Budgy

Legal documents

Privacy Policy

Last updated: August 14, 2026

Table of contents (26)
  1. 1. Data controller
  2. 2. Scope of this policy
  3. 3. Summary
  4. 4. Data you can create in the App
  5. 5. Attachments, photos and receipts
  6. 6. Location, maps and addresses
  7. 7. Camera, photo library and barcodes
  8. 8. Notifications
  9. 9. iOS widget and App Group
  10. 10. Subscriptions and purchases
  11. 11. Firebase Analytics
  12. 11-bis. Budgy account and syncing
  13. 11-ter. Shared accounts
  14. 12. Crashlytics and diagnostics
  15. 13. Firebase for legal documents
  16. 14. What we do not do
  17. 15. Purposes and legal bases
  18. 16. Data sharing
  19. 17. International transfers
  20. 18. Retention
  21. 19. Security
  22. 20. Your rights
  23. 21. Withdrawal of consent and permissions
  24. 22. Minors
  25. 23. Changes to this Privacy Policy
  26. 24. Contact

This Privacy Policy describes how Budgy ("App") processes information when you use the App. The App is provided by Thomas Mauriello, an individual developer based in Italy ("we", "us", "our", "controller" or "provider").

Budgy started as a local app: the financial data you enter is stored on your device. It stays there alone until you connect an account: from that moment the App can copy it to our servers to sync it across your devices and for shared accounts, and you can turn either of those off whenever you want.

Two features do: personal data sync, which copies your data to Firebase so you can find it on your other devices, and shared accounts, which make some expenses visible to another person you invite. Neither happens without connecting an account. Some features may also involve Apple, Google/Firebase or services chosen by you, as explained below.

1. Data controller

For purposes of Regulation (EU) 2016/679 ("GDPR"), the data controller is:

Thomas Mauriello
Italy
Email: it.mauriello.thomas@gmail.com

2. Scope of this policy

This policy covers:

This policy does not govern the privacy policies of Apple, Google/Firebase or other third-party services, which remain responsible for processing carried out for their own purposes.

3. Summary

4. Data you can create in the App

Depending on how you use Budgy, you may create or save locally:

These data are normally stored on your device in local stores, local files or UserDefaults. Some summary data are copied into the App Group to allow the widget to work.

5. Attachments, photos and receipts

If you add attachments or photograph a receipt, the App may compress and save the image as a local file managed by the App.

If you use receipt scanning, the App may process the image with Apple Vision and CoreImage on the device to recognize text, amount, date, currency, notes, possible payment method, possible category and possible address. The results may be applied to the transaction form.

The App keeps a small in-memory OCR cache for the current session, so it does not need to run recognition again on the same photo. This cache is not designed to be sent to the provider's servers.

Receipt photos are stored as attachments only when the feature is available for your plan and you choose to save them or when the App attaches them according to the intended flow. You must always verify recognized data before saving.

6. Location, maps and addresses

Location is optional. If you authorize access to location, the App may request the device's current location to associate it with a transaction.

You may also associate a location by choosing a place on the map or by using addresses recognized from a receipt. In these cases, the App may use Apple services such as CoreLocation, CLGeocoder, MapKit and MKLocalSearch to resolve coordinates, addresses or places.

Coordinates and addresses saved in a transaction remain in the App's local data. Analytics events, if enabled, may indicate only technical flags such as "the transaction has a location", but must not include precise coordinates or addresses.

7. Camera, photo library and barcodes

The camera may be used to:

The photo library may be used to select images to attach to a transaction.

Scanned barcodes are used to fill in or save local gift card or loyalty card records. We do not sell or share those codes with third parties for advertising purposes.

You can manage camera, photo and location permissions from iOS settings.

8. Notifications

Local notifications. The App may schedule local notifications for reminders, budgets or recurring transactions. They are handled by iOS on the device and do not pass through any server.

The content of a local notification may include information useful for the reminder, such as category, date, amount, currency or notes, depending on the configured feature. This information may be visible on the lock screen or in the notification center depending on iOS settings.

Shared account notifications. If you use a shared account and have granted notification permission, when the other person records an expense our server tells you with a push notification, which travels through Firebase Cloud Messaging (Google) and Apple's notification service.

To receive them, the App registers on our servers a delivery address provided by Apple for that installation, together with the device language and an installation identifier. It is not an advertising identifier and we do not use it to track you.

The message that goes out carries the name of whoever recorded the expense, the amount, the currency and the category: your phone needs them to compose the sentence you read, and the text is composed on the device. This means that this data passes through Google's and Apple's services in order to be delivered.

You can revoke notification permission from iOS settings at any time.

9. iOS widget and App Group

To display the widget, the App saves some summary data in a shared App Group area, such as:

These data are local to the device and are used to make the widget work. They may be visible in the widget depending on how you configure it and on device settings.

10. Subscriptions and purchases

PLUS subscriptions are managed through the Apple App Store and StoreKit. Apple processes payment, billing, tax, receipt, free-trial eligibility, renewal, cancellation and refund data according to its own terms and privacy policy.

The App receives from StoreKit the technical information needed to manage PLUS access, such as product identifier, subscription status, expiration date, possible revocation, auto-renewal status and eligibility for introductory offers.

We do not receive or store the full payment card number or credentials of your Apple account.

11. Firebase Analytics

If you have given consent to analytics, the App may use Firebase Analytics to understand general use of the App, improve the product, and measure onboarding, paywall, purchase and feature funnels.

Analytics events may include, for example:

Analytics events must not include:

You can revoke analytics consent from the App's settings. When consent is denied or revoked, the App disables analytics collection and requests analytics data reset through the Firebase SDK, within the technical limits of the service.

11-bis. Budgy account and syncing

You can use Budgy without an account. Connecting one serves two purposes, and only those: finding your data on another device of yours, and using shared accounts.

How you sign in. With Sign in with Apple or with Google. We never create or store passwords. From Apple and Google we receive an account identifier and — if you choose to share them — your name and email. If you sign in with Apple and choose to hide your email, we only receive the relay address Apple creates.

What gets sent. With personal data sync on, the App copies to Firebase Firestore the data you have created: accounts, transactions, amounts, dates, categories, notes, budgets, tags, goals, debts and credits, cards, and attachment metadata. The attachment bytes — receipt photos — are uploaded to Firebase Cloud Storage. Everything is stored in the European Union (region europe-west8, Milan).

You can turn it off. The “Sync personal data” switch is in Settings → Data → Account. Turning it off stops the App from sending anything, and offers to delete the copy already uploaded: these are two different requests and we ask them separately.

Who can read that copy. Only you. Firebase security rules allow access to an account's documents only to that account, and they are enforced by the server: they do not depend on the App installed on your phone.

11-ter. Shared accounts

A shared account is the only feature in Budgy where some of your data becomes visible to another person, and it only happens if you open one or accept an invitation.

What the other person sees. That account's transactions — amounts, dates, categories, payment method, notes, recurrence — and the name you appear under, next to the expenses you entered. They also see the receipts you attach to a shared expense, and the location, if you chose to add it to that expense. Finally, they see the reactions each of you leaves on the other's expenses.

What they do NOT see. Your other accounts, budgets, goals, debts and credits and cards: they are not visible and are not sent to the shared space. They do not see the tags you put on expenses either, not even on a shared expense: tags stay on your device and in your copy, and never cross the boundary.

Receipts in a shared account live with the account, not in your personal archive: both people can open and delete them, and they are removed together with the account when it is deleted.

The name we show. Your account's name, and nothing else. If you signed in with Apple and chose to hide your name and email, the other person sees a generic label: we never fall back to your email address, because that would undo the choice you just made.

Who can take part. At most two people per account, and only by invitation: whoever opens the account generates an expiring code, valid for one person and one use.

When you leave. You can leave at any time and take a copy of the transactions into an account of your own. The expenses you entered stay in the other person's account: they are theirs too, and removing them would empty their books. Whoever opened the account can instead delete it for both of you, with thirty days to cancel, during which the data stays readable and exportable by both.

If the subscription of whoever opened the account expires, the account becomes read-only: nobody can add expenses any more, but the data stays visible, exportable and copyable. It is never deleted for this reason.

12. Crashlytics and diagnostics

If you have given consent to diagnostics, the App may use Firebase Crashlytics to collect crash reports and non-fatal errors in order to improve stability and security.

Reports may include technical data such as:

The App is designed not to send to Crashlytics amounts, notes, descriptions, wallet names, addresses, precise coordinates, attachment content or imported file content.

If you revoke diagnostics consent, the App disables Crashlytics collection and requests deletion of unsent reports. Reports already sent may continue to be processed by Firebase/Google according to applicable settings, terms and retention periods.

The App may download Terms, Privacy Policy or other informational documents from Firebase, for example Firebase Storage or related services.

When the App downloads these documents, Firebase/Google may process technical data necessary for the request, such as IP address, user agent or technical network information, according to its own terms and security measures. Downloading legal documents does not require sending your local financial data.

14. What we do not do

We do not sell your personal data.

We do not use local financial data for behavioral advertising.

We do not create a mandatory Budgy account.

Without a connected account we do not send to our servers amounts, notes, descriptions, attachments, wallets, barcodes, gift cards, loyalty cards or precise coordinates. With a connected account we send what syncing and shared accounts need, and only that: see sections 11-bis and 11-ter.

We do not access the App's local data remotely.

We process data for the following purposes:

Legal bases may include:

16. Data sharing

We may share or make data available to:

We do not share local financial data with data brokers or advertisers.

17. International transfers

If you turn on syncing or use a shared account, your data is stored on Firebase in the European Union: the Firestore database and the attachment storage are in region europe-west8 (Milan), and the server functions that run shared accounts operate in the same region. Without these features enabled, Budgy does not transfer your financial data to the provider's servers.

Google may still process technical and service data outside the European Economic Area, under its own terms and safeguards.

Apple, Google/Firebase and other services you choose to use may process data in countries other than yours, including countries outside the European Economic Area. Such transfers are governed by the terms, security measures and safeguards of the respective providers, including any mechanisms required by the GDPR.

18. Retention

Local data remain on the device until:

Synced data remain on Firebase until you delete them: you can delete the copy on the server from the sync switch, or delete your whole account, which removes the data and the attachment photos. Rows you delete in the App leave a technical marker on the server, needed so that the deletion reaches your other devices; that marker is removed automatically after 90 days.

Shared accounts follow the same rules, with two differences: the expenses you entered stay visible to the other person even after you leave, because they are theirs too; and a deleted shared account is permanently destroyed thirty days after the request, together with all its content.

Exported or shared data remain with the service or destination chosen by you.

Analytics events and Crashlytics reports, if enabled and sent, are retained according to the applicable settings, terms and retention periods of Firebase/Google.

Support emails or requests may be retained for as long as necessary to respond, manage any follow-up and comply with legal obligations.

19. Security

We adopt reasonable and proportionate measures. The App keeps data on the device until you turn on syncing or a shared account.

For data that reaches the server:

The security of local data also depends on:

No system is 100% secure. We recommend protecting your device and carefully evaluating where you export your data.

20. Your rights

If you are in the European Economic Area, the United Kingdom or other jurisdictions with similar rights, you may have the right to:

Because Budgy stores core financial data locally, many operations can be performed directly in the App: viewing, editing, exporting or deleting data.

For requests relating to data processed by us or for privacy questions, you can write to:

it.mauriello.thomas@gmail.com

We may need to ask for additional information to verify identity or understand the request, within the limits allowed by law.

You can manage analytics and diagnostics from the App's privacy settings.

You can manage location, camera, photos and notifications from iOS settings. Revoking a permission may make some features unavailable.

You can manage device iCloud Backup and iCloud settings through iOS and, for the option exposed by the App, through Budgy's internal settings.

22. Minors

The App is not designed to knowingly collect personal data from minors through the provider's servers. However, the App may be available on the App Store with a rating suitable for a broad audience.

If you are a minor, use the App with the consent or supervision of a parent or guardian where required by law. If a parent or guardian believes that a minor has provided personal data processed by us through remote services, they may contact us at the address above.

23. Changes to this Privacy Policy

The July 31, 2026 update describes the Budgy account, data syncing and shared accounts: before that date the App did not send financial data to our servers.

The August 14, 2026 update adds shared account notifications, which did not exist before, and corrects three points that had become inaccurate in the meantime: the receipts on a shared expense are visible to both people, tags no longer are, and the English version of this document had fallen behind the Italian one.

We may update this Privacy Policy when the App, features, services used, legal requirements or the way we process data change.

The last updated date indicates the current version. If a change is material, we may notify you in the App or by other reasonable means.

24. Contact

For questions about this Privacy Policy or data processing:

Thomas Mauriello
Email: it.mauriello.thomas@gmail.com