Eden Budget
  • Method
  • Features
  • Pricing
  • Guide
Log InStart Free Trial

Legal

Privacy Policy

What Eden Budget collects, why, who else sees it, and how long we keep it.

Effective August 5, 2026. Operator: Eden Living LLC, an Oklahoma limited liability company, 9905 S Pennsylvania Ave, Ste A, Oklahoma City, OK 73159. Privacy contact: support@edenbudget.com.

In one paragraph. Eden Budget collects only what we need to run your budget for you. We never sell your data. We do not share it with advertisers. We do not run third-party analytics or session replay. Angel runs on our own servers and never sends your conversations to OpenAI, Anthropic, Google, or any other third-party AI provider. We delete account, financial, and receipt data 24 months after you cancel.

1. Scope and your relationship with us

This Privacy Policy describes how Eden Living LLC handles personal information when you visit the Eden Budget website, create an account, use the Service, or contact support. By using Eden Budget you agree to this Policy. If you do not agree, do not use the Service.

Because Eden Budget collects financial-account information from you and from your bank, our handling of that information is also subject to applicable financial-privacy law (including the Gramm-Leach-Bliley Act where it applies to us as a service provider to consumers). The disclosures in this Policy are intended to satisfy our notice obligations under those laws.

2. Collection, use, and disclosure

This section describes the categories of information we collect, where we get it, why we use it, and the parties with whom it may be shared.

What we collect

  • Account registration data. Email address, password (stored only as an Argon2id hash), display name.
  • Authentication artifacts. TOTP secret (encrypted), WebAuthn public credentials, OAuth identifiers if you sign in through a provider you have configured. We do not receive or store biometric data; if you use a fingerprint or face sensor to unlock a passkey, that data stays on your device. See Security page for details.
  • Login and security events. Timestamps, IP address, user-agent, success/failure status, and the email attempted (used to detect credential-stuffing and lock compromised accounts).
  • Subscription and billing. Plan tier (monthly or annual), the last four digits of your payment card, the card brand, a non-reversible processor token, the billing IP and user-agent. We never see your full card number or PayPal credentials.
  • Profile and household. Family-plan member names and emails (only the ones you invite), display preferences, home-layout choices.
  • Manual financial data. Accounts, transactions, categories, scheduled transactions, goals, payees, payee rules, saved filters, payee favorites, account notes, budget assignments, template directives.
  • Bank-linked financial data. If you connect an institution via SimpleFIN: account balances, account types, posted and pending transactions, transaction descriptions, and the organization name returned by your bank. The SimpleFIN access URL itself is sealed with AES-256-GCM at rest.
  • Receipts. Photos or PDF documents you choose to upload and attach to a transaction, plus their content type and size.
  • Angel chat content. The text of the question you submit to Angel and the response generated for you. Angel runs on a self-hosted LLM operated by Eden Living LLC; prompts and responses are not retained long-term (see Retention below) and are never sent to any third-party AI vendor.
  • Support communications. Emails, in-app messages, and any attachments you send to us.
  • Cookies and local storage. A first-party session cookie (encrypted, HttpOnly, SameSite=Lax, Secure in production), and a small amount of browser local storage used to remember UI preferences (sidebar group toggles, theme). We do not use third-party cookies, advertising cookies, or cross-site tracking cookies.
  • Server logs. Request paths, response codes, latency, and error stack traces. We deliberately avoid logging request or response bodies for endpoints that carry personal data.

What we do not collect

  • Biometric identifiers.
  • Precise geolocation (we derive only an approximate region from your IP for security and audit purposes).
  • Information about your political views, religion, ethnicity, sexual orientation, or health, unless you choose to type it into a free-text field such as a memo, account note, or Angel prompt.
  • Government-issued identification numbers (no SSN, no driver's license number, no passport number).
  • Behavioral tracking data sold or shared with advertisers.

Where we get it

  • Directly from you, when you create an account, enter a transaction, upload a receipt, message Angel, invite a family-plan member, or contact support.
  • From your linked institutions, through the SimpleFIN access URL you authorized.
  • From your payment processor (PayPal or Helcim) on successful charges or refunds.
  • Automatically from your browser or device when you interact with the Service (IP address, user-agent, timestamps).

How we use information

  • To provide and operate Eden Budget: authenticate you, render your budget, sync linked accounts, generate Angel responses, charge your subscription, send receipts.
  • To improve the Service: fix bugs surfaced by error logs and study aggregated, non-identifying trends in feature adoption.
  • To secure the Service: detect credential stuffing, block brute-force attempts, lock compromised accounts, investigate abuse reports.
  • To communicate with you: transactional emails (security alerts, password resets, receipts, billing notices, legal notices), and, only if you opt in, occasional product updates.
  • To comply with law: respond to lawful requests, enforce our Terms, defend ourselves against claims.

We practice data minimization: we collect what we need to operate the Service for you and avoid collecting anything else. Where a feature can work without collecting an additional field, we choose not to collect it.

Legal bases (UK, EEA, Switzerland)

Where the GDPR or UK GDPR applies, we rely on these legal bases: performance of the contract between you and us, our legitimate interests (operating, securing, and improving the Service), legal obligations (tax, regulator response), and your consent (for optional features such as marketing emails and SimpleFIN linkage). You may withdraw consent at any time.

Who receives information

  • Service providers (subprocessors): Hetzner Online GmbH (hosting in Ashburn, Virginia, United States), Cloudflare, Inc. (encrypted off-site backup storage), SimpleFIN Bridge (bank aggregation, only if you opt in), PayPal Holdings, Inc. (payment), Helcim, Inc. (payment).
  • Family-plan members you invite: the people you add to a shared plan can see the shared plan's transactions, categories, budgets, and other shared content. They cannot see your password, two-factor secrets, billing information, or any separate private plan you maintain.
  • Successor entities: if Eden Living LLC merges, is acquired, sells assets, or otherwise transfers the Service, the successor receives information subject to the protections of this Policy.
  • Law enforcement and regulators: only in response to a legally valid request, or where we have a good-faith belief that disclosure is necessary to protect rights, property, or safety. We will resist overbroad requests and challenge gag orders where lawful.

What we never do. We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not run third-party behavioral analytics or session-replay tools. We do not send your data to AI training pipelines.

Automated decision-making and AI

Eden Budget does not use automated decision-making to produce legal or similarly significant effects about you. Angel and the automatic payee-rule engine assist you; they do not gate access to features, credit, employment, or anything outside the app. Angel runs on Eden Living LLC's own LLM server on a private LAN; your conversations are not used to train any model and are not transmitted to any third-party AI vendor. You may avoid using Angel entirely; nothing else in the app depends on it.

3. Cookies, local storage, and Do Not Track

We use a single, first-party encrypted session cookie to keep you logged in. The cookie is HttpOnly, SameSite=Lax, and (in production) Secure. "Remember me" extends the cookie lifetime to 30 days; otherwise the cookie ends with the browser session. We also store a small amount of UI state in browser local storage (sidebar toggles, theme). We do not use third-party cookies, advertising cookies, or cross-site trackers. Because we do not engage in tracking that would be covered by Do Not Track, we treat DNT and Global Privacy Control signals as confirmation of the default behavior.

4. Data retention

  • Account and financial data: retained while your subscription is active and for 24 months after cancellation. After 24 months we automatically delete account, financial, and receipt data, unless a legal hold or active dispute requires longer retention.
  • Login and security events: retained for 24 months, then deleted.
  • Support emails: retained for 36 months from the last contact, then deleted.
  • Angel conversations: prompts and responses live in memory only for the duration of the request and are discarded once the answer is delivered; we do not maintain a persistent chat history.
  • Encrypted database backups roll off on a 30-day window.
  • Email address (only): retained after deletion solely as a record that the account was deleted, so we can confirm the deletion if you ask. You may request removal of that residual record.
  • Account deletion: when you request deletion from Settings, your data is held for 14 days during which you may cancel the request; after that, removal proceeds on the schedule above.

5. Security

We use industry-standard administrative, technical, and physical safeguards to protect your personal information, including encryption in transit (TLS 1.2 or higher), encryption at rest for sensitive secrets (AES-256-GCM), Argon2id password hashing, optional TOTP and WebAuthn passkeys, server-side session management, rate limiting, and brute-force protection. Full details are in our Security page. No system is perfectly secure; we cannot guarantee absolute security, but we will tell you when something goes wrong (see Section 6).

6. Breach notification

If we discover unauthorized access to your personal information, we will notify the affected account holders within 72 hours of confirmed discovery, by email, and we will publish a public post-mortem describing the scope, the root cause, the remediation, and the prevention plan. Where required by law we will also notify the applicable regulator.

7. Third-party applications and integrations

If you connect an institution via SimpleFIN, the SimpleFIN service receives the authorization you grant at your bank and returns an access URL. SimpleFIN's handling of your bank credentials is governed by its own terms and privacy policy. Eden Budget never sees your bank login credentials; we only see the read-only access URL SimpleFIN returns. You may revoke that URL at any time from Manage Connections.

Eden Budget does not expose your account data to third-party plug-ins, browser extensions, or AI assistants beyond the integrations described in this Policy.

8. Children's privacy

Eden Budget is not intended for children. We do not knowingly collect personal information from children under 13 (or under 16 for residents of the EEA or the UK). If you believe a child has provided personal information to the Service, contact support@edenbudget.com and we will delete it promptly.

9. Your rights and choices

Depending on where you live, you may have the following rights:

  • Access - request a copy of the personal information we hold about you.
  • Correction - ask us to fix inaccurate data. You can correct most data directly inside the app.
  • Deletion - delete your account from Settings, or email support@edenbudget.com.
  • Portability - export your transactions, budgets, and other Eden-stored data in a machine-readable format from Settings.
  • Restriction or objection - ask us to pause processing pending verification of a dispute.
  • Withdraw consent - disconnect SimpleFIN, unsubscribe from marketing email, or remove an integration at any time.
  • Lodge a complaint - with your local data-protection authority, if applicable.

To exercise any of these rights, email support@edenbudget.com from the address on your account. We may need to verify your identity before fulfilling sensitive requests. We will respond within 30 days, or 45 days where applicable law permits an extension with notice. Residents of U.S. states with comprehensive privacy laws have additional rights in Section 10.

10. State-specific rights (U.S.)

This Section supplements the rest of this Policy with additional disclosures and rights for residents of U.S. states that have comprehensive consumer-privacy laws. Where this Section conflicts with the general Policy, this Section controls for the residents it covers.

10.1 Who this Section applies to

You may rely on this Section if you are a resident of a U.S. state that has enacted a comprehensive consumer privacy law. As of the effective date, those states include California (CCPA / CPRA), Colorado (CPA), Connecticut (CTDPA), Virginia (VCDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), Indiana (CDPA), Tennessee (TIPA), Delaware (DPDPA), New Hampshire (NHPA), New Jersey (NJDPA), Nebraska (NDPA), Maryland (MODPA), Minnesota (MCDPA), Rhode Island (RIDTPPA), and Kentucky (KCDPA). We apply rights from subsequent state laws as they take effect.

10.2 Notice at collection (California)

This Section serves as the "notice at collection" required by the California Consumer Privacy Act for personal information collected from California residents. We collect the categories listed in Section 2, for the business and commercial purposes listed in Section 10.4, and retain that information for the periods described in Section 4. We do not sell or share personal information for cross-context behavioral advertising.

10.3 Categories of personal information collected

In the past 12 months, Eden Budget has collected the following categories under California Civil Code section 1798.140 and analogous state statutes:

  • Identifiers - name (if provided), email address, account ID, IP address, user-agent.
  • Customer records - billing information (last 4 of card, card brand, billing IP, processor token), subscription tier, family-plan membership.
  • Commercial information - purchase history, refund history, plan-change history.
  • Internet or other network activity - login events, request logs, error logs, in-app UI preferences.
  • Audio, visual, or similar information - receipt images or PDFs you upload.
  • Sensitive personal information - account login credentials in combination; financial-account information; contents of communications (Angel prompts) where you choose to include them.
  • Inferences - categorization labels you assign to transactions, plus patterns the payee-rule engine derives from those labels.

10.4 Business and commercial purposes

We use the categories above for the purposes defined under California regulation 11 C.C.R. § 7012:

  • Providing, operating, and maintaining the Service you signed up for.
  • Customer support and account management.
  • Detecting security incidents and protecting against malicious or illegal activity.
  • Debugging and fixing intended functionality.
  • Short-term, transient use to render the page you requested.
  • Auditing related to interactions with you and compliance with applicable laws.
  • Performing services on your behalf (running your budget, syncing your bank, generating Angel responses).
  • Internal research for service improvement.
  • Complying with legal obligations.

10.5 Sensitive personal information

Eden Budget uses sensitive personal information only for purposes permitted by applicable law without a separate opt-in: providing the Service, ensuring security and integrity, detecting and responding to malicious activity, short-term and transient use to complete a requested transaction, and complying with legal obligations. We do not use sensitive personal information to infer characteristics about you.

10.6 No sale, no share, no profiling

We do not sell personal information. We have not sold personal information in the past 12 months. We do not share personal information for cross-context behavioral advertising. We do not process personal information for profiling that produces legal or similarly significant effects. We do not knowingly sell or share the personal information of consumers under 16 years of age.

10.7 Your state-privacy rights

  • Right to know / access. Request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties to whom we have disclosed it. Look-back is 12 months minimum; we will return the full window where state law requires more.
  • Right to correct. Request that we correct inaccurate personal information.
  • Right to delete. Request that we delete personal information we have collected from you, subject to the legal exceptions in the applicable statute.
  • Right to portability. Receive a copy of your personal information in a structured, commonly used, machine-readable format.
  • Right to opt out of sale, share, or processing for targeted advertising or profiling. Eden Budget does not engage in any of these; the right exists and we honor it by default.
  • Right to limit use of sensitive personal information. You may direct us to limit use of sensitive personal information to the permitted purposes in Section 10.5. This is our default practice.
  • Right to non-discrimination / non-retaliation. We will not deny you service, charge you a different price, provide a different quality of service, or retaliate because you exercised a privacy right.
  • Right to appeal. If we deny a rights request in whole or in part, you may appeal by replying to our denial email or contacting support@edenbudget.com. We respond within 60 days. If we deny the appeal we provide instructions for contacting the relevant state Attorney General or data-protection authority.

10.8 How to submit a rights request

  • Email. Send to support@edenbudget.com from the address on your account, subject line "Privacy Rights Request," with a brief description.
  • In-app. Many requests (export, deletion, correction of in-app data) are available directly in Settings.
  • Mail. Send to Eden Living LLC, 9905 S Pennsylvania Ave, Ste A, Oklahoma City, OK 73159.

Verification. We may need to verify your identity before fulfilling sensitive requests, proportionate to sensitivity. For access and deletion of sensitive information, we may require a second factor.

Timing. We confirm receipt within 10 business days and respond within 45 days, or 90 days where state law permits a single 45-day extension with notice.

Authorized agents. You may designate an authorized agent. The agent must submit signed written permission and we may contact you directly to confirm authority.

10.9 Shine the Light (California Civil Code section 1798.83)

Eden Budget does not disclose personal information to third parties for those third parties' own direct marketing purposes.

10.10 Notice of financial incentive

Eden Budget does not currently offer any financial incentive or price difference in exchange for the retention, sale, or sharing of personal information.

10.11 Request metrics

In the prior calendar year, Eden Budget received fewer than the threshold number of consumer privacy requests that would require us to publish detailed CCPA request metrics under 11 C.C.R. § 7102. Once we cross that threshold we will publish the metrics here.

11. Marketing emails

Transactional emails (security alerts, password resets, receipts, billing notices, legal notices) are required for account safety and cannot be unsubscribed without deleting the account. Any non-transactional product email we send contains an unsubscribe link in the footer; clicking it stops all non-transactional email immediately. You can also email support@edenbudget.com to be removed from product-update mail.

Email addresses you may see from us

  • support@edenbudget.com - replies to your support questions, privacy requests, and any other two-way correspondence. Monitored by a human.
  • no-reply@edenbudget.com - automated transactional notifications (receipts, password resets, security alerts, billing notices, family-plan invitations). Replies to this address are not read; for help, write to support@edenbudget.com instead.
  • info@edenbudget.com - occasional product-update mail when you have opted in. Carries an unsubscribe link in every message.

Mail from any address ending in @edenbudget.com is authenticated with SPF, DKIM, and DMARC; messages claiming to come from Eden Budget that fail those checks are not from us. If you are unsure whether a message is legitimate, do not click any links and forward the message to support@edenbudget.com.

12. Family-plan data sharing

When you invite someone to a family plan, you choose to share the plan's transactions, categories, budgets, and other shared content with that person. They do not see your password, two-factor secrets, billing information, or any separate private plan you maintain. If the plan owner removes a member, the removed member has 30 days from the date of removal to subscribe to their own plan and keep their private data; after 30 days their access ends and their data is removed on the retention schedule above.

Visibility runs one way. The plan owner can read the private plans that members create inside the family plan. Members cannot read each other's private plans and cannot read the owner's. Because every plan a member creates while in a family belongs to that family, a member who wants a plan the owner cannot read has to leave the family plan. We say this plainly here because it is the one place in Eden Budget where another person can see data you did not explicitly share.

13. Deceased users and account inheritance

If an Eden Budget user passes away, an authorized representative (executor, administrator, surviving spouse, or other legally authorized party) may contact us at support@edenbudget.com to request account closure and an export of the account data. We may ask for documentation, such as a death certificate and proof of authority, before fulfilling the request.

14. International transfers

Eden Budget is operated from the United States, with all production data stored on servers in Ashburn, Virginia, United States. If you access Eden Budget from outside the United States, your information will be transferred to, stored, and processed in the United States. For transfers from the UK or EEA, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum, where applicable). You may request a copy of the safeguards by emailing support@edenbudget.com.

15. Changes to this Policy

We may update this Policy from time to time. For material changes, we will notify you at least 14 days in advance by email or by in-product notice. The "Effective" date at the top reflects the most recent update. Earlier versions are available on request.

16. Contact

Privacy questions and rights requests: support@edenbudget.com.

Mailing address: Eden Living LLC, 9905 S Pennsylvania Ave, Ste A, Oklahoma City, OK 73159.

17. Further reading

Security - the technical and organizational controls behind this Policy.

Terms of Service - the agreement governing your use of the Service.

Your Privacy Choices - in-app controls for your privacy preferences.

Questions about this document?

Reach a human at support@edenbudget.com

One inbox for support, privacy, security, accessibility, and legal. We answer every message.

Email support
Eden Budget

A service of Eden Living LLC.

Product

  • Method
  • Features
  • Pricing
  • Guide

Legal

  • Terms of Service
  • Security
  • Privacy Policy
  • Accessibility
  • Your Privacy Choices

Contact

  • support@edenbudget.com
  • One inbox for support, privacy, security, accessibility, and legal.
© 2026 Eden Living LLC · Part of the Eden Living suite