Privacy policy
Effective and last updated:
Budget Lightly is run by me, Matthew Scholefield, under the business name Matthew Scholefield's Software. In this policy, “we,” “us,” and “our” refer to me as the operator responsible for deciding why and how personal information is processed for Budget Lightly.
Our “Services” are the Budget Lightly public website, web and mobile application, and related support and privacy communications. “Personal information” means information that identifies, relates to, or can reasonably be linked to a person, including information treated as personal data by applicable law. This policy does not govern independently operated websites we link to; their own notices apply when you visit them.
You can immediately delete an authenticated account through the account-deletion page. You can ask questions or make other privacy requests using the email and postal channels below. Reading this policy or using Budget Lightly is not blanket consent to unrelated processing.
The short version
- Your account and budget: we handle your username, display name, authentication information, workspace membership, and the financial records you or other workspace members enter. Registration does not ask for an email address.
- Private information: budgeting data can be sensitive. Notes and other free text can reveal more than the structured fields request. Avoid unnecessary personal details and never put banking passwords in your budget.
- Why and with whom: we use information to provide and secure the service, synchronize changes, respond to you, and meet legal duties. Shared workspace members see shared records; infrastructure and communication providers process information needed for their services. Legal grounds depend on the purpose and applicable law.
- Other sources: workspace members can enter information about you. A currency-rate service supplies exchange-rate data. When you choose receipt processing, OpenAI extracts receipt details and can suggest budget categories.
- Storage and deletion: the app keeps offline copies. Deleting an expense hides it from ordinary views but does not erase its stored row or all synchronization history. The authenticated account-deletion page immediately deletes the account and private budgets; shared budgets remain for their other members with account attribution removed.
- No advertising features: the current Services do not sell personal information, use it for targeted advertising, or include third-party advertising or analytics tools.
- Your choices: rights depend on the law that applies. You can use the account-deletion page or contact us about access, correction, deletion, or other privacy concerns. Security measures reduce risk but cannot guarantee that information will never be accessed or disclosed without authorization.
1. Information we handle
Account and authentication information
Creating an account requires a username, display name, and password. We store your username, display name, internal account identifier, account status, preferred display currency, and creation time. The server stores a password hash, not a readable copy of your password. Authentication also involves session credentials; server session records store a hash of the session token and associated account and timing information.
You do not have to create an account to read the public website. Without the required account information, we cannot provide an authenticated account. You can update your display name and display currency in the app and change your password. For other account corrections, contact us.
Budget and workspace records
We handle workspace names and timezones, memberships and invitations, incomes, category and subcategory names, allocations, estimates, recurring plans, expense dates, amounts and currencies, exchange rates and their provenance, notes, and identifiers and timestamps recording who created or changed a record. The app calculates budget totals and available spending from these records. It does not connect to your bank or require bank-login credentials or payment-card numbers.
You decide which financial records to enter. Required fields are needed for the particular action, such as recording an expense; notes are optional. Other authorized workspace members can add or change shared information, including information about you. Check entries for accuracy and use the available editing controls or contact us to correct a problem.
Support and technical information
If you email or write to us, including to ask about Budget Lightly, we receive your contact details, the content you send, and any attachments. This is separate from account registration. Do not send passwords, session tokens, or a complete financial history in an ordinary support email.
Connections to the Services expose network and request information to the serving infrastructure, such as IP address, requested URL, time, response status, and browser or client information. Access and error logs can record this information for operation and troubleshooting. The application also keeps synchronization identifiers, change records, pending commands, and error details needed to coordinate updates across devices. These operational records are not an advertising or cross-site browsing profile.
Sensitive information and device access
Financial records are private even when they are not a legally defined “sensitive” category. Account-access information can receive additional legal protection. We do not ask for racial or ethnic origin, religious beliefs, sexual orientation, health information, or similar special-category information as profile fields. However, a category name, note, support message, or receipt could reveal such details. Include only information needed for your budget and that you are entitled to provide about others. Additional lawful conditions, including specific consent where required, are necessary for processing legally protected sensitive information; this policy alone does not provide that consent.
The current Android app requests internet access. It does not request location, contacts, camera, microphone, or notification access, and Budget Lightly does not currently send push notifications. You can inspect the permissions available for an installed app in your device settings. Copying an invitation or a pending-change recovery file places that information on your clipboard at your request.
Exchange-rate providers return currency metadata and rates. Those responses do not supply a personal profile about you. OpenAI returns extracted receipt data and possible category suggestions when you request receipt processing, as described in section 6. These outputs can be personal information and can contain errors.
2. How we use information
- Provide the service: create and authenticate accounts, manage sessions and preferences, maintain workspaces, calculate budgets and currency conversions, record expenses, and synchronize your changes.
- Process receipts at your request: extract expense details and suggest categories through OpenAI using the receipt and relevant category names, as explained in section 6.
- Communicate with you: answer inquiries, support requests, and privacy requests and provide necessary service or security information.
- Maintain and protect Budget Lightly: diagnose errors, resolve conflicting updates, prevent duplicate commands and unauthorized access, investigate misuse, and make service improvements based on reported problems. The current app has no separate analytics or crash-reporting SDK.
- Meet legal responsibilities: respond to valid legal requirements and, where necessary and lawful, establish, exercise, or defend legal claims.
We do not use your budget to determine creditworthiness, insurance, employment, or eligibility for essential services. The Services do not currently make solely automated decisions with legal or similarly significant effects. We do not run a survey, contest, or event-registration program through the app.
Before using information for a materially different purpose, we will provide the information required by applicable law and obtain specific consent when that law requires it. An update to this notice is not itself consent.
3. Legal grounds
Which legal rules apply depends on the operator's activities, your location, and the processing involved—not just whether the website is accessible in a country. Different laws use different legal grounds.
Where the EU or UK GDPR applies: necessary account, budgeting, workspace, and synchronization processing supports performance of the service you request, or steps you ask us to take before providing it. Necessary service-security, misuse-prevention, troubleshooting, and legal-defense processing can be based on our legitimate interests in a reliable, secure service and protecting legal rights, only where those interests are not overridden by your rights. Compliance with a binding legal duty is based on that duty. Optional processing for which consent is required depends on a separate, informed choice. We do not rely on a routine “vital interests” or public-authority purpose for this budgeting app.
Where Canadian privacy law applies: consent must be meaningful and appropriate to the information and purpose. It may be express or implied where the law permits; sensitive, unexpected, or materially risky processing calls for express consent. You can withdraw consent subject to applicable legal or contractual limits and reasonable notice. We will explain relevant consequences. Narrow statutory exceptions, such as a valid court order or a qualifying safeguarded business transfer, are not permission for unrelated use of your budget.
Where Taiwan's Personal Data Protection Act applies: collection and processing must have a permitted ground, such as a contractual relationship with the required safeguards or valid consent, and use must stay within the necessary scope of the stated purpose unless a legal exception applies. The data categories, purposes, recipients, retention criteria, choices, and consequences of not providing information are explained in this notice.
Where Swiss data-protection law applies: processing is subject to its requirements of legality, good faith, proportionality, transparency, purpose limitation, and security. Swiss law is not simply the EU legal-basis list. Applicable consent and other justification requirements must be met in the circumstances.
4. Sharing and service providers
Workspace members. Authorized members can see shared budget and expense records and member identities, including usernames and display names. An invitation link allows a person with a valid token to preview the workspace name and join. Treat that link as private and use invitation-revocation controls if needed. We cannot retrieve copies another member has already made.
Infrastructure and communications. Our application servers and database are hosted by InterServer in the United States. InterServer processes information as needed to provide hosting and related infrastructure services. Email providers process messages you send to us and our replies. A provider processing information on our behalf must be subject to the restrictions and contractual protections required by applicable law. This does not mean every provider acts only as our processor for all of its own operational information.
Currency rates. The backend requests currency metadata and currency-pair/date rates from a configured rate provider; the application's default provider is Frankfurter. These requests do not include your username, expense notes, or expense amounts. The provider can still receive the server's network/request information. This notice does not promise a particular retention period for that provider.
Legal and safety needs. We may disclose information where required by a valid legal process or law, or where necessary and legally permitted to address misuse, protect rights, or respond to a serious threat to safety. We assess the legal basis and scope of the particular request; this is not routine monitoring for emergencies or financial abuse.
Business changes. If a merger, acquisition, financing, or sale of all or part of the business is proposed or completed, necessary information may be disclosed to advisers or transaction participants, subject to applicable confidentiality, purpose, safeguarding, return/deletion, and notice requirements. This is a possible business event, not an existing sale of personal information.
OpenAI. When you choose receipt processing, OpenAI receives the submitted receipt content and relevant category names to extract expense details and suggest categories. This is service-provider processing, not a sale of your information. We do not disclose information to third parties for their own direct marketing or for cross-context behavioral advertising.
5. Cookies and local storage
The web app and the account-deletion page use an app-host authentication cookie so that the backend can recognize your session. The deletion page sends authenticated requests from the public-site origin to the app host; the cookie remains scoped to the app host. Production authentication cookies are configured as Secure, HttpOnly, and SameSite=Lax. The web app also uses browser local storage for account/sign-out markers and a persistent browser database for cached financial records, pending changes, and synchronization state.
Native clients use a local per-account SQLite database for offline data and a separate secure-storage mechanism for bearer credentials. Secure credential storage does not mean the whole financial database is encrypted. Storage makes it possible to show your budget offline and send pending changes when connectivity returns.
The public website does not use tracking pixels, web beacons, advertising cookies, analytics tracking, or browser credential storage. Signing in on the deletion page uses the app host's session cookie only for the deletion flow. Infrastructure can still produce the request logs described in section 1. There is no separate Cookie Notice.
Your browser can refuse or delete cookies and clear site storage. Refusing the session cookie can prevent web sign-in; clearing browser or app data can remove offline records and unsent changes. Clearing local storage does not delete server records. Review pending changes before clearing a device, and see retention and deletion limits.
6. Optional receipt processing with OpenAI
When you submit a receipt for processing, we send its image or text to OpenAI through a business/API account. Image analysis and natural-language processing extract structured expense details and can suggest budget categories.
A receipt can include names, addresses, transaction details, payment fragments, and purchases revealing sensitive information. Text transcribed from a receipt can still be personal information. OpenAI receives the submitted receipt content, processing instructions, and relevant category and subcategory names for suggestions. Category names can themselves contain personal information. We do not include your expense history, budget balances, or workspace-member identities as additional categorization context; a receipt or category name can still contain those details if you put them there.
Receipt processing is optional and begins only when you choose to submit a receipt. You can enter expenses manually instead without sending a receipt to OpenAI. We process the submission to provide the extraction you request, subject to the applicable legal grounds in section 3. Where applicable law requires separate consent, including for sensitive information, that consent is required before submission. Reading this policy or using other budget features is not consent to sending receipts.
Training and the different kinds of retention
For receipt processing, we use an API/business account with training disabled, not a consumer ChatGPT workflow. OpenAI's API data-controls documentation says API inputs and outputs are not used to train or improve models unless the customer explicitly opts in. We do not opt in to that training use.
OpenAI's standard abuse-monitoring arrangement retains logs, potentially containing inputs, outputs, and related metadata, for up to 30 days, with longer retention where required by law or reasonably necessary to prevent harm. That is not a promise that every copy is stored only for abuse monitoring or erased exactly 30 days after submission.
Application state is separate. Stored responses, uploaded files, other endpoint objects, and caches can have different lifetimes; some persist until deleted. Image and file inputs can also be retained for safety review in limited circumstances, including suspected child sexual abuse material, even under some enhanced retention controls. The endpoint, model, file handling, and storage settings determine which rules apply. The 30-day abuse-log period does not override those separate rules.
We discard original receipt images from Budget Lightly after processing rather than keeping them for later viewing. We retain the resulting expense records you save, including extracted details and any category selection, under the same retention rules as other expense records and synchronization history. Our disposal of a receipt image does not erase a copy already processed or retained by OpenAI, or a copy on your device.
Provider arrangements and your control
OpenAI's processing is governed by the relevant business/API terms and data-processing terms. OpenAI also uses subprocessors. A business account alone does not establish a particular storage country, zero retention, or a guarantee of security; provider-side processing and storage are distinct from our U.S. application hosting.
You can avoid further provider processing by not submitting more receipts. Stopping submissions or withdrawing consent does not itself erase data already sent; deletion requests need to address both our records and provider-held information, subject to applicable law and retention exceptions. You should submit only receipts you are entitled to share, remove unnecessary details where possible, and check extracted amounts and suggestions for errors. Category suggestions are assistive, not decisions about credit, benefits, or other legal or similarly significant matters. These responsibilities do not waive your privacy rights or our obligations.
7. International processing
Our application servers and database are hosted in the United States by InterServer. Information can also be accessed from Taiwan to operate and support Budget Lightly.
Using the Services can involve processing outside your country, where protections may differ. OpenAI, its subprocessors, and email providers can process information in other countries under their applicable arrangements; U.S. application hosting does not mean every provider-held copy stays in the United States. This notice does not claim a particular adequacy decision, certification, or signed international-transfer agreement for Budget Lightly.
Where EEA, UK, Swiss, or other applicable law restricts a transfer, the relevant legal requirements and a valid transfer mechanism or exception must be satisfied; your use of the app is not a substitute for them. You can contact us for information about recipients, processing locations, and any safeguards applicable to your information, including how to obtain a copy where the law provides that right.
8. Retention and deletion limits
Retention depends on the record's purpose, the service you continue to use, shared-workspace needs, and specific legal or security requirements. There is not one deletion period for every copy.
- Account deletion: after successful password confirmation on the account-deletion page, the account/profile, password credentials, sessions, memberships, associated invitations, and user FX quotes are deleted immediately. There is no additional waiting or recovery period.
- Private budgets: budgets without another member are permanently deleted in the same operation, including their expenses, plans, and synchronization history.
- Shared budgets: shared financial records remain for the other members until they delete the budget. The departing account's expense attribution and personal-category association are removed. Shared text can still contain information entered by members. Historical shared changes are cleared; scrubbed collaborator command receipts remain while the budget exists to prevent duplicate replay.
- Deleted expenses and synchronization history: outside complete budget deletion, expense deletion marks a stored row as deleted. Change payloads and command receipts can retain earlier financial and free-text content to support synchronization and prevent duplicate operations. The current system has no automatic pruning schedule for these records. Deleting an expense is not complete erasure.
- Sessions, invitations, and rate records: sessions normally have a 30-day validity period and invitations a seven-day validity period. Account deletion removes the account's sessions, associated invitations, and user FX quotes immediately. Other revocation or expiry prevents further use as applicable but does not prove that every log has been erased.
- Support and privacy correspondence: we retain correspondence indefinitely, with no scheduled deletion, to keep a record of requests, responses, and their resolution. You can request deletion; applicable legal duties and limits still govern what we may retain.
- Operational logs: we have no confirmed fixed retention or automatic-deletion schedule, so access and error logs may remain indefinitely. They support troubleshooting, service security, and investigation of incidents. This does not override applicable requirements to limit retention or honor a deletion request.
- Receipt images and provider data: we discard original receipt images after processing and retain the expense records you save. Account deletion does not itself erase information previously submitted to OpenAI. OpenAI's separate retention rules, including standard abuse-monitoring logs retained for up to 30 days with stated exceptions and separate storage lifetimes, are explained in section 6.
- Backups: no database backups are currently enabled. Offline app data, correspondence, and information retained by service providers are separate copies, not a database-backup service.
- Device copies and exports: offline databases, pending changes, clipboard exports, downloaded archives, and copies made by you or workspace members are not remotely erased. They remain until their holders remove them. Eligible explicit logout clears local database rows when there are no pending changes or you choose to discard them; session expiry alone does not do so.
Automated account deletion addresses active account records, private budgets, and the departing identity in shared budgets. It cannot remotely erase independent copies held by other people or on devices outside our control, operational logs, previous correspondence, or provider-held information. If a particular legal obligation or claim requires retention, we will explain the limitation where permitted. Fraud prevention, troubleshooting, investigations, or enforcing terms are not blanket reasons to retain an entire account indefinitely.
For a broader privacy request concerning records outside the automated flow, use the contact channels below. Provider-held information has its own applicable terms; the OpenAI limits are explained in section 6.
9. Security
The application uses password hashing, hashed server-side session tokens, workspace access checks, session revocation, and request-origin protections. Its production web-session configuration uses secure, HttpOnly cookies; native credentials use the platform's secure-storage facility. These measures do not mean that every stored financial copy is encrypted or that the service has a security certification.
Matthew Scholefield is the only person with administrative access on our side. Service providers process information within their roles, and authorized workspace members retain access to their shared records; sole administration does not mean those necessary disclosures do not occur.
No internet transmission or storage system is completely secure. Unauthorized access, theft, loss, alteration, and disclosure remain possible. Use a unique password, protect devices that contain offline budgets, use the HTTPS service, and keep invitation links and recovery exports private. Tell us promptly if you suspect unauthorized access. This guidance does not transfer our legal responsibilities to you or limit your statutory rights.
10. Children and younger users
Budget Lightly is a general-audience budgeting app aimed at adults, not an adults-only service or a service directed to children. We do not market to children or sell children's data. The app does not ask for a birth date, verify age, or operate a parental-authorization process.
Legal protections and consent requirements for minors vary by location; the U.S. rules for children under 13 are not a universal age rule. General-audience availability does not remove any requirement to obtain parental consent before collecting a child's information. If you believe a child has provided information in circumstances that require protection or parental consent, email matthew331199@gmail.com. We will investigate and take the action required by applicable law, which can include restricting an account, stopping collection, and arranging deletion. A parent or guardian can use the same channel to raise a concern.
11. Privacy rights and consent choices
Depending on the applicable law and circumstances, you may have rights to:
- Find out whether we process your information, receive information about that processing, and access or obtain a copy of your information.
- Correct or supplement inaccurate or incomplete information.
- Request deletion, restriction, or cessation of collection, processing, or use.
- Receive eligible information in a portable format or object to specified processing.
- Withdraw consent where processing relies on consent.
- Receive information and safeguards concerning qualifying automated decisions, including relevant factors and human review where the law provides for them.
These rights are not identical everywhere or absolute. EU/UK and Swiss rights have statutory conditions and exceptions. Canadian federal law provides access, correction, and complaint rights, but not every right in this list; provincial law can add protections. Taiwan's law provides inquiry/review, copies, supplementation/correction, cessation, and erasure rights where it applies. U.S. state rights also depend on the law's scope.
Contact us to withdraw consent or exercise a right. Withdrawal concerns future consent-based processing and does not make prior lawful processing unlawful. It does not stop processing supported by another valid ground. If withdrawal or a necessary deletion prevents us from providing a requested feature, we will explain that consequence; it does not justify withholding unrelated services.
Budget Lightly does not make the significant solely automated decisions described above. Budget arithmetic and assistive receipt-category suggestions are not credit or eligibility decisions. You do not need to identify a particular statute to ask us for help, although assistance beyond legal requirements is not a promise that every statutory right applies worldwide.
12. Complaints and regulators
Please tell us about a privacy concern by email or post. Include your username if relevant, what happened, and the outcome you seek. We will assess the concern and explain our response under the law that applies.
If UK data-protection law applies, we will acknowledge a qualifying data-protection complaint within the applicable statutory 30-day period, investigate and respond without undue delay, keep you informed of progress, and explain the outcome. This is not a universal 30-day deadline for every privacy request.
You can also use the complaint or other remedies available under applicable law. Contacting us does not remove your right to approach a competent regulator:
- EEA: the relevant supervisory authority, including where you live or work or where an alleged infringement occurred. The EDPB authority directory provides current contacts.
- UK: the Information Commissioner's Office complaint service; helpline 0303 123 1113.
- Switzerland: the Federal Data Protection and Information Commissioner.
- Canada: the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner, depending on the activity and law.
- Taiwan and elsewhere: the authority competent for your situation, where the applicable law provides that route.
13. Browser privacy signals
The current Services do not implement a separate technical response to browser Do Not Track (DNT) signals. They do not track your activity across unrelated websites for advertising.
Global Privacy Control (GPC) is different from DNT and can be a legally recognized opt-out preference signal. The current Services do not have a dedicated GPC handler; they also do not sell information, share it for cross-context behavioral advertising, or use it for targeted advertising. That absence of processing applies whether or not a signal is enabled. If practices change, required signal handling and other choices must be in place before the affected processing begins, and this notice will be updated. Nothing here limits a legally required opt-out.
14. U.S. state disclosures and rights
State privacy laws differ in their scope, exemptions, thresholds, and effective dates. A small user base is not a universal exemption, and living in a state does not by itself establish that every provision of its law applies to this operator.
Categories handled by the Services
The following uses common state-law category names to explain the processing described in this policy, including optional receipt processing. It does not mean that we request every example included in a statutory definition. Information you volunteer in notes, receipts, workspace records, correspondence, or attachments can fall into additional categories even when no dedicated field asks for it.
- A. Identifiers
- Usernames, display names, internal account and session identifiers, and network/request identifiers; also contact details you send in correspondence. Phone numbers and postal addresses are not registration fields.
- B. Customer-record information
- Name/contact information and budgeting and financial records. We do not ask for all the education, employment, or other information that can appear in the California statutory definition.
- C. Protected characteristics
- Not requested as structured fields. Age, gender, race, national origin, marital status, or similar details could be volunteered in text; we do not use them to build demographic profiles.
- D. Commercial information
- Expense and transaction records, amounts, dates, currencies, categories, recurring plans, and related financial entries. Recording an expense is not payment processing or a connection to a financial account.
- E. Biometric information
- No fingerprint, voiceprint, facial-recognition, or other biometric-identification feature.
- F. Internet or network activity
- Operational request/error information and application change/synchronization records, not cross-site browsing or search histories collected for advertising.
- G. Geolocation
- No device-location permission or location-tracking feature. A workspace timezone is a setting you choose, not a GPS reading. Network addresses can incidentally suggest an approximate location.
- H. Audio, visual, or other sensory information
- Receipt images you submit for processing and images you choose to send in support correspondence. There is no audio/video or call-recording feature.
- I. Professional or employment information
- No dedicated employment or applicant fields. Work-related details can occur in financial entries or correspondence you provide.
- J. Education information
- No student-record or education feature. Any such detail voluntarily included in a message or note is handled as part of that content.
- K. Inferences
- Receipt-category suggestions derived from receipt content and category names, not personal-characteristic or advertising profiles or significant eligibility decisions. Budget totals are calculated from your entries.
- L. Sensitive personal information
- Account-access credentials and any protected sensitive details included in submitted content can fall within legal definitions. Passwords are hashed on the server. Financial amounts alone are not the same as an account number combined with an access credential. We do not request banking credentials or use sensitive information to infer personal characteristics.
Section 1 explains the sources, section 2 the purposes, section 4 the recipients, and section 8 the retention criteria and deletion limits. Providers receive information necessary for their role; workspace disclosure concerns shared records and member identities, not other members' passwords. Service delivery or necessary troubleshooting is not permission to sell records or use them in public demonstrations.
These categories describe how the Services handle information when used, not a claim that every category has been collected throughout the preceding 12 months. As of this policy's last-updated date, the app has not been publicly released and has no production-user history. Where applicable law entitles you to an account of collection, business-purpose disclosures, sales, or statutory sharing, you can request it using the channels below. Ordinary provider processing and workspace sharing are distinct from “sharing” for cross-context behavioral advertising. We do not sell personal information or engage in that advertising-related sharing.
Rights, requests, and appeals
Where a state law applies, you may have rights to confirm processing, know and access information, correct inaccuracies, request deletion, receive a portable copy, and opt out of sale, targeted advertising, or profiling that produces legal or similarly significant effects. Not every state grants every listed right. We will not unlawfully discriminate against you for exercising a privacy right.
Additional rights can include information about processed categories in Minnesota; recipient categories in California, Delaware, and Maryland; specific recipients in Minnesota and Oregon; and parties to whom information was sold in Connecticut. Connecticut and Minnesota provide additional rights to understand, question, and correct qualifying profiling. California provides a right to limit certain sensitive-information uses and disclosures; Florida provides certain rights to opt out of sensitive-data and voice/facial-recognition collection. Each is subject to the relevant law's scope and conditions. Listing these rights does not imply we sell data, collect biometrics, or perform significant profiling.
We use account-access information for authentication and security, and financial content for the service you request—not to infer protected characteristics. Any required sensitive-data consent or limitation must be handled under the applicable law; ordinary service use is not a substitute for required consent.
To appeal a denied request where an appeal right applies, email us with “Privacy appeal,” identify your original request, and explain why you disagree. We will review it and give a written decision and reasons within the applicable legal period. If the appeal is denied, we will provide any legally required information about contacting your state attorney general or other competent authority. See section 16 for verification and authorized-agent requests.
California “Shine the Light.” We do not currently disclose personal information to third parties for their own direct marketing. Where California Civil Code §1798.83 applies, California residents can make a free written request once a year about qualifying disclosures in the preceding calendar year, including information categories and recipient names and addresses. Use the email or postal channel below.
15. Policy updates
The current policy is available at this page, linked from the public website footer. We will update its date when it changes. For material changes, we will provide a prominent website or app notice, or direct notice where appropriate and feasible, as required by applicable law. Because accounts use usernames rather than email addresses, do not assume every revision will arrive by email.
Before introducing a materially different use, we will check that the notice matches the actual processing and provide any required information and choices. Describing an optional feature does not give us blanket permission to process information for it without your choice or any legally required consent.
16. Contact and privacy requests
For questions, complaints, access or review, correction, deletion, consent withdrawal, or applicable appeals, contact:
Matthew Scholefield's SoftwareAttn: Matthew Scholefield
18327 Perth Ave
Homewood IL 60430
USA
matthew331199@gmail.com
Use the authenticated account-deletion page to delete your account without downloading the app or waiting for manual approval. Email and post remain available for questions and other privacy requests.
- Identify your Budget Lightly username, describe your request, and give a way to respond. Indicate your country or state if relevant to a particular right. Do not send your password, session token, or complete financial records.
- We may need to verify that the request relates to you, using existing information and only proportionate additional information where necessary. An email address alone does not prove ownership of a username-based account. Verification information is used to handle and secure the request, not for unrelated purposes.
- An authorized agent should identify you and provide evidence of authority. We may ask for written or signed permission and confirmation of identity where the law permits. We can decline an unverified or unauthorized request and will explain the reason where required.
- We will assess the request and respond within the applicable legal time limits, explaining any lawful extension, denial, fee, or retention limitation. We will not disclose another person's information or authentication secrets in an access response. Where a right does not apply, you can still ask for help; we will explain what is available.
You can edit supported profile, budget, and expense fields in the app. The account-deletion page closes the account, deletes private budgets, and removes the departing identity from shared budgets immediately after password confirmation. Deleting an expense, logging out, or uninstalling the app is not account deletion. For access, correction, or deletion requests involving logs, correspondence, provider-held information, or other copies outside that automated operation, contact us and identify the information concerned. The limits in section 8 still apply.