AnytimeBudget (the “Service”) is designed so that your financial records remain on your device. This Privacy Policy explains the limited circumstances in which data leaves your phone, where it goes, how long it lasts on our side, and the rights you have in relation to it.
01.Overview
- Your full ledger is stored locally on your device. Assistant questions can share selected summaries and transaction excerpts with your consent.
- AI features send the information needed for your request through our backend to a third-party model. Resumable assistant questions temporarily store shared inputs, attachments, progress and answers on our backend.
- We retain operational rate-limit counters and process app-verification data to protect the service. Feedback you submit is stored for support.
- We do not use your data to train any model.
- We do not sell your data, serve advertisements, or use third-party trackers on this website.
02.Data we process
2.1 Data stored on your device
Transactions, accounts, categories, budgets, receipt images, voice recordings, settings, and locale preferences are stored locally in the application. We have no access to this data unless you actively transmit it through an AI-assisted feature.
2.2 Data processed in transit
When you invoke an AI-assisted feature, the following items pass through our backend on their way to the AI provider:
- The receipt image, audio clip, text, or document you submitted.
- The base currency code requested for exchange-rate lookups.
- A device-generated request identifier transmitted in the
X-User-IDheader. A hash of this identifier is used in server-side rate-limit counters; it is not an account login.
For the assistant, the shared data may also include your question, account names, categories, planning details, requested totals and up to 200 transaction excerpts per question. Automatic dates let the assistant request relevant periods from the app; a pinned date range limits access. The app calculates totals locally. Temporary storage allows a question to continue after you leave the screen or reopen the app. See Retention below.
2.3 Data we do not collect
- We do not require a name, email address or phone number to use the core app.
- Precise location, contacts, calendar, or any other device data not strictly required by a feature.
- Behavioural analytics or web tracking on this website.
- Assistant data for advertising or model training by AnytimeBudget.
03.Legal basis for processing
Where applicable data-protection law requires us to identify a legal basis, we rely on the following:
- Performance of a contract — to provide the Service you requested, including processing AI requests and temporarily saving resumable questions.
- Legitimate interests — to operate, secure, and maintain the Service, in a manner that does not override your rights.
- Consent — where you have provided it, such as by initiating an AI-assisted feature.
04.Purposes
We process the in-transit data described above for the following purposes only:
- To produce a structured result from the AI request you submitted.
- To return current foreign-exchange rates for the base currency you specified.
We do not use your data for analytics, model training, advertising, profile-building, or any other purpose.
05.Third-party processors
We share only what is strictly necessary to deliver each feature. We do not add an account login to AI prompts. The documents and account labels you choose to share may themselves contain personal information.
- Google Firebase (Cloud Functions, Hosting) — provides our backend infrastructure, including Firestore and Cloud Storage for temporary assistant jobs and operational data. Subject to Google's Privacy Policy.
- AI model providers — depending on the request, one of OpenRouter, xAI, Alibaba Cloud, or Perplexity receives the submitted payload to perform the extraction. Each provider's own retention, training, and security policies apply to data they receive.
- ExchangeRate-API — receives only a base currency code (no personal data) and returns exchange-rate tables. See their terms.
- Apple App Store / Google Play — process subscription billing if you upgrade to Plus or Pro. We receive only the receipt metadata necessary to unlock your subscription.
06.Retention
Assistant questions expire 24 hours after creation. Their inputs, shared summaries, excerpts, attachments, progress and answers are temporarily stored so the question can resume. After the app saves an answer, or you cancel, it requests deletion of this content. Expired content is removed by scheduled cleanup; expiry immediately prevents further access, while physical deletion depends on that cleanup completing. A content-free retry marker may remain until expiry. Cancelling while offline sends the deletion request when the app reconnects. Other operational records and user-submitted feedback are separate from assistant questions. Third-party AI providers apply their own retention policies.
Subscription receipts held by Apple or Google for billing purposes are retained by those platforms under their own policies, not ours.
07.Security
All traffic between the application and our backend is encrypted in transit using TLS. Credentials for third-party AI providers are held in Google Cloud Secret Manager and are not accessible from outside the server. Temporary assistant data is protected by server-side access checks. A random per-question key is kept in device secure storage; direct client access to the server database and attachment storage is denied.
No system is perfectly secure. We follow reasonable industry practices but cannot guarantee that data in transit is never intercepted, or that infrastructure on which we depend is never compromised. The security and retention practices of third parties are governed by their own policies.
08.Your rights
Depending on the jurisdiction in which you reside, applicable data-protection law may grant you rights including:
- Access — to obtain a copy of the personal data we hold about you.
- Rectification — to correct inaccurate personal data.
- Erasure — to request deletion of personal data.
- Restriction — to limit how we process your personal data.
- Portability — to receive your personal data in a structured, machine-readable format.
- Objection — to object to processing based on our legitimate interests.
- Withdrawal of consent — at any time, where processing relies on consent.
You can cancel an active assistant question to request deletion of its temporary server content. Turning off assistant data access stops new retrieval and requests cancellation of the active question. Requests made offline are sent when the app reconnects; expired data is also covered by scheduled cleanup. Manage local records directly in the app:
- Delete individual records in-app, or clear all data from Settings.
- Uninstall the application to remove every record at once.
- Subscription billing records are administered by Apple or Google under their respective policies.
09.Children
The Service is not directed at children under 13, and we do not knowingly collect personal data from children. If you believe a child has used the Service, please take appropriate steps to remove the application from the device.
10.International transfers
Our backend operates from Google's
asia-east2
region (Hong Kong). The third-party AI providers and rate services
listed above may process data in other jurisdictions, including
the United States, the United Kingdom, mainland China, and the
European Union. By using AI-assisted features, you acknowledge
that the in-transit payload may cross these borders during the
request, including the temporary processing and storage described above.
11.Changes to this Policy
We may update this Privacy Policy from time to time. The version in force is the one displayed at this URL; the “Effective” and “Last updated” dates above reflect the current version. For material changes, we will provide notice within the application before the change takes effect.
End of document · Vol. I