Privacy Policy

Budgets by Grow With Money Plant Package: com.growwithmoneyplant.budgets

Last updated: 16 September 2026


The short version

Budgets stores your financial records so they are available on your devices. We do not sell your data, we do not share it with advertisers, and we do not use it to build a profile of you. Your spending analysis is calculated on your phone, not on a server.

This policy describes exactly what is collected, why, and how to get rid of it. If anything here is unclear, email growwithmoneyplant+support@gmail.com.


Who is responsible

Grow With Money Plant operates the Budgets app and is the data controller for the information described below. Contact: growwithmoneyplant+support@gmail.com.


What we collect

1. Account information

DataWhy
Email addressTo create your account, sign you in, and send password resets
Display nameTo address you in the app
Authentication identifiersTo keep you signed in; if you use Google Sign-In, we receive your Google account email and identifier

We never see your password. It is handled by our authentication provider (Supabase) and stored as a cryptographic hash. If you sign in with Google, we never receive your Google password at all.

2. Financial information you enter

Everything you record in the app:

expiry month/year, credit limit and current usage

We never ask for and never store full card numbers, CVV codes, PINs, or bank login credentials. Budgets does not connect to your bank and cannot move money. The card details it holds are labels to help you organise spending, not payment credentials.

3. Subscription information

If you buy a subscription, Google Play processes the payment. We receive a purchase token, product identifier, and subscription status from Google so we can unlock premium features. We never receive your payment card details.

4. Technical information

DataWhyProvider
Crash reports (stack traces, device model, OS version)To find and fix crashesFirebase Crashlytics
Basic usage eventsTo understand which features are usedFirebase Analytics
Device timezoneTo show transactions on the correct dayOn device only

Crash reports may incidentally contain technical context about what the app was doing when it failed. They do not include your transaction contents.


What we do not do


Where your data is processed

Your data is stored using Supabase, which hosts it on cloud infrastructure with encryption in transit (TLS) and at rest. Access is restricted by row-level security rules so that your account can only read and write its own records.

Receipt images are stored in a private storage bucket. They are not publicly accessible; the app generates a short-lived signed link each time you view one.

A note about your phone

The copy of your data held on your device is stored in the app's private storage area, protected by your phone's operating system sandbox. It is not separately encrypted by us. The optional biometric lock in the app protects the screen — it does not encrypt the stored data. If your phone is unlocked and compromised, that local copy could be read. Use your device's own encryption and screen lock.

We would rather tell you this plainly than imply a protection that is not there.


Sub-processors

ProviderPurpose
SupabaseDatabase, authentication, file storage, server functions
Google Firebase (Crashlytics, Analytics)Crash reporting and usage analytics
Google Play BillingSubscription purchases and renewals
Google Sign-InOptional sign-in method

Each processes data under its own terms and security commitments.


How long we keep it

cards, recurring schedules, learned category suggestions, settings and receipt files are deleted from our systems. Deletion is permanent and cannot be undone.

we keep a minimal record that a specific item was deleted (an identifier and a timestamp — no content) for 90 days.

schedule.


Your rights

You can, from inside the app:

PDF.

This is immediate and irreversible.

Depending on where you live, you may also have the right to object to processing, to restrict it, or to lodge a complaint with a data protection authority. To exercise any right not available in the app, email growwithmoneyplant+support@gmail.com.


Children

Budgets is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us with data, contact us and we will delete it.


Security

No system is perfectly secure. If you find a vulnerability, please report it to growwithmoneyplant+support@gmail.com before disclosing it publicly.


Changes to this policy

If we change this policy materially, we will update the date at the top and, where the change affects how your data is used, notify you in the app. Continued use after a change means you accept the updated policy.


Contact

growwithmoneyplant+support@gmail.com