Privacy Policy
Last updated: July 8, 2026
Overview
Envelope Budget (“we”, “the app”) is a personal finance application that helps you assign income to spending categories, track bills, and plan credit card payments. This policy describes how information is handled when you use the app at envelopebudgetapp.com or installed copies (PWA, app store wrappers).
Information we collect
- Account data: email address and password (hashed) when you register.
- Budget data: envelopes, transactions, bills, paycheck settings, and credit card details you enter.
- Payment data: subscription status via Stripe (we do not store full card numbers).
- Bank data (optional, Pro): if you connect a bank through Plaid, transaction data imported per Plaid’s terms.
- Technical data: standard server logs (IP address, browser type, timestamps) for security and operations.
- Referral data (optional): if you use a partner’s referral link or code, we store a short-lived referral cookie and, after you sign up, which partner referred you (first referral wins). If you apply to become a partner, we store your display name, preferred referral code, and payout email.
How we use information
- Provide and sync your budget across devices when signed in.
- Process Pro / Pro+ subscriptions through Stripe.
- Import bank transactions when you enable Plaid connections.
- Maintain security, prevent abuse, and improve reliability.
- Operate the optional referral partner program — attribute sign-ups, calculate commissions on qualifying subscriptions, and process partner payouts. See Terms of Service for program rules.
We do not sell your personal information.
Security
We use industry-standard practices to protect your account and budget data:
- In transit: All connections use HTTPS (TLS). Production uses HTTP Strict Transport Security (HSTS).
- At rest: Budget data stored in our database is encrypted with AES-256-GCM before it is written to disk.
- Passwords: Stored using one-way hashing — we never save or see your plain-text password.
- Sessions: Sign-in uses secure, HttpOnly cookies. Failed login attempts trigger a temporary account lockout.
- Payments: Subscription card details are processed by Stripe; we do not store full card numbers.
- Access: Your budget is tied to your signed-in account. We do not share it with advertisers or data brokers.
Where data is stored
Account and budget data are stored in a Microsoft Azure SQL database in the United States. Local device storage may cache app data for offline shell loading; budget sync requires a network connection.
Third-party services
- Stripe — subscription billing (Stripe Privacy)
- Plaid — optional bank linking (Plaid Privacy)
- Microsoft Azure — hosting and database
Referral partner program
If you visit with a partner’s ?ref= link, we may set an HttpOnly cookie (about 30 days) to remember the referral before you create an account.
After sign-up, we link your account to that partner for commission purposes. Only the first qualifying referral is kept; later codes are ignored.
If you apply to become a partner, we collect the information you submit (display name, referral code preference, payout email) and use it to review your application, generate your link, and pay commissions you earn.
- What partners see: partners see masked email addresses for people they referred (for example,
ab***@example.com), subscription status summaries, and their own commission and payout history — not your full budget or bank data. - What we see: authorized operators can view partner applications, referral attribution, commission balances, and payout records to approve partners and record payments.
- Self-referrals: we block attributing your own account to your partner link.
- Retention: referral and commission records are kept while needed to run the program and meet legal obligations. Deleting your account removes your budget and sign-in data; partner records tied to your user ID are removed with your account where applicable.
We do not sell referral or partner data. Program terms are in our Terms of Service.
Your choices
- Export or restore budget data using in-app backup tools (Pro).
- Manage subscriptions in Stripe Customer Portal from Settings.
- Request account deletion in Settings → Account, or contact support.
- Decline partner status by not applying, or contact support if you want a pending partner application withdrawn.
Children
The app is not directed at children under 13. We do not knowingly collect data from children.
Changes
We may update this policy. The “Last updated” date at the top will change when we do.
Contact
Questions about privacy: support@envelopebudgetapp.com