Privacy Policy
Effective date: April 12, 2026
1. Overview
BudgetMaxxing ("BudgetMaxxing," "we," "us") provides budgeting and cash-planning software for service-business operators. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over it.
2. Information we collect
- Account information: name, email address, password hash, workspace name, and role.
- Financial connection data: when you connect a bank account through Plaid, we receive account, balance, and transaction information from your financial institution via Plaid.
- Application content: categories, budgets, rules, notes, and other information you create inside BudgetMaxxing.
- Operational data: log entries, IP addresses, device and browser information, and timestamps used to operate the service.
3. How we use your information
- To operate, maintain, and improve BudgetMaxxing.
- To present transactions, balances, budgets, and forecasts inside your workspace.
- To authenticate you, secure your account, prevent fraud, and respond to support requests.
- To comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information, and we do not use your financial data for advertising.
4. Plaid
BudgetMaxxing uses Plaid Inc. ("Plaid") to securely connect your bank accounts. By using BudgetMaxxing to link a financial account you also agree to Plaid's end user privacy policy, available at plaid.com/legal. Plaid acts as our service provider and data processor for the purpose of retrieving and refreshing account and transaction data from your financial institution.
5. Subprocessors
We rely on the following subprocessors to operate BudgetMaxxing:
- Supabase — managed Postgres database, authentication, and file storage.
- Vercel — application hosting and edge delivery.
- Plaid — bank connectivity and transaction retrieval.
- Stripe — subscription billing and payment processing.
- Resend — transactional email delivery.
6. Security
- All data is encrypted in transit using TLS 1.2 or higher.
- All data is encrypted at rest by our managed database provider using AES-256.
- Access to production systems requires multi-factor authentication.
- Workspace isolation is enforced at the database layer using row-level security.
- Multi-factor authentication is required before any user can connect a new financial institution.
7. Data retention and deletion
We retain personal and financial information for as long as your account is active and only for as long as needed to provide the service. For complete details on retention windows and how to request deletion, see our Data Retention & Deletion Policy.
8. Your rights
Depending on where you live, you may have rights to access, correct, port, restrict, or delete the personal data we hold about you, and to object to certain processing. To exercise any of these rights, contact us at cole@promptmaxxing.ai.
9. Children
BudgetMaxxing is not directed to children under 16, and we do not knowingly collect personal information from children under 16.
10. International transfers
BudgetMaxxing is operated from the United States. If you access the service from outside the United States, you understand that your information will be processed in the United States.
11. Changes to this policy
We may update this policy from time to time. Material changes will be communicated through the application or by email before they take effect. Continued use of BudgetMaxxing after the effective date of an updated policy constitutes acceptance of the changes.
12. Contact
Questions about this Privacy Policy or our data practices can be sent to cole@promptmaxxing.ai.