Connect
Connect using one of the following authentication providers.
Last updated: 24 August 2026.
This notice describes how BudgetApp stores and uses your data.
We never use your data to profile you, and we never sell it, in either mode described below.
We encrypt the identity of people and companies you pay or receive money from, plus a few financial identifiers. That includes:
We do not encrypt your own labels (profile names, account names) or amounts. Those stay as ordinary database values so totals and unique names can use the database.
When you first connect, you choose one of two ways to protect the encrypted data above:
You can switch between these at any time from Settings. Switching never re-encrypts your data — it only changes who can unwrap the same underlying key — but going from "we hold the key" to "you hold the key" is the only direction that gives you the passphrase-based guarantee above; the reverse hands the key back to us.
If you hold your own key: we cannot reset your passphrase for you unless you opted in to a backup copy. If you forget it, use the recovery key shown when you set it up. Unlocking with that key requires you to choose a new passphrase; we then issue a new recovery key and the old one stops working. If you opted into a backup copy, the operator can issue a one-time reset token instead. That token never shows your financial data to the operator. You use it to set a new passphrase.
You can remember a device. That device holds its own key. The operator cannot use it.
We can read data that is not counterparty identity, because we need it to run the product:
BudgetApp runs on the server (Blazor Server). While your session is unlocked, the server decrypts your financial data so it can show screens, match imported transactions, and generate reports.
That means a changed copy of the app, or a live unlocked session, could send your decrypted data somewhere else. We state that we will not do that. This notice is that promise in writing. Encryption in the database does not make that promise cryptographically impossible to break.
BudgetApp does not put personal or financial information in its application logs. These logs contain only non-personal technical information needed to run the service, such as timestamps, event types, and status codes.
Questions about this notice go to the operator of this instance.
Connect using one of the following authentication providers.