Key Points Summary
- Sign in with Apple or Sign in with Google may be required to access secure app sessions on supported platforms. Sign in with Google is offered on the web/PWA only; the iOS app uses Sign in with Apple.
- Uploaded financial files are never stored on our servers after parsing. Server-persisted data is limited to account authentication credentials (via Apple/Google Sign-In), subscription and upload-quota records, and anonymous usage analytics. No statement contents are among them.
- Learned rules and session data are stored only on your device and never transmitted to us.
- No third-party analytics, ads, or tracking are used.
- Support emails are handled externally (by your and our email provider); the app does not store or process support communications.
- Children’s privacy is protected; the app is not for children under 13.
- You control your data: delete individual saved uploads, clear session history, delete learned rules, and opt out of analytics at any time.
- Paid subscriptions are live. We never see your card number — payments go to Stripe (web) or Apple (iOS). We do keep a record of your subscription status and a count of how many statements you have analyzed, so we can apply the free allowance and your plan limits. See Sections 1 and 6.
See below for full details.
Privacy Policy for MyBudgetNerd
MyBudgetNerd is offered by Athena Analytics LLC, doing business as Athena Data Labs.
Effective date: August 6, 2026
This Privacy Policy describes how MyBudgetNerd (“we,” “us,” or “our”) processes information when you use our mobile application (iOS) and web application (collectively, the “Service”). By using the Service, you agree to the practices described in this policy and to our Terms of Service.
1. Information You Provide or We Process to Operate the Service
Depending on how you use the Service, the following types of information may be provided by you or processed on your behalf:
- Apple Sign In authentication data (when sign-in is enabled): We process Apple-issued identity and access credentials needed to authenticate your session. This can include an Apple identity token, a stable Apple user identifier, token expiry metadata, and cryptographic nonce/state values used to validate sign-in requests. If Apple and your settings provide profile information (such as relay or direct email and display name), we may process that data for account/session display and support purposes.
- Google Sign In authentication data (web/PWA only, when sign-in is enabled): If you choose Sign in with Google on the web or PWA, we process Google-issued identity and access credentials needed to authenticate your session. This can include a Google ID token, a stable Google user identifier (sub), token expiry metadata, and cryptographic state values used to validate sign-in requests. If Google and your account provide profile information (such as email and display name), we may process that data for account/session display and support purposes. Sign in with Google is not used by the iOS app.
- Financial data you choose to upload: Transaction descriptions, amounts, dates, and account type information may be extracted from bank statements you upload so the app can parse, categorize, analyze, and display your information back to you. Uploaded files are processed request-by-request and purged from backend request memory/temporary handles after parsing completes. We do not store uploaded statement files or parsed transaction datasets on our servers as a retained customer financial dataset.
- Learned categorization rules: When you recategorize a transaction and choose to remember it, a personal merchant–category rule (normalized merchant name, chosen category, timestamps, and counters) is stored locally on your device only (in browser or app local storage). Rules never leave your device and are never transmitted to our servers.
- Device-local session data: When Session History is enabled, parsed and categorized data, plus locally cached Oracle/Financial Story snapshots needed to reopen the app without recomputing, may be stored on your device using a retention window you select (default 120 days; options include off, 6 hours, 30, 60, 90, 120 days, or 1 year). You can also delete individual saved uploads from Session History inside the app, which removes the associated on-device cached analysis for that upload.
- Subscription and entitlement data: To operate the free allowance and the paid tier, we store on our servers: your subscription status and its source (Stripe or Apple), the period it expires, and a reference identifier issued by the payment processor (such as a Stripe customer or subscription ID, or an Apple original transaction ID). We never receive or store your card number, CVV, or bank details — those go directly to Stripe or Apple and are never transmitted through our servers.
- Upload-quota records: To enforce the 3-analysis free allowance and the plan limits, we store a timestamped record of each successful statement analysis, associated with your account identifier. These records contain no statement contents — no merchant names, amounts, balances, dates from your statements, or file names — only the fact that an analysis occurred and when. We also keep an audit log of entitlement changes and blocked-upload decisions for support and dispute handling.
- Quota record that survives account deletion: Because deleting an account and signing up again would otherwise reset the free allowance indefinitely, we retain one minimal record after deletion: a one-way hash of your identity provider identifier paired with a count of statements analyzed. It holds no email, name, or statement data, and cannot be reversed to identify you. It exists solely to keep the free-tier allowance from being reset by repeated account deletion. Everything else associated with the account is deleted as described in Section 9.
2. Authentication and Account Security
- On supported flows, we use Sign in with Apple for account authentication. On the web/PWA, Sign in with Google is also available.
- We do not receive or store your Apple password.
- Authentication tokens are stored using platform security controls (for example, iOS secure storage/Keychain and browser-controlled secure storage where applicable).
- You can revoke app authorization from your Apple ID settings (or, for Google sign-in on the web/PWA, from your Google account’s “Apps with access to your account” settings). Revocation can require you to sign in again to continue using authenticated features.
3. Anonymous Usage Analytics
We collect anonymous, non-personal usage analytics to understand how features are used and improve the Service. Analytics events are stored on our servers and include:
- Event type (e.g., app opened, file uploaded, export used, Oracle opened, categorization applied).
- An anonymous, locally generated device identifier (not tied to your name, email, or any account).
- App version and platform (web or iOS).
- Basic counts (e.g., number of transactions parsed).
Analytics never include transaction descriptions, merchant names, file names, account numbers, email addresses, or any personally identifiable information. Sensitive metadata is stripped before storage.
You can disable analytics at any time in the app’s Settings. When disabled, no events are sent.
4. Information We Do Not Collect
- We do not use third-party analytics services, tracking pixels, advertising cookies, or ad networks.
- We do not collect precise location data or device fingerprints.
- We do not link to or access bank accounts directly. All data comes from files you upload.
5. How We Use or Process Information
- To provide budgeting insights including statement parsing, transaction categorization, trend visualization, and Oracle forecast/anomaly analysis.
- To improve app functionality, including reusing learned categorization rules to reduce redundant processing.
- To monitor anonymous usage patterns and improve the Service (analytics).
- To respond to your support and contact requests. However, the app itself does not store, log, or transmit any user communications or emails. Any emails you send to us are handled externally by your email provider and ours (e.g., Gmail), and may be retained according to their respective policies. We cannot guarantee the security or deletion of emails outside our immediate control. We recommend you do not send sensitive information (such as bank statements or personal data) via email or support channels. Athena Analytics LLC is not responsible for the security, retention, or transmission of communications handled by third-party email providers.
- To enforce our Terms of Service and protect the rights, safety, and security of users and the Service.
6. Third-Party Services
If you enable AI-assisted features, the Service sends limited, sanitized data to a third-party AI provider (currently OpenAI) for processing. This data is transmitted securely via OpenAI’s API; contractually, OpenAI does not use data submitted via their API to train their AI models, and data is retained by OpenAI solely for abuse monitoring according to their data privacy terms. The specific data sent includes:
- Categorize AI: Sanitized transaction descriptions and account type only.
- Oracle written insight & follow-up AI (Advisor mode): Sanitized summary and aggregate financial signals only (e.g., 30-day projection, confidence label, anomaly counts, top rising/falling category names, monthly income/spend estimates). These signals are used to phrase the short Oracle insight headline and to answer Ask Oracle follow-up questions. All figures are computed on your device and validated before display; the AI rephrases wording and does not generate the numbers.
- Financial Story AI: Sanitized aggregate signals only (e.g., total income, total spend, net flow, top category labels and amounts, credit net, savings rate). No merchant names, account numbers, or raw transaction rows are sent.
Raw PDFs, full statement text, account numbers, and full statement balances are never sent to any third-party provider. All AI features are opt-in and can be disabled at any time.
When Sign in with Apple is used, Apple acts as an identity provider and processes authentication data under Apple’s policies. When Sign in with Google is used (web/PWA only), Google acts as an identity provider and processes authentication data under Google’s policies. We only request and process identity data needed to authenticate and secure your session.
Payment processors. If you subscribe, payment is handled entirely by a third-party processor and your card details never pass through our servers:
- Stripe (web subscriptions) collects and processes your payment details as an independent controller under its own privacy policy at stripe.com/privacy. We receive back only a customer/subscription reference and the resulting status.
- Apple (iOS subscriptions) is the merchant of record and processes payment through your Apple Account under Apple’s privacy policy. We receive only a transaction identifier and the resulting entitlement status.
We do not use any third-party analytics, advertising, or tracking services. All usage analytics are collected and stored on our own servers.
7. Data Storage and Security
- All traffic is served over HTTPS end-to-end.
- The Service runs on Amazon Web Services infrastructure hosted in the United States. Application secrets are held in managed secret storage rather than in source code, and deployment access is restricted to authorized maintainers.
- Uploaded files are request-scoped and purged from backend request memory/temporary handles after parsing. Parsed statement datasets are not persisted on our servers as retained customer financial data.
- Learned categorization rules are stored locally on your device only and are never transmitted to our servers. No raw transaction descriptions, amounts, or account numbers are stored in rules.
- Device-local Session History data, including locally cached Oracle and Financial Story snapshots, is stored only on your device and is never transmitted to our servers as part of local caching.
- The server-side datasets we persist are: anonymous usage analytics, subscription/entitlement records, and upload-quota records. None of them contain the contents of your statements.
8. App Store (iOS) Disclosures
- The iOS app requires Sign in with Apple for protected upload and analysis sessions.
- We do not use third-party advertising SDKs, ad identifiers, or cross-app tracking for advertising.
- Because the app does not track users across third-party apps or websites for advertising, the current shipping app does not rely on App Tracking Transparency.
- We do not sell personal information.
- The app offers auto-renewing subscriptions. The subscription name, length, and price are shown in the app before purchase, alongside links to these Terms and this Privacy Policy, as Apple requires. Purchases are billed by Apple through your Apple Account and can be managed or cancelled in your Apple Account subscription settings.
9. Your Rights
- You can delete individual saved uploads, disable Session History, or clear all cached data at any time within the app.
- If account auth is active (Sign in with Apple, or Sign in with Google on the web/PWA), you can permanently delete your account in-app from Settings under Data controls. As explained in Section 1, one minimal record survives deletion: a one-way hash of your provider identifier plus a count of statements analyzed, kept only so the free allowance cannot be reset by deleting and recreating an account. It contains no email, name, or statement data.
- Deleting your account does not cancel an active subscription. Cancel a web subscription through the billing portal, or an iOS subscription through your Apple Account settings, before deleting the account.
- You can delete any learned categorization rule at any time through the app.
- You can disable anonymous usage analytics at any time in Settings.
- You can request access to or deletion of any personal data we hold by contacting us at support@mybudgetnerd.com.
10. Data Retention
Uploaded files are processed request-by-request and purged from backend request memory/temporary handles after parsing. Parsed statement datasets are not retained on our servers as a stored customer financial dataset. Device-local Session History retains data for a period you choose (default 120 days; options include off, 6 hours, 30, 60, 90, 120 days, or 1 year), supports deletion of individual saved uploads, and can be cleared at any time. When available, cached Oracle and Financial Story snapshots follow the same on-device retention and deletion behavior. Learned categorization rules are stored on-device and can be cleared at any time through the app. Anonymous analytics events are retained on our servers for operational purposes.
Subscription and entitlement records are kept while your subscription is active and afterwards for as long as needed to handle billing disputes, refunds, and tax and accounting obligations. Upload-quota records and the billing audit log are kept for the same purposes. The post-deletion hashed quota record described in Section 1 is retained indefinitely, because a record that expired would reopen the free-allowance reset it exists to prevent.
11. Children’s Privacy
The Service is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly.
12. Data Sharing
We do not sell, rent, or trade your personal information. We do not share your data with third parties except as described in Section 6 (Third-Party Services) — which includes our payment processors, Stripe and Apple, for subscription billing — or when required by law to comply with legal obligations, protect our rights, or ensure the safety of our users.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page. We encourage you to review this policy periodically. Continued use of the Service after changes constitutes acceptance of the updated policy.
14. Security and Data Breach Notification
We implement technical and organizational security measures designed to protect the information we process, including HTTPS-only transmission, platform-standard secure storage for authentication tokens, and the infrastructure controls described in Section 7. However, no security measure is perfect or impenetrable, and we cannot guarantee the absolute security of your data.
In the event of a data breach that affects personal information we hold, we will notify affected users and relevant authorities as required by applicable law, without undue delay. Where we have your contact information, notification will be provided by email. We will also post a prominent notice on our website or within the app as appropriate.
15. Contact Us
If you have any questions or concerns about this Privacy Policy or your data, contact us at support@mybudgetnerd.com.
If you contact us for support, please note: the app does not store, log, or transmit user communications or emails. Emails are handled by external email providers and may be retained under their respective policies. We recommend you do not send sensitive information (such as bank statements or personal data) via email or support channels. Athena Analytics LLC is not responsible for the security, retention, or transmission of communications handled by third-party email providers.