Privacy

Last changed 6 October 2026

Published by Pragmtk Limited

Questions about this document: support@budj.nz

This policy describes what personal information budj collects, why it is collected, and what happens to it afterwards.

It is organised by the thing being collected rather than by legal heading, so that everything about one piece of information sits in one place. Each section answers the same six questions.

Where a section describes something budj does not do yet, it says so. Today budj collects two things: an email address for the waitlist, and - only if you agree to it - how you use this site.

Your email address

What is collected

The email address you type into the waitlist form, and nothing else. You are not asked for a name, and none is stored.

Your IP address is used to limit how often the form can be submitted from one place. It is used at the moment of submission and is not stored alongside your address.

Why

To email you when budj launches. That is the only reason it is collected and the only thing it will be used for.

You will not receive anything else, and the address is not used to build a profile, to advertise, or to match you against any other list.

Who it is disclosed to

Kit, the mailing list provider that stores the list and sends the email. Kit also handles the unsubscribe link on everything sent.

Nobody else. The address is not sold, shared, or given to any other service.

Where it is held

With Kit, in the United States. That is outside New Zealand, and Kit is subject to the laws of the country it operates in.

How long it is kept

Until you unsubscribe, or until you ask for it to be removed. There is no fixed period, because nothing deletes the list on a schedule - the address stays on the list until one of those two things happens.

If budj never launches, the list is deleted rather than kept.

How to have it removed

Use the unsubscribe link at the bottom of any email. That removes you from the list immediately and takes no further action from anyone.

You can also write to the contact address above and ask, and it will be done for you.

How you use this site

What is collected

Only if you choose Accept in the cookie banner: the pages you visit, how you arrived at the site, how long you stay, your browser and device type, and your approximate location, worked out from your IP address. Google Analytics does not store the IP address itself.

If you choose Reject, or make no choice, no analytics cookie is set. The site still loads Google Analytics in a mode that sends Google a limited signal without cookies and without identifying you - for example, that a page was viewed.

Why

To understand how people use the site, so it can be improved. That is the only use.

It is not used for advertising. The signals Google uses for advertising are switched off whatever you choose.

Who it is disclosed to

Google, which provides Google Analytics and processes this information on budj’s behalf.

Nobody else.

Where it is held

With Google, which may store and process it outside New Zealand, including in the United States.

How long it is kept

Google Analytics sets cookies named _ga and _ga_ followed by an identifier, which last up to two years unless you remove them.

Your choice itself is remembered in your own browser, so you are not asked again on every visit. It is passed to Google Analytics only so that it can follow it.

How to have it removed

Use the Cookies link at the foot of any page to change your choice. Choosing Reject removes the Google Analytics cookies from your browser.

You can also block or delete cookies in your browser settings, or install Google’s opt-out browser add-on.

Your budj account

This describes handling that applies when the feature becomes available. It is not happening now.

What is collected

You sign in with Apple, so budj receives the email address associated with your Apple ID and an identifier from Apple. budj never receives or holds an Apple password.

A display name and an avatar, if you set them. Your email address is not copied into your profile - it is read from the signed token each time it is needed.

Your rules: the names, descriptions and conditions you write. This is free text you author, so whatever you type is stored, including a merchant name if you choose to write one.

A device identifier and a notification token for each device you use, so budj can send the alerts you asked for.

A subscription record from the App Store - a transaction identifier, which plan, and whether it is current. No card details reach budj at any point; Apple handles payment entirely.

Why

To know who you are when you sign in, to keep your rules attached to you rather than to anyone else, and to send notifications to your devices.

The subscription record exists to know whether your subscription is current. The Apple identifier is kept so that your access to budj can be revoked with Apple when you delete your account.

Who it is disclosed to

Apple, which handles sign-in and payment and which budj checks your subscription against.

Supabase and Render, which run the database and the server budj is built on. They store and process it on budj’s instructions and do not use it for anything of their own.

Nobody else.

Where it is held

In the Supabase database in Sydney, Australia, and processed by the budj server in Singapore. Both are outside New Zealand.

How long it is kept

For as long as your account exists. There is no fixed period and none is claimed, because nothing deletes this on a schedule.

How to have it removed

Delete your account in the app. It removes your profile, your rules, your devices, your subscription record and your bank connections together.

Deleting your budj account does not cancel your App Store subscription - budj cannot cancel it for you, and Apple keeps charging until you cancel it in your Apple account settings.

Deleting your budj account also does not unsubscribe you from the waitlist email list. They are separate, and the list has its own removal above.

Your bank accounts

This describes handling that applies when the feature becomes available. It is not happening now.

What is collected

When you connect a bank account, budj asks your bank - through Akahu, and only after you have signed in with your bank directly - for the accounts you choose to share, the name they are held in, your name and email as your bank has them, the balances of those accounts, and the transactions on them. It also asks for permission to move money between your own accounts, which is described further down.

What is stored is much less than what is read. For each account budj keeps an identifier, the account name, its type and currency, and whether it can send or receive payments. For each connection it keeps the institution’s name and logo. That is all.

No transaction is stored. A transaction is evaluated against your rules as it arrives and is not written down; the server never learns what you spent. No account number is stored.

No balance is stored either, though budj does ask your bank for one. A rule can watch for an account falling below an amount you set - “if my everyday account drops under $200, move $50 back from savings” - and answering that question means reading the balance at the moment the rule is checked. It is used for that and discarded. budj keeps no record of what you had, and cannot tell you or anyone else what your balance was last week.

Both credits and debits are requested, because your bank requires them to be asked for as a pair, even though only money arriving matters to budj. Neither is kept.

budj also asks for the name your account is held in. It is not used today; it is requested now because it is needed to check that an account you are paying belongs to who you think it does, and asking later would mean sending you back through your bank a second time.

Connecting an account does give budj permission to move money, and it is fair to be cautious about that. Three things limit it. budj can only move money between accounts you have connected yourself, so it cannot pay anyone else. Every payment has to be one you approved - budj proposes, you decide, and nothing moves on its own. And the limits on how much can move, in one payment and over a period, are set by you when you authorise the connection and are enforced by your bank, not by budj.

Why

To notice when money arrives in your account, so that a rule you wrote can act on it. That is what budj is for: a rule fires when your salary lands, which is something a scheduled bank payment cannot express, because neither the amount nor the timing is known in advance.

The account list exists so you can choose which accounts a rule applies to. The payment-capability flags exist so budj does not offer you a rule your bank cannot carry out.

Who it is disclosed to

Akahu, the New Zealand open banking provider that connects budj to your bank. Akahu holds the authorisation and passes on what your bank sends. budj never sees your bank login.

Supabase and Render, on the same basis as above.

Nobody else.

Where it is held

In the Supabase database in Sydney, Australia, and processed by the budj server in Singapore. Both are outside New Zealand.

Akahu is a New Zealand company and holds its part of the connection here.

How long it is kept

For as long as the connection exists. Revoking the connection ends the access, and deleting your budj account removes what was stored.

There is no fixed period, and none is claimed, because nothing deletes this on a schedule. It is kept while your account exists and removed when it does not.

One exception is worth naming. If a payment is still in flight when you delete your account, a record of that payment survives deletion - an amount and a payment identifier, with no name, no account and no link back to you - until the payment finishes. It is then removed. Without it, a payment already moving could not be reconciled.

How to have it removed

Revoke the connection, either in budj or through your bank. Both work, and either one ends budj’s access.

Delete your budj account to remove everything that was stored, including the credential that authorises the connection.

What budj does not collect

No cookie is set unless you accept analytics. Besides your cookie choice, the site remembers one thing in your browser - whether you chose the light or dark appearance - and that is a setting you chose, stored on your own device, never sent anywhere. Clearing your browser data removes it.

budj holds no transaction history, no balances and no account numbers. Those absences are deliberate and are defended when new features are designed, rather than being an accident of what has been built so far. Two of the three are things budj does read and then discards; not writing them down is a decision taken again every time a feature is designed.

Your rights

Under the Privacy Act 2020 you can ask what personal information budj holds about you, and ask for it to be corrected if it is wrong. Write to the contact address above and you will get an answer.

You can also complain to the Office of the Privacy Commissioner if you are not satisfied with how a request was handled.

Changes to this policy

The date at the top of this page is the date it last changed.

If what budj does with your information changes in a way that matters, you will be told rather than left to notice. A policy quietly edited to match something that already happened is not a policy.