Bud

Privacy Policy

Last updated July 2026

The short version

Bud never asks for your bank login. We do not sell your data, we do not run ads, and we do not allow third-party trackers in the app. What we do keep is your Bud account and the spending you put into it, because that is what lets your data follow you to a new phone and lets a split add up the same for everyone in it.

This policy covers Bud for iPhone and Bud for Android. Most of it is identical. Where the two differ, it says so.

What we store on our servers

Your Bud account lives in our database, hosted with Supabase. That includes the transactions you log — amount, merchant, category, currency, date, payment method and any note you add — plus your budget and settings, your recurring payments, your splits and the people in them, and your profile (name, email, and phone number if you give one).

We are being specific about this because it is the part people assume works the other way. Your spending is not locked to a single handset. It is stored under your account so that signing in on a new phone brings it back, and so that a split shows the same totals to everyone sharing it. Every row is protected by row-level security, which means the database itself refuses to hand your rows to another account.

We do not have a bank connection, we never see your card or account numbers, and we cannot move money.

What stays on your device

On Android: your conversations with Buddy stay on the phone, in Bud's local database. They are not stored on our servers. Individual messages are sent to the AI service to get a reply — see below — but the history is yours and it is local.

On iPhone: Buddy conversations sync to your account so they are there when you sign in elsewhere.

On both platforms, receipt photos taken in the add flow are processed and discarded rather than filed away. Drafts you never save never leave the phone at all.

What we collect, and why

Email address. So we can sign you in and send transactional messages — account recovery, verification codes, split invitations you asked us to send. We use Resend to deliver these from auth@budtheapp.com. We do not send marketing email without explicit consent.

Split-bill data. When you create or join a split, the information needed to settle it — names, the email or phone you invited someone with, amounts owed, group name, settlements and any comments posted on the expense — is stored so that everyone in the group sees the same numbers. If you invite someone by email, we send that invitation on your behalf.

Buddy AI requests. When you talk to Buddy, your message and relevant context — such as your recent transactions — are sent through our server to Google's Gemini API to generate the reply.

Quick add and receipt scanning. When you paste or share text into Bud for it to interpret, that text goes to the same AI service. When you scan a receipt, the text is read on your device and the photo is sent along with it so the model can read what the OCR could not. The photo is used to produce the expense and is not stored.

Merchant names, for tidying and for logos. A raw payment string is not a readable merchant name, so we send it to the AI service to clean it up and suggest a category. We also use the merchant name to look up that company's logo from a logo provider (logo.dev), falling back to DuckDuckGo's and Google's icon services if it has none. Those providers receive a merchant domain and your device's IP address. They do not receive your name, your account, or the amount.

Profile photo. Optional. If you upload one, it is stored in a public bucket, which means the image URL is reachable by anyone who has it. Do not upload a photo you would not be comfortable being publicly accessible.

Subscription state. Bud Plus is managed through the App Store or Google Play via RevenueCat. RevenueCat receives your Bud account identifier and your purchase state. We see whether you are subscribed. Neither we nor RevenueCat sees your card.

Crash and diagnostic data. If Bud crashes, we may receive a crash report through Sentry so we can fix it. These are configured to strip personal information: no email, no username, no IP address, no location, no screenshots and no session recording. On iPhone, Apple's own crash sharing is separate and controlled in iOS Settings.

Reading payment notifications (Android only)

On Android, Bud can log your spending automatically by reading the notifications your payment apps post. This is entirely optional, it is off until you turn it on, and Bud works normally without it. Apple provides no way for an app to read notifications, so nothing in this section applies to Bud for iPhone.

What we access. With your permission, Android lets Bud see the notifications on your phone. Bud acts only on notifications from a fixed list of banks, cards and wallets it recognises, and only on messages that look like a payment you made. Notifications from every other app — your messages, your email, your chat apps — are ignored, and Bud does not act on one-time passcodes.

What we take from them. Three things: the amount, the currency, and the name of who you paid. The text of the notification itself is never stored, never written to a log, and never sent anywhere.

How it is used and shared. Those three details are saved to your Bud account so your spending appears on every device you sign in to. The merchant name and amount may be sent to Google's Gemini API, through our server, to turn a raw payment string into a readable name and pick a category. The merchant name may also be used to look up that merchant's logo, as described above. Captured payments are logged for you automatically and Bud tells you each time it does so; you can edit or delete any of them.

What we never do with it. We do not sell your notification data. We do not share it with advertisers or data brokers, and we do not use it for advertising or profiling. We do not use it to build any picture of you beyond your own spending record inside Bud.

Your control. You can turn this off at any time, either inside Bud (Account → Easy Access → Auto-log every payment) or in Android Settings. Bud stops reading notifications immediately. Turning it off does not delete spending already logged — you can delete individual entries, reset all your data, or delete your account from inside the app.

Who we share data with

The processors named above and nobody else: Supabase (database and file storage), Google Gemini (AI parsing, categorisation and Buddy), Resend (transactional email), Apple and Google Play with RevenueCat (subscriptions), Sentry (crash reports), and logo.dev with DuckDuckGo and Google as fallbacks (merchant logos).

We do not sell, rent, or trade your data, ever. We do not run advertising in Bud, and we do not allow third-party trackers or analytics SDKs in the app — there is no Firebase Analytics, no Amplitude, no Mixpanel, no ad network, and no advertising identifier.

Security

Everything Bud sends travels over TLS. Server-side data is protected with row-level security, so a row belonging to one account is never readable by another. Local data is protected by your phone's own on-disk encryption.

On Android, Bud deliberately excludes your sign-in token and any pending captured payments from Google's cloud backup and device-to-device transfer, so a restored backup cannot carry a live session onto another device.

Your rights

You can delete your account from inside the app at any time, which removes your data from our backend and erases the local database. You can also reset your data while keeping the account, and export everything you have logged as a spreadsheet or PDF. Email shreyas@kalsdesigns.com with any access, correction, deletion, or portability request and we'll respond within 30 days.

Children

Bud is not designed for anyone under 13. If you believe a child has signed up, please email us and we will remove the account.

Changes to this policy

If we update this policy, we'll change the date at the top and, for material changes, ping you in-app before the change takes effect.

Contact

Bud is made by Kals Designs LLC. Questions? shreyas@kalsdesigns.com

← Back to Bud