Legal

Privacy Policy

Effective September 13, 2026

1. Who We Are and What This Policy Covers

Bao Budget is a paid-subscription personal finance application operated by NAS Innovation LLC, a Massachusetts limited liability company ("Bao Budget," "we," "us," "our"). Our registered postal address, which is also our registered agent's address, is 82 Wendell Ave Ste 100, Pittsfield, MA 01201.

Bao Budget consolidates your accounts, transactions, budgets, and goals in one place. Bao Budget is not a bank and does not hold, move, or have custody of your money. Our access to any bank account you connect is read-only. We cannot initiate transfers, make payments, or move funds.

This policy explains what personal information we collect, why we collect it, who we share it with, how long we retain it, and the choices and rights available to you. It applies to our applications and to our marketing website.

Intended audience. Bao Budget is offered only to users located in the United States. We do not offer the service to users in the European Economic Area or the United Kingdom, and this policy does not describe rights under the GDPR or UK GDPR.

This restriction is enforced. We check the country from which your request originates, and we refuse to create an account from outside the permitted list. The check runs at both methods of creating an account — email-and-password signup and Sign in with Google or Sign in with Apple — and again at subscription checkout, so no path creates a paying customer outside that list. The list comprises the United States together with the five inhabited U.S. territories: Puerto Rico, the U.S. Virgin Islands, Guam, American Samoa, and the Northern Mariana Islands. If we cannot determine where a request originated, we refuse it rather than assume it is permitted.

Two limits apply. First, the check gates account creation, not signing in: if you already have an account and you are travelling, you may still sign in and reach your own data. Second, geolocation is sometimes wrong — a VPN, a corporate network, or a mis-mapped address will produce that result — and there is no override and no appeals process. If you are in the United States and were refused, trying again from a U.S. connection is the only remedy.

Age. Bao Budget is intended for adults. You must be at least 18 years old to create an account or use the service. Our email-and-password signup flow requires a date of birth and enforces this minimum age. Our Google and Apple sign-in flow also requires you to confirm your date of birth, through a consent step completed immediately after sign-in and before you may reach any part of the app. In all cases, Bao Budget is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has created an account, contact privacy@baobudget.com and we will delete the account and its data.

Accessibility. We do not publish an accessibility conformance statement.

Contact. Privacy questions and requests: privacy@baobudget.com. Legal notices: legal@baobudget.com. Security and vulnerability reports: security@baobudget.com. Support: support@baobudget.com and https://baobudget.com/support.


2. Information We Collect

We collect four distinct categories of information, of which financial account data is its own named category.

2.1 Account and Identity Data

Information you provide when you create and maintain an account:

  • Contact and identity information: your email address, name, and date of birth
  • Your password, stored only as a cryptographic hash (we never store the password itself), and any other authentication credentials you establish, such as multi-factor authentication, a passkey, or an API key
  • Account settings, such as your time zone
  • If you sign in with Google or Apple, the email address and basic profile they return to us

2.2 Financial Account Data Obtained Through Connected Institutions

If you connect a financial institution, we receive account and transaction data from that institution through our aggregation provider. We never see or store your bank login credentials. You authenticate directly with your institution inside the provider's own hosted flow. We do not store full bank account numbers, routing numbers, Social Security numbers, or tax identification numbers. Your institution does supply the last four digits of an account, and we include them in that account's display name so you can tell two accounts at the same bank apart — they appear in the app and in your data export.

What we do receive and store, for the accounts on the connection: your accounts — name, type, currency, institution name, and balance; your transaction history — date, amount, description, merchant, and the institution's own category; your liabilities, which for credit and loan accounts means credit limits, statement balances, minimum payments, due dates, and interest rates; and — where applicable — your investment holdings, including standard security identifiers, and your investment transactions. We also store the budgets, goals, and income and expense tracking you establish around this data.

You may enter any of the above manually instead of connecting an institution. Bao Budget is fully usable with manual entry alone.

2.3 Usage and Device Data

  • Security and audit events, such as sign-in, multi-factor changes, export, and deletion, which record your IP address and user agent
  • Product analytics concerning how the application is used (see section 6)
  • Information you provide when you report an issue, enable push notifications, or participate in gamification and community features (achievements, leaderboards, and the share cards you choose to create). Leaderboards identify you by a non-identifying display handle rather than your name or email address.
  • Merchant enrichment contributions. When you categorise a transaction by hand, that categorisation may contribute, in aggregated form, to a shared merchant dictionary that helps everyone's transactions categorise more accurately. This setting is on by default, and you can switch it off at any time in Settings.

What a merchant enrichment contribution is. This is the one use of your data that benefits other users as well as you, and it is limited as follows.

  • Only your own manual choices contribute. A contribution happens when you categorise a transaction yourself and your choice is the one that sticks. A category that came from your bank, from an automation rule, or from one of our own suggestions does not contribute, and a transaction with no merchant produces none.
  • What leaves your account: a shortened form of the merchant name — a short brand fragment, with store, location, and processor detail taken off — and the category you chose, expressed in the same category list the rest of the product uses. Nothing else.
  • What never leaves: your amounts, your dates, your transaction descriptions, your account and institution names, your balances, and your identity.
  • Contributions are aggregated. The shared merchant dictionary records what a merchant is generally categorised as. It holds no user identifier of any kind, and no individual contribution in it is identifiable to a person. Your identity is used for one thing only: keeping track of which merchants you have already contributed to, so that one person counts once. That record is never published and never included in another user's data.
  • One person cannot establish an entry. An entry is used to help categorise other people's transactions only once enough separate people have independently agreed on the same category for it. Below that point it is not used.

Turning merchant enrichment off. The "Help improve auto-categorization" switch in Settings turns it off, immediately and for good; the same setting is also reachable through your privacy preferences. There is no delay and no confirmation step. Every active enrichment consent record on your account is revoked and no further contribution is made from your transactions. It does not withdraw contributions you already made — those remain and continue to count toward the entries they supported, an established entry stays in the shared dictionary, and there is no in-product way to remove past contributions. Deleting your account removes your contribution records, but does not recalculate the shared entries they had already counted toward; an established entry keeps the agreement count it had, and contains no identifier of yours either way.

Where IP addresses are stored. We store your IP address in two places: with the security-relevant account activity described above, and — separately, with anonymization disabled — on a security-monitoring analytics project we operate to detect abuse across requests. Our main product-analytics project, by contrast, truncates IP addresses before storing them. Both are subject to the same one-year analytics retention limit described in section 6.

2.4 Support Communications

When you contact us, we retain what you send us and our replies, including the email address you write from and any information you choose to include.

2.5 California Statutory Categories

Where California law requires us to describe what we collect using its own category labels (Cal. Civ. Code §1798.140(v)(1)(A)–(K)), the categories we collect are:

Statutory categoryDo we collect it?What it is, for us
(A) IdentifiersYesEmail, name, account identifiers, IP address (see 2.3)
(B) Personal information under Cal. Civ. Code §1798.80(e)YesName and financial account information (see 2.2)
(C) Protected classification characteristicsYes — age onlyDate of birth
(D) Commercial informationYesSubscription, purchase, transaction, and merchant records
(E) Biometric informationNoPasskeys and device unlock happen on your device; we receive a public key, never a biometric.
(F) Internet or other network activityYesProduct analytics and device/usage information
(G) Geolocation dataYes — coarse onlyThe city and region a transaction is associated with. We do not collect device GPS location.
(H) Sensory data (audio, visual, thermal, olfactory)No
(I) Professional or employment-related informationYes — limitedIncome data, and equity-compensation values within investment holdings
(J) Non-public education informationNo
(K) Inferences drawn to create a profileYes — limitedCategorization, spending patterns, and projections generated to power the product for you

Sensitive personal information. Under California law, credentials allowing access to an account are sensitive personal information (§1798.140(ae)(1)(B)). The bank access tokens we hold on your behalf fall within that category. We use sensitive personal information only to provide the service you requested, and for no secondary purpose — so there is nothing for you to limit under §1798.121. See section 7.

2.6 Sources, Purposes, Recipients, and Retention by Category

California requires these four elements to be stated for each category of personal information (Cal. Civ. Code §1798.130(a)(5)(B)–(C) and §1798.100(a)(3); 11 CCR §7011(e)), not only in aggregate. The table below does so, using the same statutory categories as the table in section 2.5.

CategoryWhere we get itBusiness or commercial purposeCategories of third parties we disclose it toHow long we keep it
(A) IdentifiersYou; Google or Apple if you sign in with them; automatically, for the IP addressAccount creation and security; authentication; billing; support; legal complianceHosting/database, email, payments, rate-limiting, and analytics providers; aggregation provider (internal identifier only)While your account is active, then per section 10
(B) Personal information under §1798.80(e)You; your financial institution via our aggregation providerProviding the product; billing; legal complianceHosting/database providers; payments processor; aggregation providerWhile your account is active, then per section 10
(C) Protected classification characteristics (age)You, on the email-and-password signup path onlyConfirming eligibility to use Bao BudgetHosting/database providersWhile your account is active, then per section 10
(D) Commercial informationYour financial institution via our aggregation provider; you, if entered manually; our payments processorProviding the product; billingHosting/database providers; payments processorWhile your account is active, then per section 10. Imported transaction history is retained when you disconnect an institution
(F) Internet or other network activityAutomatically as you use the product; issue reports you submitMeasuring and improving the product; security monitoringAnalytics provider (including its security-monitoring project); hosting providerAnalytics: 1 year, our analytics provider's plan retention window. Hosting-provider traffic data: see section 10
(G) Geolocation data (coarse, transaction-derived)Your financial institution via our aggregation providerDisplaying and categorizing your transactionsHosting/database providersRetained with the transaction it belongs to — see category (D)
(I) Professional or employment-related informationYour financial institution via our aggregation provider; you, if entered manuallyIncome tracking, budgeting, and projectionsHosting/database providersWhile your account is active, then per section 10
(K) InferencesGenerated by us from the categories aboveProviding the productHosting/database providersWhile your account is active, then per section 10

Categories (E), (H) and (J) are not collected, so there is nothing to state for them.


3. Connecting a Financial Institution

To connect an account, we use a single licensed data-aggregation provider:

We request from Quiltt the account, balance, transaction, liability and investment data described in section 2.2. You give us express written consent to retrieve that data when you complete the connect flow, and you may withdraw it at any time by disconnecting the institution.

Data derived from your connected-account data is used solely for your benefit. We do not use it for aggregate benchmarking, for population-level products, or to train models, unless you separately and specifically consent.

Our relationship to them. The provider acts as our service provider for the purpose of retrieving your account data at your direction. When you use the provider's connect flow, you also enter into a direct relationship with that provider, governed by their policy linked above. We are separately responsible for how we use the data once we receive it, and that use is described in this policy.

How the connection works.

  1. You select your institution inside the provider's hosted flow.
  2. You authenticate directly with your institution. We never see, receive, or store your bank username, password, or one-time codes.
  3. The provider returns an access token to us, which we store encrypted (see section 9). We never receive your credentials themselves.
  4. We receive the account, transaction, balance, liability, and investment data described in section 2.2.

Your consent. By completing the connect flow, you give us your express written consent to access, retrieve, store, and use your financial account data as described in this policy, for the purpose of providing Bao Budget to you. You may withdraw that consent at any time by disconnecting the institution in the app, which revokes our access with the provider (see Disconnecting an institution below).

What we record when you consent. When a connection completes, we write one consent record: the version of this policy you agreed to, the provider, the products the connection granted, the institution name, the provider's identifier for that connection, and the time it was granted. The scope recorded is what the connection actually granted, as the provider states it — not what we asked for. Re-connecting an institution you are already connected to does not write a second record; your original record, and its grant date, stand.

Attribution. Where our connect experience is white-labeled, it carries "Powered by Quiltt" attribution as required by our agreement with Quiltt.

Read-only. Completing a connection grants us read-only access, through the provider, to the accounts you select at the institution you select. We cannot initiate transfers, make payments, move funds, or change anything at your bank.

Disconnecting an institution. You can disconnect an institution at any time, from inside the app. You do not need to contact us, and there is no waiting period. In one operation we tell the provider to sever the connection; mark our stored credential revoked and inactive, so nothing can sync on it again; disconnect every account on that connection in your app and release any goal reserves held against those accounts; and revoke the bank-connection consent record for that connection.

Two limits on disconnecting. The provider-side revocation is best-effort and has no retry or reconciliation behind it: if the provider is unreachable at that moment we log the failure and continue, so a silently failed call can leave the connection live at the provider after we have marked it revoked on our side. The consent-record revocation is likewise best-effort and non-blocking — a failure there is logged and the disconnect still completes, which can leave a consent record marked active for a connection that is gone.

Disconnecting stops future data flowing to us; it does not erase the history already in your account. To remove that history, delete your account (section 11). How long we keep each category of connected-account data is set by the table in section 2.6 and the rules in section 10.

Re-authorization. We flag active bank-connection consents that are more than one year old, and count them. That is all that happens today. Nothing notifies you, nothing re-prompts you for authorization, and nothing stops collecting data on a consent that has aged past a year. Re-authorization does not happen today, and nothing in this policy should be read as saying that it does.


4. How We Use Your Information

We use your information to:

  1. Provide the product — display your accounts, transactions, budgets, goals, net worth, and projections; categorize transactions; detect recurring streams; and maintain synchronization with connected institutions.
  2. Authenticate you and secure your account — sign-in, multi-factor authentication, passkeys, session and refresh-token management, rate limiting, and the audit log.
  3. Bill you — process your subscription through Stripe, and send billing and receipt communications.
  4. Communicate with you — service, security, and account messages; product notifications you have enabled; and replies to your support requests.
  5. Operate and improve the product — determine which features are used, diagnose errors, and prioritize work, using the analytics described in section 6.
  6. Operate the gamification and community features you use — experience points, achievements, streaks, leaderboards, and share cards you choose to create.
  7. Improve merchant naming data — as described in section 2.3, subject to the constraints stated there.
  8. Comply with law and enforce our terms.

We do not use your financial account data for advertising, and we do not use it to build profiles for anyone other than you. See section 7. If this ever changes, we will update this policy, publish a new version, and notify you before the change takes effect.


5. Artificial Intelligence

Bao Budget does not use artificial intelligence or large language models to process your financial data. There is no AI or LLM integration in the product: your accounts, balances, transactions, merchants, goals, and investments are not sent by us to any AI service, and are not used by us as prompts or as training data.

Our engineering team uses Anthropic's Claude for AI-assisted software development; that tooling may read production systems, which can include your financial account data, during an active, human-directed work session. It is disclosed as its own recipient in section 8.

The categorization, recurring-stream detection, and projection features in Bao Budget are deterministic rules and statistical calculations that run on our own servers against your own data.

If this ever changes, we will update this policy, publish a new version, and notify you before the change takes effect.


6. Cookies, Analytics, and Other Tracking

Cookies we set. A session cookie for signing you in (authjs.session-token, HTTP-only, SameSite=Lax, 8-hour lifetime), the standard cross-site-request-forgery, callback, and PKCE cookies used by our authentication library, a referral cookie (bao.incentive.ref, which is readable by scripts on our own site), and a habit-share binding cookie (HTTP-only).

Browser storage. We store certain preferences in your browser's local storage, including — if you select "remember me" — your email address (bao.rememberedEmail), your preferred sign-in method, your referral code, your time-zone sync flag, and various interface preferences such as whether the navigation is collapsed and which introductory tips you have seen. On mobile, your authentication tokens and app-lock state are stored in the operating system's secure storage.

Analytics.

  • PostHog (United States) provides our product analytics.
    • On the web it is served first-party through our own domain and uses local storage rather than cookies.
    • In the mobile applications it is not proxied: the applications send events directly to PostHog's own endpoint.
    • Autocapture is disabled on the web application. What we do collect on the web is the events we instrumented by name, page views, and error reports. We also perform a redaction step in your browser before any event is sent. Money-bearing components are additionally marked for exclusion from capture.
    • We do not use session recording. Session replay is not enabled in our analytics configuration, so we do not record video-style replays of your screen, your cursor, or your keystrokes, and screens containing your financial data are not recorded. If this ever changes, we will update this policy, publish a new version, and notify you before the change takes effect — and, under our own internal standard, session replay would only ever be deployed mask-by-default with an explicit allowlist, not the reverse.
  • Vercel Web Analytics and Speed Insights
    • measure site traffic and page performance.

Nothing here loads until you have made a choice. On the Bao Budget web application, none of the three — PostHog, Vercel Web Analytics, Vercel Speed Insights — is loaded on a page until a consent decision exists for that visitor. Our §6 set this out in full.

How long analytics data is retained. The two providers operate differently, and each is stated separately.

  • PostHog (product analytics, and our security-monitoring events). Retention is 1 year

  • Vercel (traffic and performance analytics, and logs). Retention is 12 months for website traffic analytics and 30 days for page-performance metrics.

6.1 Do Not Track

Some browsers offer a "Do Not Track" ("DNT") setting. We do not currently respond to DNT signals, because there is no common industry standard for what a DNT signal should mean. This disclosure is made under California Business and Professions Code §22575(b)(5).

6.2 Global Privacy Control

Global Privacy Control ("GPC") is a signal distinct from DNT, and we treat it differently.

What we do:

  • We read the Sec-GPC: 1 header on every request to the Bao Budget web application, before anything renders — not only when a form is saved.
  • We read it whether or not you are signed in.
  • It sets both preferences: your do-not-sell/share preference and your analytics opt-out. Those are two distinct fields in our system, and a GPC signal sets both.
  • It stops every analytics technology we operate on the web — PostHog, Vercel Web Analytics and Vercel Speed Insights alike — because with GPC present none of them is loaded at all.
  • A subsequent "accept" does not override it. If your browser sends GPC we do not present an accept/decline prompt; we inform you that the choice has already been made. And if a request to record "accept" reaches us on a connection carrying GPC, we record declined and state so.

Two limits. This describes the web application. And the mobile applications have no GPC equivalent, because GPC is an HTTP header sent by a browser and there is no browser in a native application; their analytics behaviour is described in §6.1.

Because we do not sell or share personal information in the first place (section 7), the do-not-sell component of this does not change what we do with your data. The analytics component does.

6.3 Third-Party Collection Across Sites

We do not permit third parties to collect personal information from our applications for their own cross-site behavioral advertising. Our analytics providers process data on our behalf for the purposes set out in section 4.


7. What We Do Not Do With Your Data

  1. We do not sell your personal information We do not transfer personal information to anyone for any consideration, and we have no commercial arrangement under which anyone pays us or provides us anything of value for it.
  2. We do not share your personal information for cross-context behavioral advertising — not with advertisers, not with ad networks, not with anyone, as of today. If we ever introduce an advertising partnership, a disclosure to that partner could constitute a "sale" or "share" under some states' broad definitions of those terms, and we will update this policy before that occurs.
  3. There is no advertising SDK, no attribution SDK, and no data broker in Bao Budget. There is no Google Analytics, no Google Tag Manager, and no Meta pixel.
  4. We do not send your financial data to any AI or LLM service (see section 5).
  5. We do not have your bank login credentials, so we cannot lose them, and we cannot provide them to anyone.
  6. We cannot move your money. Our access is read-only.
  7. We do not publish your identity on leaderboards or share cards. Those surfaces use a display handle and avatar you control.
  8. We do not sell, rent, or otherwise disclose data obtained from your connected institutions to marketers or to any third party. This is also a binding term of our agreement with our aggregation provider.

One exception, stated expressly: our marketing website and our application run the traffic and product analytics described in section 6, including for visitors who are not signed in. No advertising or attribution technology is involved and no data is sent to an ad network, but it is data collection about visitors.

Bao Budget is a paid subscription, and your subscription is how we generate revenue.


8. Who We Share Your Information With

We share personal information only with the service providers identified below, only for the purposes listed, and only to the extent necessary for those purposes.

Quiltt is our only aggregation provider. Our GLBA / Regulation P Privacy Notice describes our aggregation provider in generic terms; Quiltt is the provider it refers to.

ProviderWhat we send them / what they processPurpose
QuilttAn internal user identifier from us; accounts, transactions, balances, investments, and liabilities flow back to us. Your browser also loads Quiltt's connector script from cdn.quiltt.io and frames the connector interface from a quiltt.app addressBank data aggregation — our only aggregation provider
StripeYour email address, name, and an internal user identifierSubscription billing. Card details go directly to Stripe and never touch our servers.
Google / AppleYour email address and basic profile, if you choose to sign in with them, on the web or in the mobile appsSign-in
VercelApplication hosting; Web Analytics and Speed Insights run only for a visitor who has consented to analytics — they sit behind the same gate as our product analytics and are not loaded for anyone who has declined, has not yet answered, or is sending a Global Privacy Control signal (section 6, section 6.2). Retention of the data they do collect is set by our plan, not by us — Vercel exposes no retention control (section 6)Hosting, traffic and performance analytics
NeonHosts our PostgreSQL database, and therefore all stored user dataData storage
UpstashRate-limit counters keyed by IP address or email addressAbuse prevention
PostHog (United States)Product analytics events. On the web these are proxied first-party through our own domain; the mobile apps send them directly to PostHog. Where our server-side tracing and log export is configured, application traces and application log records are also sent to PostHog server-to-server. A separate second PostHog project receives security-monitoring events where its key is configured, and IP-address anonymization is off on that project, so it stores full IP addresses (section 2.3)Product analytics; application performance monitoring; security monitoring
ResendRecipient address, subject, and body of emails we send youEmail delivery
Browser push services (Google, Apple, Mozilla, Microsoft)Encrypted web-push payloadsPush notification delivery
Frankfurter / European Central BankA currency code and a date — no user data. We pull from this vendor; nothing of ours is sent to itExchange rates
AnthropicRead access to production systems, which can include your financial account data, during an active, session-scoped, human-directed engineering work session — not a standing automated pipeline. Used for AI-assisted software development, not to power any part of the product you use (see section 5)Software engineering support

We do engage an AI vendor, Anthropic — for engineering support with production access, not within the product. See section 5.

Other disclosures. We may also disclose personal information: to comply with law, legal process, or a lawful government request; to enforce our terms or protect the rights, safety, and property of our users or of ourselves; and in connection with a merger, acquisition, or sale of assets, in which case we will notify you before your information becomes subject to a different privacy policy.


9. How We Protect Your Information

9.1 Encryption

  • In transit: all traffic uses TLS. We set HTTP Strict Transport Security (max-age=63072000; includeSubDomains; preload), X-Content-Type-Options, X-Frame-Options: DENY, a Referrer-Policy, and a Permissions-Policy, among other browser security headers.
  • Application-layer encryption applies to exactly two things: the bank access-token bundle we hold on your behalf, and your multi-factor authentication (TOTP) secret. Both use AES-256-GCM envelope encryption with per-record data encryption keys and key-encryption-key rotation.
  • Everything else — balances, transactions, merchant names, your name, your email address, and your date of birth — is stored as ordinary database columns, protected by our database provider's storage-level encryption at rest, which is a property of that provider's infrastructure rather than an additional layer we apply.

9.2 Other Measures

  • Multi-factor authentication using time-based one-time codes, single-use backup codes, and self-hosted WebAuthn passkeys. Step-up authentication freshness is recorded server-side and cannot be asserted by a client token.

  • If you have enrolled a second factor, both data export and account deletion require it. Multi-factor authentication is optional in Bao Budget, and there is no setting that compels enrollment: for an account with no second factor enrolled, export and deletion proceed on the signed-in session alone. Enrolling a second factor is therefore a meaningful protection for these two actions specifically.

  • Both export and deletion must originate from a signed-in browser session and are refused to an API key, and both are same-origin enforced.

  • Passwords are hashed with bcrypt at cost factor 12. Sign-in sessions last 8 hours. Mobile uses a database-backed rotating refresh-token chain with family-wide reuse detection.

  • Named rate limits: sign-in 5 per 15 minutes, multi-factor 10 per 15 minutes, account recovery 1 per hour, bank connection 10 per hour, data export 3 per day, account deletion 3 per day. If our rate-limit infrastructure is unavailable, rate limiting fails open: it degrades to per-instance in-memory counting rather than failing closed. The degradation is not silent: it is recorded as an error in our monitoring and raises an alert to us.

  • An append-only, hash-chained audit log. It is tamper-evident for the fields within the chain — the action, who performed it, the record it concerned, the attached metadata, the timestamp, and — as of the fix described below — the IP address and user agent. Altering any of those breaks the chain and is detectable. One field remains deliberately outside the hashed set: the flag marking a record whose subject has been erased. It is also not tamper-proof in any event: the chain uses SHA-256 without a keyed MAC and is not anchored to an external system.

  • Per-user query scoping on the routes that serve your account. An automated check on our code asserts that database reads and writes in those routes are scoped to the authenticated user. Its scope is limited in three ways. It excludes our administrative, scheduled-job and provider-webhook routes, which are guarded differently; it verifies that a query is scoped, which is not the same as verifying ownership in every case; and it runs as an automated check on our code rather than as part of the production build.

  • Secret scanning and static security analysis in our build pipeline; secrets redacted from logs.

9.3 Limitations

No method of transmission or storage is 100% secure. We cannot guarantee absolute security, and this policy does not promise it.

If a security incident affects your information, we will notify you as required by applicable law.


10. How Long We Keep Your Information

DataRetention
Account and all associated dataFor as long as your account is active, subject to the dormancy row below
Data after you request deletion30 days, then permanently deleted (see section 11)
Dormant accountsAfter 3 years of inactivity we email you a warning. If the account is still inactive 30 days later, the account and all of its data are permanently deleted.
Security audit eventsTarget retention 730 days.
Webhook processing ledgerTarget retention 90 days
Product analytics events (including security-monitoring events)1 year
Website traffic analytics at our hosting providerA 12-month availability window.
Page-performance metrics at our hosting providerA 30-day availability window.
Server request logs at our hosting provider30 days,
Free-trial anti-abuse ledger24 months after the trial ends. Survives account deletion — see the paragraph below this table

Transaction history from a connected institution is deliberately retained when you disconnect that institution. Disconnecting stops future data flowing to us; it does not erase the history already in your account. To remove it, delete your account (section 11).

Free-trial records outlive the account. To prevent repeated free trials, we retain some data for up to 24 months after the trial ends.These records are not deleted when you delete your account. The data is one-way hashed and stored securely.

We have no anonymization path. When you exercise a deletion right, the outcome is deletion or retention under a legal obligation — we do not retain an "anonymized" copy as an alternative to deletion.


11. Accessing, Exporting, and Deleting Your Data

11.1 Export

You may export your data from the app. The export is JSON only (no CSV), requires a signed-in browser session (an API key is refused), is limited to 3 requests per day, and is recorded in the audit log. If you have enrolled a second authentication factor, it is required as well — see section 9.2 for why that protection is conditional. The export must also originate from the app itself: a request that arrives carrying another site's origin is refused.

What the export contains, and what it deliberately omits. The export covers your accounts, transactions, balances, goals, budgets, income and expenses, investment holdings and transactions, reimbursements, recurring streams, notifications, the sharing and gamification data you have generated, support communications, forecast data, your own custom categories, your leaderboard snapshots, and your merchant-enrichment contributions — in short, essentially everything in section 2 that is meaningfully about your own activity. Three categories are excluded:

  • Security and authentication material — your multi-factor secret, backup codes, passkey credentials, and session/refresh tokens. Exporting these would not provide you anything portable; it would provide the means to bypass your own account's security to anyone who obtained the file. This is the same reasoning that already excludes your bank access token and password from the export.
  • Another person's personal information contained within a shared record — for example, the identity of a person you invited to share your account, where that would reveal their email address. Your right of access is to your own data; it is not a license for us to disclose a third party's information to you without their own basis for that disclosure.
  • Records that describe our own systems rather than you — job queues, sync bookkeeping, rate-limit counters, and similar internal state that references your account but does not describe anything you did or experienced.

If you seek data you believe is missing for a reason other than the three above, contact us at privacy@baobudget.com and we will provide it or identify which of these three reasons applies.

11.2 Deletion

You may delete your account from the app. Deletion requires a signed-in session, is same-origin enforced, and requires you to type both DELETE and your account email address to confirm. It is limited to 3 requests per day. If you have enrolled a second authentication factor, it is required as well — see section 9.2 for why that protection is conditional.

Deletion proceeds as follows:

  1. We verify that the email address you typed matches your account.
  2. We revoke our connections to your financial institutions with the aggregation provider. This is best-effort: we call the provider's removal endpoint, and if the provider is unreachable at that time, the revocation may need to be retried. Data already delivered to us is handled by steps 3 and 4 in either case.
  3. Your account is soft-deleted immediately — you lose access, and the data is no longer used to provide the service.
  4. After 30 days, the data is permanently deleted. The permanent deletion re-checks for any legal hold at the time it runs, replaces audit records with tombstones, and cascades the deletion across every related record.

On mobile, deletion is likewise native and in-app — the mobile application does not hand this off to a browser. You confirm your account email address (verified against the server, not merely your device's cached copy) and your second factor if you have one enrolled, and the request is sent at most once. One difference from the web flow: the web additionally requires you to type the word DELETE; mobile's confirmation is the email match alone. Both platforms then follow the same steps 1–4 above.

If you cannot reach the in-app tool on either platform, you may request deletion at https://baobudget.com/delete-account, which is reachable without signing in, or by writing to privacy@baobudget.com.


12. Your Privacy Rights

Depending on where you reside, you may have the right to:

  • Know and access the personal information we hold about you and how we use it

  • Correct inaccurate personal information

  • Delete your personal information

  • Obtain a portable copy of your personal information

  • Opt out of sale or sharing — we do not sell or share your personal information. We provide a "Do Not Sell or Share My Personal Information" control regardless, and honor Global Privacy Control (GPC) signals, even though our no-sale/no-share position means the control has no present effect to opt you out.

  • A public page at /privacy-choices, reachable without an account (same pattern as /delete-account), linked from Settings and from the footer of every sign-in/register/recover screen.

  • A logged-out visitor's choice is stored in a first-party cookie (bao.consent.donotsell, httpOnly, one year), not an account field — there is no account to attach it to. A Sec-GPC: 1 header forces the stored value to opted-out regardless of what a form submission asks for — the signal cannot be overridden by a subsequent "accept," matching the same non-overridable pattern this policy already states for the analytics half in section 6.2.

  • If you later create an account, your anonymous choice carries over automatically — it is read from the cookie at the moment of signup and written into your account's stored preference in the same transaction that creates the account.

  • One function (doNotSellShareGate) decides the resulting value everywhere it is used — the page, the write route, and the signup migration all call the same code rather than three independent implementations of this rule.

  • Limit the use of sensitive personal information — we use it only to provide the service, which is the standard that removes this obligation

  • Not be discriminated against for exercising any of these rights. We will not deny you service, charge you a different price, or provide you a lower quality of service because you exercised a privacy right.

How to exercise them. Use the export and deletion tools in the app, or write to privacy@baobudget.com. We will verify your identity through your account before acting on a request. We respond within the time limits set by applicable law.

Authorized agents. You may use an authorized agent to submit a request on your behalf, with written permission that we may verify with you directly.

Appeals. If we decline a request, you may appeal by replying to our response. The response times, extension rules, and appeal deadlines that apply are set out in section 3.3 of our U.S. State Privacy Notice, which is the single statement of those mechanics. If we deny your appeal, we will inform you how to contact your state attorney general.

Rhode Island. We have not sold personal data to any third party. There is therefore no list of third parties to whom personal data has been sold.

Financial data and state privacy law. Data we collect and process under the federal Gramm-Leach-Bliley Act is subject to that Act rather than to certain state privacy statutes. The marketing and analytics data described in section 6 is not covered by that exemption and is fully subject to state privacy law.

The per-category sources, purposes, recipients, and retention that California requires are set out in section 2.6. Further detail is set out in our U.S. State Privacy Notice, and our federal financial privacy notice is set out in our GLBA / Regulation P Privacy Notice.


13. Communications and Notifications

  • Service, security, and billing emails are an inherent part of holding an account. Opting out of marketing email does not stop them, and it will not prevent us from notifying you of a security event or a charge.
  • Notification emails — the occasional message we send when updates have been waiting for you in the app — are optional. Every one carries a one-click unsubscribe link, and you can turn them off at any time from Settings; doing so stops every notification email we send. It does not affect the service, security, account, and billing emails described above, which continue regardless.
  • Marketing email, if we send it, carries a one-click unsubscribe and our physical postal address, and we honor opt-outs promptly.
  • Push notifications are optional and may be disabled in the app or in your device settings. We do not include balances, amounts, or account identifiers in push payloads or lock-screen previews. The app functions without push enabled.
  • We do not currently send SMS or text messages. If that changes, we will update this policy, publish a new version, and notify you before the change takes effect — and, separately, add the consent, opt-out, and disclosure terms an SMS program requires to our Terms of Service before any SMS message is sent.

14. Amendments to This Policy

We maintain a version number and effective date on this policy, together with the changelog below. Your recorded consent is tied to a specific version.

For material changes — a new category of data, a new purpose, or a new recipient — we follow the same standard as Terms of Service §22: at least 30 days' notice by email before the change takes effect, and, for a change to this policy, the same real-exit protection §22 describes for the Terms as a whole. For non-material changes we will update the version, the effective date, and the changelog.

Changelog

VersionDateChange
1.1.0September 7, 2026Material change: we now keep a free-trial record that outlives your account — a one-way hash of the email address and, where we hold one, of the payment method used for a trial, together with the trial's dates and outcome, kept for 24 months after the trial ends (section 10).
1.0.2August 25, 2026Added the analytics consent banner, Global Privacy Control handling, and the United States-only eligibility check for new accounts. Sections 1, 6 and 6.2 updated to describe them.
1.0.1August 24, 2026Editorial revisions throughout for accuracy and clarity.
1.0.0August 25, 2026Initial publication.