BudgetKit

BudgetKit Privacy Policy

Effective date: September 30, 2026

1. Who this policy covers

BudgetKit is a budgeting app from Kaiser Works. This policy explains what BudgetKit handles on your device, what can reach Kaiser Works or other services, and the choices available to you. Features depend on your build, sign-in status, and Free, Trial, Lifetime, or Premium access.

You can use core budgeting offline without an account. BudgetKit does not connect to your bank account, move money, or pay bills. Kaiser Works does not sell your budgeting data.

Request deletion of your BudgetKit account and associated data

2. Information on your device

BudgetKit stores the budget you enter in a local database: people and income sources, paydays, bills and recurring charges, payment plans, balances and adjustments, extra money, savings reservations, months, and Budget Ahead/NextUps planning information. It also stores app settings such as appearance and reminder preferences, a local Trial record, and, when applicable, sign-in, entitlement, and sync state. Calculated views such as Safe to Spend are derived from those records.

Your local-only budget does not need to be sent to Kaiser Works to use core features. If you choose to export a .budgetkit file, the app creates a local file for the system share sheet; you choose where it goes. An app or service you share it with may keep its own copy.

3. Optional account and cloud features

Where cloud sign-in is configured, Firebase Authentication handles email/password, Google, or Sign in with Apple, as available in your build. Firebase processes the sign-in information and credentials needed for your chosen method. BudgetKit stores a protected session on your device and sends a Firebase ID token to BudgetKit Cloud to authorize cloud requests. Kaiser Works does not store your password.

BudgetKit Cloud resolves your provider identity to a separate Kaiser Works account ID. It may store your verified email when provided, linked sign-in identities, device or installation links, Trial and entitlement facts, and security or session records. A Firebase UID, your budgeting person names, and the Kaiser Works account ID have different roles; a budgeting person is not an account holder.

With authenticated cloud sync or backup, budget records can be copied to BudgetKit Cloud, hosted with PostgreSQL on Railway. Those copies can include amounts, dates, names, notes, obligations, savings, and related change or backup records. The app also keeps local sync queues, cursors, and conflict copies so it can work offline. Trial and paid Premium can allow cloud features when an eligible account and server entitlement are available. Lifetime keeps local paid features but does not include household cloud sharing or backup.

4. Shared households

If you intentionally join or share a cloud household, its authorized members can receive and view shared budget records, including financial information, on their devices. BudgetKit Cloud stores household identity, membership, roles, and authorization data. The code also supports invitation records, including an intended email and protected invitation-code digests, but invitation routes and invitation email delivery are not currently enabled in the running service. An invitation alone does not grant access; sign-in and membership authorization are required.

Removing someone from a household prevents future authorized cloud access, but it cannot erase copies that person already downloaded and may still have offline.

5. Purchases and advertising

The Free tier permits advertising, but the current BudgetKit app has no active advertising provider or ad delivery. No BudgetKit AdMob integration currently collects an advertising ID. We will update this policy before activating an ad provider, including its data practices and choices.

Where a build offers the one-time Lifetime purchase, Apple App Store or Google Play processes payment under its own terms. BudgetKit does not receive your payment-card details. Purchasing or restoring requires sign-in so the purchase can be bound to your Kaiser Works account. The app sends store purchase proof, product ID, and store name to BudgetKit Cloud; the server checks the proof with Apple or Google before granting a signed entitlement. It retains the store, product, verification status, account link, and a one-way digest of the transaction reference or purchase token. The raw Google purchase token is not stored in the BudgetKit database. Store purchasing is enabled only in builds with the required store and server setup.

Premium subscription and receipt-processing capabilities are planned separately. BudgetKit does not currently capture, upload, or process shopping receipts.

6. Reminders, diagnostics, and analytics

If you enable reminders and allow notifications, BudgetKit schedules bill and planning reminders on your device. Lock-screen text is generic and omits bill names, amounts, and balances. BudgetKit does not send these reminders as cloud push notifications.

Production and store-sandbox builds do not currently deliver BudgetKit product-usage analytics. Approved development and test builds can send a limited set of feature-use events to Kaiser Works, with a random BudgetKit installation ID, event time, app version, and platform. Those events do not contain budget amounts, records, account IDs, household IDs, or advertising IDs. The in-app Data Log shows the practice for the build you are using.

Network services necessarily receive connection information such as an IP address when you use sign-in, cloud, or store verification. BudgetKit Cloud records limited service health and outcome logs; application logging is designed to exclude budget contents, credentials, purchase proof, and invitation secrets. No separate crash-reporting SDK is integrated into BudgetKit.

7. Why data is used and who handles it

BudgetKit uses information to provide local planning, authenticate optional accounts, authorize and sync shared households, restore backups, verify purchases and entitlements, schedule reminders, prevent misuse, operate the cloud service, and, in enabled test builds, understand limited feature use. Relevant outside services are Firebase Authentication and the chosen Apple or Google identity provider; Railway for BudgetKit Cloud hosting and PostgreSQL; Apple App Store or Google Play for enabled purchases; and any app you choose for a portable-file export. Each provider also has its own privacy practices.

8. Retention and deletion

Local budget data, preferences, and caches generally remain until you remove the app or clear its data, subject to your device backup settings and any files you exported. Signing out clears the local sign-in session; it does not delete your Kaiser Works account, cloud budget, store purchase history, or copies on other devices.

Account and associated-data deletion requests are handled manually. In versions with the request path, open Settings → Kaiser Works account → Request account deletion. It opens an email draft or the public request page and does not require sign-in. To request deletion without the app, use the BudgetKit deletion-request page or email contact@kaiserworks.app. Review and send the email yourself; opening a draft does not submit a request. A draft may include your sign-in email and Kaiser Works account ID, but no budget records, passwords, or session tokens. Request correspondence is handled through email providers; no fixed correspondence retention period is currently published.

Kaiser Works will verify account ownership and reply with the scope of deletion and any records retained for legal, security, or fraud-prevention reasons. Requests cover BudgetKit-held account, Firebase sign-in, and associated cloud data. Shared household records require review because they can also belong to other members. Copies already downloaded by members cannot be erased through this process. It does not delete your Apple or Google account or cancel store billing.

There is no automated account-deletion control or published fixed completion or automatic purge period for cloud budgets, backups, purchase evidence, or operational logs. Some changed or deleted cloud records remain in sync history or backups until separately removed.

In analytics-enabled test builds, pending events and the local analytics ID can be reset in the Data Log. Kaiser Works deletes received raw analytics events after 24 calendar months; resetting the local ID does not immediately erase events already received.

9. Children, security, and location

BudgetKit is not directed to children. If you believe a child has provided personal information through an account or cloud feature, contact us using the address below.

BudgetKit uses protected local sign-in storage, authenticated cloud requests, and household membership checks. No electronic storage or transmission method is completely secure. When you use network features, information may be processed in the United States or other countries where Kaiser Works and its service providers operate.

10. Changes and contact

We will update this page and its effective date when the policy changes, including when advertising, receipt processing, or other new data practices become active. Questions and privacy or deletion requests can be sent to contact@kaiserworks.app.