Privacy Policy

Effective date: July 21, 2026

This Privacy Policy explains how Peasy Software LLC (“Peasy Software,” “BudgetPeasy,” “we,” “us,” or “our”) collects, uses, stores, discloses, and protects personal information when you use the BudgetPeasy website, web application, iOS application, Android application, and related services collectively referred to as the “Service.”

BudgetPeasy is operated by Peasy Software LLC, a limited liability company.

For privacy questions or requests, contact us at: [email protected]

1. Scope of This Policy

This Privacy Policy applies to information processed through BudgetPeasy, including information submitted through personal wallets, shared wallets, ChatBot features, voice entry, account settings, subscriptions, customer support, and privacy requests.

This Policy does not replace the privacy policies or terms of independent services that process purchases, authentication, or other information under their own terms, including Paddle, Apple, Google, and OpenAI.

2. Information We Process

The information we process depends on the features you use.

Account and contact information

We may process:

  • your name;
  • primary and recovery email addresses;
  • account status;
  • language, locale, date, time, and timezone preferences;
  • account creation and verification information.

A display name or profile image may be optional where the relevant feature allows it.

Authentication and security information

We may process:

  • Sign in with Apple or Google identity identifiers;
  • passkey public credential information;
  • email verification status;
  • hashed session and API tokens;
  • device sessions;
  • login and account-security events;
  • authentication recovery information.

BudgetPeasy does not need to receive or store your Apple or Google account password.

Device, network, and diagnostic information

We may process limited technical information such as:

  • IP address;
  • browser or device type;
  • operating system and platform;
  • app version;
  • user agent;
  • session name;
  • push notification token, where enabled;
  • request correlation identifier;
  • route, request method, response status, and processing duration;
  • integration status and technical error codes.

Our application metrics are designed not to include request bodies, query-string content, financial descriptions, ChatBot messages, transcripts, authorization headers, cookies, or payment details.

Financial records you enter

BudgetPeasy processes the information you choose to enter into the Service, including:

  • wallets and wallet memberships;
  • budget sources and accounts;
  • categories and subcategories;
  • payees and tags;
  • expenses and income;
  • amounts and currencies;
  • transaction dates;
  • descriptions and notes;
  • recurring expenses and income;
  • budgets, limits, and related rules;
  • information about who created or modified a shared-wallet record.

These are records entered manually by users. BudgetPeasy does not connect directly to users’ bank accounts and does not intentionally collect bank-account numbers.

Free-form financial descriptions can reveal personal or sensitive circumstances. You should avoid entering health, government identification, payment-card, authentication, or other sensitive information unless it is genuinely necessary for your own records.

ChatBot information

When you use the BudgetPeasy ChatBot, we may process:

  • the message you submit;
  • relevant wallet currency;
  • relevant category, subcategory, or payee context;
  • the structured draft generated from your message;
  • confirmation or processing status;
  • links to expenses created from the draft;
  • technical processing information.

ChatBot text and draft content are encrypted at the application level while retained.

Voice information

When you use voice expense entry, we may process:

  • a temporary audio recording;
  • file type and limited upload metadata;
  • a transcript of the recording;
  • processing status and timing;
  • structured expense drafts created from the transcript.

Voice recordings are placed in private temporary storage for processing. We delete successfully processed recordings as part of the processing workflow. Orphaned or abandoned uploads are automatically deleted within 24 hours under the default retention configuration.

Voice transcript content may be retained as encrypted ChatBot content for up to 90 days and then scrubbed as described in the retention section below.

BudgetPeasy does not use voice recordings for voice identification or advertising.

Subscription and purchase information

When you purchase or manage a subscription, we may receive and process:

  • subscription provider;
  • product and plan;
  • subscription status;
  • purchase and renewal history;
  • cancellation and expiration dates;
  • transaction and subscription references;
  • billing country, currency, and amount;
  • refund status;
  • limited fraud, reconciliation, and webhook information.

BudgetPeasy does not receive or store your complete payment-card number, CVV, or bank-account number.

Website subscriptions are processed by Paddle. iOS subscriptions are processed by Apple. Android subscriptions are processed by Google Play. These providers collect and process payment details under their own privacy policies and terms.

Support and privacy-request information

When you contact us, we may process:

  • your email address;
  • request type and subject;
  • messages and replies;
  • attachments you choose to submit;
  • request and resolution dates;
  • technical information needed to investigate the issue.

Support and privacy-request message content is encrypted at the application level while retained.

Do not send passwords, complete payment-card numbers, government identification numbers, or other information that is unnecessary to resolve your request.

Security, subscription, and financial audit information

We maintain limited audit records to protect users, shared wallets, subscriptions, and the Service.

These records may contain:

  • internal actor or account identifier;
  • affected wallet or object identifier;
  • event type;
  • approved before-and-after status fields;
  • timestamps;
  • administrator access or permission events;
  • subscription and entitlement changes.

Ordinary audit records exclude financial descriptions, ChatBot text, support-message content, transcripts, authorization credentials, and complete provider payloads.

Generated files

When requested, BudgetPeasy may generate:

  • PDF or CSV reports;
  • account data exports;
  • temporary private uploads.

Generated reports are stored for a limited period. Privacy exports are provided through authenticated or protected delivery and are not intended to remain permanently available.

Account-deletion records

After account deletion, we may retain a minimal technical deletion record containing:

  • a random deletion reference;
  • a keyed cryptographic representation of the deleted account identifier;
  • request, recovery, and completion dates;
  • request source;
  • deletion status;
  • a technical error code, if processing failed.

This deletion record is designed not to contain your name, email address, raw IP address, user agent, wallet content, expense descriptions, or authentication credentials.

3. Information We Do Not Intentionally Collect

BudgetPeasy does not intentionally collect:

  • precise or approximate GPS location;
  • address-book or contact-list data;
  • photos or photo libraries;
  • health or fitness data as a dedicated data category;
  • advertising identifiers;
  • browsing history outside BudgetPeasy;
  • complete payment-card numbers;
  • CVV codes;
  • bank-account numbers;
  • data for targeted advertising.

However, information you voluntarily enter into a financial description, support request, ChatBot message, or voice recording may contain details that BudgetPeasy did not ask you to provide.

4. How We Use Information

We use information to:

  • create and maintain your account;
  • authenticate users and manage sessions;
  • provide personal and shared wallets;
  • store and organize financial records;
  • generate budgets, reports, and exports;
  • process ChatBot and voice expense commands;
  • provide Premium subscription access;
  • synchronize subscription entitlements across supported platforms;
  • send authentication, security, account, support, and service messages;
  • respond to support and privacy requests;
  • detect abuse, unauthorized access, fraud, and security incidents;
  • investigate technical problems;
  • maintain auditability and service reliability;
  • enforce our Terms of Use;
  • comply with legal, accounting, tax, and regulatory obligations;
  • establish, exercise, or defend legal claims.

We do not use the contents of your financial records for targeted advertising.

5. Legal Bases for Processing

Where applicable law requires a legal basis, we process personal information under one or more of the following bases:

Performance of a contract

We process information needed to create your account, store your financial records, provide shared wallets, deliver reports, process selected ChatBot or voice features, and provide subscription access.

Legitimate interests

We may process limited information to:

  • secure the Service;
  • prevent fraud and abuse;
  • diagnose failures;
  • maintain appropriate audit records;
  • respond to support requests;
  • improve the reliability and usability of BudgetPeasy.

We consider the nature of the information and the effect of the processing on users before relying on legitimate interests.

Consent

We may rely on your consent where required, including when requesting microphone access, enabling optional device features, or introducing optional cookies or processing that requires consent.

You may withdraw consent through the relevant device, browser, or BudgetPeasy setting. Withdrawal does not affect processing that occurred before the withdrawal.

Legal obligations

We may process or retain limited information where required for tax, accounting, fraud prevention, consumer protection, regulatory, litigation, or other legal obligations.

6. ChatBot, Voice Entry, and OpenAI

ChatBot and voice features are optional.

When you use one of these features, BudgetPeasy may send the message or audio you submit to OpenAI for transcription or interpretation. We also send only the context reasonably necessary to interpret the command, such as currency and relevant category or payee information.

We do not intentionally send your payment-card information, bank-account information, authentication credentials, or complete financial history to OpenAI.

BudgetPeasy configures applicable OpenAI API requests with application-state storage disabled where supported. OpenAI may nevertheless retain limited API content and metadata for abuse monitoring under its API terms and data controls, generally for up to 30 days unless different retention controls apply.

Information submitted through ChatBot or voice entry is not used by Peasy Software for advertising or to create advertising profiles.

AI-generated transcripts, categories, payees, amounts, dates, or structured drafts may be inaccurate. You should review generated records before confirming or relying on them.

7. How We Disclose Information

We do not sell personal information.

We do not share personal information for cross-context behavioral advertising or targeted advertising.

We may disclose limited information in the following circumstances.

Shared-wallet participants

Information entered into a shared wallet is visible to its owner and authorized members according to their roles and permissions.

Shared-wallet participants may be able to view financial records, descriptions, amounts, categories, dates, and creator attribution. Do not add information to a shared wallet that you are not authorized to share with its members.

Service providers and infrastructure

We use service providers for functions such as:

  • application hosting;
  • database and private-storage hosting;
  • backups;
  • network delivery and security;
  • transactional email;
  • technical monitoring;
  • customer support;
  • AI transcription and command interpretation.

These providers may process only the information reasonably required to perform their services, subject to their agreements and applicable law.

Paddle

Paddle processes website subscription purchases and acts as the seller or authorized reseller for applicable transactions. Paddle independently processes checkout, payment, fraud, tax, billing, refund, and buyer-support information under its own privacy notice and buyer terms.

Apple

Apple may process:

  • Sign in with Apple information;
  • App Store purchases;
  • subscription status;
  • refund requests;
  • device and platform information.

Apple processes this information under its own terms and privacy policies.

Google

Google may process:

  • Google authentication information;
  • Google Play purchases;
  • subscription status;
  • refund requests;
  • device and platform information.

Google processes this information under its own terms and privacy policies.

OpenAI

OpenAI receives selected text, audio, and limited financial-entry context only when you choose to use a ChatBot or voice feature that requires its services.

Legal and safety disclosures

We may disclose information where we reasonably believe it is necessary to:

  • comply with applicable law or valid legal process;
  • protect users or the public;
  • investigate fraud, abuse, or security incidents;
  • enforce our agreements;
  • protect the rights, property, or safety of Peasy Software, BudgetPeasy, or others;
  • establish, exercise, or defend legal claims.

Business transfers

If Peasy Software is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.

8. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Policy.

Our default retention periods are:

  • API request metrics: 30 days;
  • integration-attempt records: 90 days;
  • generated PDF reports: 7 days;
  • orphaned temporary voice uploads: no more than 24 hours;
  • ChatBot message, voice transcript, and structured draft content: 90 days;
  • encrypted billing webhook payload content: 90 days;
  • financial audit events: 365 days;
  • security and subscription audit events: up to 7 years;
  • closed support and privacy tickets: 2 years after closure;
  • wallets, expenses, budgets, categories, recurring rules, and related financial records: for the lifetime of the applicable account or wallet, until an authorized deletion workflow removes them or a legal retention requirement applies.

After the 90-day ChatBot and voice-content retention period, the message, transcript, and structured draft content is scrubbed from eligible completed, failed, canceled, or superseded processing records. Limited status information and links to financial records already created may remain.

After the billing webhook retention period, encrypted payload content is scrubbed while limited event identifiers, status, timing, and reconciliation information may remain.

Retention periods may be extended where reasonably necessary to investigate fraud or security incidents, resolve disputes, comply with legal obligations, or preserve legal claims. Any retained information should remain limited to what is necessary for that purpose and should have a defined expiration or review period.

9. Account Deletion

You may request deletion through the Privacy & Data section of BudgetPeasy or through our public account-deletion process.

Deletion requires recent authentication or another reasonable identity-verification step.

When deletion is requested:

  1. the account is locked promptly;
  2. active web and mobile sessions are revoked;
  3. a seven-day recovery period begins;
  4. you may restore the account during that recovery period;
  5. permanent processing begins when the recovery period expires;
  6. production deletion or anonymization is completed no later than 30 days after the recovery period ends.

Personal wallets

Wallets solely owned by the deleted account, together with their related expenses, accounts, budgets, recurring records, memberships, and other relational data, are permanently deleted.

Shared wallets

Deleting one member’s account does not automatically delete financial records belonging to another owner’s shared wallet.

When a member’s account is deleted:

  • their membership and invitations are deleted;
  • their personal profile information is removed;
  • creator references on records retained in another owner’s wallet are anonymized;
  • the attribution may be displayed as “Deleted member.”

A shared-wallet owner may be required to transfer ownership, delete the wallet, or remove other members before deleting the owner account.

Records retained for limited reasons

We may retain a minimal record where necessary for:

  • billing reconciliation;
  • fraud prevention;
  • security investigations;
  • subscription disputes;
  • tax or accounting obligations;
  • compliance with law;
  • proving that a deletion request was completed.

Such records are retained without unnecessary wallet, expense, message, or profile content and are assigned a finite retention or review period.

Backups

Deleted information may remain in encrypted backups until those backups expire under our normal backup-rotation schedule, generally within 30 to 90 days.

Backups are isolated from normal production access and used only for disaster recovery. If an older backup is restored, BudgetPeasy uses its deletion ledger to remove accounts and data that were already subject to completed deletion requests before production access is restored.

10. Clearing ChatBot History

You may clear your retained ChatBot history independently from deleting your account.

Clearing ChatBot history removes eligible retained messages, voice files, transcripts, and processing content. It does not automatically delete expenses or other financial records that were already created and saved from those messages.

History deletion may be temporarily unavailable while a voice command is actively processing.

11. Data Export

BudgetPeasy provides an authenticated account-export feature.

Depending on your role and permissions, an export may include:

  • profile information;
  • personal wallets;
  • accounts and budget sources;
  • expenses and income;
  • recurring records;
  • budgets and limits;
  • categories;
  • memberships;
  • subscription metadata;
  • relevant consent and request information.

For shared wallets, members may export records they created or are otherwise authorized to receive. Wallet owners may export records belonging to wallets they own, subject to the rights of other participants and applicable law.

Exports do not include passwords, private authentication credentials, payment-card information, complete billing-provider payloads, internal fraud signals, or information the requester is not authorized to access.

12. Security

We use administrative, technical, and organizational measures designed to protect personal information.

These measures include, as appropriate:

  • TLS encryption for production web, API, webhook, and storage traffic;
  • secure production cookies and security headers;
  • provider-managed encryption for production database volumes, private storage, and backups;
  • application-layer encryption for ChatBot text, transcripts retained as message content, support messages, billing payloads, and selected billing metadata;
  • restricted production access;
  • least-privilege credentials;
  • multi-factor authentication for administrative and provider access;
  • log redaction;
  • session and token revocation;
  • audited administrator permissions;
  • restricted access to private voice transcripts;
  • scheduled retention and deletion workflows;
  • independent encrypted backups;
  • periodic restore testing.

No method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we work to reduce foreseeable risks and respond appropriately to identified incidents.

13. Administrator Access

Administrative access to private financial or message content is restricted.

Voice transcripts are hidden from administrators by default. An administrator must be explicitly granted the relevant private-content permission before revealing transcript content.

Permission changes and transcript reveals create security audit events.

Authorized administrators may access limited user information where reasonably necessary to:

  • provide requested support;
  • investigate an incident;
  • correct a technical failure;
  • administer subscriptions;
  • comply with law;
  • protect users and the Service.

14. International Processing

Peasy Software is based in the United States.

BudgetPeasy and its service providers may process information in the United States and other countries. These countries may have privacy laws that differ from those where you live.

Where applicable law requires safeguards for an international transfer, we use an appropriate legal mechanism, which may include contractual data-protection commitments, approved standard contractual clauses, or another legally recognized transfer mechanism.

15. Your Privacy Rights

Depending on where you live, you may have the right to:

  • request access to personal information;
  • request correction of inaccurate information;
  • request deletion;
  • obtain a portable copy of information;
  • restrict or object to certain processing;
  • withdraw consent;
  • opt out of targeted advertising, sale, or certain sharing;
  • appeal a decision relating to a privacy request;
  • lodge a complaint with a privacy or data-protection authority.

BudgetPeasy does not currently sell personal information or use it for targeted or cross-context behavioral advertising.

You may exercise available rights through:

  • the Privacy & Data section of your account;
  • the account-deletion process;
  • the data-export feature;
  • ChatBot-history controls;

We may need to verify your identity and authority before completing a request. Some information may be exempt from a request or retained where allowed or required by law.

Authorized agents may submit a request where applicable law permits, but we may require evidence of authorization and identity verification.

16. Cookies and Similar Technologies

BudgetPeasy uses essential cookies and similar storage technologies for purposes such as:

  • authentication;
  • session management;
  • security;
  • preferences;
  • fraud prevention;
  • maintaining application functionality.

The audited Service does not currently contain advertising pixels, cross-app tracking, or behavioral-advertising trackers.

If we introduce non-essential analytics, advertising, or similar technologies, we will update our disclosures and provide consent or preference controls where required.

Additional details may be provided in our Cookie Policy.

17. Children’s Privacy

BudgetPeasy is not directed to children under 13.

You must be at least 13 years old to create an account. Where the law of your country requires a higher minimum age to consent to online services or data processing, that higher age applies.

We do not collect a birth date as part of the standard account-creation process.

If you believe a child has provided personal information without valid authorization, contact us at [email protected]. We will investigate and take appropriate action.

18. Automated Decision-Making

BudgetPeasy may use automated tools to transcribe voice input, interpret expense commands, suggest categories, and prepare structured drafts.

These tools do not make decisions intended to produce legal or similarly significant effects about users.

Users remain responsible for reviewing and confirming their financial records.

19. Changes to This Privacy Policy

We may update this Privacy Policy when:

  • BudgetPeasy features change;
  • we begin processing a new category of information;
  • retention periods change;
  • service providers change;
  • legal or regulatory requirements change;
  • security or operational practices change.

We will update the effective date and provide additional notice where required by law or where a change materially affects users’ rights or how we process information.

20. Contact Us

For privacy questions, requests, or complaints, contact:

Peasy Software LLC
Email: [email protected]