1. Who we are and what this covers
Pixel Pulse LLC operates WiseBudget. This policy covers the WiseBudget marketing site and web application during the free beta. It describes the product behavior implemented as of the effective date.
WiseBudget is a manual-first budgeting product. The current product does not connect to bank accounts, charge users, offer paid plans, or process payments.
2. Information WiseBudget stores
Depending on the features you use, WiseBudget stores the following information:
- Account and sign-in information: your email address, Supabase authentication record, sign-in dates and status, and Google identity information if you choose Google sign-in. Password handling belongs to Supabase Auth; WiseBudget application tables do not store your password.
- Financial records: financial account names, types, balances and currencies; transactions, payees, merchants, descriptions, notes, categories, attachments and split or transfer relationships; monthly plans, groups, items, targets and carryover information.
- Ledger evidence: reconciliations, balance snapshots, statement-comparison sessions, imported files represented as parsed rows, validation and duplicate decisions, recurring templates and occurrences, saved reports, and financial audit events.
- Capture data: receipt or statement images, voice recordings and other supported attachments stored in the private captures bucket; capture drafts, extracted receipt line items, transcripts, model and token metadata, results and errors.
- Assistant data: conversation threads, messages, attachments, generated blocks, tool-call records, saved assistant memories, model usage and privacy-limited invocation or tool-execution telemetry.
- Preferences and alerts: language, theme, currency and onboarding settings; alert preferences, saved notifications, push endpoints and encryption keys, and the browser user-agent associated with a push subscription.
- Product and audit events: one-time milestones such as signup, first account, first transaction, first import or reconciliation, plus acquisition source, referring host, campaign fields, route, environment and timestamps. Product-event rows do not include amounts, merchants, account names, notes or uploaded document contents.
- Support and administration records: administrative access events, audit summaries, access-grant records and support-action history when those records are created.
3. Why the data is used
- To create and authenticate your account and recover access.
- To maintain your accounts, ledger, budgets, imports, reconciliations, recurring review, forecasts, reports and alerts.
- To process images, audio, tables and questions you deliberately send to capture or assistant features.
- To produce a portable export, keep a financial audit trail, diagnose failed operations and provide support.
- To understand limited signup and activation milestones without placing financial amounts or document contents in product-event records.
4. Service providers and outbound data
- Supabase provides the database, authentication, private file storage and server functions. Account identifiers, financial records, uploads, conversations, settings, notifications and operational records are stored or processed there.
- Cloudflare Pages hosts and delivers the marketing site and web application.
- Google provides optional Google sign-in and the active Gemini models used for assistant and capture processing. OpenAI, Anthropic and xAI appear in an inactive model catalog but are not active in the current runtime and do not receive assistant or capture requests from the implemented code.
- ExchangeRate-API is used when a production API key is configured; fxapi.app is the fallback. Requests contain the requested base currency, target currency and date. The exchange-rate function does not send a user identifier or the user’s ledger to either provider.
- Push messages are sent through the endpoint supplied by your browser using the Web Push protocol. The downstream push service depends on your browser and device; the repository does not select or record that provider by name. The endpoint, encryption keys and notification title, body and destination URL take part in delivery.
- Supabase Auth handles signup and password-recovery email workflows. The repository does not identify a separate production SMTP or transactional-email provider.
- The site loads Instrument Sans and IBM Plex Mono from Google Fonts, so a visitor’s browser makes font requests to Google.
5. What reaches the AI provider
When you use the assistant, WiseBudget sends Google Gemini your current request, up to the recent conversation history used by the request, and a system context that serializes your default currency, account IDs, account names and currencies, categories, active budget groups and items with planned amounts, monthly exchange rates, and assistant memories. If the assistant calls a financial tool, the tool result used to prepare the answer can also contain transaction descriptions, dates, amounts, currencies, merchants, categories or calculated totals.
Images, audio and parsed table contents you attach are also sent to Google Gemini for the requested analysis. The separate capture feature sends the submitted image, audio or text to Gemini for extraction. Do not use these features if you do not want that material and the relevant financial context sent to Google.
WiseBudget stores conversation content in Supabase. Its AI telemetry stores model, timing, token, cost, status and payload-hash metadata, but its telemetry tables are designed not to store raw prompts, responses, financial labels or amounts.
6. Uploaded files and the portable export
Receipt images, statement images and supported audio can be kept in a private Supabase Storage bucket under a path scoped to your user ID. Database records keep the related storage path and extracted or transcribed content.
The in-app portable export is a JSON file. It includes the implemented export tables for accounts, plans, transactions and splits, recurring data, merchants, reconciliations, statement comparisons, import evidence, capture-job metadata, receipt line items, financial audit events, product events, exchange rates, saved reports, alert preferences, saved notifications, settings, assistant threads, messages and memories.
The portable export does not download the binary files in Storage. It also does not include push-subscription rows, AI invocation or tool-execution telemetry, the full Supabase authentication record, administrative records, or backup copies.
7. What the owner can see
The current administration console is restricted in code to the sole owner account. It can show user email addresses, signup and last-sign-in dates, account status, activation and acquisition events, aggregate counts, system configuration status, and summaries from financial and administrative audit records.
The current console and admin API do not retrieve raw assistant-message content. The database has service-only records for reasoned, expiring and revocable raw-AI access grants, but the repository does not connect those grants to a raw-content viewer or technically enforce them against every possible service-role database access. This policy therefore does not promise that every privileged access path is blocked by that grant record.
8. Retention, deletion and backups
WiseBudget keeps account and financial records while the account remains active. A deleted transaction is soft-deleted: it stops affecting balances, budgets, reports and reconciliation, but remains recoverable in Recently deleted. No automatic purge currently removes those rows after a fixed period.
You can request account deletion directly from Account Settings. Deletion is scheduled with a 30-day grace period during which you can cancel at any time. When purged, your account, files in Storage, and records across all application tables are atomically deleted, and the email is permanently redacted to a SHA-256 hash in historical audit logs.
Daily database and Storage backups are automated to Cloudflare R2 off-site object storage with 30-day retention and a 36-hour watchdog alert. Because backups execute from the maintainer’s primary machine, an outage can occur if that machine is powered off overnight.
9. Your controls
- Download the portable JSON export from the Trust Center while signed in.
- Restore soft-deleted transactions from Recently deleted.
- Turn browser push off and delete saved notifications available to your account.
- Contact support to ask about your data or begin an account-deletion request. No response or completion time is promised in this beta.
10. People under 18
WiseBudget is not directed to anyone under 18. Do not create or use an account if you are under 18.
11. Contact and version
Questions about this policy, an export or an account-deletion request can be sent to [email protected].
The effective date at the top identifies this version. Pixel Pulse LLC is based in Arizona, United States. This draft does not state a response deadline, regulatory certification, external audit, encryption guarantee or service-level commitment.
Questions about your data or account?
Write from the email address associated with your account so the request can be located and verified.