Privacy Policy
Effective Date: August 2, 2026
Our Promise
Your financial data belongs to you, and only you.
We don’t sell it, we don’t advertise against it, and we don’t run analytics or tracking on you. You can export all of it, free, at any time, and you can delete it.
Where Your Data Lives
Your Budget: In Your Account
Building your own budget requires an account, and the data behind it - your plan, categories, accounts, transactions, balance sheet and settings - is stored in our PostgreSQL database on servers we operate. That’s what lets the same budget open on your laptop and your phone, and lets you share it with one other person.
To create an account we store your email address and name, either from the sign-up form or from Google if you sign in that way. Passwords are stored hashed; we never see them in the clear.
Example Budgets: Only in Your Browser
The example households need no account and reach no server. When you open one, the entire app runs against a dataset generated in your browser tab. You can change anything in it - the edits are real, and they are also confined to that tab and gone when you close it. Nothing about an example session is sent to us or stored by us.
Who Else Touches Your Data
We use a small number of outside services, only for the features that need them:
- Your bank (via SimpleFIN) - if you connect bank feeds. Access is read-only and Hierarchy Budget never sees or stores your bank credentials: you authenticate at your bank through SimpleFIN and paste in a token, which we store encrypted. Nothing can move money. See Bank Sync.
- Google (Gemini AI) - if you use the AI-assisted features. Reading a PDF statement, parsing a forwarded receipt, and AI categorization all work by sending the relevant document or transaction text to Google’s Gemini API for processing. If you’d rather no document of yours went to a third party, import CSV or OFX instead and categorize by hand; both work without AI.
- Postmark - handles email. That covers messages we send you, like password resets and verification, and receipts you forward to your personal receipts address.
- Stripe - handles payment if you subscribe. Card details go to Stripe directly; we never see or store them.
- Sentry - error monitoring, self-hosted on our own infrastructure rather than a vendor’s. Crash reports carry technical context about what broke, not your budget.
That’s the whole list. No advertising networks, no data brokers, no analytics platforms.
Sharing With Another Person
If you invite a second person to your household, they sign in as themselves and can read and edit the same budget you can. That’s the point of the feature, but it’s worth stating plainly: an invitation grants a real person real access to your financial data. You can revoke it at any time from Settings > Sharing.
Getting Your Data Out
Export to CSV, Excel and PDF is always available and never behind the subscription - including after a subscription lapses. The CSV is plain text and isn’t locked to this app. See Sharing & Your Data.
Deleting Your Data
Start the plan over in Settings > Data clears your plan. To delete your account and everything in it, email support@hierarchybudget.com and we’ll remove it. Export first if you want a copy - deletion has no undo.
What We Don’t Do
- We don’t sell your data.
- We don’t track you with analytics.
- We don’t show ads.
- We don’t use your financial data to train AI models.
Questions
Email support@hierarchybudget.com.