Last updated: 6 October 2026
Privacy Policy
Budgetku ("we", "us") is committed to protecting your personal data. This policy explains what data we collect, why, and your rights under the Indonesian Personal Data Protection Act (UU PDP No. 27/2022).
Data we collect
When you sign up and use Budgetku, we collect:
- Email address — for authentication, account recovery, and important notifications.
- Name — the one you enter at sign-up or change in the profile menu (top right) → Account, or the one Google sends if you sign in with Google. Members of your workspaces can see it.
- Password — stored as an Argon2id hash; we never see your raw password.
- Workspace name, base currency, language preference.
- Financial transaction data you input (accounts, categories, transactions, budgets, invoices).
- IP address, User-Agent, and request timestamps — for security, abuse prevention, and technical analytics.
- Login history (network, device) for suspicious-activity detection.
How we use your data
We use your data to:
- Provide the core service — authentication, workspace isolation, transaction storage.
- Process subscription payments for paid plans.
- Send transaction notifications, invoices, team invitations, and security emails.
- Prevent abuse (rate limiting, suspicious-login detection).
- Comply with legal and audit obligations (UU PDP, ITE Law, tax regulations).
- AI features — the Assistant, which drafts transactions from your messages, and category suggestions are optional: both run only when you use them, and you always review a draft before it is saved. The dashboard insight is generated automatically for accounts set to Indonesian and uses only percentages and category names.
Third parties
We share the minimum data required with the following service providers. Each has its own privacy policy worth reading.
- Licensed payment service providers — process your payments (QRIS, Virtual Account, e-wallets and retail outlets).
- Email service provider — delivery of transactional email (invoices, verification, password reset).
- Server hosting provider (VPS) — runs the application and stores the Budgetku database.
- AI service provider (located outside Indonesia) — processes the messages you send to the Assistant together with up to six earlier messages and replies from the same session, plus your local date, time zone and default currency; merchant names, notes and category names when you ask for a category suggestion; and a percentage summary and category names for the dashboard insight. Budgetku does not send your email, password, account balances, receipt photos, or full transaction history to the provider, unless you type them into a message yourself. The provider does not use this data to train its models and deletes it within 30 days, unless the law requires otherwise or it is needed to deal with abuse.
Sign in with Google
If you sign up or sign in with a Google account:
- What we receive from Google: your Google account ID, email address, name, and profile photo link. Signing in with Google does not give us access to your Gmail, Drive, or contacts.
- What we use it for: signing you in, showing you and the members of your workspaces who you are, and helping you when you contact support.
- We do not copy your photo. We store only its link, and the photo loads straight from Google's servers.
- You can change your name at any time in the profile menu (top right) → Account. Once your account is linked to Google, a name you have changed is not overwritten by Google. The photo follows your Google account and is updated each time you sign in with Google.
- If you delete your account, your name and profile photo link are deleted with it.
Google data (Google Sheets integration)
If you connect Google Sheets (Pro and Business plans), Budgetku asks for one Google permission: to create and edit files that Budgetku creates in your Google Drive (drive.file). Budgetku cannot read any other file in your Drive.
- What we store: the email address of the connected Google account and an encrypted access token, used only to update your workspace's spreadsheet.
- What we write: your workspace's financial data (transactions, summaries, and for Business: profit & loss, invoices, customers) into a spreadsheet you own.
- We do not sell or share your Google data or use it for advertising or to train models. Our use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- You can disconnect at any time in Settings → Integrations, or remove Budgetku's access from your Google account. On disconnect the token is deleted and revoked at Google, unless another of your workspaces still syncs with the same Google account — in that case, that Google access is kept for that workspace. The spreadsheet stays yours.
Storage and retention
Your data is stored in data centres in the Asia-Pacific region. While your account is active, data remains available. After you delete your account, personal account data (email, name, profile photo link, password hash) is removed immediately; workspace data is retained for audit and tax compliance up to 7 years, unless you request earlier deletion in writing and no legal hold applies. One limited exception: if the account used any free AI tries, we keep a one-way fingerprint (hash) of the email address, made with our secret key, together with the number of free AI tries used and the date the account was deleted. This is kept for at most 12 months, solely to prevent abuse of the free AI tries: if the same email is used to sign up again, the new account continues with the tries that were left instead of starting over. The email address itself is not kept, and the fingerprint cannot be turned back into the email address without our secret key.
Your rights (UU PDP 2022)
As the data subject, you have the right to:
- Access and download all your data — self-service in the profile menu (top right) → Account → Download my data.
- Correct inaccurate data — via the app interface or by contacting us.
- Request account deletion — the profile menu (top right) → Account → Delete account.
- Withdraw consent at any time — withdrawal is not retroactive.
- Object to specific processing — contact us for review.
Cookies
We use essential cookies (httpOnly authentication) that are required for the app to work and do not need consent. Optional cookies (analytics, marketing) are only set after you give explicit consent via the cookie banner. You can change or withdraw that consent at any time through the “Cookie settings” link at the bottom of every page.
Security
We apply Postgres Row-Level Security for workspace isolation at the database layer, Argon2id password hashing, TLS for all traffic, audit logging for sensitive actions, and rate limiting on sensitive endpoints. No system is 100% secure — you remain responsible for keeping your password confidential.
Changes to this policy
We may update this policy from time to time. Material changes will be announced via email and/or in-app notice at least 14 days before they take effect.
Contact
For privacy questions, data access requests, or complaints about how we process your personal data, contact: support@budgetku.com.