BudgetLoop Privacy Policy
Last updated: 2026-08-16
BudgetLoop is a household budgeting application. This policy describes what data we collect, how we use it, and the choices you have. The short version: your financial data is used only to show you your own budget. We do not sell data, we do not run ads, and no household can ever see another household's data.
What we collect
- Account identity. When you sign in with Google, we receive your name, email address, and a unique account identifier from Google (via Firebase Authentication). We never see or store your Google password.
- Bank data via Plaid. When you connect a bank through Plaid Link, we receive transaction data (date, description, amount) and account display information (institution name, account name, last four digits of the account number). We receive this through Plaid; your bank credentials are entered with Plaid directly and are never visible to BudgetLoop.
- Content you create. Budget amounts, category names and definitions, manual category corrections, manually recorded transactions, and household membership (who you invite).
How we use it
- To display and categorize your household's transactions, compute budgets, and generate spending analysis — the features of the app. That is the only use.
- AI processing. Transaction descriptions and aggregated monthly figures are sent to Anthropic's Claude API to categorize transactions and generate narrative analysis. Under Anthropic's API terms, this data is not used to train their models.
- We do not sell or rent your data, show advertising, or share your data across households. Each household's data is isolated.
Who processes your data
| Processor | Purpose |
|---|---|
| Google Cloud / Firebase | Hosting, database, authentication |
| Plaid | Bank connectivity (you authorize each connection in Plaid Link) |
| Anthropic (Claude API) | Transaction categorization and spending analysis |
Security
All data is encrypted in transit (TLS 1.2+) and at rest. The database rejects all direct client access; every request goes through our backend, which verifies your identity and your household membership on every call. Bank access tokens are stored server-side only and are never sent to your device. Operational secrets live in Google Cloud Secret Manager under least-privilege access.
Retention and deletion
- Your data is retained while your household is active.
- Disconnect a bank at any time in the app; this also revokes BudgetLoop's access at Plaid immediately.
- Delete your account in the app (Settings → Delete account): this permanently deletes your household's data and your authentication record.
Children
BudgetLoop is not directed to children under 13, and we do not knowingly collect data from them.
Changes
We will update this page when the policy changes and note the date above. Material changes will be announced in the app.
Contact
[contact email — 上线前填]