Privacy Policy
Last updated July 6, 2026
BudgetMyLife is a personal-finance app for tracking expenses on your own and in shared groups. This policy explains exactly what we process and what we deliberately do not. BudgetMyLife is currently a free beta; it is free now and paid at launch.
What we collect
- Account & authentication data. Handled by our authentication library (Better Auth): your name, email address, and either a hashed password or an identifier from the social provider you sign in with (Google or GitHub). We store active sessions so you stay signed in.
- Financial data you enter. The expenses, groups, splits, categories, and settlements you create. This is the content of the service and is stored so we can show it back to you and to the group members you share with.
- Product usage events. Server-side only. When you take key actions (for example signing up, creating a group, or logging your first expense) we record a small event: your user id, the event name, and optional non-sensitive metadata. These are written by our own servers to our own database. There are no third-party trackers, no advertising or analytics SDKs, and no cross-site tracking of any kind.
What we do not do
We do not embed third-party trackers, advertising pixels, or analytics SDKs. We do not sell or rent your data, and we do not use it for advertising. All usage measurement is first-party and server-side.
Receipt scanning
When you scan a receipt, the photo is sent to our extraction provider (OpenRouter, which routes it to Google's Gemini model) so the line items, merchant, and total can be read back into an editable draft. We do not store the image: it is held in memory only for the length of that one request and discarded afterwards — nothing is written to our database. Scanning always proposes a draft that you review and edit before anything is saved, and it is entirely optional; you can enter every expense by hand instead.
Sub-processors
At this stage our only sub-processors are infrastructure providers:
- Application hosting (Cloudflare) — serves the app and its API.
- Managed PostgreSQL database — stores your account, financial data, and usage events.
- Receipt extraction (OpenRouter, routing to Google's Gemini model) — reads receipt photos you choose to scan. The image is sent for extraction only and is not stored by us or used to train models.
We do not use a third-party email provider, and we do not yet use a payment processor — billing has not launched during the beta, so no payment data is collected or shared.
Data residency
We target EU/EEA data residency for the database that stores your personal and financial data.
Retention
We keep your data for as long as your account is active. When you delete your account, your authentication credentials, sessions, and purely personal (non-shared) records are removed. Data that other group members depend on — shared expenses, splits, and balances — is retained but your identity on those records is anonymized to “Deleted user” so the group's history and balances stay correct.
Your rights
You can export your data and delete your account at any time from your account settings. Deletion is described under Retention above. For access or correction requests, contact us through the app.
Manage your data in Settings