Privacy Policy
Effective May 22, 2026
HansonsBudget is a free personal-finance web app that helps you understand your money and decide your next best move. This page explains what we collect, why, and your choices. By using HansonsBudget, you agree to this policy.
HansonsBudget is an educational personal-finance tool and does not provide financial, investment, tax, or legal advice. For decisions that need professional judgment, talk to a qualified fiduciary advisor.
Information you provide directly
- Account information. Your email address and password. Passwords are handled by our authentication provider and stored only as secure hashes — we never see your plain-text password.
- Profile and preferences. Your pay schedule, take-home pay, savings goals, retirement-plan inputs, budget targets, persistent notes you save, and any category overrides you make.
- Quiz and chat content. Answers to in-app quizzes (e.g., the credit-card decision tree) and messages you send to the AI assistants.
- Recommendation history. Past “Next Money Move” allocations and similar outputs we generate from your inputs.
- Page feedback. Feedback messages, optional ratings, and an optional email address when you submit feedback from a page in the app or a public tool.
Information collected through connected accounts
When you link a financial account, you authorize the connection through Plaid Inc. — your bank credentials are entered directly with Plaid and never touch our servers. From Plaid we receive:
- Account names, types, masks (last four digits), and balances
- Transactions (date, amount, merchant, category) for the accounts you connect
- Institution metadata (the bank's name and logo)
We do not receive or store your bank username or password. Plaid's separate handling of your data is governed by the Plaid End User Privacy Policy.
How we use your information
- To show your accounts, transactions, budget, net worth, and retirement projection.
- To generate plain-English recommendations — most notably the Next Money Move allocator — using rule-based logic grounded in your data.
- To power the in-app AI features — the money coach, AI categorization, and the monthly summary — using Anthropic's Claude API. These are off until you turn them on: the app asks for your permission in the coach before any of your data is sent, and you can withdraw it any time under Money Profile → Account. When enabled, we send Anthropic your questions and the financial details needed to answer them: budget lines and spending totals, goals, merchant names from transactions, and notes you save with the coach. We never send your bank login — connecting a bank is read-only and credentials never pass through HansonsBudget. Anthropic processes this data as a service provider under our agreement with them, is contractually required to protect it, and does not use it to train its models.
- To operate, secure, debug, and improve the service.
- To review feedback you choose to submit about a page or tool.
- To communicate with you about your account.
How your data is stored and protected
- User financial data lives in a Postgres database hosted by Supabase with row-level security so each user can only access their permitted rows. Page feedback is stored in a private inbox available only to authorized review code and administrators.
- Plaid access tokens are encrypted at rest with AES-256-GCM.
- All traffic is encrypted in transit over HTTPS/TLS.
- We never store your bank username or password — Plaid handles authentication directly.
No internet-connected service is perfectly secure. We do our best and will tell you promptly if something material happens.
Who can see your data?
Other users can never see your information. Every person's financial data and conversations with the AI are isolated at the database level by row-level security, so when you sign in, the app can only ever read rows that belong to you. There is no screen — for other users or for us — that lists another person's money or chats.
Being straight with you about our own access: HansonsBudget is not end-to-end encrypted, and someone has to operate the database the app runs on. That means our team technically has the ability to access stored data directly — the same as the team behind essentially any finance app that isn't end-to-end encrypted. We hold ourselves to a simple rule: we don't browse your data. We open an individual account only when it's necessary to fix a bug or respond to a support request you've made, and we'll ask first when it's tied to your account. We never look out of curiosity, and we never use your data for anything beyond running and improving the product for you.
We're not end-to-end encrypted on purpose: the features people rely on — categorizing your transactions, the monthly summary, and the AI assistants — have to read your numbers on our servers to work at all. Your data is encrypted in transit (HTTPS/TLS), and sensitive secrets like Plaid access tokens are encrypted at rest. The trusted providers that help us run the app — including Anthropic for the AI features — are listed under “When information may be shared” below, each bound by their own privacy commitments and none of them permitted to use your data for their own purposes.
What HansonsBudget does not do
- We do not sell your personal or financial data.
- We do not use your financial data for advertising or for any party outside the service providers needed to run the product.
- We do not store your bank login credentials.
- We do not provide personalized investment, tax, or legal advice.
- We do not act as a financial advisor, broker, lender, bank, or fiduciary.
When information may be shared
We share data only with the service providers needed to run the product, each governed by their own privacy commitments:
- Plaid — bank-account connections and transaction sync.
- Supabase — managed Postgres database and user authentication.
- Vercel — application hosting and edge delivery.
- Anthropic — AI features (assistants, monthly summary).
- PostHog — product analytics, when analytics is enabled in our deployment.
- Google Analytics — visitor measurement on our public marketing pages only. It is not loaded on your dashboard.
- Resend — transactional and opted-in check-in email delivery.
We may disclose information if required by law (e.g., a valid subpoena), or to protect the rights and safety of HansonsBudget or its users.
Affiliate and referral partners
HansonsBudget may earn a referral fee or commission if you click a partner link and sign up for certain products (for example, a high-yield savings account, credit card, tax software, or investing platform). We do not pass your personal or financial data to those partners just because you clicked a link — a partner receives information only after you choose to sign up directly with them under their own terms and privacy policy. See our Affiliate Disclosure and How HansonsBudget Makes Money pages for the full picture.
Cookies and analytics
We use cookies set by our authentication provider to keep you signed in and to protect your session. When analytics is enabled in our deployment, we use PostHog to record page views and selected product events. Our configuration disables automatic capture of form and input data, because financial inputs can be sensitive.
We also use Google Analytics, but only on our public marketing pages — the home page, the calculators, and the content pages. It is deliberately not loaded once you are signed in, so the pages you visit inside your dashboard are never reported to Google. Where it does run, we send the page path only, never the query string, and IP addresses are anonymised.
Your choices and data deletion
You can review, correct, export, or delete your data at any time:
- Disconnect a bank. In Settings, remove any connected institution. This stops new transactions from syncing and revokes our access token for that bank.
- Delete your account. Email us at [email protected] and we will delete your personal and financial data from our systems, subject to short-term backup retention and any legal obligations.
- Request a copy. Email the same address and we will export your data.
Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA. We honor those rights.
Children's privacy
HansonsBudget is not directed to children under 18, and we do not knowingly collect data from anyone under 18. If you believe a child has provided us with personal information, email us and we will delete it.
Updates to this policy
We may update this policy as the product evolves. Material changes will be reflected by a new effective date at the top of this page, and we'll notify signed-in users by email when the change is significant.
Contact
Questions about this policy or about your data? Email us at [email protected].