Privacy Policy
Effective: May 10, 2026 · Last updated: July 3, 2026
Contents
- 1. Overview
- 2. Information We Collect
- 3. How We Use Your Information
- 4. Third Parties We Share Data With
- 5. Advertising — What We Never Do
- 6. Cookies and Tracking
- 7. Data Retention
- 8. Security
- 9. Developer and Admin Access
- 10. Your Privacy Rights
- 11. Children's Privacy
- 12. International Data Transfers
- 13. Changes to This Policy
- 14. Contact Us
1. Overview
BudgetCal — a product of HeroLabs, a trade name of 17981341 Canada Inc. ("we," "us," "our") — is committed to protecting your privacy. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have over your data. We built BudgetCal on a simple principle: your financial data belongs to you. We do not sell it, rent it, or use it for advertising. We collect only what is necessary to run the service. This policy applies to budgetcal.app and all related BudgetCal services.
2. Information We Collect
Information You Provide
- Name and email address (when you register) - Password (stored as a one-way bcrypt hash — we cannot read it) - Transaction data: names, dates, amounts, categories, and notes you enter - Account information: account names, starting balances, account types - Attachments: receipt images or bill photos you upload (BudgetCal plan) - Payment information: billing address and last 4 digits of card (stored by Stripe, not by us) - Support messages: emails you send to contact@budgetcal.app
Information Collected Automatically
- IP address and country (for security and fraud prevention) - Browser type and operating system (for compatibility) - Pages visited and features used within BudgetCal (aggregated, not tied to individual sessions for advertising) - Error logs and crash reports (for debugging — contain no financial data) We use Vercel Analytics for aggregated, privacy-friendly usage statistics. It does not use cookies or fingerprinting.
What We Do NOT Collect
- Your banking login credentials - Your social insurance number, social security number, or government ID - Keystrokes, mouse movements, or screen recordings - Behavioral data for advertising purposes - Data from third-party advertising networks
3. How We Use Your Information
We use your information only to: - Provide and maintain the BudgetCal service - Process subscription payments through Stripe - Send transactional emails: account confirmation, password reset, billing receipts - Send weekly spending digest emails (BudgetCal plan, only if enabled in Settings) - Provide AI-powered receipt scanning (BudgetCal plan) — images are sent to Anthropic's API and immediately discarded, not stored - Respond to support requests - Detect and prevent fraud and abuse - Comply with legal obligations We do not use your financial data to train machine learning models, build advertising profiles, or infer information about you for any purpose beyond running your personal budget calendar.
4. Third Parties We Share Data With
We share data only with the following service providers, each bound by a data processing agreement, and only to the extent necessary to operate BudgetCal: Supabase, Inc. (USA) Purpose: Database storage and file storage Data shared: All User Content, account credentials Privacy: supabase.com/privacy Stripe, Inc. (USA) Purpose: Payment processing and billing Data shared: Email, billing address, subscription details Privacy: stripe.com/privacy Resend, Inc. (USA) Purpose: Transactional and digest emails Data shared: Email address and email content Privacy: resend.com/privacy Anthropic PBC (USA) — BudgetCal plan only Purpose: AI receipt scanning Data shared: Receipt images submitted for scanning only. Images are not stored by Anthropic after processing. Privacy: anthropic.com/privacy Vercel, Inc. (USA) Purpose: Hosting and aggregated performance analytics Data shared: Anonymized request logs (no financial data) Privacy: vercel.com/legal/privacy-policy We do not share your data with: data brokers, advertising networks, social media platforms, analytics companies beyond the above, or any other third party.
5. Advertising — What We Never Do
BudgetCal runs no advertising of any kind. We make no money from advertising. We never: - Show you ads inside BudgetCal - Share your data with Meta, Google Ads, or any advertising network - Use your spending patterns to build an advertising profile - Install advertising trackers, pixels, or beacons on our site - Sell, rent, or trade your personal or financial information Our only revenue comes from your subscription. Our incentive is to make the app better for you, not to monetize your data.
7. Data Retention
Active Accounts: We retain your data as long as your account is active. After Account Deletion: - Transaction data, categories, settings, and attachments are deleted from active systems within 7 days. - Backup copies are fully purged within 30 days. - Third-party service providers are notified of deletion within 7 days. Billing Records: Stripe billing history (payment amounts, dates) is retained for up to 7 years as required by financial regulations. This contains no financial transaction data from inside your budget. Support Records: Emails to our support team are retained for 2 years, then deleted. Aggregated Analytics: Non-identifiable, aggregated usage statistics (e.g., "500 users added transactions on Tuesday") may be retained indefinitely for product improvement. These cannot be traced back to any individual.
8. Security
We take reasonable and industry-standard steps to protect your data: - All data in transit is encrypted using TLS 1.2 or higher - Data at rest is encrypted using AES-256 (Supabase's default) - Passwords are stored as bcrypt hashes — we cannot view your password - Row-Level Security (RLS) is enforced at the database level — each query is automatically filtered to your user ID, so no user can ever access another user's data - Access to production systems is restricted to authorized personnel only - We perform regular security reviews of our infrastructure No system is 100% secure. If we discover a breach that poses a real risk of significant harm to you, we will notify you within 72 hours of becoming aware of it, as required by applicable law (PIPEDA, GDPR). If you discover a security vulnerability, please disclose it responsibly to contact@budgetcal.app with "Security" in the subject line.
9. Developer and Admin Access
We believe transparency about internal access is just as important as protecting against external threats. Row Level Security (RLS) is enforced at the database level, so the application only ever serves you your own data — no user can access another user's data. Internal support access: BudgetCal operates a restricted internal support dashboard, accessible only to named administrators, used solely to run the business and help you when you contact us. Through it, administrators can see: - Your name, email, signup date, and last sign-in - Your subscription and trial status (from Stripe) - Usage statistics (e.g., number of transactions, referrals) - The names, types, and currencies of your accounts (e.g., "Chequing — CAD") - Error logs generated by your sessions The support dashboard has no capability to display your balances, transactions, notes, attachments, or receipts — administrators cannot see what you spend, earn, or save, at all. Access is used only for customer support you initiate, billing administration (extending trials, applying discounts, processing refunds), and investigating fraud, abuse, or technical errors. Automated server-side processes also access user data with no human in the loop: - Bill reminder emails (only if you enable reminders in Settings) - Stripe subscription management - Account provisioning when you first sign up (seeding your default categories) Beyond the limited support access described above, we do not read, analyze, review, or monitor individual users' financial data for any reason — including debugging, analytics, or curiosity. If an investigation ever requires deeper access to your data, we will contact you first and request your explicit permission.
10. Your Privacy Rights
Regardless of where you live, you have the following rights over your data: Access: Request a copy of all personal data we hold about you. Correction: Request correction of inaccurate or incomplete information. Deletion: Delete your account and all associated data yourself at any time from your profile menu (avatar → Account & Data → Delete My Account), or email us to request deletion. Export: Download all your accounts and transactions in a machine-readable format (CSV) at any time from your profile menu (avatar → Account & Data → Export My Data). Opt-out of marketing: Unsubscribe from non-essential emails at any time using the unsubscribe link in any email. To exercise any of these rights, email contact@budgetcal.app with "Privacy Request" in the subject line. We will respond within 30 days (or 15 days for Quebec residents under Law 25). Additional regional rights (CCPA, GDPR, PIPEDA, Australian Privacy Act) are described in our Terms and Conditions, Section 15.
11. Children's Privacy
BudgetCal is not directed at or intended for use by children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has created an account, please contact contact@budgetcal.app and we will delete it immediately.
12. International Data Transfers
BudgetCal is operated from Canada. Our service providers (Supabase, Stripe, Resend, Vercel, Anthropic) are based in the United States. By using BudgetCal, you acknowledge that your data may be transferred to and processed in the United States and other countries where our service providers operate. For EU/UK users: We rely on Standard Contractual Clauses (SCCs) where required for lawful data transfers outside the EEA/UK.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email at least 14 days before the changes take effect and update the "Last Updated" date at the top of this page. Your continued use of BudgetCal after the effective date constitutes acceptance of the updated policy.
14. Contact Us
For privacy questions, data requests, or to exercise your rights: 17981341 Canada Inc., carrying on business as HeroLabs Email: contact@budgetcal.app General support: contact@budgetcal.app Website: https://budgetcal.app We aim to respond to all privacy inquiries within 5 business days.