Privacy Policy
Last Updated: July 24, 2026
SAFE Budget is designed so the developer cannot read your financial ledger.
The app has no SAFE Budget account service, advertising system, analytics service, or
developer-operated ledger server. Readable financial data is processed on your devices. When CloudKit is
available, ledger values sync through encrypted CloudKit fields and attachments use CloudKit assets.
Optional Apple, bank-provider, public-government-data, merchant-search, sharing, export, and support paths are described below.
1. The Short Version
- The developer does not receive your readable balances, transactions, budgets, receipts, bank login, or provider credentials through the app.
- CloudKit encrypts designated ledger fields on the device before upload and encrypts CloudKit assets by default. Limited identifiers, routing fields, timestamps, and sync/share metadata remain available to Apple systems so they can store, route, and reconcile records.
- SAFE Budget includes no advertising, cross-app tracking, or developer-operated product analytics.
- Optional features communicate with Apple, SimpleFIN, Plaid, FHFA, the U.S. Census Bureau, HUD and its ArcGIS/Esri service, NHTSA, FuelEconomy.gov, the European Central Bank, the U.S. Bureau of Labor Statistics, the U.S. Treasury, DuckDuckGo, invited household members, or your chosen export/support destination only when you use those features.
- Your Apple Account controls CloudKit access, and Face ID, Touch ID, or your device passcode protects access to the local app. SAFE Budget has no separate sync password.
2. Data SAFE Budget Stores
SAFE Budget can store information you enter, calculate, or import, including accounts, balances,
transactions, budgets, bills, loans, savings goals, categories, tags, receipts, household membership,
provider connections, and app preferences.
Local and CloudKit-protected ledger
On iPhone and iPad, SAFE Budget places its local ledger files under Apple's complete file-protection
class inside the app sandbox. On Mac, the app sandbox and the Mac's platform/FileVault configuration protect
the local files. When CloudKit is available, designated ledger values use CloudKit encrypted fields and
attachments use CloudKit assets. Opaque record identifiers and the limited routing, version, timestamp,
deletion, and relationship fields required for CloudKit operation are not financial values and remain
available to Apple systems for sync and sharing.
Local query index
While a household is unlocked, SAFE Budget maintains a separate plaintext query index on that device so
it can sort, search, graph, and calculate quickly. The index is derived from the local ledger, never syncs
to CloudKit, is excluded from device backups, and uses the same iPhone/iPad complete file-protection class.
It is cleared when the app locks or logs out and can be rebuilt after the next unlock. SAFE Budget excludes
it and its database sidecars from reset-device and rolling safety snapshots; older snapshots are cleaned
when found. A full erase removes the live index and every local safety snapshot.
3. Information the Developer Does Not Receive Automatically
- No readable ledger, bank login, or provider credential is sent to the developer.
- No advertising identifier, cross-app tracking data, or developer product-analytics event is collected.
- No developer crash-analytics or telemetry service is included.
- Photos are accessed only when you deliberately attach a receipt or other supported image.
This does not mean that no external service processes data. Apple provides iCloud, CloudKit, iCloud
Keychain, system backups, and FinanceKit. SimpleFIN or Plaid processes bank-connection data when you enable
that provider. FHFA, Census, HUD/Esri, NHTSA, FuelEconomy.gov, the European Central Bank, the U.S. Bureau of Labor Statistics, or the U.S. Treasury receive the bounded request described below only when you
deliberately use the corresponding public-data tool. DuckDuckGo receives a merchant search when you deliberately open merchant-cancellation help.
A support email provider processes information you choose to send to support.
4. iCloud, CloudKit, Keychain, and Backups
When the signed-in Apple Account and entitled CloudKit container are available, SAFE Budget
automatically stores designated ledger values in CloudKit encrypted fields in the user's private database;
attachments use CloudKit assets, which Apple encrypts by default. CloudKit also stores the record
identifiers, routing, record type, modification/deletion state, and sharing metadata needed to operate
sync. A named household share uses Apple's CloudKit sharing system to make records available only to the
invited participant. If CloudKit is temporarily unavailable, the app remains usable from its local store
and catches up later.
Under standard iCloud protection, Apple encrypts this data in transit and on its servers. If the user
enables Advanced Data Protection for their Apple Account and Apple's documented sharing conditions are
satisfied, Apple states that the CloudKit encrypted fields and assets are end-to-end encrypted and that
Apple does not hold the keys. SAFE Budget cannot enable Advanced Data Protection for the user.
Bank access credentials, connection tokens, and an optional user-supplied Census Data API key that need to reach the same user's other trusted devices
are stored as synchronizable Apple Keychain items and may sync through end-to-end-encrypted iCloud
Keychain. Device-local provider checkpoints, such as a Plaid transaction cursor, do not sync through
iCloud Keychain. Eligible Keychain items may also migrate through Apple's encrypted device-backup and
restore systems.
Depending on the user's Apple backup settings, an operating-system backup may include the
platform-protected local ledger and local safety snapshots. The plaintext query index is marked as excluded from backup.
CloudKit sync and operating-system backup are separate Apple services, controlled by the user's Apple
Account and system settings. SAFE Budget's developer does not receive either copy.
Apple's practices apply to these services. See Apple's
iCloud data security overview
and Privacy Policy.
5. Optional Bank Connections
Bank connections are optional. Imported accounts and transactions are stored in the local and
CloudKit-protected SAFE Budget ledger, but the selected provider necessarily processes data for the connection.
SimpleFIN
- The SimpleFIN Access URL or credential you provide is stored in Keychain.
- When you connect or refresh, the app sends that credential directly to your selected SimpleFIN Bridge and receives account and transaction data directly on the device.
- SAFE Budget does not proxy this traffic through a developer server.
Bring-your-own Plaid
- You supply your own Plaid developer client ID and secret. Those credentials, Plaid access tokens, and connection state are stored in Keychain.
- The app sends the Plaid credentials, access token, an opaque member-scoped
client_user_id, account data, transaction data, and lifecycle requests directly between your device and Plaid as needed to create, repair, refresh, or remove a Plaid Item.
- Plaid LinkKit presents Plaid's bank-linking experience. SAFE Budget and its developer do not receive the bank username or password entered in Plaid Link.
- SAFE Budget has no Plaid webhook receiver, credential relay, or always-on refresh server. Refreshes are initiated from the app on the user's device.
- Keeping confidential Plaid client material in a distributed app and the user's Keychain differs from Plaid's conventional server-held-secret architecture. This advanced bring-your-own configuration is controlled by the user and remains subject to Plaid's terms and account permissions.
SimpleFIN and Plaid are independent services that you authorize directly. SAFE Budget's
developer is not affiliated with, does not own, and does not control either provider. The developer does
not receive the direct connection traffic between your device and the provider. Your use of either service
is governed by its own terms, privacy policy, retention practices, and the permissions you choose.
Removing a provider connection stops future access through that connection and, where supported,
requests remote disconnection. Already imported ledger history remains until you delete those rows or erase
the household. Provider retention rules may also apply. See
SimpleFIN and
Plaid.
6. Optional Apple Wallet Access (iPhone only)
Apple supports Apple Wallet account access (FinanceKit) on iPhone only; it is not available on
iPad or Mac. On those devices SAFE Budget shows an explanatory note instead of a connect option,
and no FinanceKit authorization is requested. Accounts you connect on your iPhone reach your other devices
through the same encrypted iCloud sync as any other account.
With explicit FinanceKit permission on a supported iPhone, SAFE Budget can read supported Apple Wallet
account, balance, and transaction data on the device, including supported Apple Card, Apple Cash, and
Savings with Apple Card data. Imported Wallet data uses the same local platform protection and CloudKit
encrypted fields/assets as the rest of the ledger. The developer
does not receive Wallet data. FinanceKit access is optional and can be revoked in Apple system settings.
Revocation stops future reads; already imported history remains until you delete it or erase the household.
7. Optional Public Reference Data
SAFE Budget can use public government and central-bank data without routing the request through a developer server.
- FHFA home-price index: If you tap Load Official State Indexes, the app downloads FHFA's complete public quarterly state purchase-only table from one fixed HTTPS URL. The request has no query string and does not contain your selected state, dates, address, ZIP code, home value, or calculation input. State/date selection and index-ratio math happen locally, and the response is not placed in the app's HTTP cache. The result is a broad planning estimate, not an appraisal or comparable-sale analysis. This product uses FHFA data but is neither endorsed nor certified by FHFA.
- Census ZIP housing context: Nothing is sent until you enter a five-digit ZIP, supply your own Census Data API key, and tap Check ZIP context. The request sends that ZIP and key directly to Census; it does not send a street address, saved home value, household/account identifier, or other ledger data. If you choose Remember in iCloud Keychain, the key is stored only in your Apple Keychain for your trusted devices. The pinned ACS response shows separate ZIP-area survey medians and published margins for owner-occupied value, monthly owner costs by mortgage status, gross rent, and annual real-estate taxes. SAFE Budget does not turn them into your home's value, tax bill/rate, rent, range, yield, affordability score, or personal budget, and warns that owner costs can already include property taxes. Adding the result saves encrypted context and limitations only. This product uses the Census Bureau Data API but is not endorsed or certified by the Census Bureau.
- HUD Small Area Fair Market Rent context: Nothing is sent until you enter a five-digit ZIP and tap Check rent benchmark. The app first validates the expected public HUD ArcGIS item and service identity, then sends only that ZIP directly to the HUD/Esri query endpoint; bedroom selection stays on your device. It does not send a street address, property value, household/account identifier, or other ledger data, and the response is not cached. SAFE Budget shows every distinct overlapping schedule rather than choosing or averaging one. These are federal Housing Choice Voucher gross-rent program benchmarks—not asking rent, market rent, an appraisal, comparable-rental evidence, or property value. Adding the result saves encrypted context only and never changes your selected value, range, budget, or net worth.
- NHTSA vehicle identity, recalls, and safety ratings: If you tap Look Up with NHTSA, the entered 17-character VIN is sent directly to NHTSA's public vPIC service over HTTPS. The returned identity and specifications can suggest an encrypted asset name but never change its value, basis, depreciation, valuation source, confidence, or evidence. After a clean decode, a separate model-level recall request sends only the returned model year, make, and model—never the VIN, mileage, asset value, account, or household information. A crash-safety lookup is separate again and occurs only if you tap Check NHTSA Safety Ratings, choose a tested model and variant, and tap Show Safety Rating; those requests contain only public year/make/model taxonomy and the selected public NHTSA vehicle ID. These responses use ephemeral, no-cache requests, are not saved or synced, and never change the asset valuation. Model-level recalls do not prove that a particular VIN is affected or unrepaired, and NCAP ratings describe a selected tested variant rather than the entered vehicle's current condition or guaranteed real-world safety. SAFE Budget links to NHTSA's official VIN-specific recall and complete safety-rating resources. SAFE Budget does not persist the VIN merely because it was looked up.
- FuelEconomy.gov operating-cost planner: Opening the planner sends nothing. If you tap Load FuelEconomy.gov Vehicles, the app requests public menus and sends your selected year, make, model, and configuration directly to FuelEconomy.gov for the selected public vehicle record. It does not send a VIN, asset value, account or household information, or your annual-mileage input. The response is not placed in the app's HTTP cache, and custom-mileage calculations happen locally. The result is an operating-cost estimate, not a vehicle valuation, dealer quote, or resale estimate.
- ECB exchange-rate reference: Opening Exchange Rates sends nothing. If you tap Refresh tracked currencies, the app downloads the European Central Bank's complete public daily reference-rate file from one fixed HTTPS URL with no query string. It does not send your tracked currencies, balances, holdings, account or household information. The device selects relevant currencies and calculates USD cross-rates locally. The response is not placed in the app's HTTP cache. Results are informational reference rates, not guaranteed transaction or settlement prices.
- BLS inflation context: Opening Forecast Assumptions sends nothing. If you tap Check latest official CPI-U, the app downloads one fixed CPI-U series from the U.S. Bureau of Labor Statistics Public Data API using a queryless HTTPS request. It does not send your household identifier, ledger data, balances, categories, or user-entered assumption. The device calculates the latest valid same-month 12-month percent change locally, and the response is not placed in the app's HTTP cache. Applying the result requires a second explicit tap. The saved source, observed month, and retrieval day are encrypted with the assumption. The result is historical context, not a forecast or automatic replacement for your assumption. BLS.gov cannot vouch for the data or analyses derived from these data after the data have been retrieved from BLS.gov.
- U.S. Treasury yield context: Opening Forecast Assumptions sends nothing. If you tap Compare official Treasury yields, the app downloads the current calendar year's public Daily Treasury Par Yield Curve feed using an ephemeral, no-cache HTTPS request. The query contains only the fixed dataset name and current year; it does not send an account, balance, household identifier, saved cash APY, maturity selection, or forecast assumption. The device selects the latest complete curve and displays six maturities only in the open sheet. The result is not saved, synced, or applied to your cash-return assumption. These nominal par yields are planning benchmarks, not bank APYs, product returns, mortgage quotes, guarantees, or recommendations.
- BLS used-vehicle market context: Opening the calculator sends nothing. If you tap Load official BLS index, the app downloads fixed public series CUUR0000SETA02 using a queryless HTTPS request. It does not send your VIN, vehicle description, mileage, known value, known-value date, accounts, household identifier, or other financial data. The device selects your exact month and the latest available monthly index, then calculates the index ratio locally; the response is not placed in the app's HTTP cache. Applying the result requires a second explicit tap. The full source, periods, indexes, formula result, retrieval date, limitations, and disclaimer are saved only inside your encrypted asset-valuation observation. This national constant-quality index adjusts for depreciation, mileage, and quality change, so SAFE Budget does not present the result as vehicle-specific depreciation, condition, local demand, an appraisal, trade-in value, or resale quote and never automatically combines it with the separate depreciation scenario. BLS.gov cannot vouch for the data or analyses derived from these data after the data have been retrieved from BLS.gov.
FHFA, Census, HUD/Esri, NHTSA, FuelEconomy.gov, the ECB, BLS, and Treasury are independent public-data services. Their availability, server logs,
retention practices, and privacy notices apply when you make the corresponding request. See
FHFA Privacy,
Census Privacy,
HUD Privacy,
Esri Privacy,
NHTSA Privacy, and
FuelEconomy.gov Privacy/Security,
ECB Privacy, and
BLS API Terms, and
BLS Used Cars and Trucks Methodology, and
U.S. Treasury Privacy.
8. Ask SAFE
Ask SAFE processes your questions and ledger context on the device. Recognized money questions use
deterministic local calculations. On supported systems, other answers can use Apple's on-device Foundation
Models. SAFE Budget does not send Ask SAFE prompts, ledger context, or answers to the developer or to an
external AI service. Ask SAFE provides estimates and explanations, not financial, tax, investment, or legal
advice.
9. Household Sharing
SAFE Budget shares a household only with a person the owner explicitly authorizes. For a different Apple
Account, the owner grants that named participant access through a private CloudKit share. Authorized
participants receive the shared CloudKit records on their authorized devices.
Revoking a named participant removes that participant's server-side CloudKit share access.
Revocation cannot recall readable information the participant already viewed, exported, screenshotted, or
otherwise copied. Owners should treat a former participant as having had access to data available before
revocation.
10. Optional Merchant Help
If you choose How to cancel for a detected recurring merchant, SAFE Budget opens a
DuckDuckGo web search containing that merchant or payee name and cancellation-related search words. This is
user-initiated; the app does not send balances, amounts, account numbers, or the rest of your ledger with
the query. Your browser and DuckDuckGo's privacy practices apply.
11. Exports
SAFE Budget can create user-requested backups and supported CSV exports on the device. Plaintext JSON or
CSV exports are readable files. An encrypted backup is protected by the export passphrase you choose.
After you export or share a file, the destination you select controls its storage, access, backup, and
deletion. SAFE Budget's developer does not automatically receive exports.
12. Reset and Erasure
- Reset this device removes the working local store but leaves the CloudKit household available for recovery. It may retain a sanitized, platform-protected local safety snapshot; the plaintext query index and its sidecars are excluded.
- Erase all data — owner: removes the local store, query index, local safety snapshots, app preferences, summaries, and stored bank credentials, and requests deletion of the household's private CloudKit zone. If iCloud is unavailable, the app records a pending deletion and retries after connectivity/account access returns.
- Erase or leave — participant: removes the participant's local copy and app-held provider credentials, but a participant cannot delete the owner's CloudKit household.
- Removing a bank connection does not automatically delete transaction history already imported into the ledger.
Because SAFE Budget operates no developer ledger server, the developer has no separate readable ledger
copy to erase. Apple, bank providers, public government services, browser/search providers, export destinations, and email providers
apply their own deletion and retention rules to information they process.
13. Security and Recovery
- On iPhone and iPad, SAFE Budget uses Apple's complete file-protection class and the app sandbox for its local ledger files. Mac protection depends on the app sandbox and the Mac's platform/FileVault configuration.
- Face ID, Touch ID, or the device passcode controls access to the local app. SAFE Budget has no separate sync passphrase or recovery key.
- CloudKit encrypts designated fields on the device before upload and encrypts assets by default. Advanced Data Protection provides Apple's additional end-to-end guarantee when the user enables it and its documented conditions are met.
- No security design can guarantee that a compromised, unlocked, or previously authorized device has not copied readable data. Protect your device passcodes, Apple Account, exports, and provider credentials.
14. Support and Voluntary Contact
If you email support, the developer and the email provider receive the address, message, attachments,
and other information you choose to send. SAFE Budget can generate a non-sensitive sync-diagnostics summary
for you to copy into a message; it is designed not to include account names, balances, household IDs, or
financial details. Review any message or attachment before sending it. Support information is used to
investigate and respond to your request and may be retained as needed for that purpose or legal obligations.
15. Children's Privacy
SAFE Budget is a general personal-finance application and is not directed to children. The developer
does not knowingly collect children's personal information through a SAFE Budget account or ledger server,
because the app has neither.
16. Changes and Contact
Material changes to these practices will be reflected in this policy and its updated date. Questions or
privacy requests can be sent to support@aitodoplus.app or through
SAFE Budget Support.
Privacy summary:
- ✅ No developer-operated readable-ledger server, ads, tracking, or product analytics
- ✅ Apple platform protection locally and CloudKit encrypted fields/assets for sync
- ✅ Plaintext local query index never syncs, is excluded from backups and snapshots, and is cleared on lock
- ✅ Optional Apple, bank, public-government-data, search, sharing, export, and support paths are user-controlled and disclosed
- ✅ Named household access with honest revocation limits
- ✅ Owner-controlled export, reset, and erase tools
© 2026 SAFE Budget. This privacy policy is effective as of July 22, 2026.