Draft — pending owner approval. This document is a draft and has not been reviewed or approved by the owner or by legal counsel. It is published for review purposes only and does not yet represent final policy.
The operating entity is shown as Nordic Tug LLC. The contact address proofofbudget@nordictug.me is the confirmed contact.
Proof of Budget is a native personal finance app for iOS, iPadOS, and macOS covering budgets, transactions, subscription and recurring-bill tracking, goals and debt, and Bitcoin on-chain tracking. It is operated by Nordic Tug LLC, referred to here as "we", "us", or "our".
Questions about this policy: proofofbudget@nordictug.me.
We use Sign in with Apple as the authentication method. Apple provides us with a pseudonymous user identifier (the "sub" claim in the Apple identity token). If you choose to share your name or email at sign-in, Apple may relay them; you may also elect to hide your email, in which case Apple provides a private relay address instead of your real one.
If you link a financial institution, we use Plaid to establish and maintain that connection and to sync transactions. Linking produces a Plaid item identifier, an institution label, and a Plaid access token. Plaid collects and processes your institution credentials and financial data directly under its own privacy policy — we do not receive or store your institution login credentials.
Your budgets, transactions, categories, subscriptions, recurring bills, goals, debts, and Bitcoin tracking records are stored on your device. If you enable Apple CloudKit sync, those records sync between your own devices through your personal Apple account (iCloud). CloudKit sync is governed by Apple's privacy policy; we do not operate the CloudKit store and do not receive a server-side copy of these records.
If you purchase a subscription, the purchase is processed by the Apple App Store. We receive entitlement and subscription-tier metadata sufficient to unlock features. We do not receive or store your payment card details.
Our backend is a thin Cloudflare Worker relay for Plaid. The complete set of data it stores is:
What we do not store server-side. We do not store your transaction data, balances, account details, holdings, or investment transactions on our servers. Those financial payloads are fetched on demand and returned to the authenticated caller — they are never persisted and never logged.
Plaid access tokens are never returned to clients and never logged. Log lines are constructed from a strict field allowlist, so no Apple user identifier, client IP address, Plaid item identifier, access token, or financial payload appears in our logs.
We do not use your information for advertising, profiling, or automated decision-making.
We do not sell your data. We do not share financial data with third parties for their own purposes.
You can remove a linked financial institution from within the app. Deleting a linked account removes the Plaid item, which revokes the Plaid connection and deletes the stored encrypted access token and the associated metadata for that item from our servers.
Because your budgets, transactions, and other financial records are stored on your device (and, if enabled, in your own iCloud account), deleting the app and its CloudKit data removes those records from your control directly — we hold no server-side copy to delete.
For account deletion or any other deletion request, contact proofofbudget@nordictug.me.
No system is perfectly secure, and we make no guarantee that unauthorized access will never occur.
We retain your pseudonymous Apple identifier, linked-item records (Plaid item ID, institution label, encrypted access token), and entitlement metadata for as long as your account exists or the item remains linked. Removing a linked account deletes that item's encrypted token and metadata. Webhook replay metadata is retained only as long as needed to detect replays. Financial payloads are never retained, because they are never stored.
Proof of Budget is not directed to children and is not intended for use by anyone under the age required to enter a binding contract in their jurisdiction. We do not knowingly collect information from children. If you believe a child has provided us information, contact us and we will delete it.
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to object to or restrict certain processing. Given the limited data we hold, most of these are exercised directly in the app: unlinking an institution deletes its stored record, and your financial records live on your device. To make a request, contact proofofbudget@nordictug.me. We do not sell personal information, so there is nothing to opt out of in that respect.
The app and this site may reference third-party services — notably Plaid, Apple, and your financial institution. Their handling of your information is governed by their own privacy policies, not this one. We are not responsible for the content or practices of third-party sites and services.
We may update this policy from time to time. Material changes will be reflected in the effective date above and, where appropriate, communicated in the app. Continued use after an update means you accept the revised policy.
Nordic Tug LLC
proofofbudget@nordictug.me