In short
- Budgeloom is a personal budgeting app. You type in your own figures; it never connects to your bank.
- When you are signed in, your records are stored in your private cloud account so they sync between your devices.
- We use service providers to run that account, deliver email, process subscriptions and host this website.
- We do not sell your data, and the app shows no ads.
- You can export your records and delete your account in the app, or delete your account without the app on our Delete account page.
What Budgeloom is
Budgeloom is a personal budgeting app. You enter your own income, spending, bills, savings goals and budgets. Budgeloom does not connect to your bank, does not ask for bank or card credentials, does not move money, and does not provide lending or investment services. We do not sell your data. Budgeloom shows no ads, and the app contains no advertising, analytics or tracking libraries. Two built-in components send their own providers limited technical data, described below: Google’s on-device text recognition (ML Kit) and our subscription service.
Information the app handles
| Information | Why | Where |
|---|---|---|
| Account details: email address, username, and a password (stored only as a salted hash by our account service). If you choose Google or Apple sign-in, the identifier that provider gives us. | To create and secure your account. | Our secure cloud account service |
| Budgeting records you enter: profile and currency preferences, categories, budgets, income, spending, bills, savings goals and contributions, forecasts and reports. These are financial records about you. | To provide the app and to sync between your devices. | On your device and, when you are signed in, in your private cloud account |
| Receipt images and PDFs you attach. | To store your receipts. Text recognition runs on your device; the document content is not sent to a recognition service. | On your device and, when you are signed in, in private cloud file storage for your account |
| Device registration: a public key created on your device, a device name, platform, app version and a session reference. | To recognise your trusted devices and send security notices. | Our secure cloud account service |
| Security events (for example a new device added) and the email we send you about them. | Account protection. | Account security records in our cloud account service; emails are delivered by a transactional email service |
| Subscription status: your Budgeloom account ID, used as the customer identifier with our subscription service and Google Play; purchase and entitlement state. | To unlock Premium and handle restore, renewal and cancellation. We never receive your card details. | Google Play, our subscription-management service, and our account system |
| Support and feedback messages and any attachments you send; app version, platform and OS version when you contact us. | To answer you and to look after the service. | Our secure cloud account service and private file storage |
| Technical diagnostics from the on-device text-recognition component (Google ML Kit): device and app information, performance metrics, error codes and a per-installation identifier. Never the content of your receipts. | Google uses it for diagnostics and usage analytics of that component; Google states it does not transfer this data to third parties. |
App Lock and biometric unlock are handled by your device; Budgeloom does not receive your fingerprint or face data. Reminders are scheduled locally on your device; the app does not use remote push notifications.
Information this website handles
- Signed-out help requests sent from the Support page: the category you choose, the email address you give for our reply and your description. They become a support case handled by our support staff, exactly like a signed-out request from the app.
- Account deletion requests from the Delete account page: the email address you enter. If it belongs to an account, our account service emails that address a one-time sign-in link; signing in with it creates a short session (at most one hour) used only to confirm the deletion.
- Abuse protection: to limit repeated requests, the website uses your IP address and the email address you entered only in the form of keyed, irreversible digests that are deleted after 24 hours. The digests are not linked to your account.
- Cookies: the website sets no advertising, analytics or tracking cookies. The only cookies it sets are strictly necessary, short-lived ones used during a deletion sign-in; they need no consent and are removed when you finish or cancel.
- Hosting logs: our website hosting service processes standard request information (such as IP address, browser type and requested page) to deliver and protect the site, under its own policies. The logs our website code writes contain no IP address and no content of your forms, and are kept for a short period (about a day on our current plan).
Service providers and data sharing
We do not sell your personal information or share it for advertising. We use the following kinds of service providers to run Budgeloom. They handle data to provide their services to us, under their own terms and privacy policies:
| Type of provider | What it does for Budgeloom | Data involved |
|---|---|---|
| Cloud account and database service | Sign-in, your private cloud account, synced records, receipt and attachment storage, server functions | Account details, budgeting records, receipts, devices, security events, support cases, subscription status |
| Subscription-management service | Works with Google Play Billing to record whether Premium is active, renewed, restored or cancelled | Your Budgeloom account ID, purchase/entitlement state, and basic device and app information its in-app component sends to validate purchases (not your card details) |
| Transactional email service | Delivers sign-in, verification and security emails | Your email address and the content of those emails |
| Website hosting and domain services | Serve this website and our domain, and protect them from abuse; also host our internal operations tools | Standard request information such as IP address and requested page |
Services you choose. If you sign in with Google or Apple (where offered), that company confirms your identity under its own privacy policy. Purchases are made through Google Play, which processes your payment under Google’s terms; we never receive your card details.
Your cloud account, budgeting records and stored files are hosted in the United States (Amazon Web Services, us-east-1). Our other providers may process data in other countries, including the United States and the European Union, so your data may be handled outside the country where you live. Data is encrypted in transit between your device, our website and these services. We may disclose information if the law requires it, or where necessary to protect the rights, safety or security of our users or the service.
Our staff can see account and support information only for a purpose such as a support case. They cannot read your budgeting records unless you grant Support Access for a case, which you can turn off in the app.
Security
Data is encrypted in transit. Access to cloud records is restricted to your own account. Privileged actions by our staff are logged.
Retention and deletion
We keep your data while your account exists. You can export your data and permanently delete your account in the app (Profile → Account), or from the Delete account page without the app. Deleting your account removes your account, budgeting records and receipts from the cloud; deleting in the app also clears the copy on that device, while deleting on the website cannot reach a phone, so uninstall the app (or clear its storage) to remove a device copy.
Limited records can remain after deletion:
- a minimal deletion record (account ID, deletion time, former username) that prevents reactivation;
- support records subject to a legal or security hold;
- purchase records held by Google Play and our subscription-management service under their own rules;
- our encrypted operational backups (daily copies kept for 14 days, then weekly and monthly copies, about three months in all), from which deleted data disappears as the backups are rotated out. Our cloud database plan keeps no separate provider backups.
Support and feedback records become eligible for removal three years after a case closes. The automatic clean-up that removes them is not running yet, so until it is, they may be kept longer than three years. Deleting your account does not cancel a Google Play subscription; cancel it in Google Play.
Your choices and rights
You can export your budgeting records as CSV files in the app, correct them by editing, and delete your account. To ask for a copy of other personal data we hold about you (for example support records), or to raise any other privacy request, email privacy@budgeloom.com; we confirm the request comes from the account holder before responding. Depending on where you live, you may have further rights under local law, such as to object to or restrict certain processing, or to complain to a data protection authority.
Children
Budgeloom is intended for adults aged 18 and over and is not directed at children. We do not knowingly collect personal data from anyone under 18; if you believe a child has created an account, contact us and we will delete it.
Changes
We will update this page and its effective date when our practices change.