Privacy Policy
Version 1.0 · Effective September 7, 2026
This policy explains what personal data Lemonbudget collects, why, who it is shared with and what you can demand of us. It covers the lemonbudget.app website and the Lemonbudget application.
1. Who is responsible
This service is Lemonbudget, a non-commercial project operated by a private individual in Switzerland. You can reach us at contact@lemonbudget.app, and for anything concerning your personal data at contact@lemonbudget.app.
The operator’s full legal name and, where required, postal address are disclosed to any user, supervisory authority or court that requests them.
The operator is a private individual established in Switzerland. Because this is a non-commercial project with a small, non-systematic user base and because the data processed is not special-category data, we consider the Art. 27(2)(a) GDPR exemption for an EU representative to apply. If that assessment changes, a representative will be appointed and this policy updated.
2. Which law applies
We are established in Switzerland, so the revised Swiss Federal Act on Data Protection (revFADP) governs our processing. Because we offer the service in German, French, Italian and Spanish and accept users in the European Union, the EU General Data Protection Regulation may also apply to us under Art. 3(2).
Where the two regimes differ, we apply whichever gives you the stronger protection rather than the narrower reading.
3. What data we collect
- Account data
- Your name, email address, whether that address has been verified, and an optional profile image. If you sign in with a password we store only a hash of it, never the password itself.
- Authentication data
- Session records containing a session token, its expiry, your IP address and browser user-agent string. If you register a passkey we store its public key and a device type — never a private key, and never biometric data, which stays on your device and is not transmitted to us.
- Financial data
- The accounts, transactions, categories, tags, budgets, goals and scheduled entries you create. Names, descriptions and notes are encrypted at rest; amounts, dates, currencies, types and structural identifiers (such as which account a transaction belongs to) are kept in plaintext so the application can calculate balances and answer searches.
- Usage data
- One record per meaningful action (for example "a transaction was created"), with a timestamp, a coarse category and the surface it came from. These records deliberately contain no names, notes or amounts.
- Correspondence
- The content of emails and support messages you send us.
- Technical data
- Server and error logs generated when you use the service, and request metadata needed to operate and secure it.
We do not buy personal data, we do not enrich your profile from external sources, and we do not ask you for data we have no use for.
4. What is encrypted
Sensitive text in your financial records is encrypted at rest using AES-256-GCM. This includes the names and descriptions you give to accounts, categories, tags, budgets, goals, scheduled transactions, income sources and account types; and any notes or descriptions you attach to transactions.
Each user has a unique 256-bit data-encryption key (DEK). The DEK is derived from your password with PBKDF2 (100,000 iterations, SHA-512) and a per-user salt. Your password itself is never stored; only a credential hash is kept for authentication. The DEK is never written to the database in plaintext. Instead it is encrypted by a session-specific key that is derived from your session token, and the encrypted DEK is stored with the session.
Because the session token is only available while you are signed in and only you (or your browser) hold it, someone who merely reads the database — including us — cannot decrypt your text fields. We cannot turn your encrypted data into readable names or notes without your password or your recovery key.
Keep your recovery key
Your recovery key is a 16-character code generated when your account is created. It is independent of your password and can derive the same DEK. If you forget your password and lose your recovery key, the encrypted text in your records becomes unreadable. We cannot reset it, regenerate it, or read your data on your behalf. Store it somewhere you will still have it in a year.
Receipt scanning runs entirely in your browser. The image is processed on your own device and the picture itself is not uploaded to us.
5. What is not encrypted, and why
Encryption is not applied to everything, because some data has to remain searchable, queryable and computable. The following categories stay in plaintext:
- Account data: your name, email address, profile image, and whether your email is verified. This is needed to run the service, send you email and manage your account.
- Session records: session token hash, expiry, IP address and user-agent string. These are needed for authentication, security and rate limiting.
- Numeric and structural financial data: transaction amounts, account balances, currencies, dates, transaction types, category assignments, transfer links, goal targets and budget thresholds. These stay readable so the application can calculate totals, run reports and answer search queries on the server.
- Workspace and sharing data: workspace names, member lists, roles and invitations. These are kept readable so that shared workspaces function and so other members can see what you have invited them to.
- Usage and technical data: action counts, error logs and server request metadata. These are kept in plaintext for security, debugging and to understand how the service is used.
- Payment identifiers: if you subscribe, the Stripe customer and subscription identifiers are stored. No card number, CVV or expiry ever reaches our servers; those are entered directly into Stripe.
This means that while a database observer could not read your written notes or the custom names you give to accounts and categories, they could in principle see the amounts, dates and structural facts of your records. The encryption protects your subjective labels and narrative, not the arithmetic of the underlying data.
A note on what we can see
The server can only decrypt your encrypted text fields while it is actively processing one of your requests, because that is the only moment it has your session token and therefore your DEK in memory. We do not retain the DEK or decrypted content after the request finishes, and we do not use it for any purpose other than serving you. This is the strongest protection a hosted web application can offer without being a local-only app, but it is not end-to-end encryption against the operator: a malicious version of the server could in theory capture data in memory during a request.
6. Why we process it, and on what legal basis
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Providing the budgeting service you signed up for | Account, authentication, financial | Art. 6(1)(b) — performance of a contract |
| Verifying your email address and sending service notices | Account data | Art. 6(1)(b) — performance of a contract |
| Keeping the service secure: rate limiting, abuse prevention, debugging | Authentication, technical | Art. 6(1)(f) — legitimate interests |
| Understanding which features are used so we can improve them | Usage data | Art. 6(1)(f) — legitimate interests |
| Sending product news and marketing email | Account data | Art. 6(1)(a) — consent, withdrawable at any time |
| Sending browser push notifications | Push subscription endpoint | Art. 6(1)(a) — consent, withdrawable at any time |
| Meeting retention duties under tax or accounting law | Payment and billing records, when applicable | Art. 6(1)(c) — legal obligation |
Under the revFADP our processing of the data you knowingly give us in order to receive the service does not require separate consent; it follows from the contract between us and from the principles of good faith and proportionality in Art. 6 revFADP. Where we rely on consent above, you may withdraw it at any time without affecting the lawfulness of what came before.
8. Email we send you
Transactional email — address verification, password resets and billing notices, when applicable — is part of the service and is sent on the basis of our contract with you. It comes from noreply@notifications.lemonbudget.app.
Product news and marketing email is sent only if you have opted in, and every such message carries a one-click unsubscribe link. Unsubscribing from marketing does not stop transactional messages, because those are necessary to operate your account.
10. Disclosure abroad
Some of our providers are established in the United States. Switzerland recognises the Swiss-US Data Privacy Framework, and for recipients outside it we rely on the European Commission’s Standard Contractual Clauses together with the additional safeguards required by Art. 16 revFADP and Chapter V GDPR. The table above records which basis applies to each provider.
11. How long we keep it
- Account and financial data: for as long as your account exists.
- Raw usage records: 90 days, after which only anonymous daily counts remain.
- Session records: until expiry or sign-out.
- Server and error logs: a short rolling window, normally measured in weeks.
When you delete your account we erase your account, financial, usage and authentication data. What survives is the minimum we are legally required to retain for accounting purposes, when applicable.
12. Your rights
Under both the revFADP and the GDPR you can:
- Ask what data we hold about you and get a copy of it (Art. 25 revFADP, Art. 15 GDPR).
- Have inaccurate data corrected (Art. 32 revFADP, Art. 16 GDPR).
- Have your data deleted (Art. 32 revFADP, Art. 17 GDPR).
- Receive your data in a portable, machine-readable format (Art. 28 revFADP, Art. 20 GDPR).
- Object to processing based on our legitimate interests (Art. 30 revFADP, Art. 21 GDPR).
- Ask us to restrict processing while a dispute is resolved (Art. 18 GDPR).
- Withdraw any consent you have given, at any time.
- Not be subject to a decision made solely by automated means. We make no such decisions about you.
You can exercise the most common of these yourself and immediately: your settings include a full data export and an account deletion that actually erases your data rather than flagging it as hidden. For anything else, write to contact@lemonbudget.app. We answer within 30 days, and we will not charge you or ask you to justify the request.
If you think we have handled your data unlawfully you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch). If you are in the EU or EEA you can instead complain to the supervisory authority of your country of residence or workplace.
13. Security
Beyond the encryption described above, we serve everything over TLS, store passwords only as hashes using a slow key-derivation function, support passkeys and rate-limit authentication endpoints to frustrate credential stuffing. Access to production systems is limited to those who need it.
If a breach occurs that is likely to result in a high risk to you, we will notify the FDPIC and any competent EU authorities as required and tell you directly.
If you believe you have found a vulnerability, please report it to contact@lemonbudget.app rather than disclosing it publicly. We will not pursue good-faith security research.
14. Children
The service is not directed at children. You must be at least 16 to create an account. If you believe a child has given us personal data, tell us and we will delete it.
15. Changes to this policy
We may revise this policy as the service changes. The version and effective date are shown at the top. If a change materially affects how we use your data we will tell you by email before it takes effect, rather than relying on you to notice a new date.