Privacy policy

Budgetify exists to read your receipts, so it necessarily holds some of the most ordinary and most revealing data there is: where you shop, when, and what you bought. This page says exactly what we keep, who else touches it, and how to get rid of it.

Effective 16 September 2026Yeti Technology Pty Ltd

Who we are

Budgetify is operated by Yeti Technology Pty Ltd (ACN 700 052 188), a company registered in Australia. We are the data controller for the information described below. You can reach us at contact@yeti.technology.

This policy covers the Budgetify mobile app (Android application ID app.budgetify.budgetify), its backend API, and this website.

What we collect

Only what the app needs to do its job. There is no advertising SDK, no third-party analytics, and no behavioural profiling in Budgetify.

WhatSpecificallyWhy
AccountYour account identifier, your email address, your currency preference and your time zone.To sign you in and to attach your data to you.
ReceiptsMerchant name, purchase date, category, currency, subtotal, tax, tip and total, an optional location line printed on the receipt, a business/personal flag, processing status and timestamps.This is the expense record itself.
Line itemsEach item’s description, quantity, unit price and total price, plus any note you add.So a receipt is itemized rather than just a total.
Raw extractionThe complete response from our OCR provider for each receipt, stored alongside it.So a mis-read can be corrected or re-parsed without asking you to photograph the receipt again.
Receipt imagesThe photo or PDF you captured, uploaded or imported.So you can check the original against the extracted figures.
BudgetsYour monthly limit for each spending category.To show how much of each budget you have used.
Processing recordsThe status, per-step progress, error message and timings of each extraction job.To show you progress, and to debug failed scans.
Server logsRequest metadata, including your IP address, the endpoint called and the time.Security, abuse prevention and diagnosing faults.

Your password never reaches us

Authentication is handled entirely by Clerk. We never see or store your password. If you sign in with Google, we never see your Google credentials either. The only piece of profile information we copy out of Clerk is your primary email address, read once when your account record is first created and used for support and for confirming deletion requests.

Device permissions

The app asks for camera access to photograph a receipt, and for photo-library or file access when you choose to import one. These are used only for the image you select, at the moment you select it. Budgetify does not request location, contacts, calendar, microphone or advertising identifiers.

What we do not do

  • We do not sell your personal information, and we do not share it for advertising or cross-context behavioural advertising.
  • We do not use your receipts to build a marketing profile of you, and we do not pass them to data brokers, retailers or card issuers.
  • There are no advertising SDKs or third-party analytics in the app.
  • We do not use your receipt data to train machine-learning models, ours or anyone else’s.

How receipts are processed

When you capture a receipt, the image is uploaded over TLS to a private cloud storage container — it is never publicly readable, and it is never given a public URL. The image is then sent to Microsoft’s Azure AI Document Intelligence service, which reads the merchant, date, totals and line items and returns them to us. We store that response and turn it into the expense you see in the app.

When the app needs to show you the original, our server mints a read-only link that expires after 15 minutes and is issued only to your authenticated session. An image link that ends up in a screenshot, a log or a shared chat stops working almost immediately.

No AI chatbot processing today. The only automated analysis Budgetify performs on your receipts is the optical character recognition described above. Categorization is done by rule on our own servers. If we later add a feature that sends your data to a large language model, we will update this policy and tell you before it ships — not after.

Who else touches your data

We use a small number of processors. Each one only receives what it needs, and each is bound by its own contractual confidentiality and security obligations.

ProcessorWhat it handlesWhere
ClerkAuthentication and identity — your email address, sign-in credentials and sessions.United States
Microsoft AzureApplication hosting, the PostgreSQL database holding your receipts and budgets, and the private storage holding your receipt images.Australia East (Sydney)
Azure AI Document IntelligenceOptical character recognition — reads each receipt image you submit.Australia East (Sydney)
GoogleOnly if you choose “Continue with Google” to sign in. Google tells us your email address; we tell Google nothing about your spending.United States

International transfers

Your receipts, line items, budgets and images are stored in Australia East (Sydney). Your identity record is held by Clerk in the United States, which means your email address and sign-in metadata are transferred overseas. Where a transfer is subject to the Australian Privacy Principles or the GDPR, we rely on the processor’s standard contractual clauses and equivalent safeguards.

How long we keep it

  • Your receipts, items, budgets and images are kept for as long as your account is open. They are yours; we do not expire them.
  • A receipt you delete in the app is removed immediately, along with its line items, its processing records and its stored image.
  • Your whole account is erased within 30 days of a verified request — see Delete your account.
  • Server logs containing IP addresses are retained on a short operational cycle and then discarded.

Security

  • All traffic between the app and our servers is encrypted with TLS.
  • Receipt images are held in a private container with no public read access, and are reachable only through short-lived, per-request signed links.
  • Every API request is authenticated, and every database query is scoped to the requesting account — one account cannot read another’s receipts.
  • Credentials and signing keys are held as server-side secrets, never shipped in the app.

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the relevant regulator as required by the Notifiable Data Breaches scheme and any other applicable law.

Your rights

You can ask us to:

  • Access the personal information we hold about you.
  • Correct anything that is wrong — you can also fix a receipt’s merchant, date, category, total and business flag yourself, on its detail screen in the app.
  • Delete your account and everything attached to it.
  • Export a copy of your receipts and budgets.
  • Object to or restrict processing, where that right applies to you.

Email contact@yeti.technology from the address on your account. We respond within 5 business days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. If you are in the EEA or the UK, you may instead complain to your local supervisory authority.

Children

Budgetify is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

If we change how we handle your data in a way that materially affects you, we will update the effective date at the top of this page and tell you in the app before the change takes effect. Minor clarifications will be reflected here with a new effective date.

Governing law

This policy is governed by the laws of New South Wales, Australia, without affecting any rights you have under the privacy law of the place you live.

Questions, or want your data gone? Email contact@yeti.technology, or read how account deletion works.