Privacy Policy
Last updated: July 26, 2026
Mindless Budget is a zero-based budgeting app operated by Mindless Budget LLC, an Indiana limited liability company (“Mindless Budget”, “we”, “us”). Because the app connects to your bank accounts, we want you to know exactly what data we handle, where it goes, and what control you have over it. This policy describes our actual practices — not boilerplate.
The short version: we collect only what the app needs to work, we never sell your data, we use no advertising, analytics, or tracking of any kind, and you can export your data or permanently delete your entire account yourself, at any time, from inside the app.
1. Information we collect
Information you provide
- Account details: your name, an optional nickname, email address, and password. Passwords are stored only as strong one-way hashes (PBKDF2-SHA512) — we cannot read them.
- Optional profile photo: stored with your account if you add one.
- Budget data you create: budget groups and items, amounts, savings goals and target dates, debt balances and minimum payments, income amounts and pay schedule, and manually added accounts.
- Transaction categorizations: the budget categories and splits you assign to transactions.
- Support messages: anything you write in the in-app support chat.
- AI assistant messages: anything you write to the AI assistant.
- Two-factor authentication data: if you enable 2FA, a TOTP secret (stored encrypted) and one-time backup codes (stored only as hashes).
- Referral data: your referral code and, if you used one at signup, who referred you.
Information from your bank, via Plaid
When you connect a bank account, you do so through Plaid. Your online banking credentials go directly from your browser to Plaid — we never see or store them. Plaid gives us a secure access token (which we store encrypted with AES-256-GCM) and, through it, we receive and store:
- Account information: institution name, account names and types, the last four digits of account numbers, and balances.
- Transaction history: dates, merchant/description names, amounts, pending status, currency, and Plaid’s category labels.
Plaid’s handling of your data is governed by the Plaid End User Privacy Policy. When you unlink a bank or delete your account, we instruct Plaid to remove the connection on their side too.
Information created as you use the app
- AI conversation history: your AI assistant conversations are saved to your account so the assistant has context. You can view and permanently clear this history at any time from the assistant.
- AI usage metering: monthly token counts, kept to enforce fair-use limits.
- Email delivery records: we record the delivery outcome of emails we send you (delivered, bounced, or marked as spam), kept 180 days, so we stop mailing a dead address.
- Security records: hashed session and verification tokens (sessions last up to 30 days; verification codes minutes to an hour). We do not keep a log of your IP address in our database; the app uses IPs only in server memory for rate limiting (e.g. login throttling), and our web server keeps standard access logs — which include IP addresses — on the server for a short period (roughly 10 days).
2. No cookies. No trackers. No ads.
The Mindless Budget website and app set no cookies at all — not even session cookies. There are no analytics scripts, no advertising pixels, no fingerprinting, and no third-party fonts or CDNs beside Plaid’s bank-linking widget. Your session tokens and cached budget data are kept in your own browser’s local storage on your device, where we cannot observe them; they are removed from the browser when you sign out.
3. How we use your information
- To provide the service: syncing transactions, computing your budget, sending you the emails needed to verify your address or reset your password. Emails contain only your name and the code or link — never financial data.
- To power the optional AI assistant and automatic transaction categorization (see section 4).
- To answer your support messages (see section 6).
- To keep the service secure: login throttling, abuse prevention, verifying webhooks from Plaid and our email provider.
We do not sell personal information, share it with data brokers or advertisers, or use it for marketing to third parties.
4. The AI assistant
Mindless Budget includes an AI assistant and automatic transaction categorization powered by Anthropic Claude models running on Amazon Bedrock (an AWS service). Relevant parts of your financial data — such as your transactions, account balances, budget contents, and recent conversation — are processed by the model in three ways: to answer questions you ask the assistant, to suggest categories in the background when new transactions sync, and to prepare a short monthly recap of your budget shown in the assistant panel. Per AWS policy, Amazon Bedrock does not store your prompts or use them to train models. Your conversation history stays in your account until you clear it or delete the account.
If you use the assistant’s optional voice input, your speech is transcribed by your browser’s built-in speech-recognition feature — depending on your browser, that audio may be processed by the browser’s vendor (for example Google for Chrome or Apple for Safari). The microphone is only used when you tap the mic button and grant permission; typing never involves it.
5. Aggregated, anonymous categorization patterns
To suggest categories for common merchants, we maintain anonymous, aggregated statistics of how users categorize a given merchant (for example, “most users file this coffee chain under Eating Out”). These aggregates contain no user identifiers and a merchant pattern is only used when at least five different users share it, so no individual’s choices can be singled out. Custom category names that don’t match a fixed standard list are never shared through this system.
6. Support chat and Telegram
Our support team receives your in-app support messages through Telegram: your name, the text of your message, and the app page you were on are forwarded to our private support channel, and replies come back into the app. To help resolve your issue, our support tooling can also surface your email address and signup date to the support team there. Please don’t post full account numbers or credentials in support chat. Support conversations are deleted from our database shortly after your issue is closed (typically within days); copies delivered to Telegram are subject to Telegram’s privacy policy. If the app shows you support replies as desktop notifications, that happens only with your browser’s permission.
7. Service providers
| Provider | What they do for us | What they receive |
|---|---|---|
| Plaid Inc. | Bank account connections and transaction data | Your bank credentials (directly — never through us); account and transaction data |
| Amazon Web Services | All hosting: database, servers, AI (Bedrock), email delivery (SES). US region (Ohio). | All service data is stored/processed on AWS infrastructure |
| Telegram | Delivers support-chat messages to our support team | Your name, support message content and page context; email and signup date for account lookups |
| Zoho Mail | Hosts our company email inboxes | Any email you send to our addresses |
We may also disclose information if required by law or legal process, to protect the rights and safety of our users or the service, or as part of a business transfer (in which case this policy continues to apply to your data).
8. Storage, security, and retention
- All traffic is encrypted in transit (HTTPS/TLS). Data is stored in the United States on AWS.
- Bank access tokens and 2FA secrets are encrypted at the application layer (AES-256-GCM); passwords, backup codes, and session tokens are stored only as one-way hashes.
- Every user’s data is isolated with database row-level security.
- Your data is kept for as long as your account exists. Email bounce records are deleted after 180 days; closed support threads are deleted after a short grace period; database backups are retained for a limited period for disaster recovery. If you have ever paid for a subscription, our payment processor keeps its own record of that transaction, as payment and tax records must be retained by law; those records live on their systems rather than ours, and we cannot delete them on your behalf.
- No system is perfectly secure. If a breach affects your personal data we will notify you as required by law at the email on your account.
9. Your rights and controls
Everything below is self-serve, inside the app, with no waiting on us:
- Export: download a JSON copy of your profile and budget data (Account Settings → Data & Privacy → Export My Data).
- Delete: permanently delete your account and every row of your data from our systems (Account Settings → Danger Zone). Your budget, transactions, and account are erased from our servers. Deletion is immediate and irreversible, and we instruct Plaid to remove your bank connections upstream.
- Correct: edit your name, nickname, email, and photo on the Profile page.
- Unlink banks: disconnect any linked bank at any time from the Accounts page.
- Clear AI history: wipe your assistant conversation history from the assistant panel.
The JSON export covers your profile and the budget data you created; if you also want a copy of anything it doesn’t include (such as synced bank-transaction history or your AI conversation history), email us and we will provide it. If you live in a state with a consumer privacy law (such as California), you may have formal rights to access, delete, correct, and port your data — use the in-app tools above or email us to exercise any of them. We do not sell or share personal information as those laws define it, and we never discriminate for exercising your rights.
10. Children
Mindless Budget is for adults. You must be at least 18 to use it, and we do not knowingly collect data from anyone under 18. If you believe a minor has an account, contact us and we will delete it.
11. Changes to this policy
If we make material changes, we will update the date at the top and notify you in the app or by email before the changes take effect. Continued use after that means you accept the updated policy.
12. Contact
Questions or privacy requests: privacy@mindlessbudget.com · Support: support@mindlessbudget.com