đź’¸ Budget

Privacy Policy

Last updated October 1, 2026

The short version

  • We collect what you give us to run your budget: your email, the transactions you import, and, if you choose to link a bank account, the account details and transactions you authorize us to receive.
  • Budget never receives or stores your bank login credentials. Bank connections are handled by Stripe Financial Connections and its service providers. When your bank supports it, you sign in directly with your bank.
  • We use your financial data only to run your budget. We don’t sell it, show ads, or track you across other apps or websites.
  • You can disconnect a linked account, or delete your Budget account and all of its data, at any time from Settings.

Who we are

Budget is a personal budgeting service available at www.lekkalabs.com and as an iPhone app, operated by Lekka Labs (“we”, “us”). This policy explains what information we collect when you use Budget, how we use it, and the choices you have. It applies to both the website and the iPhone app.

Information we collect

Account information. Your email address and password when you sign up (passwords are stored only in hashed form by our authentication provider), the invite code you used, and whether your account has administrator access.

Financial information. Budget gets your financial information in the ways you choose:

  • Statement imports. When you import a bank or credit-card statement (a CSV file), we store the transactions in it: date, merchant name, description, amount, and the account name you choose. We don’t keep the original file, only the transactions read from it and its file name.
  • Linked accounts. If you choose to link a bank or card account, the connection is made through Stripe Financial Connections. Before anything is shared, Stripe shows you which institution and accounts are involved and what data Budget is requesting, and nothing is shared unless you approve it. Depending on the permissions you approve, we may receive: your financial institution’s name; each account’s name, type (for example, checking or credit card), and last four digits; account balances; and transactions, including date, amount, description or merchant, and status. We request only what Budget needs to show your spending and balances, and we don’t receive your full account or routing numbers. While an account stays linked, Budget may refresh this information periodically so your budget stays up to date.
  • Optional email import. If you turn on automatic email import and forward bank alert emails to your private import address, we receive those emails and store their sender, subject, and text so we can create transactions and show you an activity log.
  • What you create. Categories, budgets, categorization rules, notes, and, for statement imports, the column layout of each bank’s file so your next import is automatic.

Expense splits. If you split an expense, we store the names (and an email address, if you enter one) of the people you split with and the amounts they owe. They don’t need a Budget account, and we don’t contact them.

Payments. If you pay for Budget, your payment is processed by Stripe. Your card details go directly to Stripe; we never receive or store your full card number. We may receive limited information from Stripe, such as your name, email, billing country, the last four digits of your card, and the status of your payments or subscription.

Technical information. Our hosting providers automatically log basic request data such as IP address, browser or device type, and the time of each request, which is used to operate and secure the service. The website uses cookies only to keep you signed in; the iPhone app stores your sign-in session in the iOS Keychain on your device. When you link an account, Stripe’s connection screens may collect device and usage information for security and fraud prevention, under Stripe’s privacy policy. We don’t use advertising or analytics cookies, and Budget contains no advertising or analytics SDKs.

What we don’t collect. Budget never receives or stores your bank login credentials. If you choose to connect a financial account, the connection is provided through Stripe Financial Connections. Depending on your financial institution, you authenticate either directly with your institution (OAuth), or through Stripe and its service providers, which may store credentials to maintain the connection. Either way, Budget never sees them. We don’t access your contacts, location, or photos, or any files other than the statement files you choose to import.

How we use your information

  • To provide Budget: import and categorize your transactions, show your spending against your budgets and your account balances, and track expense splits.
  • To keep linked accounts up to date, by periodically retrieving new transactions and balances while an account remains linked.
  • To learn your categorization preferences: when you correct a transaction’s category, we save a rule so similar transactions are categorized the same way next time.
  • To secure your account and the service, and to prevent abuse.
  • To process payments and manage subscriptions, if you purchase one.
  • To respond to you when you contact us, and to send essential service messages (for example, about your account or changes to this policy). We don’t send marketing email.

We don’t use your financial data for advertising or marketing, to make credit or lending decisions, or for any purpose unrelated to running your budget.

Community categorization

To suggest categories for merchants you haven’t categorized yet, Budget keeps a shared, anonymous tally of how merchants are categorized across users, for example “COFFEE SHOP → Eating out: 12 votes.” This tally contains only a normalized merchant name, a category name, and a vote count. It does not contain your identity, amounts, dates, balances, or account details, and it can’t be linked back to you.

How we share information

We do not sell or rent your personal information or financial data, and we don’t share it for advertising. We share it only with service providers that run Budget on our behalf, under their own privacy and security commitments:

  • Supabase stores your account and budget data and hosts our API and authentication.
  • Vercel hosts the website.
  • Cloudflare provides DNS and, if you use email import, receives forwarded emails.
  • Stripe processes payments and, when you choose to link a financial account, provides account connectivity through Stripe Financial Connections and its service providers (third-party financial data providers). Stripe and its service providers handle account authentication; Budget does not receive your bank login credentials. Stripe’s handling of your information is described in the Stripe Privacy Policy.
  • Apple distributes the iPhone app; Apple’s own privacy policy covers App Store downloads and purchases.

We may also disclose information if required by law, to protect the rights, safety, or property of our users or others, or as part of a merger or sale of the service, in which case this policy will continue to apply to your information.

How we protect your information

All data travels over encrypted connections (HTTPS). Your data is accessible only through our API, which checks your signed-in session on every request and only ever returns your own data. Direct database access is blocked for everyone else. Budget never holds your bank credentials. No method of storing or sending data is perfectly secure, but we work to protect it and will notify you as required by law if a breach affects you.

Disconnecting accounts, deleting data, and how long we keep it

We keep your information for as long as your Budget account exists, unless you delete it sooner.

Disconnecting a linked account. You can disconnect a linked account at any time in Settings. Disconnecting stops Budget from receiving any new data from that account through Stripe. It does not, by itself, delete what we already received: transactions already imported stay in your budget so your history remains intact, and you can delete them yourself or by deleting your Budget account. You can also ask us to delete the data we received from a linked account by contacting us.

Deleting your Budget account. You can permanently delete your account at any time in Settings → Delete account on the website or in the iPhone app. This disconnects any linked accounts and immediately deletes your account and all of your data, including transactions (imported or received from linked accounts), balances, budgets, categories, rules, splits, and imported emails. Copies may remain in our providers’ backups for a limited time before they are overwritten.

Data held by Stripe. Stripe keeps the information it collects to provide Financial Connections and payments under its own privacy policy and legal obligations, and may keep it after you disconnect an account or delete Budget. You can ask Stripe to delete it as described in the Stripe Privacy Policy, and we’ll help with that request if you contact us. Payment records are kept as required by law.

The anonymous community tally described above isn’t linked to you, so it isn’t affected by disconnecting or deleting.

Your rights and choices

Linking a bank account is always optional; statement imports work without it. You can view and edit your data in the app, disconnect linked accounts, export your transactions by contacting us, and delete your account at any time. Depending on where you live (for example, in California or the European Economic Area), you may have additional rights to access, correct, delete, or receive a copy of your personal information, or to object to certain processing. We honor these requests regardless of where you live. To make a request, email us at the address below; we may need to verify that the request comes from you.

Children

Budget is not intended for children under 13, and we don’t knowingly collect information from them. If you believe a child has given us personal information, contact us and we’ll delete it.

Where your information is processed

Budget is operated from the United States, and our providers may process information in the United States and other countries. By using Budget, you understand your information will be processed in these locations.

Changes to this policy

We’ll update this page when our practices change and revise the date at the top. If a change is significant, we’ll let you know in the app or by email before it takes effect.

Contact us

Questions or requests about your privacy: privacy@lekkalabs.com