1. Who we are
Digitau OÜ (registry code 14415874), Tallinn, Estonia, is the data controller for personal data processed in connection with the bud mobile application (“bud”, “the App”, “the Service”). References to “we”, “us”, “our” mean Digitau OÜ.
Contact: privacy@bud.digitau.eu
2. What data we collect and why
2.1 Account and authentication
When you create an account we collect your email address and a hashed password (managed by Supabase Auth). This is required to provide the sync service and to let you recover access.
2.2 Financial entries you create
Accounts, transactions, categories, budgets, goals, and tags you create are stored locally on your device and, if you enable sync, on our servers. This data is yours: you can export it (Settings → Export) and delete it (Settings → Delete Account) at any time.
2.3 Settings and preferences
App preferences such as currency, locale, and theme are stored locally on your device only and are not transmitted to our servers.
2.4 Diagnostic and crash data
We use Sentry for crash reporting. If the app crashes, a report is sent that includes the device model, OS version, app version, and a stack trace. Reports are masked to remove email addresses, amounts, and other user-supplied content before transmission.
2.5 Purchase and subscription data
Subscriptions are processed by Apple or Google through their respective app stores. We use RevenueCat to verify subscription status. RevenueCat receives an anonymous app user ID and the purchase receipt; it does not receive your financial entries or your email address from us.
2.6 Website analytics
This website uses Umami, a privacy-friendly analytics service that sets no cookies and collects no personally identifiable information. We see aggregate page views and referrers only.
2.7 Support communications
If you contact us for support, we process your email address and any information you include in your message in order to respond to you.
3. Legal bases for processing (GDPR)
- Article 6(1)(b) — performance of a contract (your account, sync, subscription).
- Article 6(1)(f) — legitimate interests (diagnostic crash reports, security, aggregate analytics).
- Article 6(1)(c) — legal obligation (tax records, fraud prevention).
4. Service providers
- Supabase (EU) — database hosting, authentication, file storage.
- PowerSync — offline sync infrastructure. Data is processed in transit only.
- Sentry — crash and error reporting. Masked diagnostic data only.
- RevenueCat — subscription management. Anonymous user ID + purchase receipt only.
- Apple App Store / Google Play — distribution and subscription billing.
- Umami — privacy-friendly website analytics. No cookies, no PII.
Each provider is bound by a data processing agreement and is prohibited from using your data for their own purposes.
5. International transfers
Where service providers may process data outside the EEA, we rely on the European Commission’s Standard Contractual Clauses (SCCs) or an equivalent transfer mechanism to ensure an adequate level of protection.
6. Retention
| Data | Retention |
|---|---|
| Account + financial entries | For as long as your account is active; purged from live systems immediately on deletion; encrypted backups purged within 30 days. |
| Diagnostic reports | 90 days |
| Support emails | 2 years |
| Purchase records (tax) | 7 years (anonymized) — Estonian Accounting Act §12 |
7. Your rights (GDPR)
Under the GDPR you have the right to: access your data; correct inaccurate data; erase your data; restrict or object to processing; data portability; and to lodge a complaint with a supervisory authority. To exercise any of these rights, contact privacy@bud.digitau.eu. We respond within 30 days.
You may also lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee) or the supervisory authority in your EU member state.
8. California residents (CCPA / CPRA)
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We have no financial incentive program. This “Do Not Sell or Share My Personal Information” link is provided as required by California Civil Code §1798.135.
Categories of personal information we collect (mirroring our App Store privacy labels):
- Identifiers — email address (account creation only)
- Customer records — financial entries you create, stored end-to-end on your device unless you enable sync
- Internet/network activity — masked crash diagnostics, aggregate page views
- Commercial information — anonymous purchase receipt for subscription verification
California residents have the right to:
- Know what categories of personal information we collect and the purposes of collection
- Request a copy (right to know)
- Request deletion (right to delete)
- Correct inaccurate personal information
- Limit use and disclosure of sensitive personal information (we do not process sensitive PI as defined by CPRA)
- Opt-out of sale or sharing (no opt-out is necessary because we neither sell nor share)
- Non-discrimination for exercising these rights
To exercise these rights, email privacy@bud.digitau.eu with subject line “California privacy request”. We verify identity by matching your account email and respond within 45 days.
9. Other US state residents
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Tennessee (TIPA), Iowa (ICDPA), Indiana (INCDPA), Delaware (DPDPA), New Hampshire (NHDPA), New Jersey (NJDPA), Minnesota (MCDPA), and Maryland (MODPA) have substantially the same rights set out in Section 8 above. Email the same address with subject line “[State] privacy request”.
10. App Store privacy labels
The following categories are declared in our Apple App Store privacy details and Google Play Data Safety form. They mirror Sections 2 and 8 above and are maintained in sync:
- Data linked to you: email address, user-generated financial entries (only when sync is enabled), purchase history (anonymized).
- Data not linked to you: diagnostic crash logs (masked), product interaction telemetry.
- Data used to track you: none.
11. Security
All data in transit is encrypted using TLS 1.2+. Data at rest in Supabase is protected by row-level security policies that ensure only your authenticated account can access your data. Diagnostic reports are masked before transmission. No security measure is perfect; we encourage you to use a strong unique password and keep your device OS up to date.
12. Children
bud is not intended for persons under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, contact us immediately at privacy@bud.digitau.eu and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you in the app or by email before the changes take effect. The date at the top of this page reflects the most recent update.
14. Contact
Digitau OÜ · Tallinn, Estonia · privacy@bud.digitau.eu