Privacy Policy
Last Updated: September 19, 2026
Operator / seller: Gallahadd Software LLC. Contact: [email protected].
SAFE Budget is designed so the developer cannot read your financial ledger.
The app has no SAFE Budget account service, advertising system, analytics service, or developer-operated ledger server.
Readable financial data is processed on your devices. When CloudKit is available, ledger values sync through encrypted CloudKit fields and attachments use CloudKit assets.
1. The Short Version
- The developer does not receive your readable balances, transactions, budgets, receipts, bank login, or provider credentials through the app.
- CloudKit encrypts designated ledger fields on the device before upload. Limited identifiers, routing fields, timestamps, and sync/share metadata remain available to Apple systems so they can store, route, and reconcile records.
- SAFE Budget includes no advertising, cross-app tracking, or developer-operated product analytics.
- Optional features communicate with Apple, SimpleFIN, Plaid, public government data sources, DuckDuckGo, invited household members, or your chosen export/support destination only when you use those features.
- Your Apple Account controls CloudKit access. Face ID, Touch ID, or your device passcode protects access to the local app.
2. Data SAFE Budget Stores
SAFE Budget can store information you enter, calculate, or import, including accounts, balances, transactions, budgets, bills, loans, savings goals, categories, tags, receipts, household membership, provider connections, and app preferences.
On iPhone and iPad, local ledger files use Apple’s complete file-protection class inside the app sandbox. On Mac, the app sandbox and platform/FileVault configuration protect local files. When CloudKit is available, designated ledger values use CloudKit encrypted fields and attachments use CloudKit assets.
While a household is unlocked, SAFE Budget maintains a separate plaintext query index on that device for sorting, search, and graphs. The index never syncs to CloudKit, is excluded from device backups, and is cleared when the app locks or logs out.
3. Information the Developer Does Not Receive Automatically
- No readable ledger, bank login, or provider credential is sent to the developer.
- No advertising identifier, cross-app tracking data, or developer product-analytics event is collected.
- No developer crash-analytics or telemetry service is included.
4. Optional Third-Party Services
When you enable optional features, your device may communicate directly with:
- Apple — iCloud, CloudKit, Keychain, FinanceKit (iPhone), App Store, on-device Foundation Models
- SimpleFIN / Plaid — optional bank connections you authorize; credentials stay in Keychain; no developer relay or webhook receiver
- Public data providers — FHFA, Census, HUD/Esri, NHTSA, FuelEconomy.gov, ECB, BLS, Treasury (only when you use those tools)
- DuckDuckGo — optional merchant-cancellation search you initiate
- Support email — only what you voluntarily send to [email protected]
5. Household Sharing
A household owner can grant a named participant access through Apple’s private CloudKit sharing. Revoking a participant removes server-side share access going forward but cannot recall information already viewed or exported.
6. Exports, Reset, and Erasure
Settings provides supported exports and passphrase-protected backups. Reset this device keeps the CloudKit household. An owner using Erase all data removes local data and requests deletion of the private CloudKit zone.
7. Children
SAFE Budget is not directed to children under 13. We do not knowingly collect personal information from children through a Gallahadd backend.
8. Contact
Privacy requests: [email protected] or
SAFE Budget Support.
© 2026 Gallahadd Software LLC. This privacy policy is effective as of September 19, 2026.