Privacy policy

How we collect, use, and protect your data.

Effective date: July 5, 2026

Borderless Budget ("we," "us," "our") is a multi-currency budgeting app built for people who live in more than one currency. This privacy policy explains what data we collect, why we collect it, how we use it, and what rights you have over it.

We believe in plain language. No legal fog. If something is unclear, email us at privacy@borderlessbudget.com and we'll explain it.


What we collect

Account information

When you create an account, we collect your name, email address, and a password (stored as a secure hash, we never see your actual password).

Financial data

When you connect a bank account, we receive your account balances, transaction history, and account metadata (account name, type, and currency) through our banking providers. We don't receive or store your banking credentials, those go directly to your bank through our banking providers.

Amazon order data

If you choose to connect your Amazon account, we import your own Amazon order history through Amazon's official data portability service. This includes item names, prices, quantities, order and return dates, subscriptions, and the marketplace the order was placed on (for example amazon.es or amazon.com). You authorize this directly with Amazon, and you choose whether it is a one-time import or an ongoing connection. We never receive your Amazon password.

Usage data

We collect basic usage data to keep the service running: pages visited, features used, and error logs. We don't track you across other websites.

Consent records

When you agree to our terms or authorize a bank connection, we store a record of that consent along with a timestamp and IP address. This is required for legal compliance.


Why we collect it

We use your data to:

  • Provide the budgeting service, display your accounts, track spending, and manage budgets across currencies
  • Convert transactions between currencies using daily exchange rates
  • Categorize your transactions and generate budget recommendations using AI
  • Match and itemize your Amazon charges, if you connect your Amazon account, so you can categorize them by what you bought
  • Send you service-related emails (account alerts, bank connection issues)
  • Fix bugs and improve the product

We don't sell your data. We don't show you ads.


AI data processing

We use AI to automatically categorize your transactions and generate budget recommendations. Here's exactly how that works:

  • What we send: merchant name, transaction description, amount, account type, and, if you have connected Amazon, the item names from a matched Amazon order. We don't send your name, email, account numbers, or bank credentials.
  • Where it's processed: AI models running within our own cloud infrastructure.
  • Data storage: Our AI provider does not store your transaction data after processing. Your data is not used to train AI models.

You can opt out of AI categorization before connecting your bank accounts. If you opt out, you can still categorize transactions manually.


AI assistants (MCP)

You can connect external AI assistants such as Claude or ChatGPT to your Borderless Budget account using the Model Context Protocol (MCP). This is strictly opt-in. No data is shared with an external assistant until you explicitly authorize a connection from your account settings.

When you ask a connected assistant a question about your finances, it requests the data needed to answer:

  • What gets sent: your transactions, your financial accounts (names, types, and balances), your budgets, your recurring charges, your spending categories, and summaries derived from these such as spending by category, cash flow, and net worth, on demand, as the assistant requests them. The assistant transmits this data to the LLM provider that runs it (for example, Anthropic for Claude, or OpenAI for ChatGPT).
  • Who sees it: the LLM provider behind the assistant you connect. Their handling of your data is governed by their own privacy policy, not ours. Once your data leaves our servers, we don't control how they store, log, or use it.
  • What we log: we keep a 30-day audit trail of every tool call made by a connected assistant, including the raw arguments passed (for example, the date range of transactions requested). Audit log entries older than 30 days are automatically deleted by a daily job.
  • Email notifications: you'll receive an email each time a new assistant connects to your account, and another whenever access is revoked.
  • How to revoke: visit Settings → Connected Apps to see every assistant connected to your account and revoke access. Revocation is immediate, and changing your password also revokes all connected assistants.

Amazon order data

Amazon charges on a bank statement are opaque: a single "Amazon" charge tells you nothing about what was in the order. If you connect your Amazon account, we use Amazon's official data portability service to import your own order history so we can make those charges meaningful. This connection is strictly opt-in.

  • What we import: your Amazon order history, returns, and subscriptions, including item names, prices, quantities, order dates, and the marketplace (for example amazon.es or amazon.com).
  • What we do with it: we match each Amazon order to the card transaction already in your budget and itemize that charge, so you can categorize it by what you actually bought, including splitting one charge across several categories.
  • What we don't do: we use this data only to enrich your own budget. We never sell it, share it for advertising, or use it to build profiles or train models.
  • How to revoke: you can disconnect at any time from your account settings, or from Amazon's "Manage Apps and Services with Data Access" page. When you revoke access or delete your account, we delete the imported Amazon order data.

Who we share data with

We share data only with the services needed to run Borderless Budget:

ServicePurposeData shared
Banking provider (US & Canada)US and Canadian bank connectionsOur banking provider connects directly to your bank. We receive transactions and balances.
EU banking providerEuropean bank connectionsOur EU banking provider connects directly to your bank. We receive transactions and balances.
Cloud infrastructure providerCloud hosting and infrastructureAll data is stored and processed on our cloud servers (database, compute, storage).
Email providerTransactional email (account and bank connection alerts)Your name and email address, to deliver service emails. We don't send marketing email this way.
AI providerAI categorization and budget generationMerchant name, description, amount, account type. No personal identifiers.
Connected AI assistants (opt-in, MCP)External AI assistants you authorize via Model Context ProtocolTransactions, balances, budgets, and recurring charges. Only when you explicitly connect an assistant. Revocable in Settings → Connected Apps.
Payment processorPayment processingEmail and payment details for subscription billing. We don't store your card number.
Analytics (Google Analytics)Marketing-site usage analyticsSite usage events and identifiers, only if you accept analytics cookies. Not used on your logged-in account data.

We don't share your data with advertisers, data brokers, or anyone else.

Law enforcement and government requests

If a law enforcement agency or government authority requests your data, we review the request to confirm it is legally valid, we challenge requests that are overbroad, and we disclose only what the law requires, nothing more. Where the law allows it, we will notify you before we respond so you have the opportunity to object. If we are legally prohibited from telling you at the time, for example by a nondisclosure order, we will notify you as soon as that restriction is lifted. We keep a record of every request we receive and how we responded.


Where your data is processed

Borderless Budget is operated by Borderless Budget LLC, a company based in the United States, and our servers run on cloud infrastructure in the United States. If you are in the EU or EEA, this means your personal data, including bank transaction data and any Amazon order data you import, is transferred to and processed in the United States.

We rely on the following safeguards for that transfer:

  • Your explicit consent when you connect an account or authorize an import.
  • Standard Contractual Clauses with our processors, and the EU-US Data Privacy Framework where applicable.

EU representative. Because we are established outside the EU, we have appointed an EU representative under Article 27 of the GDPR: Data Protection Representative Limited (trading as DataRep), which maintains contact locations across the EU and EEA. To contact our representative about how we handle your personal data, email DataRep at datarequest@datarep.com quoting "Borderless Budget LLC", or use their webform at datarep.com/data-request. For general questions about Borderless Budget, email us at privacy@borderlessbudget.com.


How we protect your data

  • All data is encrypted in transit (TLS) and at rest (AES-256)
  • Your database runs in a private network, it's not accessible from the public internet
  • Banking credentials are never stored by us, they go directly to your bank through our banking providers
  • We use phishing-resistant authentication (passkeys/WebAuthn)
  • Access to production systems requires multi-factor authentication

How long we keep your data

While your account is active

We keep your transaction data, budgets, and account information for as long as your account is active. You can export or delete your data at any time.

When you delete your account

  • Within 30 days, we delete all your personal data, transaction data, budgets, and bank connections.
  • We revoke all access tokens with our banking providers.
  • We retain a minimal compliance record (hashed user ID, account creation date, deletion date) for 7 years, as required for financial record-keeping.

Your rights

Wherever you live, you can exercise the following rights by emailing privacy@borderlessbudget.com or through your account settings:

  • Access: Request a copy of all data we hold about you.
  • Portability: Export your data in a standard format (JSON or CSV).
  • Correction: Update or correct inaccurate data.
  • Deletion: Delete your account and all associated data.
  • Withdraw consent: Withdraw consent for data processing at any time. Withdrawing consent for bank data access will disconnect your bank accounts.

For EU/EEA residents (GDPR)

Our legal basis for processing your data is your consent (for bank connections, AI processing, and any Amazon account you connect) and legitimate interest (for providing the budgeting service you signed up for). You have the right to lodge a complaint with your local data protection authority. If you are in Spain, that authority is the Agencia Española de Protección de Datos (AEPD). You can also contact our EU representative, listed under "Where your data is processed" above, about how we handle your data.

For California residents (CCPA)

You have the right to know what personal information we collect, to delete your personal information, and to opt out of the sale of your personal information. We don't sell your personal information.


Cookies

We use essential cookies to keep you logged in and remember your preferences. These are always on, because the service can't work without them.

On our marketing site we also use Google Analytics to understand how visitors find and use the site. These analytics cookies are optional: they load only if you accept them in the cookie banner, and you can decline. If you decline, we don't set them. We don't use advertising cookies, and we don't track you across other websites.


Children

Borderless Budget is not intended for anyone under 18. We don't knowingly collect data from minors.


Changes to this policy

If we make significant changes, we'll notify you by email and update the effective date at the top of this page. Continued use of Borderless Budget after changes means you accept the updated policy.


Contact us

Questions about your privacy? Email us at privacy@borderlessbudget.com.