Privacy Policy

Last updated: August 17, 2026

This policy explains what information Budge collects, how it is stored and used, who else processes it, and the rights you have — in plain language.

1. Who is responsible for your data

Budge is operated by Hirolabz, which is the data controller for the information described here. For any privacy question or request, including the rights set out in section 9, contact us at [email protected]. We answer privacy requests within 30 days.

2. What we collect

Account information

Your email address and a password, used to create and secure your account, plus an optional display name and profile photo. Passwords are handled by Firebase Authentication; we never see or store them in plain text.

The records you enter

Budge stores what you put into it: bills, cut-off periods, payment methods you name yourself, credit cards, checks, debts, projects and their invoices, schedules, categories, currency preferences, and any health-related records you choose to add.

Files you upload

If you set a profile photo it is stored in Firebase Storage. Project documents you attach are stored the same way and are reachable only through your account.

Health information

Budge's family health features let you record conditions, medications, allergies, immunizations, lab results, appointments and healthcare providers. Under the GDPR this is “special category” data, and in some US states it is “sensitive personal information”. We process it only because you chose to enter it, on the basis of your explicit consent, and solely to show it back to you and the workspace members you have invited. We do not use health data for any other purpose, and you can delete any record, or the whole family member, at any time. Budge is not a medical device and is not a substitute for professional medical advice or record-keeping.

What we do not collect

  • No bank or card credentials — Budge never connects to financial institutions.
  • No contact list, no location data, no advertising identifiers.
  • No third-party advertising or ad tracking in the mobile app.
  • We do not buy personal information about you from data brokers.

3. Why we process it, and on what legal basis

  • To provide the Service — storing and syncing your records across your devices. Legal basis: performance of our contract with you.
  • To enable sharing — showing workspace content to members you invited, and emailing the invitation. Legal basis: performance of our contract with you.
  • To keep accounts secure — authentication and abuse prevention through Firebase Authentication and Firebase App Check. Legal basis: our legitimate interest in a secure service.
  • To store health records — see section 2. Legal basis: your explicit consent, which you can withdraw by deleting the records or your account.
  • To respond to support requests — legal basis: our legitimate interest in answering you.

Bill reminders are scheduled and shown by your own device. Budge has no push-notification service, so producing a reminder sends nothing to us or to anyone else.

We do not sell or share your personal information, we do not use it for advertising or profiling, and we make no automated decisions with legal or similarly significant effects.

4. Who else processes your data

We keep the list of processors deliberately short. Each one acts on our instructions for the purpose named:

  • Google (Firebase / Google Cloud)— Firebase Authentication for sign-in, Cloud Firestore for your records, Firebase Storage for uploaded files, and Firebase App Check for abuse prevention. Google Fonts may serve the app's typefaces, which involves a request to Google from your device.
  • Resend— delivers workspace invitation emails. It receives the invited email address, the workspace name and the inviter's name, and nothing else.
  • Vercel — hosts this marketing website and provides its aggregate, cookie-free traffic analytics. Vercel processes no app account data.

We do not share your data with anyone else, and we will not add a processor that changes the nature of this processing without updating this policy first.

5. Where your data lives, and international transfers

Your account is managed by Firebase Authentication and your records are stored in Cloud Firestore on Google Cloud infrastructure, encrypted in transit and at rest. Access is enforced by security rules: only your account — and members of a workspace you have joined — can read or write that workspace's data.

Google and Resend operate globally, so your data may be processed outside your own country, including in the United States. Where that involves a transfer out of the UK, EEA or Switzerland, it relies on the European Commission's Standard Contractual Clauses or an equivalent approved safeguard in the relevant provider's data processing terms.

6. Sharing within workspaces

If you join or create a shared workspace, its members can see and edit the records in that workspace — including health records, if you have added any. Invite people accordingly. Invitations are sent by email to the address you supply. Leaving a workspace, or having your access removed, ends your access to its data.

7. This website

This marketing site sets no advertising cookies and asks you for no personal information. It holds no account data of its own and cannot read anything from your Budge account. Aggregate page-view analytics tell us which pages are visited, not who visited them.

8. How long we keep it

  • Your account and records — for as long as your account exists. Deleting your account removes them immediately, as described below.
  • Workspace invitations — until accepted, declined, or deleted by either side.
  • Support emails — up to 24 months after the conversation ends.
  • Backups— residual copies may persist in our providers' encrypted backups for up to 30 days after deletion, after which they are overwritten.

You can permanently delete your account and all associated data at any time from inside the app: open the More tab, tap your name, then choose Delete Account. The account deletion page sets out the steps. Deletion runs immediately on confirmation and cannot be undone.

9. Your rights

Because Budge shows you everything you have entered, you can read, correct and delete your records directly in the app at any time. In addition, depending on where you live, you may have the right to:

  • access a copy of the personal information we hold about you;
  • correct information that is inaccurate or incomplete;
  • delete your information, including by deleting your account;
  • receive your data in a portable form, or have it sent to another provider;
  • object to, or ask us to restrict, a particular use;
  • withdraw consent you previously gave, such as for health records;
  • for California residents under the CCPA/CPRA: know what we collect and why, delete it, correct it, and limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of. We will never discriminate against you for exercising these rights.

Email [email protected] to exercise any of these. We may need to confirm you control the account before we act. You can also authorize an agent to make a request on your behalf. If you are in the UK or EEA and think we have got something wrong, you may complain to your local data protection authority.

10. Security and breach notification

Data is encrypted in transit and at rest, access is governed by server-side security rules rather than by the app alone, and Firebase App Check restricts backend access to genuine installations of the app. No system is perfectly secure, so if a breach affects your personal information and creates a risk to you, we will notify you and the relevant regulator without undue delay and, where required, within 72 hours of becoming aware of it.

11. Children

Budge is not directed at children and may not be used by anyone under 18. We do not knowingly collect personal information from children. An adult may record information about their own child — for example a family health record — and remains responsible for that content. If you believe a child has created an account, contact us and we will delete it.

12. Changes to this policy

If we make material changes we will update the date at the top of this page and give notice in the app or by email before the changes take effect. Continuing to use Budge after that means the updated policy applies.

13. Contact

Privacy questions, requests, or complaints: [email protected].