GuardMyBucks LogoGuardMyBucks Back to sign in

Privacy Policy

Last updated September 2026

1. What we collect

Account info: your name, email address, and password (stored as a bcrypt hash, never in plain text) — or, if you sign in with Google, the basic profile info Google shares with us.

Financial data you add: bank/wallet/investment accounts, transactions, bills, credit cards, loans, budgets, and goals you enter manually or import via CSV/PDF/OFX/screenshot. This is the core of what the app does — we only have what you give it.

Uploaded documents: statements, receipts, and credit reports you upload for parsing, stored in object storage tied to your account.

Usage & audit logs: sign-ins, account changes, and similar security-relevant events, so we (and you, in Profile > Recent activity) can see what happened on your account.

2. AI processing — what actually happens

If you use the AI Advisor, AI-assisted document import, or credit report parsing, the relevant text or document content is sent to an AI provider to generate a response. Which provider depends on your setup:

  • Bring your own key (BYOK): if you've added your own Anthropic/OpenAI/Gemini/self-hosted API key in Settings, your requests go directly to that provider using your key. We store the key encrypted at rest (AES-256-GCM) and never see the plaintext key after you save it.
  • Server-side fallback: if BYOK isn't configured or enabled for your plan, and an administrator has configured a fallback provider key, your request is sent using that shared key instead.

Either way, we don't use your financial data to train models, and we don't sell it to anyone. AI providers process the request under their own data-handling terms as an independent processor.

3. How we use your data

To run the app: showing your dashboards, computing budgets/forecasts/net worth, sending bill and spending alerts (if enabled), and generating the AI insights described above. We don't use your financial data for advertising, and we don't sell it.

4. Security

Passwords are hashed with bcrypt. Sensitive fields — AI provider API keys and two-factor secrets — are encrypted at rest with AES-256-GCM before they ever touch the database. Connections to the app are encrypted in transit (HTTPS/TLS). Uploaded documents live in access-controlled object storage scoped to your account. No system is perfectly secure, but we don't store anything sensitive in plain text.

5. Data retention

Your data stays until you delete it. Two settings in Settings > Data let you control retention specifically: whether uploaded credit reports are kept after parsing, and whether imported source documents are retained. Audit log entries tied to your account are removed if you delete your account, except where we're required to keep minimal records for security/fraud purposes.

6. Your rights

From Profile settings inside the app, you can:

  • Download a copy of your data (“Download your data”)
  • Permanently delete your account and associated data (“Delete account”)
  • Update or correct your profile information at any time

7. Cookies & sessions

We use a session cookie to keep you signed in (via NextAuth). We don't use third-party advertising or tracking cookies.

8. Third parties

Depending on your configuration and plan, your data may pass through: your chosen or the platform's configured AI provider (see §2), an email delivery provider (only if outgoing email is configured, for things like bill reminders or password resets), and our object storage provider (for uploaded documents). We don't sell your data to anyone, for any reason.

9. Changes to this policy

If we make material changes, we'll update the date at the top of this page. Continuing to use GuardMyBucks after a change means you accept the updated policy.

10. Contact

Questions about your data? Email support@finsage.dev.