Privacy Policy

Last updated: January 29, 2026

1. Introduction

This Privacy Policy explains how Koala Budget ("we", "us", or "our") collects, uses, and protects your personal information when you use our service.

2. Information We Collect

Account Information

When you create an account, we collect your email address and password. If you sign up via a third-party provider (Google, GitHub), we receive your name and email from that provider.

Financial Data

You may enter financial data including account balances, transactions, budgets, and goals. If you connect a bank via Plaid, we receive transaction data and account balances from your financial institution.

Usage Data

We collect standard log data such as IP addresses, browser type, pages visited, and timestamps to maintain security and improve the service.

3. How We Use Your Information

  • To provide and maintain the service
  • To process your financial data and generate reports
  • To sync bank transactions via Plaid
  • To process payments via Stripe
  • To send transactional emails (account verification, password reset)
  • To detect and prevent abuse or unauthorized access
  • To improve the service based on aggregated, anonymized usage patterns

4. Third-Party Services

We use the following third-party services that may process your data:

  • Plaid — Bank account linking and transaction retrieval
  • Stripe — Payment processing and subscription management
  • Sentry — Error tracking (no financial data is sent)

Each provider operates under its own privacy policy. We only share the minimum data necessary for each service to function.

5. Data Storage and Security

Your data is stored in encrypted databases. We use HTTPS for all communications, and sensitive credentials are never stored in plain text. We follow industry best practices to protect your information, but no method of transmission or storage is 100% secure.

6. Data Retention

We retain your data for as long as your account is active. If you delete your account, we will permanently delete your personal and financial data within 30 days, except where retention is required by law.

7. Your Rights

You have the right to:

  • Access your personal data
  • Export your data in a portable format (CSV)
  • Correct inaccurate information
  • Delete your account and all associated data
  • Withdraw consent for optional data processing

To exercise any of these rights, use the relevant features in your account settings or contact us through our support channels.

8. Cookies

We use essential cookies to maintain your session and preferences (such as language and dark mode). We do not use third-party advertising or tracking cookies.

9. Children's Privacy

The service is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children.

10. International Data Transfers

Your data may be processed in countries other than your own. By using the service, you consent to the transfer of your information to these countries, which may have different data protection laws.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. The 'Last updated' date at the top of this page indicates when the policy was last revised.

12. Contact

If you have questions about this Privacy Policy or how we handle your data, please contact us through our support channels.