Data Retention and Disposal Policy
Budget Factor — last updated August 11, 2026
Purpose
This policy defines how long Budget Factor retains different categories of data, and how that data is disposed of when it's no longer needed.
Retention by data category
| Data category | Retention period |
|---|---|
| Receipt photos | Not retained at all. Processed once by our vision model and discarded immediately when the request completes — never written to any storage. |
| Account, budget, and transaction data (including bank transaction data synced via Plaid) | Retained for the lifetime of the household that owns it. Where a budget is shared between two people, deleting one person's account does not delete the shared budget while the other member still has it. |
| Bank connection credentials (Plaid access tokens) | Retained only for as long as the bank connection remains active on the account. |
Disposal process
Because Budget Factor is currently a single-founder operation without a self-service deletion flow in the app, disposal is a manual process: a user emails a deletion request, and the founder deletes the associated rows directly from the production database. This permanently and irreversibly removes the account, budget, transaction, and bank-connection-credential data for that user — our systems retain no copy and no backup path is used to restore it afterward.
For bank connections specifically: disconnecting a bank explicitly revokes the access token with Plaid before the stored credential is deleted on our side, so the connection is invalidated at Plaid as well as removed from our database. Transactions already imported from that bank remain in the user's own budget until the account itself is deleted.
Shared budgets and abandoned households
Budget data belongs to a household rather than to an individual account, so that a shared budget survives one member deleting their account. When the last member of a household leaves or deletes their account, the household is flagged as abandoned rather than deleted automatically. That is deliberate: an automatic cascade would remove stored bank-connection credentials without first revoking them with Plaid, leaving a live token in existence. Abandoned households are reviewed on a recurring basis; any remaining bank connection is explicitly revoked with Plaid, and the household's data is then permanently deleted.
Legal basis
Data is retained no longer than needed to provide the app's own features, and is deleted promptly on request — consistent with data-minimization and right-to-deletion principles found in applicable consumer privacy laws. Budget Factor does not currently hold a formal legal compliance certification for any specific regulatory framework.
Policy review
This policy is reviewed at least annually, and whenever our data practices change.
Policy owner
David Jensen (founder) — davejensen175@gmail.com
See also our Privacy Policy and Security page.