Privacy Policy
Last updated May 2026
The short version
Bud is a personal finance app for iPhone. Your transactions, budgets, and conversations with Buddy live on your device. The only data that ever leaves your phone is the bare minimum we need to make features like split-bill sync, AI assistance, and authentication work, and we keep that minimum genuinely minimal.
What stays on your iPhone
Every transaction you log, every budget you set, every recurring payment, every splash of your spending breakdown, and every chat with Buddy is stored locally in SwiftData on your device. We can't see this data, and we don't copy it to our servers.
What we do collect, and why
Email address. When you sign up, we keep your email so we can sign you in and send transactional messages (waitlist confirmations, account recovery). We use Resend to deliver these emails from auth@budtheapp.com. We don't send marketing emails without explicit consent.
Split-bill data, only when you split. If you create or join a Split, the minimum information needed to settle the bill (member identifiers, amounts, group name) is synced to our Supabase database so everyone in the group sees the same totals. The rest of your finances never goes there.
Buddy AI requests. When you talk to Buddy, the message you send and relevant context (e.g. your last few transactions) are sent to Google's Gemini API to generate the response. Google processes the request and returns the answer. We do not retain Buddy chats on our backend.
Subscription state. Bud Plus subscriptions are managed through Apple via RevenueCat. We see your subscription status and entitlement, not your card.
Crash + diagnostic data. If you opt in via iOS Settings, Apple shares anonymized crash reports with us so we can fix what broke. You can turn this off any time.
Who we share data with
The processors above (Supabase, Resend, Google Gemini, Apple/RevenueCat) and nobody else. We do not sell, rent, or trade your data, ever. We do not run advertising in Bud, and we do not allow third-party trackers in the app.
Security
Local data is protected by the iPhone's on-disk encryption. Data in transit uses TLS. Server-side data is protected with Supabase's row-level security so a row belonging to one user is never readable by another.
Your rights
You can delete your account from inside the app at any time, which removes your row from our backend and erases the local database. You can also email shreyas@kalsdesigns.com with any access, correction, deletion, or portability request and we'll respond within 30 days.
Children
Bud is not designed for anyone under 13. If you believe a child has signed up, please email us and we will remove the account.
Changes to this policy
If we update this policy, we'll change the date at the top and, for material changes, ping you in-app before the change takes effect.
Contact
Questions? shreyas@kalsdesigns.com