Privacy Policy
Your privacy matters. Here's how Bulga handles your data.
Effective Date: July 23, 2026
Overview
Bulga ("we", "our", or "us") is a personal budgeting application. This Privacy Policy explains what information we collect, how we use it, and your choices regarding your data.
By using Bulga, you agree to the collection and use of information as described in this policy.
Data We Collect
We collect the minimum amount of data necessary to provide and improve our service:
- Account Information: When you create an account, we collect your email address and authentication credentials through Firebase Authentication. If you sign in with Google, we receive your name and email from your Google profile.
- Budget Data: Income and expense categories, amounts, and frequencies that you enter into the app. This data is stored to provide the budgeting service.
- Planner Data: Debts and savings goals, including balances, interest rates, target amounts, and priorities that you enter into the Financial Planner. This data is stored to provide the financial projections and payoff calculations.
- Preferences: Your chosen theme (dark/light), accent color, language settings, and currency symbol preference.
- Payment Information: If you subscribe to a premium plan, payment processing is handled entirely by Stripe. We do not store your credit card number or full payment details. We only store your Stripe customer ID and subscription ID to manage your subscription status.
- Contact Form Submissions: If you contact us through the in-app form, we receive your name, email, and message content via Formspree.
- Payment Reminders: If you set up payment reminders on budget entries, we store your scheduling preferences (day of week, day of month, or date of year) alongside the associated entry. This data is used solely to calculate and display your upcoming payments.
- Receipt Files & Images: When you upload receipts (as files or taken via your device camera), the files are stored securely in Google Cloud Storage (Firebase Storage) to be served back to you. They are only accessed to display them to you and are deleted when you delete the receipt or your account.
- AI Receipt Scanning: When you use the receipt scanner, photos are transmitted securely over HTTPS to the Google Gemini API solely for real-time text extraction (merchant, date, amount, category). Images are processed transiently in memory, are not stored by Google, and are never used to train public AI models.
- Biometric & App Lock Data: Security PINs and WebAuthn biometric credentials (Fingerprint / Face ID) are processed exclusively on your local device and are never sent to or stored on our servers.
- Device Camera Access: If you use the "Take Photo" feature, we request access to your device's camera. This processing is done entirely on your device (client-side) to capture a photo of your receipt. We do not stream, record, or store any camera feeds on our servers.
- Push Notifications: If you opt-in to push notifications, we store your push subscription credentials (tokens, endpoints, and encryption keys) via Firebase Cloud Messaging. This data is used solely to deliver payment reminders and can be revoked at any time in your device or profile settings.
- Partner & Shared Data: When you connect with a partner, we collect your partner's email and UID to link your accounts. Split expense details (original amounts, split percentages, paid-by states) and historical settlement records are stored in Firestore to synchronize your shared balances.
How We Use Your Data
We use the information we collect to:
- Provide and maintain the budgeting service
- Authenticate your identity and secure your account
- Process premium subscription payments
- Save and sync your preferences across devices
- Respond to your support inquiries
- Improve the app based on usage patterns and feedback
We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes.
Third-Party Services
Bulga uses the following third-party services that may process your data according to their own privacy policies:
- Firebase (Google) — Authentication, cloud database (Firestore), and cloud storage (Firebase Storage) for storing your account, budget data, and receipt files.
- Google Gemini API (Google AI) — AI-powered visual receipt text extraction. Uploaded receipt images are processed transiently in-memory for real-time form auto-fill and are not retained or used for model training.
- Stripe — Secure payment processing for premium subscriptions.
- Formspree — Contact form submission handling.
Data Storage & Security
Your data is stored securely on Google Cloud (Firebase) servers. All data in transit is encrypted using HTTPS/TLS. Authentication tokens are managed by Firebase Authentication with industry-standard security practices.
While we implement appropriate security measures, no method of electronic storage or internet transmission is 100% secure. We cannot guarantee absolute security of your data.
The app also uses local storage to cache your budget entries, planner items, and preferences locally on your device. This enables offline access and seamless syncing. When you are signed in, these local changes are securely synchronized with our servers once you go back online. If you are using the app as a guest, your data remains solely in your browser's local storage.
Your Rights
You have full control over your data:
- Access & Export: You can view all of your budget data within the app at any time.
- Erase Data: You can erase all budget data from your Profile page — this permanently removes your categories and entries.
- Delete Account: You can permanently delete your entire account, including all associated data, from your Profile page. Any active partnerships you have will be automatically disconnected, resetting active shared balances. Historical settlements remain archived.
- Manage Subscription: You can cancel or modify your premium subscription at any time through the Stripe customer portal.
Children's Privacy
Bulga is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated effective date. We encourage you to review this page periodically. Continued use of the app after changes constitutes acceptance of the updated policy.
Contact Us
If you have any questions about this Privacy Policy or how your data is handled, please reach out through our Contact page.