Privacy policy

What happens to your data

Updated September 24, 2026

Budget Guru is a one-developer project, not a company with a legal department, so this document is written in plain language and says what actually happens, without boilerplate like “we may share data with partners” — there are no such partners.

What you enter yourself

There is no bank syncing and there never will be — this is a deliberate decision (see the home page). Everything that ends up in the app, you enter manually: accounts and balances, transactions, budget items, working hours, tax rules and invoices. It is stored in a database hosted by Supabase.

Who can see your data

The database is protected at the row level (Row Level Security): every query is filtered by your id directly inside the database, not only in the app code. This means that even when accessing the database directly, one user physically cannot get another user’s data.

Administrative access to the infrastructure (which bypasses this protection) technically exists only for the developer and is used solely for technical support, fixing outages and at your direct request. User data is not viewed for marketing or any other personal purposes.

The AI assistant and Anthropic

When you ask the assistant a question, a snapshot of the figures needed for the answer (balances, plan, upcoming payments — what your own app has already calculated) and the question itself are sent to the server. The request is processed by the Claude model through Anthropic’s commercial API, called from a server-side function — the API key never reaches the browser code. The assistant does not keep your conversation history on its side beyond the time needed to process the request.

Under Anthropic’s commercial API policy (as of the publication of this document): data sent through the API is not used to train their models and is kept on the provider’s side for a limited time — only for abuse monitoring, no longer than that purpose requires.

Feedback

If you write through the “Feedback” form in the app, the text and the attachment (if you added one) are saved in the database — only the developer sees them, manually, through the Supabase dashboard. This data is not used for mailings or marketing.

Analytics

The site and the app use Vercel Web Analytics — by default it does not use cookies and does not build a profile of an individual visitor, only aggregated statistics (which pages/screens are opened, how many people visit). No personal data is passed to it.

Password and sign-in

Sign-in is by email and password through Supabase Auth. The password is stored hashed; nobody sees it in plain text, including the developer.

Your rights: access, correction, deletion, export

You can at any time request a copy of your data, its correction, or its complete deletion from the system (the right to be forgotten). There is no automatic “delete account” button yet — the app is in early access and this feature is still in development.

To get a copy of your data or to fully delete your account and all records linked to it, write to the Telegram support bot or through the feedback form in the app. If Telegram doesn’t suit you, you can email aa.salkov@gmail.com. Deletion usually takes no more than 72 hours.

Related documents

The terms under which the app operates at all (not about data, but about responsibility and the early-access status) are in the terms of use.

Questions

If anything in this document is unclear or raises questions, write to the Telegram support bot, through the “Feedback” form in the app, or at aa.salkov@gmail.com.