Privacy Policy
Last updated: August 25, 2026
This Privacy Policy explains how RetroBudget: AI Spend Tracker (“RetroBudget,” “the app,” “we,” or “I”) handles information. RetroBudget is built and maintained by Pushpinder Pal Singh, an independent developer.
The short version
- RetroBudget never asks for your bank password and does not connect to live bank accounts.
- You choose which supported credit-card statement PDFs to import.
- PDFs shared through the iOS share extension are held temporarily in the app's App Group container while they wait to be imported or retried.
- Imported PDFs and the spending records created from them are stored in your iCloud-backed app storage until you delete the statement in RetroBudget.
- The marketing website sends limited page and interaction analytics to PostHog. Automatic interaction capture and session recording are disabled, and the website never receives your statement PDFs.
- We do not sell your information or use it for advertising.
Information you provide
Statement PDFs and financial information. When you import a supported credit-card statement PDF, RetroBudget reads the document to identify available transaction, merchant, card, date, and amount information and create a spending breakdown. The original PDF and extracted records are saved in your iCloud-backed app storage so you can view the statement and its results in the app.
Account information. If you use Sign in with Apple, Apple provides a unique account identifier and may provide a name or relay email address. RetroBudget uses this to authenticate backend services and sync categories. We never receive your Apple password.
Categories and settings. Your selected and custom spending categories, plus app preferences, are stored to provide the app and may be synced through the services described below. Category names and IDs are sent with statement-processing requests so the returned transactions can be assigned to your selected categories.
How statement processing works
A supported credit-card statement PDF is sent over an encrypted connection to RetroBudget's Cloudflare Worker and then to the configured AI processing provider. The live production deployment selected OpenRouter when verified on August 8, 2026, and the repository configuration defaults to OpenRouter. A deployment can explicitly select OpenAI instead. The request also includes category names and IDs for category matching. The application handles the request synchronously and does not intentionally write statement PDFs, extracted transactions, provider responses, or parsing annotations to its configured D1, KV, R2, or queue storage. Cloudflare platform or edge logging outside the repository's disabled Workers Logs configuration has not been independently inventoried.
When OpenAI is selected, RetroBudget sends Responses requests with store: false, which disables OpenAI response-state storage. This setting does not independently confirm whether OpenAI's limited abuse-monitoring retention or Zero Data Retention controls apply to the RetroBudget organization. We do not make a zero-retention claim for the AI provider.
When OpenRouter is selected, RetroBudget sends the PDF through OpenRouter's file-parser plugin, configured with the engine identifier cloudflare-ai. The request asks for no-data-collection and Zero Data Retention routing, but those flags are not a verified retention guarantee. RetroBudget has not independently verified the underlying parser operator or its retention behavior.
Service providers and retention
| Information | Where it is handled | Retention or deletion |
|---|---|---|
| Statement PDFs and extracted spending records | Apple iCloud and CloudKit-backed app storage | Remain until you delete the statement in RetroBudget. |
| PDFs shared through the iOS share extension | RetroBudget App Group storage on your device | Unprocessed files remain for retry. After a successful import, the file is removed and its processed marker normally remains for up to 24 hours; it can remain longer if cleanup cannot remove the file. |
| Statement processing request | Cloudflare Worker and the selected provider: OpenAI or OpenRouter | Worker memory lasts only for the request. Provider retention is governed by the provider controls and agreement described above. |
| Account, category, and refresh-token data | RetroBudget backend on Cloudflare | Account and category records support the service. Refresh-token revocation entries expire after at most 30 days. |
| App usage and diagnostic events | PostHog and Apple MetricKit summaries | Retention depends on the configured PostHog project settings and Apple's applicable service behavior; no fixed retention period is claimed here. |
| Marketing-site page and interaction events | PostHog, reached through RetroBudget's /ingest proxy | Events use an anonymous browser identifier. Retention depends on the configured PostHog project settings, and the identifier can remain in browser storage until that storage is cleared. |
| Subscription status | RevenueCat and Apple | Retained under RevenueCat and Apple's applicable service terms to provide purchases and restore access. |
Usage data and diagnostics
The RetroBudget app and backend use PostHog for product interaction events, and the app receives aggregate MetricKit diagnostics such as crash, launch, memory, and responsiveness summaries. After sign-in, these events can be associated with a pseudonymous app-specific identifier; they are not anonymous or unlinked. Event properties are designed to exclude statement contents, transaction names, merchant names, statement filenames, and PDF data.
The marketing website uses PostHog for page views and deliberately named interactions such as App Store clicks, FAQ expansions, and guide navigation. These events use an anonymous browser identifier and are not connected to Sign in with Apple in the current website. Automatic interaction capture and session recording are disabled. Before an event is sent, the website removes URL query strings and fragments, page titles, and FAQ question text.
How we use information
- To authenticate you and provide category synchronization.
- To process statements you choose to import and display spending analysis.
- To provide subscriptions, notifications, and Live Activity updates you use or opt into.
- To diagnose reliability issues and improve the app and marketing website.
Data sharing
We do not sell personal information or use it for advertising. We share information only with service providers needed to operate RetroBudget: Apple (Sign in with Apple, iCloud, CloudKit, notifications, and purchases), Cloudflare (backend processing), the selected AI provider (OpenRouter by repository default, or OpenAI when explicitly configured), PostHog (analytics), and RevenueCat (subscriptions). Each receives only what is needed for its role.
Security
RetroBudget uses encrypted network connections for statement processing. No method of transmission or storage is completely secure, so please use a device and Apple account you trust and keep both protected.
Your choices and rights
You can delete an imported statement from RetroBudget, which removes its PDF and parsed records from the app's iCloud-backed storage. Depending on where you live, you may also have rights to access, correct, or delete personal information held by RetroBudget's backend. Contact us to make a request.
Children's privacy
RetroBudget is not directed to children. If you believe a child has provided personal information, contact us so we can help address the concern.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date at the top of this page.
Contact
Questions about this policy or your data? Reach out to sayhi@swiftlysingh.com.