The short version
- Your financial data is stored on your device — not on our servers.
- Cloud backup is optional. If you opt in, only you can access your data.
- The AI assistant (Fudge) runs entirely on your iPhone. Nothing you say to Fudge ever leaves your device.
- We do not run ads, sell data, or track you across other apps.
- There are no analytics, crash trackers, or advertising SDKs in the app.
1. Who We Are
BudgeFudge is a personal budgeting app developed and published by Nathaniel Degorio ("we", "us", "our"). The app is available on the Apple App Store.
Contact:
Nathaniel Degorio
Contact form
This Privacy Policy explains what information BudgeFudge collects, how it is used, who it is shared with, and the rights you have regarding your data. It applies to all users of the BudgeFudge iOS application.
2. Data We Collect
2.1 Data you enter yourself (stored locally)
Everything you log in BudgeFudge — spending entries, income sources, recurring expenses, account balances, important dates, and any notes — is stored locally on your device in an encrypted SQLite database managed by the Expo SQLite library. This data never leaves your phone unless you explicitly enable cloud backup by creating an account.
2.2 Account data (optional cloud backup)
Creating an account is entirely optional. BudgeFudge works fully without one. If you sign up, we collect:
| Data type | Purpose | Stored where |
|---|---|---|
| Email address | Account creation, authentication, and password reset. We do not send marketing emails. | Supabase (cloud) |
| User ID | A unique identifier assigned by Supabase to link your data to your account. | Supabase (cloud) |
| Budgeting data (accounts, income, spending, recurring expenses, important dates) |
Cloud backup so you can restore your data if you lose or replace your device. | Supabase (cloud) |
Cloud backup is powered by Supabase (supabase.com), a managed PostgreSQL database service. Your data is protected with row-level security policies — only you, authenticated with your credentials, can read or write your records. Supabase's privacy policy is at supabase.com/privacy.
2.3 Purchase data (in-app purchases)
If you purchase a BudgeFudge Pro subscription or one-time purchase, the transaction is processed by Apple through the App Store. We use RevenueCat (revenuecat.com) to verify purchase receipts and manage entitlements. RevenueCat may receive:
- An anonymous or pseudonymous app user identifier
- Your purchase receipt (provided by Apple)
- Your device platform and app version
RevenueCat does not receive your name, email address, or financial card details. Apple's payment privacy policy applies to all billing. RevenueCat's privacy policy is at revenuecat.com/privacy.
We never see your credit card or payment details. Apple handles all billing.
2.4 Data we do NOT collect
- Bank account credentials or direct bank connections
- Advertising identifiers (IDFA or any equivalent)
- Analytics, usage events, or crash telemetry — there are no analytics SDKs in the app
- Location data — BudgeFudge never requests location access
- Contacts — BudgeFudge never requests contact access
- Photos or camera — BudgeFudge only accesses images you explicitly share into the app via the system share sheet
- Cross-app or cross-website tracking data
3. Fudge AI Assistant (iOS Only)
Fudge is BudgeFudge's AI assistant powered by Apple's FoundationModels framework (Apple Intelligence). All natural language processing, transaction extraction, and financial analysis run locally on your device using Apple's on-device language model.
When you share a screenshot or message into BudgeFudge for transaction import, the image or text is:
- Read locally by Apple's Vision framework (on-device OCR)
- Processed by FoundationModels (on-device language model)
- Stored in the local SQLite database if you confirm the proposed entry
At no point is your AI conversation history, imported content, or any inference result sent to our servers or to Apple's servers. This feature requires Apple Intelligence to be enabled on your device and is available on supported iPhone models running iOS 26 or later.
4. Notifications
BudgeFudge uses local push notifications only. The evening nudge reminder and upcoming-due alerts are scheduled entirely on your device using iOS's local notification APIs. No notification content is transmitted to our servers or any push notification service. Notification permission is optional — the app works fully without it.
5. Legal Basis for Processing (GDPR — EU / EEA / UK)
If you are located in the European Union, European Economic Area, or United Kingdom, we process your personal data under the following legal bases:
| Data | Legal basis |
|---|---|
| Email address and user ID (account) | Contract — necessary to provide the cloud backup service you requested by creating an account (GDPR Article 6(1)(b)). |
| Budgeting data in cloud backup | Contract — necessary to deliver the backup and restore functionality you signed up for (GDPR Article 6(1)(b)). |
| Purchase receipt data (via RevenueCat) | Contract — necessary to verify your purchase and grant you access to paid features (GDPR Article 6(1)(b)). |
We do not process personal data based on consent or legitimate interests for the purposes described in this policy. We do not engage in automated decision-making or profiling.
6. International Data Transfers
If you create an account, your data is stored on Supabase's infrastructure. Supabase offers data residency options. Depending on your Supabase project region, your data may be stored and processed outside your country of residence, including in the United States.
For transfers of personal data from the EU/EEA/UK to the United States or other third countries, Supabase relies on Standard Contractual Clauses (SCCs) approved by the European Commission. Details are available in Supabase's privacy policy and Data Processing Agreement.
If you are an EU/EEA/UK user and wish to understand where your data is stored, please contact us via our contact form.
7. How We Use Your Data
| Data | How it is used | Used for advertising? |
|---|---|---|
| Email address | Account authentication (sign-in, password reset) | No |
| User ID | Linking your budgeting records to your account in the cloud database | No |
| Budgeting data | Displaying your financial picture within the app; cloud backup and restore | No |
| Purchase receipt | Verifying your purchase and unlocking paid features | No |
We do not use your data for advertising, behavioural profiling, product recommendations to third parties, or any purpose other than operating the app for you.
8. Who We Share Your Data With
We share personal data only with the following service providers, who act as data processors on our behalf:
| Provider | Role | Data shared | Privacy policy |
|---|---|---|---|
| Supabase | Cloud database and authentication | Email, user ID, budgeting data | supabase.com/privacy |
| RevenueCat | In-app purchase verification | Anonymous user ID, purchase receipt | revenuecat.com/privacy |
| Apple Inc. | App distribution, payment processing, on-device AI | Standard app store data; billing handled entirely by Apple | apple.com/legal/privacy |
We do not sell, rent, or share your data with any advertising network, data broker, or other third party.
We may disclose your data if required by applicable law, court order, or government authority, or to protect the rights, property, or safety of BudgeFudge, its users, or the public.
9. Data Retention and Deletion
Local data
All data stored on your device remains until you delete the BudgeFudge app. Deleting the app removes the local database.
Cloud data
If you have an account, your cloud data is retained for as long as your account exists. You may request deletion at any time:
- Open BudgeFudge → Settings → Sign Out (this disconnects your device but does not delete cloud data).
- To permanently delete your account and all associated cloud data, submit a request via our contact form. We will delete your data from Supabase within 30 days and confirm by email.
We plan to add an in-app account deletion flow in a future update.
Purchase data
RevenueCat retains purchase receipt data in accordance with their own retention policy (see revenuecat.com/privacy). Apple retains billing records per their standard policies.
10. Your Rights
European Union, EEA, and United Kingdom (GDPR / UK GDPR)
You have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure ("right to be forgotten") — request deletion of your personal data.
- Restriction of processing — request that we restrict how we process your data.
- Data portability — receive your data in a structured, machine-readable format.
- Object — object to processing based on legitimate interests.
- Lodge a complaint — you have the right to lodge a complaint with your national data protection authority (e.g., the ICO in the UK, or the relevant supervisory authority in your EU member state).
California (CCPA / CPRA)
California residents have the right to:
- Know what personal information we collect, use, disclose, and sell.
- Delete personal information we have collected from you, subject to certain exceptions.
- Opt out of the sale or sharing of personal information — we do not sell or share personal information.
- Non-discrimination — we will not discriminate against you for exercising your CCPA rights.
- Correct inaccurate personal information.
- Limit use of sensitive personal information — we do not use sensitive personal information beyond the purposes permitted under the CPRA.
To submit a request, use our contact form. We will respond within 45 days.
Brazil (LGPD)
Under Brazil's Lei Geral de Proteção de Dados (LGPD), you have rights equivalent to those listed above, including access, correction, anonymisation, portability, deletion, and information about sharing. Use our contact form to exercise your rights.
Australia (Privacy Act 1988)
Australian users may request access to or correction of their personal information held by us. If you are not satisfied with our handling of your request, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
All other regions
Regardless of where you are located, you can contact us at any time to access, correct, export, or delete your personal data. We will respond within 30 days.
11. Children's Privacy
BudgeFudge is not directed at children under the age of 13 (or 16 in the EU/EEA). We do not knowingly collect personal information from children under these ages. If you believe a child has provided us with personal information, please contact us immediately via our contact form and we will delete it promptly.
The App Store rating for BudgeFudge is 4+ and the app is not marketed to children.
12. Security
We take reasonable measures to protect your data:
- Local data is stored in a SQLite database protected by iOS data protection (encrypted at rest when the device is locked).
- Cloud data is stored in Supabase, which uses row-level security to ensure only authenticated users can access their own records. All connections use TLS.
- We do not store passwords — authentication is handled by Supabase Auth.
No method of electronic storage or transmission is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
13. Third-Party Links and Services
BudgeFudge does not contain links to third-party websites. The privacy policy link in Settings points to this document. Apple's App Store, Supabase, and RevenueCat each operate under their own privacy policies, which we have linked above. We are not responsible for the privacy practices of those third parties.
14. Changes to This Policy
If we make material changes to this privacy policy, we will update the "Last updated" date at the top of this page and, where required by law, notify affected users. We encourage you to review this policy periodically. Continued use of the app after changes become effective constitutes acceptance of the revised policy.
15. Contact Us
For any questions, requests, or complaints about this privacy policy or your data:
| Name | Nathaniel Degorio |
| Contact | Contact form |
| Response time | Within 30 days (45 days for California CCPA requests) |
If you are in the EU/EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.