Privacy policy

How befinely handles personal data.

This policy describes the data used to provide the budgeting service, why it is processed, how long it is kept, and the choices available to users.

befinely does not sell personal data. It does not store full payment card details. Selected high-risk text fields use application-level encryption, while transport and infrastructure controls protect the service more broadly.

1. Data we process

  • Account data: name, email address, authentication records, locale, timezone, and account settings.
  • Budgeting data: user-created accounts, transaction records, categories, tags, budgets, goals, plans, notes, and household membership.
  • Subscription data: customer, order or transaction, subscription, plan, status, and payment event identifiers from the selected payment provider. Full card numbers are not provided to befinely.
  • Security and support data: session and refresh token records, timestamps, audit events, technical logs, and messages sent to support.
  • Device and network data: IP address and browser request metadata where needed for authentication, security, and abuse prevention.

2. Why we process data

  • Perform the contract by creating accounts, storing records, generating reports, and delivering subscription access.
  • Protect legitimate interests in security, fraud prevention, debugging, service reliability, and customer support.
  • Meet legal obligations for billing, tax records, lawful requests, and dispute handling.
  • Send optional product communications when consent is required and provided.

3. Sharing and processors

Data is shared only as needed to operate the service or comply with law. Service providers may include hosting and database infrastructure, Cloudflare for network delivery and protection, transactional email providers, monitoring services, and the supported Merchant of Record selected at checkout for payment, tax, receipts, subscription management, and refunds.

Household data is visible to members invited to that household according to application permissions. We do not disclose it to other customers.

4. Storage, encryption, and location

Production traffic uses HTTPS. At the application level, the current encrypted field registry covers user email and name, transaction notes, and selected account details. Searchable email lookup uses a keyed blind index. Not every database field is encrypted at the application layer, and we do not claim that it is.

Processors may handle data in countries outside your residence. Where required, transfers rely on appropriate contractual or legal safeguards.

5. Retention

  • Active account and budgeting data is retained while the account is active.
  • When deletion is requested, the account is disabled and scheduled for permanent purge after a 30-day restoration period.
  • Revoked authentication tokens are cleaned up after their operational retention window, including a 30-day cleanup threshold for revoked tokens.
  • Billing, security, and audit records may be retained longer when reasonably necessary for tax, fraud prevention, dispute resolution, or legal compliance.
  • Backups expire through infrastructure rotation and are not restored to create an active account after deletion, except where required for disaster recovery or law.

6. Your rights and choices

Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing, and to complain to a data protection authority. Profile settings allow correction of common account information and scheduling of deletion. Other requests can be sent to privacy@befinely.com.

We may need to verify identity before completing a request. We will respond within the period required by applicable law.

7. Children

befinely is not directed to children who cannot legally consent to online services in their jurisdiction. Do not create an account for a child unless you are authorized and applicable law permits it.

8. Changes and contact

Material policy changes will be posted on this page and may also be communicated in the service. Privacy questions can be sent to privacy@befinely.com.