Effective Date: May 23, 2026 · Operated by Broach Creative Technology LLC
Overview
BudgetBrief (“we,” “us,” “our”) is a personal finance tool that helps you understand what bills to pay first. We connect to your bank accounts, scan your email for bills, and accept uploaded documents to give you a prioritized financial picture.
We take your financial privacy seriously. This policy explains what data we collect, why, how we protect it, and your rights.
1. Information We Collect
1.1 Account Information
- Google account details: Name, email address (via Google OAuth sign-in)
- No passwords stored: We use Google OAuth — we never see or store your Google password
1.2 Financial Data (via Plaid)
When you connect a bank account through Plaid:
- Account names and types (checking, savings, credit card)
- Transaction history (merchant name, amount, date, category, pending status)
- Institution name
We do not receive or store your bank login credentials. Plaid handles authentication directly with your financial institution.
1.3 Email Data (via Gmail)
When you grant Gmail access:
- We scan the last 30 days of email for messages that look like bills, statements, payment reminders, and receipts
- We extract: sender, subject line, date, and bill-related content (amounts, due dates, account numbers)
- We do not read or store emails unrelated to financial obligations
- Raw email content is processed in memory and not stored permanently — only extracted bill items are saved
1.4 Uploaded Documents
When you upload paper bills or receipts:
- The image file is stored securely
- We use optical character recognition (OCR) to extract text
- Extracted information (amounts, due dates, merchant names) is saved as bill items
1.5 Usage Data
- Pages viewed, features used, briefing generation timestamps
- Device type and browser (via standard web logs)
- We do not use third-party analytics trackers
2. How We Use Your Information
| Purpose | Data Used |
|---|---|
| Generate your budget brief | Bank transactions, email content, uploaded bills |
| Prioritize bills by urgency | Due dates, amounts, payment status |
| Send verification codes | Email address |
| Process payments | Stripe handles billing (we store only subscription status) |
| Improve the service | Aggregated, anonymized usage patterns |
We do not:
- Sell your data to third parties
- Use your financial data for advertising
- Share your information with other users (data is isolated to your account)
- Train AI models on your personal data
3. AI Processing
BudgetBrief uses Anthropic’s Claude AI to analyze your bills and generate prioritized recommendations. When we send data to Claude:
- We send summarized email content and transaction data (not raw credentials or tokens)
- Anthropic does not retain or train on data sent via their API
- AI responses are used solely to generate your budget brief
4. How We Protect Your Information
Technical Safeguards
- Encryption in transit: All connections use TLS 1.2 or higher
- Encryption at rest: Database encrypted with AES-256 (managed by Supabase/AWS)
- Application-layer encryption: Sensitive credentials encrypted with AES-256-GCM before storage
- Row-Level Security: PostgreSQL policies ensure your data is only accessible to your account
- Multi-factor authentication: Email verification required before connecting bank accounts
- No direct database access: All data access goes through authenticated API endpoints
Organizational Safeguards
- Access to production infrastructure limited to the principal engineer
- Third-party vendors selected for SOC 2 Type II compliance (Supabase, Vercel, Plaid, Stripe)
- Audit logging for sensitive operations (token access, account deletion)
5. Third-Party Services
We share data with these services only as necessary to operate BudgetBrief:
| Service | Purpose |
|---|---|
| Plaid | Bank account connection & transaction sync |
| OAuth sign-in & Gmail access | |
| Supabase | Database & authentication hosting |
| Vercel | Application hosting |
| Stripe | Payment processing |
| Anthropic | AI-powered bill analysis |
| Resend | Email delivery (verification codes) |
| Google Cloud Vision | Receipt OCR |
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Bank transactions | Until you disconnect the account or delete your account |
| Budget briefing items | Until you delete the brief or your account |
| Email content (raw) | Not stored — processed in memory only |
| Uploaded receipt images | Until you delete them or your account |
| MFA verification codes | 10–15 minutes (auto-deleted) |
| Account data | Until you request deletion |
7. Your Rights & Choices
Access & Control
- Disconnect bank accounts at any time from Settings — we remove the connection and stop syncing
- Revoke Gmail access via your Google Account permissions — we can no longer scan emails
- Delete individual briefings from the app
- Delete your account from Settings — all data is permanently removed
Data Portability
- Budget briefings can be exported via print or email
Revoke Permissions
- Google OAuth: Revoke at myaccount.google.com/permissions
- Plaid: Disconnect in BudgetBrief Settings, or contact your bank directly
- Stripe: Cancel subscription from Settings
8. Children’s Privacy
BudgetBrief is not directed at individuals under 18. We do not knowingly collect financial data from minors. If we learn that a user is under 18, we will delete their account and data.
9. State-Specific Disclosures
California Residents (CCPA/CPRA)
- Categories of personal information collected: Identifiers (name, email), financial data (transactions, bills), internet activity (usage logs)
- Purpose: Providing the BudgetBrief service as described above
- Sale of data: We do not sell personal information
- Right to delete: Submit via account Settings or email below
- Right to know: Contact us for a copy of data we hold
- Right to opt out of sharing: We do not share data for cross-context behavioral advertising
Other States
Residents of Virginia, Colorado, Connecticut, Utah, and other states with consumer privacy laws may exercise their rights by contacting us at the email below.
10. Changes to This Policy
We may update this policy as BudgetBrief evolves. Material changes will be communicated via email or in-app notification. Continued use after changes constitutes acceptance.
11. Contact
For privacy questions, data requests, or concerns:
Email: sonja@broachcreativetech.com
Company: Broach Creative Technology LLC
This privacy policy applies solely to BudgetBrief. FamilyBrief is a separate product with its own privacy policy.