Privacy Policy
Last updated: September 7, 2026
Budget Pilot ("Budget Pilot," "we," "us," or "our") provides a household budgeting and
personal-finance application. This Privacy Policy outlines what information we collect, how
we handle and protect it, and the rights and choices available to you.
Because Budget Pilot handles sensitive personal financial data, we believe in radical
transparency and plain language rather than unnecessary legal jargon. If you have questions
about how your data is handled, you can reach us directly at
mark@trybudgetpilot.com.
1. Information We Collect
We collect only the minimum information necessary to provide and operate the Service:
- Account Information: Your email address and a display name visible to
other members of your Household.
- Billing and Payment Information: When you subscribe to a paid tier,
your transaction and billing credentials are processed directly by our payment processor,
Stripe. We receive only transaction confirmations, subscription statuses, and basic billing
identifiers (such as the card brand and last four digits) to maintain your account
access.
- Financial Data You Provide: Information you manually enter, paste, or
import via CSV/files — such as account titles, balances, transaction logs, budget
categories, bill schedules, debt interest rates, and minimum payment amounts.
- Financial Account and Transaction Data (Connected Accounts via Plaid):
If you choose to link a bank, credit card, or other financial
account instead of entering it by hand, we use Plaid Inc. ("Plaid") to retrieve and
securely transmit your data from that institution to Budget Pilot. Depending on which
accounts you link, this can include:
- Account identifiers (account name, account type, and the mask/last 4 digits of the
account number).
- Real-time and historical account balances.
- Transaction history (date, amount, payee/merchant name, category, and
description).
No access to bank credentials: you enter your
online banking username, password, and any multi-factor authentication code directly into
Plaid's own secure interface — Budget Pilot never views, transmits, or stores those
credentials on our servers. By using this feature, you agree that your information will
be collected, stored, and processed by Plaid in accordance with the
Plaid End User Privacy Policy.
- Optional AI Assistant ("Sterling"): If you choose to ask a question to
Budget Pilot's built-in AI assistant, the text of your question — and, only for questions
about your own spending, a snapshot of relevant account and budget figures computed in your
own browser — is sent to Google's Gemini API to generate a response. This request is made
under Google's paid API tier, under which Google does not use your prompts or Google's
responses to train or improve its models. Budget Pilot does not store the content of your
questions or the assistant's answers; we log only the date and time a question was asked, in
order to enforce a daily usage limit. This feature is entirely optional and is never used
unless you choose to open the assistant and ask it something.
- Household Information: When you create or join a shared Household
workspace, members of that workspace can view and edit the financial entries associated
with it.
- Authentication Data: If you choose third-party Single Sign-On (such as
Google), we receive basic profile details (your name, verified email, and
profile avatar) strictly to authenticate and recognize your account. Signing in itself
never grants us access to your external files, cloud drives, emails, or contacts.
- Optional Cloud Save (Google Drive): If you choose to save a report to
Google Drive, a separate permission step — distinct from Google sign-in — lets Budget Pilot
create that one file in your Drive. This uses Google's most restrictive file-access scope
(
drive.file), which only ever sees files Budget Pilot itself creates; it cannot
see, list, or modify your existing files or folders. This permission is requested only when
you click "Save to Google Drive," and you can revoke it at any time from your Google
Account's third-party access settings.
- Essential Technical Storage & Cookies: We use local browser storage
and first-party session tokens solely for authentication, security verification, and
workspace state. We do not use tracking pixels, advertising cookies, or
third-party behavioral analytics scripts.
2. How We Use Your Information
We use the information we collect exclusively to:
- Power application features: dashboards, debt payoff models, cash flow statements, and
budget tracking.
- Automate Budgeting Workflows: Where you've linked an account via Plaid,
to synchronize, categorize, and present your recent transactions and balances within your
Household workspace, so you don't have to import a CSV or enter transactions by hand.
- Compliance & Aggregation Limits: We use aggregated financial data
retrieved via Plaid solely to deliver budgeting and personal financial management features.
We do not use it to evaluate creditworthiness, offer credit products, or act as a consumer
reporting agency under the Fair Credit Reporting Act (FCRA).
- Authenticate your identity and manage Household permissions.
- Transmit essential account service communications (such as password reset links or
security notices). We do not send marketing or promotional emails without your explicit
consent.
- Diagnose bugs and resolve technical issues.
Our Core Privacy Pledge:
- We do not sell your personal or financial data.
- We do not share your data for cross-context behavioral advertising.
- We do not monetize your transaction records or financial metrics.
3. Data Storage, Architecture & Security
We employ industry-standard technical and organizational safeguards designed to protect
personal financial data:
- Transport Encryption: All traffic between your browser and our
application is encrypted in transit using modern HTTPS/TLS protocols.
- Database Isolation & Row-Level Security: Budget Pilot is powered by
Supabase (hosted PostgreSQL). Financial records are protected by database-level Row-Level
Security (RLS) policies, ensuring that only authenticated members of your specific
Household can query or write to your records.
- Credential Protection: Passwords and OAuth tokens are never stored in
plain text; they are processed using secure cryptographic hashing algorithms.
- Security Incident Response: While no web application can guarantee
impenetrable security, in the event of a confirmed security incident affecting unencrypted
personal data, we will notify impacted users in accordance with applicable state and
federal data breach notification requirements.
4. Third-Party Infrastructure Providers (Subprocessors)
We rely on a small set of established cloud infrastructure vendors to run the Service:
- Supabase: Hosted database, authentication engine, and backend
infrastructure.
- Netlify: Application hosting, content delivery, and frontend
deployment.
- Plaid Inc.: Provides the secure connection used to retrieve balances
and transaction data from your financial institution, for households that choose to link an
account. Plaid processes your banking credentials, account identifiers, balances, and
transaction history under its own security and privacy protocols (see the
Plaid End User Privacy Policy).
- Stripe, Inc.: Payment gateway and billing infrastructure provider. If
you purchase a paid subscription, your payment details (such as credit card numbers, billing
zip code, and expiration dates) are collected directly by Stripe via embedded, PCI-DSS
compliant elements. Budget Pilot never views, transmits, or stores your raw credit card
numbers or CVV codes on our servers. (See the
Stripe Privacy
Policy.)
- Google: OAuth identity provider for optional social sign-in, and,
separately, the Google Drive API for the optional "Save to Google Drive" export feature —
limited to files Budget Pilot creates at your request.
- Google Gemini API: Powers the optional Sterling AI assistant described
above. When you ask Sterling a question, that question — and, for spending-related
questions, a browser-computed snapshot of relevant figures — is sent to Google's Gemini API
to generate a response. This is a separate data flow from the Google sign-in/Drive
integration above, governed by
Google's
Gemini API Additional Terms of Service rather than Google's general consumer privacy
policy. We access the Gemini API under Google's paid service tier specifically so that this
data is not used by Google to improve or train its models.
Each infrastructure provider processes data solely on our behalf under strict enterprise
data-protection and confidentiality commitments.
5. Data Retention & Deletion
We retain your account and financial data for as long as your account remains active.
- User-Initiated Deletion: You may request complete deletion of your
account and associated financial data at any time by emailing
mark@trybudgetpilot.com. Upon receiving your
request, we will permanently purge your data from active production databases, typically
within 30 days, subject only to temporary backup retention cycles or legal compliance
obligations.
- Disconnecting Linked Accounts: You may unlink any connected financial
account at any time from within Budget Pilot. When you do, we immediately instruct Plaid to
revoke that connection's access token, so it stops fetching new transactions or balances
and can no longer be used to reach your account at the institution. Transactions already
saved to your Household workspace from before the disconnect are not automatically removed
— they remain in your budget ledger unless you delete them yourself or delete your
Household workspace entirely. If you permanently delete your account or Household, all
associated Plaid connections and previously synced transaction data are permanently deleted
from our primary database per the retention schedule above. You can also view, manage, or
revoke access to your connected institutions at any time through the
Plaid Portal.
6. Your Rights and Data Control
You retain full control over your financial data:
- Data Portability & Export: You can export your financial reports
(Income Statement, Balance Sheet, Cash Flow Statement) as standard CSV files at any time.
Your data is never locked into the platform.
- Modification & Deletion: You can edit or delete any individual
account, transaction, or budget item directly in the app.
- Leaving a Workspace: You may leave a shared Household at any time via
your Household settings panel.
- State Statutory Privacy Rights: If you reside in Arizona or another
jurisdiction with consumer privacy protections, we honor your rights to know, access,
correct, port, and delete your personal data. We do not discriminate against users who
exercise these privacy rights.
7. Children's Privacy
Budget Pilot is not intended for or directed to individuals under the age of 18 (and under
no circumstances children under 13). We do not knowingly collect personal data from minors.
8. Changes to This Policy
If we make material updates to this Privacy Policy, we will revise the "Last updated" date
above and post a clear notice within the application or via email prior to the changes taking
effect.
9. Contact Us
For questions regarding this Privacy Policy, data deletion requests, or security inquiries,
please contact:
Email: mark@trybudgetpilot.com
Location: Arizona, United States