Privacy Policy
Effective and last updated September 1, 2026
Budgefi helps people organize household finances. This policy describes the data the service uses and the controls available to you.
Data we process
We process account profile information, the balances, transactions, commitments, and plan inputs you enter or authorize, connection health metadata, notification preferences, and security and diagnostic events. Bank credentials are entered with the connection provider and are not provided to Budgefi.
How data is used
We use data to calculate your plan, synchronize authorized accounts, present available review workflows, send notifications you choose, secure the service, and provide support. Budgefi does not move money. We do not sell personal or financial data or use it for third-party behavioral advertising.
If you choose automatic setup, Budgefi detects repeat patterns locally first, then may send a limited pattern summary to OpenAI to classify it. The summary can include a normalized merchant label, dates, amounts, direction, and measured cadence. It does not include bank credentials, account numbers, balances, account or transaction identifiers, or your authentication identity. Suggestions remain editable and do not become plan commitments until you approve the plan. You can skip this feature and complete setup manually.
Providers
Service providers may process limited data for authentication, read-only financial connectivity, hosting, email, push delivery, security, and diagnostics. Each provider is limited to operating the service we request.
Your controls
You can use Budgefi manually, exclude accounts from planning, disable notifications, disconnect financial providers, export your data, and initiate account deletion from Privacy & data settings.
Retention and deletion
We retain data while your account is active and as needed for security, legal obligations, dispute handling, and backups. A deletion request disables your access and notifications. If you are the only active household member, it revokes connected-provider access and deletes household financial records before de-identifying the account. If another household member remains, shared records and connections remain for that member while your identity and membership are removed. Required legal retention and backup windows may still apply.
Automatic-setup results are cached briefly to avoid repeatedly processing the same activity, then removed by scheduled maintenance. They are included in account export and deletion while retained.
Security
We use transport encryption, restricted tenant access, encrypted provider credentials, device-secure storage on mobile, and privacy controls. No system can guarantee absolute security.
Contact
Privacy questions: privacy@budgefi.com.