Email: support@aitodoplus.app
Helpful to include: the SAFE Budget version and build number, device model, OS version, what you expected, and what happened. Settings → iCloud Sync can generate a non-sensitive diagnostics summary you can review and paste into your message.
Email is voluntary. The address, message, attachments, and any details you send are received by the support mailbox and used to investigate and respond. Please do not send bank credentials, device passcodes, account numbers, or screenshots containing financial details.
Readable ledger data is processed on your devices. The local ledger uses Apple's app sandbox and device/platform protection. When CloudKit is available, designated ledger values use CloudKit encrypted fields and attachments use CloudKit assets in your private database. The developer operates no readable-ledger server and does not receive your balances, transactions, budgets, or receipts. CloudKit still handles limited record, routing, timestamp, deletion, and sharing metadata needed to sync.
Encrypted fields cannot be efficiently sorted or graphed directly, so the app builds a separate query index while your household is unlocked. It stays on that device, never syncs, and is excluded from device backups and local safety snapshots. It is cleared when the app locks or logs out and rebuilt after unlock. A full erase removes it and all local safety snapshots.
Use Face ID, Touch ID, or your device passcode. SAFE Budget has no separate sync passphrase or recovery key. CloudKit access uses your signed-in Apple Account. Never send a device passcode or Apple Account credential to support.
Yes. When CloudKit is available, ledger values in encrypted CloudKit fields and CloudKit assets sync automatically through your private database. Bank credentials can sync to trusted devices on the same Apple Account through iCloud Keychain; provider progress checkpoints remain device-local. A person using a different Apple Account must be explicitly authorized as a named participant through a private CloudKit share.
Connections are optional. SimpleFIN communicates directly between your device and your SimpleFIN Bridge. Bring-your-own Plaid uses the Plaid developer credentials you supply, Plaid LinkKit for bank login, and direct device-to-Plaid API calls. SAFE Budget has no Plaid webhook receiver or always-on refresh server. Provider credentials and access tokens are stored in Keychain and are not sent to the developer. Disconnecting stops future access, but imported history remains until you delete it or erase the household.
Apple supports Apple Wallet account access (FinanceKit) on iPhone only. It is not available on iPad or on Mac — that is Apple's platform limitation, not a missing SAFE Budget feature. Connect Apple Card, Apple Cash, and Apple Card Savings from SAFE Budget on your iPhone, and the imported accounts sync to your iPad and Mac through iCloud like any other account. On iPad and Mac you can still use SimpleFIN, your own Plaid setup, file import, or manual accounts.
If you grant FinanceKit permission on your iPhone, SAFE Budget can read supported Apple Wallet balances and transactions on the device and import them into the local and CloudKit-protected ledger. The developer does not receive Wallet data. You can revoke permission in system settings; already imported rows remain until you delete them or erase the household.
No. Recognized money questions use deterministic calculations on the device. On supported systems, other answers can use Apple's on-device Foundation Models. Prompts and ledger context are not sent to the developer or an external AI service.
Revoking a named participant removes that person's server-side CloudKit share access. It cannot recall information the former participant already viewed, exported, screenshotted, or otherwise copied.
That optional action opens a DuckDuckGo search containing the merchant or payee name and cancellation-related words. It is not automatic. No balance, amount, account number, or other ledger data is added to the query.
Settings provides supported JSON/CSV exports and passphrase-protected encrypted backups. Plaintext exports are readable files, so protect the destination. Reset this device keeps the CloudKit household and can retain a sanitized, platform-protected safety snapshot for recovery. An owner using Erase all data removes the local store, local snapshots, app preferences and stored provider credentials, and requests deletion of the private CloudKit zone; an unavailable iCloud deletion is retained for retry. A participant can remove the local copy but cannot delete the owner's CloudKit household.
SAFE Budget is a native app for iPhone, iPad, and Mac, with widgets and an Apple Watch glance. Supported data syncs through the CloudKit account and sharing paths described in the Privacy Policy.
No. SAFE Budget contains no advertising, cross-app tracking, or developer-operated product analytics. Its optional Apple, bank-provider, search, sharing, export, and support functions communicate only as described in the Privacy Policy.
See also: Privacy Policy · Terms of Service
© 2026 SAFE Budget. All rights reserved.