Privacy Policy
Last updated: January 2026
Introduction
BudgetLuma ("we", "our", "us") operates the BudgetLuma mobile application for iOS. This Privacy Policy describes what data we collect, how we use it, and how we protect it. We only collect data necessary to provide the service.
Data We Collect
We collect the following data, provided directly by you through normal use of the app: Account data: email address and display name, used for authentication and identification. Financial data: wallets (name, currency, type), transactions (amount, currency, exchange rate, date, category), and categories. Collaboration data: shared wallet memberships, roles (owner, editor, viewer), and invitations. Billing identifiers: subscription status and related identifiers managed through RevenueCat and the Apple App Store. We do not store payment card information. We do not collect location data or data from third-party sources. We do not use device identifiers for advertising or tracking purposes.
How We Use Your Data
Your data is used exclusively to provide and operate BudgetLuma: - Authenticate your account and manage sessions - Store and display your wallets, transactions, and categories - Compute wallet balances - Process currency conversions using exchange rates - Manage shared wallet access and permissions - Determine your subscription status (free or premium) We may store minimal internal usage events in our database to improve reliability and user experience. These events are not used for advertising or cross-app tracking. We do not use your data for advertising, marketing, profiling, or sale to third parties.
Third-Party Services
BudgetLuma uses the following third-party services, each with a specific and limited purpose: Supabase: authentication (account creation, login) and database hosting. Supabase stores your account and financial data. Privacy policy: https://supabase.com/privacy Apple App Store: processes subscription payments. Apple handles all payment information. Privacy policy: https://www.apple.com/legal/privacy/ RevenueCat: manages subscription status and entitlements. RevenueCat receives a user identifier and subscription events. Privacy policy: https://www.revenuecat.com/privacy Frankfurter (FX rate provider): provides exchange rates for currency conversion. Only currency pair data is requested; no personal data is shared with this service. More information: https://www.frankfurter.app No other third-party services receive your personal or financial data.
Data Security
All data access is controlled by the backend, which is the single source of truth. The client application is never trusted to authorize actions. Database-level security (Row Level Security) ensures that each user can only access their own data and shared data they have been explicitly granted access to. Shared wallet access is governed by roles and permissions enforced server-side. All balances and financial computations are performed on the backend. Data is transmitted over encrypted connections (HTTPS/TLS).
Data Sharing
We do not sell, rent, or share your personal or financial data with any third party, except the services listed above, which receive only the minimum data required to perform their function. Shared wallet data is visible only to members who have been explicitly invited and assigned a role by the wallet owner.
Your Rights
You have the right to: - Access your personal and financial data through the app - Correct your account information through the app - Request deletion of your account and all associated data To request account deletion, contact us at privacy@budgetluma.com. Upon receiving your request, we will permanently delete your account, wallets, transactions, and all associated data. This action is irreversible.
Data Retention
Your data is retained as long as your account is active. When you request account deletion, all personal and financial data is permanently and irreversibly removed from our systems. We do not retain data after deletion except where required by law.
Changes to This Policy
We may update this Privacy Policy to reflect changes in the service or legal requirements. If changes are material, we will notify users through the app. Continued use of BudgetLuma after an update constitutes acceptance of the revised policy.
Contact
For privacy-related questions or data deletion requests, contact us at privacy@budgetluma.com.