Budgitify Privacy Policy

Effective Date: June 16, 2025
Last Updated: February 25, 2026

Budgitify ("we", "us", or "our") is a budgeting application operated by LzCtrl LLC. This Privacy Policy explains how we collect, use, and protect your information when you use the Budgitify app or website (the "Services").

1. Information We Collect

  • Account Info: Email address and authentication ID via Firebase.
  • Budgeting Data: Transactions, categories, budgets, and preferences you enter manually.
  • Bank Connection Data: When you connect a bank account through Plaid, we receive read-only access to account balances and transaction history. We do not store your bank login credentials. Plaid's collection and use of your data is governed by the Plaid End User Privacy Policy.
  • Payment Info: Subscription billing is handled by Apple (App Store) or Stripe. We do not store your full payment card details.
  • Device & Usage Data: Device identifiers, app version, and usage analytics via Firebase Analytics.

2. How We Use Your Data

We use your data to:

  • Provide and improve the Services, including populating your transaction history from connected bank accounts
  • Secure your account and detect fraud or abuse
  • Process subscription payments and manage billing
  • Send transactional notifications (e.g. budget alerts)
  • Fix bugs and optimize performance

We do not sell your data or use it for advertising purposes.

Marketing Communications: With your consent, we may use your email address to send newsletters and product updates related to Budgitify and other LzCtrl apps. You can opt out at any time by clicking "Unsubscribe" in any email or by contacting info@lzctrl.com.

3. Data Storage & Security

Your data is stored securely in a PostgreSQL database hosted on Render (SOC 2 Type 2 certified). Authentication and analytics are powered by Firebase (Google). Bank connections are facilitated by Plaid, and encrypted access tokens are stored at rest using AES-256 encryption. All data is transmitted over TLS. We implement security best practices throughout our infrastructure.

4. Data Retention & Deletion

We only retain your data for as long as it is necessary to provide the Services or as required by law.

  • Active accounts: All personal and financial data (transactions, accounts, categories, and preferences) is retained for the lifetime of your account.
  • Account deletion: When you delete your account, your personal information is deactivated and made inaccessible immediately. Your data is scheduled for permanent deletion within 30 days, except where retention is required by law.
  • Bank connection data: If you disconnect a linked bank account or delete your Budgitify account, your bank connection access token is revoked immediately through Plaid's API. No further data is fetched after revocation.
  • Subscription & billing records: Records related to purchases and billing are retained for up to 7 years to comply with applicable financial record-keeping laws.
  • Backups: Encrypted database backups are purged within 90 days of creation.

You may request deletion of your data at any time by deleting your account in the app or by emailing info@lzctrl.com. We will respond to verified deletion requests within 30 days.

5. Sharing of Information

We do not sell your personal information. We share data only with the following trusted service providers, strictly to operate the Services:

  • Firebase / Google — authentication and analytics
  • Plaid — bank account connectivity and transaction data retrieval
  • Stripe — payment processing for web subscriptions
  • Apple — payment processing for App Store subscriptions and Sign in with Apple
  • Render — cloud infrastructure and database hosting

We may also disclose information when required by law or to protect our legal rights.

6. Your Rights

You may delete your account in the edit profile section of the app. You may also request access to or deletion of your data by emailing info@lzctrl.com.

7. California Privacy Rights (CCPA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: You may request information about the categories and specific pieces of personal data we have collected about you.
  • Right to Delete: You may request deletion of your personal data, subject to certain exceptions.
  • Right to Opt-Out of Sale: We do not sell your personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.

To exercise these rights, email us at info@lzctrl.com. We will respond within 45 days.

8. Children's Privacy

Budgitify is not intended for children under 13. We do not knowingly collect personal data from children.

9. Changes to This Policy

We may update this Privacy Policy. Changes will be reflected on this page with an updated "Last Updated" date.

10. Contact

If you have questions or concerns about this Privacy Policy, please contact: info@lzctrl.com