Trust & Transparency

Privacy Policy

Your privacy matters. Here's how Bulga handles your data.

Effective Date: September 14, 2026

Overview

Bulga ("we", "our", or "us") is a personal budgeting application. This Privacy Policy explains what information we collect, how we use it, and your choices regarding your data.

By using Bulga, you agree to the collection and use of information as described in this policy.

Data We Collect

We collect the minimum amount of data necessary to provide and improve our service:

  • Account Information: When you create an account, we collect your email address and authentication credentials through Firebase Authentication. If you sign in with Google, we receive your name and email from your Google profile.
  • Budget Data: Income and expense categories, amounts, and frequencies that you enter into the app. This data is stored to provide the budgeting service.
  • Planner Data: Debts and savings goals, including balances, interest rates, target amounts, and priorities that you enter into the Financial Planner. This data is stored to provide the financial projections and payoff calculations.
  • Preferences: Your chosen theme (dark/light), accent color, language settings, and currency preferences (ISO currency code and symbol).
  • Payment Information: If you subscribe to a premium plan, payment processing is handled by Stripe (on web browsers) or Google Play Billing (within the Android app). We do not store your credit card number or full payment details. We only store pseudonymous transaction IDs, customer IDs, or subscription tokens necessary to verify and manage your subscription status.
  • Contact Form Submissions: If you contact us through the in-app form, we receive your name, email, and message content via Formspree.
  • Payment Reminders & Auto-Add: If you set up payment dates or enable auto-add on budget entries, we store your scheduling preferences (day of week, day of month, or date of year). If auto-add is enabled, a scheduled backend process automatically logs the entry into your budget on the designated date.
  • Receipt Files & Images: When you upload receipts (as files or taken via your device camera), the files are stored securely in Google Cloud Storage (Firebase Storage) to be served back to you. They are only accessed to display them to you and are deleted when you delete the receipt or your account.
  • Financial Statement Import: When you upload bank or credit card statements (PDF, Images, CSV, Excel), document contents are transmitted securely over HTTPS to the Google Gemini API solely for real-time transaction extraction (merchant, date, amount, category). Statement files are processed transiently in memory, are not stored by Google, and are never used to train public AI models.
  • AI Receipt Scanning: When you use the receipt scanner, photos and documents (PDF, images) are transmitted securely over HTTPS to the Google Gemini API solely for real-time text extraction (merchant, date, amount, category). Files are processed transiently in memory, are not stored by Google, and are never used to train public AI models.
  • AI Smart-Fill & Express Entry: When you use quick text or voice prompts to log an expense, your prompt text is transmitted securely over HTTPS to the Google Gemini API solely for real-time transaction extraction (merchant, date, amount, category). Prompt text is processed transiently in memory, is not stored by Google, and are never used to train public AI models.
  • Biometric & App Lock Data: Security PINs and WebAuthn biometric credentials (Fingerprint / Face ID) are processed exclusively on your local device and are never sent to or stored on our servers.
  • Device Camera Access: If you use the "Take Photo" feature, we request access to your device's camera. On mobile, this uses your native camera; on desktop, this uses an in-browser WebRTC video viewfinder. In both cases, processing is done entirely on your local device to capture a single photo of your receipt. We do not stream, record, or store continuous video feeds on our servers.
  • Device Microphone Access: If you use the voice dictation feature in Express Entry, we request microphone access. Speech recognition is processed locally by your browser or operating system's Web Speech API to convert your voice into text. No raw audio recordings are ever transmitted to, recorded, or saved on our servers.
  • Usage & Diagnostics Telemetry: We collect pseudonymous usage metrics and app telemetry via Google Analytics for Firebase (such as page views, button interactions, feature engagement, general device model, operating system, and approximate country). This technical data is used solely to monitor platform health, diagnose issues, and improve usability.
  • Trial & Feature Quotas: For accounts on free or trial tiers, we track basic feature usage counters (such as the count of free AI receipt scans and Smart-Fill prompts used) associated with your user ID to enforce quota limits and protect services against abuse.
  • Push Notifications: If you opt-in to push notifications, we store your push subscription credentials (tokens, endpoints, and encryption keys) via Firebase Cloud Messaging. This data is used solely to deliver payment reminders and can be revoked at any time in your device or profile settings.
  • Partner & Shared Data: When you connect with a partner, we collect your partner's email and UID to link your accounts. Split expense details (original amounts, split percentages, paid-by states) and historical settlement records are stored in Firestore to synchronize your shared balances.

How We Use Your Data

We use the information we collect to:

  • Provide and maintain the budgeting service
  • Authenticate your identity and secure your account
  • Process premium subscription payments
  • Save and sync your preferences across devices
  • Respond to your support inquiries
  • Improve app stability, diagnose technical errors, and optimize features based on aggregated usage patterns and feedback

We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes.

Third-Party Services

Bulga uses the following third-party services that may process your data according to their own privacy policies:

  • Firebase (Google) — Authentication, cloud database (Firestore), and cloud storage (Firebase Storage) for securely storing your account, budget records, and receipt files.
  • Google Analytics for Firebase (Google LLC) — In-app usage analytics and aggregate performance telemetry to monitor platform stability and feature adoption.
  • Google Gemini API (Google AI) — AI-powered visual receipt text extraction, financial statement parsing, and text/voice Smart-Fill prompt parsing. Files and prompt text are processed transiently in-memory for real-time form auto-fill and transaction extraction, and are not retained or used for model training.
  • Stripe — Secure payment processing for premium subscriptions on web browsers.
  • Google Play Billing — Secure in-app payment processing for premium subscriptions within the Android app version.
  • Formspree — Contact form submission handling.

Data Storage & Security

Your data is stored securely on Google Cloud (Firebase) servers. All data in transit is encrypted using HTTPS/TLS. Authentication tokens are managed by Firebase Authentication with industry-standard security practices.

While we implement appropriate security measures, no method of electronic storage or internet transmission is 100% secure. We cannot guarantee absolute security of your data.

The app also uses local storage and standard session identifiers (such as Google Analytics "_ga" cookies) to cache your budget entries, preferences, and authentication state locally on your device. This enables offline access, instantaneous navigation, and seamless syncing. When you are signed in, local budget changes are securely synchronized with our servers once you go back online. If you are using the app as a guest, your financial data remains solely in your browser's local storage.

Email/password accounts that have not completed email verification within 7 days of registration are automatically and permanently deleted by a scheduled process. You will receive a verification email upon sign-up; if you do not verify within this window, you may re-register at any time.

Your Rights

You have full control over your data:

  • Access & Export: You can view all of your budget data within the app at any time.
  • Erase Data: You can erase all budget data from your Profile page — this permanently removes your categories and entries.
  • Delete Account: You can permanently delete your entire account, including all associated data (categories, entries, uploaded receipt files, payment reminders, push notification subscriptions, and planner items), from your Profile page. Any active partner connections are automatically unlinked, resetting shared active balances. Historical settlements remain archived.
  • Manage Subscription: You can cancel, modify, or transfer your premium subscription at any time through the Stripe Customer Portal (for web purchases) or through your Google Play Store account settings under Subscriptions (for Android purchases).

Children's Privacy

Bulga is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated effective date. We encourage you to review this page periodically. Continued use of the app after changes constitutes acceptance of the updated policy.

Contact Us

If you have any questions about this Privacy Policy or how your data is handled, please reach out through our Contact page.