Privacy Policy
Last updated: September 1, 2026
Who we are
Otterbond ("the Service," "we," "us") is operated by Miguel Furtado, an individual based in Portugal. The Service includes both the web app and the companion mobile app, which share the same account and backend, so this policy applies to both.
For any privacy question or data request, contact budgeterinfo@gmail.com.
What we collect
Account data: the email address you sign in with, an optional display name, and your currency preference.
Financial data you enter: budgets, categories, transactions, recurring expenses, savings funds and movements, and the workspace(s) they belong to. This is the core data the Service exists to store on your behalf.
Workspace & social data: workspace memberships and roles, friend connections, and pending invites/requests between accounts.
Authentication data: one-time login codes (stored as a hash, short-lived) and refresh tokens (stored as a hash server-side; on web, held only in an httpOnly cookie your browser sends automatically, never accessible to page scripts).
Local device storage: a small set of preferences (theme, active workspace, and a flag noting you edited a past month's balance) are kept only in your browser's local storage on this device. They are never transmitted to us and are not part of any account data we hold.
We do not use analytics, advertising, or third-party tracking of any kind, and we do not use cookies other than the single authentication cookie described above.
Waitlist email: if you join the waitlist on this site, we store the email address you provide solely to notify you when the web, iOS, or Android app becomes available. We don't use it for anything else, and you can ask us to remove it at any time by contacting budgeterinfo@gmail.com.
How we use it
We use your data solely to provide the Service: authenticating you, storing and syncing the budgeting data you create, and letting you share a workspace with people you invite. We do not use your data for advertising, and we do not sell it.
Our legal basis for processing is performance of the contract between you and us (running the app you signed up to use). See "Your rights" below for how to withdraw that relationship entirely by deleting your account.
Who we share it with
We use a small number of infrastructure providers to run the Service, each acting as a data processor on our behalf, under their own security and privacy commitments:
SendGrid - delivers the one-time login codes we email you.
Render - hosts our application servers and database.
We may in the future enable error tracking (e.g. Sentry) to catch and fix bugs faster; if and when that happens, this policy will be updated first. We do not otherwise share your data with any third party, and we never sell it.
Data retention
Your account data and everything you've entered is kept for as long as your account exists. Login codes and refresh tokens expire automatically and are cleaned up shortly after they're no longer valid. If you delete your account, all of your data is permanently removed in a single operation. See "Your rights" below.
Your rights
Under the EU General Data Protection Regulation (GDPR) and similar laws, you have the right to access, correct, export, or delete your personal data, and to object to how it is processed. Two of these are already built directly into the app, under Profile → Account:
Export my data - download a complete copy of your account and everything
you've stored with us, as a single file.
Delete my account - permanently and immediately erase your account and all
associated data. This cannot be undone.
For any other request (correction, objection, or a question about how your data is handled), contact budgeterinfo@gmail.com.
California residents: under the CCPA, you have the right to know what personal information we collect, to request its deletion, and to opt out of its sale. We do not sell personal information, so no opt-out is necessary; the export and deletion tools above satisfy the equivalent access and deletion rights.
Cookies & local storage
We set exactly one cookie: an httpOnly authentication cookie that keeps you signed in. It cannot be read by page scripts and is not used for tracking. Separately, a few UI preferences are stored in your browser's local storage, as described above. These never leave your device.
Children's privacy
The Service is intended for a general audience and is not directed at children under 16. We do not knowingly collect personal data from children under 16; if you believe a child has provided us with personal data, contact us at budgeterinfo@gmail.com and we will delete it.
International data transfers
Our infrastructure providers may process data in countries other than your own. Where this happens, we rely on those providers' own safeguards for transferring data internationally in compliance with applicable law.
Changes to this policy
If we make material changes to this policy, we will update the "Last updated" date above and, where appropriate, notify you directly.
Contact
Questions, requests, or concerns about this policy or your data: budgeterinfo@gmail.com.