This Privacy Policy describes how Budgy ("App") processes information when you use the App. The App is provided by Thomas Mauriello, an individual developer based in Italy ("we", "us", "our", "controller" or "provider").
Budgy started as a local app: the financial data you enter is stored on your device. It stays there alone until you connect an account: from that moment the App can copy it to our servers to sync it across your devices and for shared accounts, and you can turn either of those off whenever you want.
Two features do: personal data sync, which copies your data to Firebase so you can find it on your other devices, and shared accounts, which make some expenses visible to another person you invite. Neither happens without connecting an account. Some features may also involve Apple, Google/Firebase or services chosen by you, as explained below.
1. Data controller
For purposes of Regulation (EU) 2016/679 ("GDPR"), the data controller is:
Thomas Mauriello
Italy
Email: it.mauriello.thomas@gmail.com
2. Scope of this policy
This policy covers:
- data processed locally by the App on your device;
- data sent to Google/Firebase when you connect an account and turn on syncing or use a shared account;
- data shared with Apple services when you use the App Store, StoreKit, iCloud, MapKit, CoreLocation, notifications, widgets or other Apple frameworks;
- data shared with Google/Firebase when you enable analytics or diagnostics, or when the App downloads legal documents or resources from Firebase;
- data that passes through Google and Apple to deliver shared account notifications;
- data shared with third parties when you choose to export, share or open files through other apps or services.
This policy does not govern the privacy policies of Apple, Google/Firebase or other third-party services, which remain responsible for processing carried out for their own purposes.
3. Summary
- You can use Budgy with no account at all: in that case no financial data leaves the device.
- If you connect an account (Apple or Google) you can turn on syncing: your data is copied to Firebase, in the European Union, so you can find it on your other devices. You can turn it off and ask for the server copy to be deleted at any time.
- A shared account makes that account's expenses visible to the person you invite, with the name of whoever entered them. Your other accounts stay yours and nobody sees them.
- Attachments on a shared expense stay private: the other person sees the transaction, not the photo.
- Budget, account, transaction, note, attachment, card and goal data remain on the device until you turn on syncing or a shared account.
- We do not sell personal data.
- We do not use behavioral advertising.
- We do not use IDFA for advertising tracking.
- Firebase Analytics and Crashlytics are disabled by default at configuration level and are enabled only based on the consent saved in the App.
- Analytics events must not include amounts, notes, descriptions, wallet names, addresses, precise coordinates, attachment content or imported file names.
- Receipt OCR uses Apple technologies on the device and does not send the receipt image to the provider's servers.
- Device iCloud Backup may include App data and attachments if it is active.
- When you export or share files, the service you choose may process those data according to its own rules.
4. Data you can create in the App
Depending on how you use Budgy, you may create or save locally:
- wallets or accounts, wallet name, currency, balance and display preferences;
- transactions, amounts, dates, income, expenses, categories, custom categories, colors, payment methods, notes, budget exclusion status and recurrences;
- positions associated with transactions, including coordinates and addresses, if you choose to use this feature;
- photos, receipts or other attachments associated with transactions;
- category budgets and reference periods;
- reminders and local notifications;
- CSV imports and metadata for imported batches;
- data exported in CSV or XLSX when you request an export;
- savings goals, contributions, deadlines and update history;
- debts, credits, counterparties, balances, notes and repayment history;
- gift cards, loyalty cards, names, barcodes, codes, balances and movements;
- App preferences, privacy settings, display settings, free limits already used and onboarding status;
- summary data shared with the iOS widget, such as wallet name, currency, monthly balance, list of wallets available for the widget and PLUS status.
These data are normally stored on your device in local stores, local files or UserDefaults. Some summary data are copied into the App Group to allow the widget to work.
5. Attachments, photos and receipts
If you add attachments or photograph a receipt, the App may compress and save the image as a local file managed by the App.
If you use receipt scanning, the App may process the image with Apple Vision and CoreImage on the device to recognize text, amount, date, currency, notes, possible payment method, possible category and possible address. The results may be applied to the transaction form.
The App keeps a small in-memory OCR cache for the current session, so it does not need to run recognition again on the same photo. This cache is not designed to be sent to the provider's servers.
Receipt photos are stored as attachments only when the feature is available for your plan and you choose to save them or when the App attaches them according to the intended flow. You must always verify recognized data before saving.
6. Location, maps and addresses
Location is optional. If you authorize access to location, the App may request the device's current location to associate it with a transaction.
You may also associate a location by choosing a place on the map or by using addresses recognized from a receipt. In these cases, the App may use Apple services such as CoreLocation, CLGeocoder, MapKit and MKLocalSearch to resolve coordinates, addresses or places.
Coordinates and addresses saved in a transaction remain in the App's local data. Analytics events, if enabled, may indicate only technical flags such as "the transaction has a location", but must not include precise coordinates or addresses.
7. Camera, photo library and barcodes
The camera may be used to:
- photograph receipts;
- scan barcodes from gift cards and loyalty cards;
- automatically fill some data through OCR.
The photo library may be used to select images to attach to a transaction.
Scanned barcodes are used to fill in or save local gift card or loyalty card records. We do not sell or share those codes with third parties for advertising purposes.
You can manage camera, photo and location permissions from iOS settings.
8. Notifications
Local notifications. The App may schedule local notifications for reminders, budgets or recurring transactions. They are handled by iOS on the device and do not pass through any server.
The content of a local notification may include information useful for the reminder, such as category, date, amount, currency or notes, depending on the configured feature. This information may be visible on the lock screen or in the notification center depending on iOS settings.
Shared account notifications. If you use a shared account and have granted notification permission, when the other person records an expense our server tells you with a push notification, which travels through Firebase Cloud Messaging (Google) and Apple's notification service.
To receive them, the App registers on our servers a delivery address provided by Apple for that installation, together with the device language and an installation identifier. It is not an advertising identifier and we do not use it to track you.
The message that goes out carries the name of whoever recorded the expense, the amount, the currency and the category: your phone needs them to compose the sentence you read, and the text is composed on the device. This means that this data passes through Google's and Apple's services in order to be delivered.
You can revoke notification permission from iOS settings at any time.
9. iOS widget and App Group
To display the widget, the App saves some summary data in a shared App Group area, such as:
- selected wallet name;
- currency;
- monthly balance;
- list of wallets and related balances for widget configuration;
- selected wallet identifier;
- PLUS status.
These data are local to the device and are used to make the widget work. They may be visible in the widget depending on how you configure it and on device settings.
10. Subscriptions and purchases
PLUS subscriptions are managed through the Apple App Store and StoreKit. Apple processes payment, billing, tax, receipt, free-trial eligibility, renewal, cancellation and refund data according to its own terms and privacy policy.
The App receives from StoreKit the technical information needed to manage PLUS access, such as product identifier, subscription status, expiration date, possible revocation, auto-renewal status and eligibility for introductory offers.
We do not receive or store the full payment card number or credentials of your Apple account.
11. Firebase Analytics
If you have given consent to analytics, the App may use Firebase Analytics to understand general use of the App, improve the product, and measure onboarding, paywall, purchase and feature funnels.
Analytics events may include, for example:
- app launch, sessions, screens viewed and onboarding completion;
- analytics or diagnostics consent;
- interactions with settings, paywall, selected plan, purchases, purchase restore and subscription status;
- use of features such as CSV import, receipt scanning, budgets, wallets, recurrences, export or feature gates;
- aggregated or bucketed counts, such as number of wallets, budgets or transactions;
- technical flags such as presence of notes, attachments, location or payment method;
- currency codes and technical categories.
Analytics events must not include:
- transaction amounts;
- wallet names;
- notes, descriptions or receipt text;
- merchants, addresses or precise coordinates;
- attachment or photo content;
- imported file names or CSV/XLSX file content;
- email, complete payment data or other personal identifiers entered by the user.
You can revoke analytics consent from the App's settings. When consent is denied or revoked, the App disables analytics collection and requests analytics data reset through the Firebase SDK, within the technical limits of the service.
11-bis. Budgy account and syncing
You can use Budgy without an account. Connecting one serves two purposes, and only those: finding your data on another device of yours, and using shared accounts.
How you sign in. With Sign in with Apple or with Google. We never create or store passwords. From Apple and Google we receive an account identifier and — if you choose to share them — your name and email. If you sign in with Apple and choose to hide your email, we only receive the relay address Apple creates.
What gets sent. With personal data sync on, the App copies to Firebase Firestore the data you have created: accounts, transactions, amounts, dates, categories, notes, budgets, tags, goals, debts and credits, cards, and attachment metadata. The attachment bytes — receipt photos — are uploaded to Firebase Cloud Storage. Everything is stored in the European Union (region europe-west8, Milan).
You can turn it off. The “Sync personal data” switch is in Settings → Data → Account. Turning it off stops the App from sending anything, and offers to delete the copy already uploaded: these are two different requests and we ask them separately.
Who can read that copy. Only you. Firebase security rules allow access to an account's documents only to that account, and they are enforced by the server: they do not depend on the App installed on your phone.
11-ter. Shared accounts
A shared account is the only feature in Budgy where some of your data becomes visible to another person, and it only happens if you open one or accept an invitation.
What the other person sees. That account's transactions — amounts, dates, categories, payment method, notes, recurrence — and the name you appear under, next to the expenses you entered. They also see the receipts you attach to a shared expense, and the location, if you chose to add it to that expense. Finally, they see the reactions each of you leaves on the other's expenses.
What they do NOT see. Your other accounts, budgets, goals, debts and credits and cards: they are not visible and are not sent to the shared space. They do not see the tags you put on expenses either, not even on a shared expense: tags stay on your device and in your copy, and never cross the boundary.
Receipts in a shared account live with the account, not in your personal archive: both people can open and delete them, and they are removed together with the account when it is deleted.
The name we show. Your account's name, and nothing else. If you signed in with Apple and chose to hide your name and email, the other person sees a generic label: we never fall back to your email address, because that would undo the choice you just made.
Who can take part. At most two people per account, and only by invitation: whoever opens the account generates an expiring code, valid for one person and one use.
When you leave. You can leave at any time and take a copy of the transactions into an account of your own. The expenses you entered stay in the other person's account: they are theirs too, and removing them would empty their books. Whoever opened the account can instead delete it for both of you, with thirty days to cancel, during which the data stays readable and exportable by both.
If the subscription of whoever opened the account expires, the account becomes read-only: nobody can add expenses any more, but the data stays visible, exportable and copyable. It is never deleted for this reason.
12. Crashlytics and diagnostics
If you have given consent to diagnostics, the App may use Firebase Crashlytics to collect crash reports and non-fatal errors in order to improve stability and security.
Reports may include technical data such as:
- App version and build number;
- bundle identifier;
- technical subscription status or error context;
- stack trace, device information, operating system and technical crash state;
- technical logs not intentionally containing personal financial data.
The App is designed not to send to Crashlytics amounts, notes, descriptions, wallet names, addresses, precise coordinates, attachment content or imported file content.
If you revoke diagnostics consent, the App disables Crashlytics collection and requests deletion of unsent reports. Reports already sent may continue to be processed by Firebase/Google according to applicable settings, terms and retention periods.
13. Firebase for legal documents
The App may download Terms, Privacy Policy or other informational documents from Firebase, for example Firebase Storage or related services.
When the App downloads these documents, Firebase/Google may process technical data necessary for the request, such as IP address, user agent or technical network information, according to its own terms and security measures. Downloading legal documents does not require sending your local financial data.
14. What we do not do
We do not sell your personal data.
We do not use local financial data for behavioral advertising.
We do not create a mandatory Budgy account.
Without a connected account we do not send to our servers amounts, notes, descriptions, attachments, wallets, barcodes, gift cards, loyalty cards or precise coordinates. With a connected account we send what syncing and shared accounts need, and only that: see sections 11-bis and 11-ter.
We do not access the App's local data remotely.
15. Purposes and legal bases
We process data for the following purposes:
- to provide App features, save local data and show information requested by the user;
- to sync your data across your devices and to operate shared accounts, when you turn those features on;
- to verify that a request comes from a genuine installation of the App, to prevent abuse;
- to manage PLUS subscriptions, purchases, restores and premium status through Apple StoreKit;
- to schedule local notifications at the user's request;
- to process receipts, attachments, barcodes, maps and locations when you use those features;
- to import, export or share data when you request it;
- to improve the App through analytics, only if you have given consent;
- to diagnose crashes and errors, only if you have given diagnostics consent;
- to respond to support, privacy or security requests;
- to comply with legal obligations or legitimate requests.
Legal bases may include:
- performance of a contract or pre-contractual measures, to provide the App and requested features;
- consent, for analytics, diagnostics, location, camera, photos, notifications or other optional features where required;
- legitimate interest, for security, support, abuse prevention and technical improvement, within the limits of the law;
- legal obligation, when we must comply with applicable rules or respond to valid requests.
16. Data sharing
We may share or make data available to:
- Apple, for App Store, StoreKit, payments, subscriptions, iCloud Backup, maps, geocoding, local notifications, widgets and iOS services;
- Google/Firebase, for analytics and crash reporting only if enabled, for downloading legal documents or remote resources, and — if you connect an account and turn on syncing — to store the copy of your data and run shared accounts;
- the person taking part with you in a shared account, limited to that account's transactions, the receipts you attach to them and your account's name;
- Google/Firebase Cloud Messaging and Apple's notification service, to deliver shared account notifications, as described in section 8;
- services chosen by you when you export, share, send or open files through other apps;
- consultants or technical providers, if necessary for support, security or legal obligations, in compliance with applicable law;
- competent authorities, if required by law.
We do not share local financial data with data brokers or advertisers.
17. International transfers
If you turn on syncing or use a shared account, your data is stored on Firebase in the European Union: the Firestore database and the attachment storage are in region europe-west8 (Milan), and the server functions that run shared accounts operate in the same region. Without these features enabled, Budgy does not transfer your financial data to the provider's servers.
Google may still process technical and service data outside the European Economic Area, under its own terms and safeguards.
Apple, Google/Firebase and other services you choose to use may process data in countries other than yours, including countries outside the European Economic Area. Such transfers are governed by the terms, security measures and safeguards of the respective providers, including any mechanisms required by the GDPR.
18. Retention
Local data remain on the device until:
- you modify or delete them in the App;
- you use the data reset or deletion feature;
- you delete the App and iOS removes the related data;
- an iCloud backup or restore preserves or restores them according to Apple settings.
Synced data remain on Firebase until you delete them: you can delete the copy on the server from the sync switch, or delete your whole account, which removes the data and the attachment photos. Rows you delete in the App leave a technical marker on the server, needed so that the deletion reaches your other devices; that marker is removed automatically after 90 days.
Shared accounts follow the same rules, with two differences: the expenses you entered stay visible to the other person even after you leave, because they are theirs too; and a deleted shared account is permanently destroyed thirty days after the request, together with all its content.
Exported or shared data remain with the service or destination chosen by you.
Analytics events and Crashlytics reports, if enabled and sent, are retained according to the applicable settings, terms and retention periods of Firebase/Google.
Support emails or requests may be retained for as long as necessary to respond, manage any follow-up and comply with legal obligations.
19. Security
We adopt reasonable and proportionate measures. The App keeps data on the device until you turn on syncing or a shared account.
For data that reaches the server:
- access is decided by rules enforced by the server, not by the App: an account's documents are readable only by that account, and a shared account's documents only by the people who belong to it;
- creating, inviting, joining, removing and transferring a shared account go through server functions: the App cannot change on its own who takes part in a space;
- requests are verified with Firebase App Check, which rejects traffic coming from apps that are not genuine;
- the author of a shared expense cannot be changed after creation: nobody can attribute to another person an expense they did not enter.
The security of local data also depends on:
- device passcode;
- Face ID, Touch ID or other security settings;
- iOS updates;
- iCloud settings;
- physical access to the device;
- apps or services to which you export or share files.
No system is 100% secure. We recommend protecting your device and carefully evaluating where you export your data.
20. Your rights
If you are in the European Economic Area, the United Kingdom or other jurisdictions with similar rights, you may have the right to:
- access personal data;
- rectification;
- erasure;
- restriction of processing;
- data portability;
- objection;
- withdraw consent, where processing is based on consent;
- lodge a complaint with a supervisory authority, in Italy the Garante per la protezione dei dati personali.
Because Budgy stores core financial data locally, many operations can be performed directly in the App: viewing, editing, exporting or deleting data.
For requests relating to data processed by us or for privacy questions, you can write to:
We may need to ask for additional information to verify identity or understand the request, within the limits allowed by law.
21. Withdrawal of consent and permissions
You can manage analytics and diagnostics from the App's privacy settings.
You can manage location, camera, photos and notifications from iOS settings. Revoking a permission may make some features unavailable.
You can manage device iCloud Backup and iCloud settings through iOS and, for the option exposed by the App, through Budgy's internal settings.
22. Minors
The App is not designed to knowingly collect personal data from minors through the provider's servers. However, the App may be available on the App Store with a rating suitable for a broad audience.
If you are a minor, use the App with the consent or supervision of a parent or guardian where required by law. If a parent or guardian believes that a minor has provided personal data processed by us through remote services, they may contact us at the address above.
23. Changes to this Privacy Policy
The July 31, 2026 update describes the Budgy account, data syncing and shared accounts: before that date the App did not send financial data to our servers.
The August 14, 2026 update adds shared account notifications, which did not exist before, and corrects three points that had become inaccurate in the meantime: the receipts on a shared expense are visible to both people, tags no longer are, and the English version of this document had fallen behind the Italian one.
We may update this Privacy Policy when the App, features, services used, legal requirements or the way we process data change.
The last updated date indicates the current version. If a change is material, we may notify you in the App or by other reasonable means.
24. Contact
For questions about this Privacy Policy or data processing:
Thomas Mauriello
Email: it.mauriello.thomas@gmail.com