Privacy Policy
Effective 16 June 2026 · Last updated 16 June 2026
Budgy AI ("the app", "we", "us") is operated by Marcus Rehbock, an individual developer based in Australia. This policy explains what data the Budgy AI app and website handle and why.
The short version: no account, no name, and no email are required to use the app. We don't sell your data, we don't share it for cross-context advertising, and we don't track you across other apps or websites.
1. Data we collect in the app, and why
| Data | Examples | Why we collect it |
|---|---|---|
| Device identifier | A random ID generated on first launch | Identifies your installation so your plans and preferences can be stored without an account |
| Meal preferences | Household size, weekly grocery budget, preferred store, dietary needs, allergies, cooking-time preference, currency | Generating your meal plans and shopping lists |
| Generated content | Meal plans, recipes, shopping lists, checked-off items | The core function of the app |
| Purchase history | Subscription status, product purchased, renewal events | Operating your Budgy Pro subscription |
| Usage data | Screens viewed, features used, app events | Understanding how the app is used so we can improve it |
All of the above is linked to the random device identifier, not to your name, email, or other contact details — we don't have those. We do not collect precise location, contacts, photos, health records, or browsing history.
2. Website and waitlist
If you join the waitlist on our website, we collect the email address you submit, plus your IP address and signup time to prevent abuse. We use this only to notify you about Budgy AI and to keep the waitlist secure — not for marketing spam. You can ask to be removed at any time by emailing us.
3. Who processes data on our behalf
We use the following service providers, who process data only to provide their service to us and are bound by their own privacy and security obligations:
- Convex (convex.dev) — database hosting for your preferences, plans, and lists.
- PostHog (posthog.com) — usage analytics, linked to the device identifier only.
- RevenueCat (revenuecat.com) — subscription management; receives the device identifier and purchase events from Apple.
- Apple — processes all payments. We never see or store payment card details.
- OpenRouter and its AI model providers (openrouter.ai) — your meal preferences (budget, household size, dietary needs, allergies, store) are sent to generate recipes. No identifiers or contact details are included in these requests, and this data is not used to train third-party models.
We do not sell personal data, and we do not share it with data brokers or advertisers.
4. Legal bases (EU/UK users)
If you are in the European Economic Area or the United Kingdom, we process your data on these legal bases under the GDPR:
- Performance of a contract — to provide the app, generate your plans, and operate your subscription.
- Legitimate interests — to understand usage and improve the app, secure the Service, and prevent abuse, balanced against your rights.
- Consent — for the waitlist email and where else required, which you may withdraw at any time via the contact process below.
5. International data transfers
Our service providers are located primarily in the United States, so your data is processed outside Australia, the EEA, and the UK. Where required, these transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. By using the Service, you understand your data may be processed in these locations.
6. Tracking
We do not track you across apps or websites owned by other companies, and the app contains no third-party advertising. Accordingly the app does not request App Tracking Transparency permission — there is nothing to ask about.
7. Your privacy rights (US states)
We do not "sell" or "share" personal information as those terms are defined under the California Consumer Privacy Act (as amended by the CPRA) or comparable US state privacy laws, and we do not process sensitive personal information for purposes that require an opt-out. Depending on your state, you may have rights to know, access, correct, or delete the data we hold. Because we hold no contact details to identify you in the app, you can exercise these rights through the deletion and contact process below.
8. Data retention and deletion
App data is retained while you use the app so your plans persist between sessions. Deleting the app removes the device identifier from your phone, permanently disconnecting you from the stored data. To have the server-side data deleted as well, email us the request from any address — include the rough date you used the app and we'll locate and delete the associated records. We respond within 30 days.
9. Children
The app is intended for adults managing a household grocery budget and is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.
10. Your rights generally
Depending on where you live — including under the Australian Privacy Act, EU/UK GDPR, and California CPRA — you may have rights to access, correct, or delete data, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority (in Australia, the Office of the Australian Information Commissioner). Because we hold no contact details in the app, exercising these rights works through the deletion and contact process above.
11. Security
Data is transmitted over HTTPS and stored with access controls by the providers listed above. No method of transmission or storage is completely secure, but we take reasonable steps to protect the limited data we hold.
12. Changes
If this policy changes materially, we'll update this page and the effective date above. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.
13. Contact
Privacy questions or a deletion request? Email marcusrehbock@gmail.com.