Privacy Policy

Last Updated: July 24, 2026

SAFE Budget is designed so the developer cannot read your financial ledger.
The app has no SAFE Budget account service, advertising system, analytics service, or developer-operated ledger server. Readable financial data is processed on your devices. When CloudKit is available, ledger values sync through encrypted CloudKit fields and attachments use CloudKit assets. Optional Apple, bank-provider, public-government-data, merchant-search, sharing, export, and support paths are described below.

1. The Short Version

2. Data SAFE Budget Stores

SAFE Budget can store information you enter, calculate, or import, including accounts, balances, transactions, budgets, bills, loans, savings goals, categories, tags, receipts, household membership, provider connections, and app preferences.

Local and CloudKit-protected ledger

On iPhone and iPad, SAFE Budget places its local ledger files under Apple's complete file-protection class inside the app sandbox. On Mac, the app sandbox and the Mac's platform/FileVault configuration protect the local files. When CloudKit is available, designated ledger values use CloudKit encrypted fields and attachments use CloudKit assets. Opaque record identifiers and the limited routing, version, timestamp, deletion, and relationship fields required for CloudKit operation are not financial values and remain available to Apple systems for sync and sharing.

Local query index

While a household is unlocked, SAFE Budget maintains a separate plaintext query index on that device so it can sort, search, graph, and calculate quickly. The index is derived from the local ledger, never syncs to CloudKit, is excluded from device backups, and uses the same iPhone/iPad complete file-protection class. It is cleared when the app locks or logs out and can be rebuilt after the next unlock. SAFE Budget excludes it and its database sidecars from reset-device and rolling safety snapshots; older snapshots are cleaned when found. A full erase removes the live index and every local safety snapshot.

3. Information the Developer Does Not Receive Automatically

This does not mean that no external service processes data. Apple provides iCloud, CloudKit, iCloud Keychain, system backups, and FinanceKit. SimpleFIN or Plaid processes bank-connection data when you enable that provider. FHFA, Census, HUD/Esri, NHTSA, FuelEconomy.gov, the European Central Bank, the U.S. Bureau of Labor Statistics, or the U.S. Treasury receive the bounded request described below only when you deliberately use the corresponding public-data tool. DuckDuckGo receives a merchant search when you deliberately open merchant-cancellation help. A support email provider processes information you choose to send to support.

4. iCloud, CloudKit, Keychain, and Backups

When the signed-in Apple Account and entitled CloudKit container are available, SAFE Budget automatically stores designated ledger values in CloudKit encrypted fields in the user's private database; attachments use CloudKit assets, which Apple encrypts by default. CloudKit also stores the record identifiers, routing, record type, modification/deletion state, and sharing metadata needed to operate sync. A named household share uses Apple's CloudKit sharing system to make records available only to the invited participant. If CloudKit is temporarily unavailable, the app remains usable from its local store and catches up later.

Under standard iCloud protection, Apple encrypts this data in transit and on its servers. If the user enables Advanced Data Protection for their Apple Account and Apple's documented sharing conditions are satisfied, Apple states that the CloudKit encrypted fields and assets are end-to-end encrypted and that Apple does not hold the keys. SAFE Budget cannot enable Advanced Data Protection for the user.

Bank access credentials, connection tokens, and an optional user-supplied Census Data API key that need to reach the same user's other trusted devices are stored as synchronizable Apple Keychain items and may sync through end-to-end-encrypted iCloud Keychain. Device-local provider checkpoints, such as a Plaid transaction cursor, do not sync through iCloud Keychain. Eligible Keychain items may also migrate through Apple's encrypted device-backup and restore systems.

Depending on the user's Apple backup settings, an operating-system backup may include the platform-protected local ledger and local safety snapshots. The plaintext query index is marked as excluded from backup. CloudKit sync and operating-system backup are separate Apple services, controlled by the user's Apple Account and system settings. SAFE Budget's developer does not receive either copy.

Apple's practices apply to these services. See Apple's iCloud data security overview and Privacy Policy.

5. Optional Bank Connections

Bank connections are optional. Imported accounts and transactions are stored in the local and CloudKit-protected SAFE Budget ledger, but the selected provider necessarily processes data for the connection.

SimpleFIN

Bring-your-own Plaid

SimpleFIN and Plaid are independent services that you authorize directly. SAFE Budget's developer is not affiliated with, does not own, and does not control either provider. The developer does not receive the direct connection traffic between your device and the provider. Your use of either service is governed by its own terms, privacy policy, retention practices, and the permissions you choose.

Removing a provider connection stops future access through that connection and, where supported, requests remote disconnection. Already imported ledger history remains until you delete those rows or erase the household. Provider retention rules may also apply. See SimpleFIN and Plaid.

6. Optional Apple Wallet Access (iPhone only)

Apple supports Apple Wallet account access (FinanceKit) on iPhone only; it is not available on iPad or Mac. On those devices SAFE Budget shows an explanatory note instead of a connect option, and no FinanceKit authorization is requested. Accounts you connect on your iPhone reach your other devices through the same encrypted iCloud sync as any other account.

With explicit FinanceKit permission on a supported iPhone, SAFE Budget can read supported Apple Wallet account, balance, and transaction data on the device, including supported Apple Card, Apple Cash, and Savings with Apple Card data. Imported Wallet data uses the same local platform protection and CloudKit encrypted fields/assets as the rest of the ledger. The developer does not receive Wallet data. FinanceKit access is optional and can be revoked in Apple system settings. Revocation stops future reads; already imported history remains until you delete it or erase the household.

7. Optional Public Reference Data

SAFE Budget can use public government and central-bank data without routing the request through a developer server.

FHFA, Census, HUD/Esri, NHTSA, FuelEconomy.gov, the ECB, BLS, and Treasury are independent public-data services. Their availability, server logs, retention practices, and privacy notices apply when you make the corresponding request. See FHFA Privacy, Census Privacy, HUD Privacy, Esri Privacy, NHTSA Privacy, and FuelEconomy.gov Privacy/Security, ECB Privacy, and BLS API Terms, and BLS Used Cars and Trucks Methodology, and U.S. Treasury Privacy.

8. Ask SAFE

Ask SAFE processes your questions and ledger context on the device. Recognized money questions use deterministic local calculations. On supported systems, other answers can use Apple's on-device Foundation Models. SAFE Budget does not send Ask SAFE prompts, ledger context, or answers to the developer or to an external AI service. Ask SAFE provides estimates and explanations, not financial, tax, investment, or legal advice.

9. Household Sharing

SAFE Budget shares a household only with a person the owner explicitly authorizes. For a different Apple Account, the owner grants that named participant access through a private CloudKit share. Authorized participants receive the shared CloudKit records on their authorized devices.

Revoking a named participant removes that participant's server-side CloudKit share access. Revocation cannot recall readable information the participant already viewed, exported, screenshotted, or otherwise copied. Owners should treat a former participant as having had access to data available before revocation.

10. Optional Merchant Help

If you choose How to cancel for a detected recurring merchant, SAFE Budget opens a DuckDuckGo web search containing that merchant or payee name and cancellation-related search words. This is user-initiated; the app does not send balances, amounts, account numbers, or the rest of your ledger with the query. Your browser and DuckDuckGo's privacy practices apply.

11. Exports

SAFE Budget can create user-requested backups and supported CSV exports on the device. Plaintext JSON or CSV exports are readable files. An encrypted backup is protected by the export passphrase you choose. After you export or share a file, the destination you select controls its storage, access, backup, and deletion. SAFE Budget's developer does not automatically receive exports.

12. Reset and Erasure

Because SAFE Budget operates no developer ledger server, the developer has no separate readable ledger copy to erase. Apple, bank providers, public government services, browser/search providers, export destinations, and email providers apply their own deletion and retention rules to information they process.

13. Security and Recovery

14. Support and Voluntary Contact

If you email support, the developer and the email provider receive the address, message, attachments, and other information you choose to send. SAFE Budget can generate a non-sensitive sync-diagnostics summary for you to copy into a message; it is designed not to include account names, balances, household IDs, or financial details. Review any message or attachment before sending it. Support information is used to investigate and respond to your request and may be retained as needed for that purpose or legal obligations.

15. Children's Privacy

SAFE Budget is a general personal-finance application and is not directed to children. The developer does not knowingly collect children's personal information through a SAFE Budget account or ledger server, because the app has neither.

16. Changes and Contact

Material changes to these practices will be reflected in this policy and its updated date. Questions or privacy requests can be sent to support@aitodoplus.app or through SAFE Budget Support.

Privacy summary:

© 2026 SAFE Budget. This privacy policy is effective as of July 22, 2026.