This website is under construction
Smart Chat Budget

Privacy Policy

Last updated: 2 August 2026

This policy explains what personal data Smart Chat Budget collects, why we collect it, who we share it with, and the rights you have over it. It applies to the web application and the Android application.

1. Who is responsible for your data

The controller of the personal data described in this policy is [COMPANY NAME TO COMPLETE], [LEGAL FORM AND REGISTRATION NUMBER TO COMPLETE], with its registered office at [ADDRESS TO COMPLETE].

For any question about this policy or to exercise your rights, contact us at [CONTACT EMAIL TO COMPLETE].

2. What we collect

Account data: your email address, your username, an irreversible hash of your password (we never store the password itself), your preferred language and your preferred interface theme.

Budget data: the budgets you create or join, their name, type, target amount, currency, member list and categories.

Financial entries: the expenses and incomes you record — amount, description, date, category — and any receipt images or PDF invoices you attach to them.

Chatbot data: the messages you send to the AI assistant, the assistant's replies, and the images, PDF documents or voice recordings you attach to a message.

Subscription data: if you subscribe, your PayPal subscription identifier, its status and the history of payments made through it. We never see or store your card or bank details.

Usage data: your AI token balance and consumption counters, and the feedback you choose to send us, including any images attached to it.

Technical data: the UTC offset of your device, sent so that your dates are displayed in the timezone in which you recorded them, and server logs containing a correlation identifier, your user identifier and the requested action.

3. Why we process it and on what legal basis

To provide the service — creating budgets, recording expenses and incomes, running the AI chatbot, synchronising data in real time between members. Legal basis: performance of the contract between you and us.

To authenticate you and secure your account — verifying your email address, resetting your password, detecting abuse. Legal basis: performance of the contract and our legitimate interest in keeping the service secure.

To bill the premium subscription and manage cancellations. Legal basis: performance of the contract.

To keep technical logs allowing us to diagnose incidents. Legal basis: our legitimate interest in operating a reliable service.

To send you transactional emails — email verification, password reset. Legal basis: performance of the contract.

4. Artificial intelligence and third-party processing

When you use the chatbot, the content of your message — including the text, images and PDF documents you attach — is sent to our AI provider so that it can be analysed and an expense extracted from it. Depending on the configuration in force, that provider is OpenAI or Anthropic.

When you send a voice message, the audio is sent to OpenAI Whisper for transcription. Only the resulting transcription is then passed to the chat model.

These providers process the data on our behalf in order to return a result. We do not authorise them to use your content to train their models.

Do not send the chatbot information you do not want to be transmitted to a third-party AI provider — in particular identity documents, health data or full bank details.

5. Other recipients

PayPal, for subscription creation, renewal and cancellation, and for payment processing. PayPal acts as an independent controller for the payment data it collects directly from you.

Our email provider, for sending transactional emails.

Our hosting provider, which operates the servers on which the application and the database run.

We do not sell your data and we do not share it with advertisers.

6. Shared budgets

A budget can be shared with other users through its secret key. Every member of a budget can see the expenses, incomes, categories and chat messages of that budget, including your username on the entries you created.

Only the administrator of a budget can see its secret key, remove members or delete the budget.

Before sharing a secret key, make sure you trust the person you are giving it to.

7. Cookies

We use two cookies, both strictly necessary to operate the service: a short-lived access token and a refresh token used to keep you signed in.

These cookies are HttpOnly — they cannot be read by JavaScript — and are sent with the Secure flag over HTTPS in production.

We do not use advertising cookies, analytics cookies or third-party trackers.

8. How long we keep your data

Your account data and your budgets are kept for as long as your account exists.

When a budget is deleted, all its expenses, incomes, chat messages, recurring entries and period settings are deleted with it.

Server logs are kept for a limited period for diagnostic purposes.

Data required to meet accounting or tax obligations relating to a subscription is kept for the period required by law.

9. Your rights

You have the right to access your data, to have it corrected, to have it erased, to restrict or object to its processing, and to receive it in a portable format.

You may withdraw your consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out beforehand.

To exercise these rights, write to [CONTACT EMAIL TO COMPLETE]. We will reply within one month.

If you consider that your rights have not been respected, you may lodge a complaint with your national data protection supervisory authority.

10. Security

Passwords are stored hashed with BCrypt and are never readable, including by us.

Access to the API requires a signed authentication token, and every request checks that you are a member of the budget concerned.

Traffic is encrypted in transit with TLS.

No system is perfectly secure. If you believe your account has been compromised, change your password and contact us.

11. Children

The service is not intended for children under 16. If you believe a child has created an account, contact us so that we can delete it.

12. Changes to this policy

We may update this policy. The date at the top of this page indicates the last revision. In the event of a significant change, we will inform you by email or through a notice in the application.