BudgetOS is a personal budgeting app. We store the financial information
you choose to enter so you can see it across your devices. We do not sell your
data, show you ads, or share your information for marketing. You have two ways to get your money
into BudgetOS: import a bank statement (processed on your device), or optionally
connect a bank or credit card to sync transactions automatically. Bank statement
files are processed on your device by default — a file only leaves your device if
you explicitly choose to send a failed statement to us so we can fix the reader. When you connect
an account, a regulated provider (Plaid) retrieves your data read-only — BudgetOS
never sees your online-banking password and can never move your money. Connecting
is always optional, and you can disconnect at any time.
1. Who we are
BudgetOS ("we," "us," "the app") is operated by IN-DEV SOLUTIONS INC., a
corporation incorporated under the Canada Business Corporations Act (CBCA) and based in Oakville, Ontario.
For any privacy question, contact us at
support@budgetos.ca.
2. Information we collect
We only collect what is needed to run the app:
Account information — your email address, used to create and secure your account.
Financial data you enter — transactions, budgets, bills, savings goals, and
account labels (e.g. "Visa," "Chequing") that you add to the app.
Statement-derived data — when you import a PDF or CSV bank statement, the file
is read and parsed on your device (in your browser/app), and only the resulting
transaction date, merchant description, and amount are saved to your account. The statement file
itself is not uploaded as part of normal import.
Connected-account data (optional bank / card sync) — if you choose to connect a
bank or credit-card account, you can authorize Plaid, a trusted third-party
financial-data provider, to share your data with us on a read-only basis. Depending on
what your institution supports, this may include your account name and type, account and routing
numbers (often masked), account balances, and transaction history (date, description, amount, and
merchant details). You enter your banking credentials directly with Plaid / your bank
— we never receive, see, or store your online-banking username or password. See "Bank & card
connections" below.
Statement files you choose to send us — if a statement fails to import and you
opt in (via "Auto-send Failed Statements" or by filing a support request with an attachment), that
file is uploaded to our storage so we can diagnose and improve the reader. This is off by
default and only happens with your explicit action. Where possible, a privacy-reduced
version (page layout/structure without account numbers or balances) is sent instead of the raw file.
If sent, this privacy-reduced version may be processed by our AI service provider (Anthropic) to learn
that statement's format and complete your import; your raw file and personal details are never sent to
the AI provider. Files sent this way are kept only while we fix the reader and are
automatically deleted from our storage after 90 days. See "Third-party services"
below.
Money Note — BudgetOS can write you an optional monthly summary of your own
spending (currently included free during our launch period). A note is written only when you open
Money Note, at most once per month. To write it, we send our AI service provider (Anthropic)
only aggregate figures about your month: your per-category spending totals and how
they changed from the prior month, your budget limits, your savings goal amounts and progress, and
your overall income and spending totals. We do not send transaction descriptions,
merchant names, account names or numbers, statement files, the names you've given your savings
goals, or any other free text. Every dollar figure in the finished note is checked against your own
records before it's shown to you. See "Third-party services" below.
Push notification token — if you enable notifications, your device's push token
is stored so we can send you bill reminders, budget alerts, and similar updates. You can turn this
off in your device settings at any time.
Subscription status — if you purchase a subscription, the purchase is handled by
Apple or Google and your subscription tier is managed through RevenueCat. We never receive or store
your full card number.
Technical/security data — limited login security signals (e.g. failed-attempt
counts for lockout, bot-protection tokens) used to protect your account.
Usage analytics (first-party) — we record a small set of product events — for
example: account created, statement import attempted, import succeeded or failed — linked to your
account, so we can see where the app works well and where people get stuck. These events contain
no transaction details, merchant names, dollar amounts, or account numbers — only
the step name and simple non-financial labels (such as an import's file type, the detected bank
format, and how many transactions were imported). They are stored in our own database (Supabase,
described below) and are never shared with third-party analytics companies, ad networks,
or data brokers.
We do not collect advertising identifiers or location. If you do not connect
an account, BudgetOS never connects to your bank at all — you can use the app entirely with
on-device statement import. If you do connect an account, the connection is read-only and your
banking credentials are handled only by Plaid and your financial institution, never by us.
3. How we use your information
To provide the core budgeting features and display your data across your devices.
To authenticate you and keep your account secure.
To operate, maintain, and improve the app's functionality.
To understand, through our own usage analytics, which features work well and where users run
into problems — so we can prioritize fixes and improvements.
We do not use your financial data for advertising, profiling for third parties, or resale.
4. Bank & card connections (sync)
Connecting an account is an optional, paid feature that lets BudgetOS keep your
transactions up to date automatically instead of importing statements by hand. It works like this:
Read-only. Connections are strictly read-only. BudgetOS and our provider
cannot move money, make payments, or transfer funds — we can only read transaction
and balance data so you can see and organize it.
Powered by Plaid. When you connect an account, you do so through Plaid's secure
interface and authorize Plaid directly to collect your account data from your
institution and share it with BudgetOS. Plaid operates as an independent data controller of
the information it collects through this connection, under its own
Plaid End User Privacy Policy — it is
not acting as our processor. Once BudgetOS receives your data, we handle it as described in
this policy. As Canada's consumer-driven banking (open banking) framework comes into force, we may
also use other regulated, accredited providers for connections.
We never see your banking password. You enter your credentials directly with
Plaid / your bank. We never receive or store them. We store only a secure access token (held on our
servers, encrypted, never on your device) that lets us retrieve your data, plus the account and
transaction data you've chosen to sync.
You're in control. You can disconnect any account at any time from within
BudgetOS, or manage and revoke connections directly through Plaid at
my.plaid.com. When you disconnect, we stop retrieving new data and
you can delete the synced data from your account.
Accuracy. Synced data may occasionally be delayed, incomplete, or inaccurate
because of your bank or the provider. It is a convenience, not a substitute for your official bank
records.
5. How your data is stored and protected
Your data is stored in our database provider, Supabase (hosted on secure cloud
infrastructure).
Every record is isolated to your account using Row Level Security — other users
cannot access your data.
Passwords are hashed with bcrypt and never stored in plaintext, are checked
against known breached-password databases, and accounts are protected by rate-limiting, one-time
email codes, and bot protection.
All data in transit is encrypted using HTTPS (TLS).
Where your data is stored — your data is hosted by Supabase on Amazon Web
Services in the United States (US East / Ohio region), and Plaid, as an
independent controller, processes connection data in the United States under its own privacy
policy. If you are located in Canada or elsewhere outside the United States, your information
is transferred to and processed in the U.S., where it may be subject to U.S. law. We rely on these
transfers to provide the Service, and we protect your information in the manner described in this
policy regardless of where it is processed.
6. Biometric authentication (Face ID / Touch ID / fingerprint)
On supported mobile devices, BudgetOS lets you enable an optional App Lock that
requires Face ID, Touch ID, or your fingerprint to open the app. This is entirely optional and is turned
off by default.
Your biometric data (face or fingerprint) is processed only by your device's operating
system and secure hardware (such as Apple's Secure Enclave). BudgetOS never sees, receives,
stores, or transmits your face or fingerprint data — the device simply tells the app whether
verification succeeded or failed.
We do not collect, retain, or share any biometric identifiers. There is no
biometric data on our servers, and none is ever sent over the network.
The only thing BudgetOS stores is a small on/off preference saved locally on your
device indicating whether you have enabled App Lock.
You can disable App Lock at any time from Profile → Security & Privacy, and you can
always fall back to your device passcode if biometrics are unavailable.
7. Third-party services
We use a small number of trusted providers strictly to operate the app:
Supabase — database, authentication, file storage, and account storage.
Plaid — when you connect a bank or credit-card account, Plaid provides the secure
connection and collects your account and transaction data (read-only) directly from your financial
institution under your authorization and Plaid's own End User Privacy Policy. For that
connection, Plaid acts as an independent data controller of the information it collects — not as
our service provider — and shares that data with BudgetOS at your direction. U.S.-based; see the
Plaid End User Privacy Policy.
Cloudflare Turnstile — bot/abuse protection during login.
Vercel — hosting of the web application.
RevenueCat with Apple App Store / Google Play —
processing and managing subscriptions. Payment is handled by Apple or Google; we do not see your card details.
Apple Push Notification service (APNs) — delivering notifications you enable.
Resend — sending service emails such as password resets and notification digests (processes the recipient email address and message content).
Sentry — app crash and performance diagnostics so we can find and fix errors (technical/diagnostic data, which may include an app user identifier).
Zoho Mail — hosting our business email; if you contact us (e.g., support@budgetos.ca), it processes your message. Hosted in a Canadian data centre.
Anthropic — our AI service provider, used for three limited purposes:
automatic import assistance, assessing feature suggestions you
submit through the in-app suggestion box, and generating your monthly Money Note
summary (currently included free during our launch period). For import assistance, if a
statement fails to import and you opt in, a privacy-reduced structural version of it (transaction
amounts, dates, and page/column layout only — with your name, account and card numbers, and merchant
details removed, and never the raw file) is sent to Anthropic to determine how to read that
statement's format; we use what is learned to complete your import and to support the same statement
format for other customers. For feature suggestions, only the suggestion text you write is sent — no
account identifiers or financial data. For Money Note, we send Anthropic only aggregate
figures — your per-category spending totals and month-over-month changes, your budget
limits, your savings goal amounts and progress, and your overall income and spending totals. We
never send transaction descriptions, merchant names, account names or numbers,
statement files, the names you've given your savings goals, or any other free text you've entered.
Anthropic drafts the note's text; we independently verify every number in it against your own
records before showing it to you, and the finished note is stored in your account like any other
data you generate in the app. Anthropic is based in the United States and processes this data on
our behalf as a service provider.
See the Anthropic Privacy Policy.
Except for Plaid (described above), these providers process data on our behalf to deliver their
service to us and are bound by their own commitments under data-processing agreements. Plaid, by
contrast, is an independent provider you authorize directly, whose handling of your information is
governed by Plaid's own privacy policy. We do not sell or rent your personal information to anyone.
8. Data retention
We keep your data for as long as your account is active. You may delete your data at any time from
within the app, or request full account deletion by emailing
support@budgetos.ca. When you delete your account, your
personal and financial records are removed from our live database immediately and are purged from
encrypted backups within 30 days, after which they cannot be recovered.
9. Your rights
Depending on where you live, you may have rights under applicable privacy laws — including
Canada's PIPEDA and Quebec's Law 25 — to access, correct, export, or delete your personal
information and to withdraw consent. To exercise any of these rights, contact
support@budgetos.ca.
Quebec residents (Law 25): the person responsible for protecting your personal
information is the Privacy Officer of IN-DEV SOLUTIONS INC., reachable at
support@budgetos.ca. You may request access to, correction of,
or deletion of your information, and you have the right to be informed of any transfer of your
information outside Quebec (see "Where your data is stored" above).
10. Children's privacy
BudgetOS is intended for users aged 16 and older. We do not knowingly collect personal information
from anyone under 16. If you believe someone under 16 has provided us information, contact us and we
will delete it.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the
"Last updated" date above and, where appropriate, by notice within the app.