

6. How long we keep it

We keep your account and budget data for as long as your account exists. If you delete a budget it is removed, along with its categories, amounts and share invitations. If you delete your account, we delete your personal data, except records we must retain by law (for example, invoices for accounting purposes, typically five years).

7. Sharing budgets

If you invite someone to a budget, they can see that budget's contents at the access level you grant. The invitation is stored against the email address you provide. The budget owner can remove access at any time. Only share budgets with people you trust with that information.

8. Your rights

Under the GDPR you can request access to your data, correction, erasure, restriction, portability, and object to processing based on legitimate interests. You can exercise most of these directly in the app — your budget data is visible and editable at any time — or by contacting us at support@budgetto.app.

If you think we have handled your data improperly you can complain to your local data protection authority. In Denmark that is Datatilsynet (datatilsynet.dk).

9. Security

All traffic is encrypted in transit (HTTPS), data is stored in an access-controlled managed database, and authentication is handled by a specialist provider. No system is perfectly secure, but we take the sensitivity of financial data seriously.

10. Children

The Service is not intended for children, and we do not knowingly collect their data.

11. Changes

We may update this policy. If a change materially affects you we will give reasonable notice by email or in the app. The date at the top shows when it last changed.