Privacy Policy

Version 1.0 · Effective September 7, 2026

This policy explains what personal data Lemonbudget collects, why, who it is shared with and what you can demand of us. It covers the lemonbudget.app website and the Lemonbudget application.

1. Who is responsible

This service is Lemonbudget, a non-commercial project operated by a private individual in Switzerland. You can reach us at contact@lemonbudget.app, and for anything concerning your personal data at contact@lemonbudget.app.

The operator’s full legal name and, where required, postal address are disclosed to any user, supervisory authority or court that requests them.

The operator is a private individual established in Switzerland. Because this is a non-commercial project with a small, non-systematic user base and because the data processed is not special-category data, we consider the Art. 27(2)(a) GDPR exemption for an EU representative to apply. If that assessment changes, a representative will be appointed and this policy updated.

2. Which law applies

We are established in Switzerland, so the revised Swiss Federal Act on Data Protection (revFADP) governs our processing. Because we offer the service in German, French, Italian and Spanish and accept users in the European Union, the EU General Data Protection Regulation may also apply to us under Art. 3(2).

Where the two regimes differ, we apply whichever gives you the stronger protection rather than the narrower reading.

3. What data we collect

Account data
Your name, email address, whether that address has been verified, and an optional profile image. If you sign in with a password we store only a hash of it, never the password itself.
Authentication data
Session records containing a session token, its expiry, your IP address and browser user-agent string. If you register a passkey we store its public key and a device type — never a private key, and never biometric data, which stays on your device and is not transmitted to us.
Financial data
The accounts, transactions, categories, tags, budgets, goals and scheduled entries you create. Names, descriptions and notes are encrypted at rest; amounts, dates, currencies, types and structural identifiers (such as which account a transaction belongs to) are kept in plaintext so the application can calculate balances and answer searches.
Usage data
One record per meaningful action (for example "a transaction was created"), with a timestamp, a coarse category and the surface it came from. These records deliberately contain no names, notes or amounts.
Correspondence
The content of emails and support messages you send us.
Technical data
Server and error logs generated when you use the service, and request metadata needed to operate and secure it.

We do not buy personal data, we do not enrich your profile from external sources, and we do not ask you for data we have no use for.

4. What is encrypted

Sensitive text in your financial records is encrypted at rest using AES-256-GCM. This includes the names and descriptions you give to accounts, categories, tags, budgets, goals, scheduled transactions, income sources and account types; and any notes or descriptions you attach to transactions.

Each user has a unique 256-bit data-encryption key (DEK). The DEK is derived from your password with PBKDF2 (100,000 iterations, SHA-512) and a per-user salt. Your password itself is never stored; only a credential hash is kept for authentication. The DEK is never written to the database in plaintext. Instead it is encrypted by a session-specific key that is derived from your session token, and the encrypted DEK is stored with the session.

Because the session token is only available while you are signed in and only you (or your browser) hold it, someone who merely reads the database — including us — cannot decrypt your text fields. We cannot turn your encrypted data into readable names or notes without your password or your recovery key.

Keep your recovery key

Your recovery key is a 16-character code generated when your account is created. It is independent of your password and can derive the same DEK. If you forget your password and lose your recovery key, the encrypted text in your records becomes unreadable. We cannot reset it, regenerate it, or read your data on your behalf. Store it somewhere you will still have it in a year.

Receipt scanning runs entirely in your browser. The image is processed on your own device and the picture itself is not uploaded to us.

5. What is not encrypted, and why

Encryption is not applied to everything, because some data has to remain searchable, queryable and computable. The following categories stay in plaintext:

  • Account data: your name, email address, profile image, and whether your email is verified. This is needed to run the service, send you email and manage your account.
  • Session records: session token hash, expiry, IP address and user-agent string. These are needed for authentication, security and rate limiting.
  • Numeric and structural financial data: transaction amounts, account balances, currencies, dates, transaction types, category assignments, transfer links, goal targets and budget thresholds. These stay readable so the application can calculate totals, run reports and answer search queries on the server.
  • Workspace and sharing data: workspace names, member lists, roles and invitations. These are kept readable so that shared workspaces function and so other members can see what you have invited them to.
  • Usage and technical data: action counts, error logs and server request metadata. These are kept in plaintext for security, debugging and to understand how the service is used.
  • Payment identifiers: if you subscribe, the Stripe customer and subscription identifiers are stored. No card number, CVV or expiry ever reaches our servers; those are entered directly into Stripe.

This means that while a database observer could not read your written notes or the custom names you give to accounts and categories, they could in principle see the amounts, dates and structural facts of your records. The encryption protects your subjective labels and narrative, not the arithmetic of the underlying data.

A note on what we can see

The server can only decrypt your encrypted text fields while it is actively processing one of your requests, because that is the only moment it has your session token and therefore your DEK in memory. We do not retain the DEK or decrypted content after the request finishes, and we do not use it for any purpose other than serving you. This is the strongest protection a hosted web application can offer without being a local-only app, but it is not end-to-end encryption against the operator: a malicious version of the server could in theory capture data in memory during a request.

6. Why we process it, and on what legal basis

PurposeData usedLegal basis (GDPR)
Providing the budgeting service you signed up forAccount, authentication, financialArt. 6(1)(b) — performance of a contract
Verifying your email address and sending service noticesAccount dataArt. 6(1)(b) — performance of a contract
Keeping the service secure: rate limiting, abuse prevention, debuggingAuthentication, technicalArt. 6(1)(f) — legitimate interests
Understanding which features are used so we can improve themUsage dataArt. 6(1)(f) — legitimate interests
Sending product news and marketing emailAccount dataArt. 6(1)(a) — consent, withdrawable at any time
Sending browser push notificationsPush subscription endpointArt. 6(1)(a) — consent, withdrawable at any time
Meeting retention duties under tax or accounting lawPayment and billing records, when applicableArt. 6(1)(c) — legal obligation

Under the revFADP our processing of the data you knowingly give us in order to receive the service does not require separate consent; it follows from the contract between us and from the principles of good faith and proportionality in Art. 6 revFADP. Where we rely on consent above, you may withdraw it at any time without affecting the lawfulness of what came before.

7. Cookies and local storage

We use no advertising cookies, no third-party tracking cookies and no analytics service. What we do store on your device is limited to what makes the application work:

NamePurposeLifetime
Session cookieKeeps you signed in. Without it the application cannot authenticate you.Until expiry or sign-out
NEXT_LOCALERemembers your language choice.One year
Theme preferenceRemembers your colour scheme so the page does not flash on load.Until you clear it
Offline cache (IndexedDB)Stores your data locally so the app works without a connection and can sync later.Until you sign out or clear it

All of these are strictly necessary to deliver a service you have asked for, or are a preference you set yourself. Under Art. 45c of the Swiss Telecommunications Act we are required to inform you about them, which this section does, and under Art. 5(3) of the EU ePrivacy Directive strictly necessary storage is exempt from the consent requirement. That is why you are not asked to dismiss a cookie banner.

8. Email we send you

Transactional email — address verification, password resets and billing notices, when applicable — is part of the service and is sent on the basis of our contract with you. It comes from noreply@notifications.lemonbudget.app.

Product news and marketing email is sent only if you have opted in, and every such message carries a one-click unsubscribe link. Unsubscribing from marketing does not stop transactional messages, because those are necessary to operate your account.

9. Who else processes your data

We do not sell your personal data and we do not disclose it for anyone else’s marketing. The following providers are part of the service’s infrastructure. Some are used only if you use a paid feature; the table notes which. Each is bound by a data processing agreement when it processes data on our behalf:

ProviderWhat they doLocationTransfer basis
Neon (database hosting)Stores the application database. Financial records in it are encrypted with a key the server can only assemble inside an authenticated session.__TODO__EU/Swiss-US Data Privacy Framework and Standard Contractual Clauses
Vercel (application hosting)Serves the application and processes request metadata such as IP addresses in transit.__TODO__EU/Swiss-US Data Privacy Framework and Standard Contractual Clauses
StripePayment processing. Card details are entered directly with Stripe and never reach our servers. Stripe is only involved for users with an active subscription or trial; otherwise no payment data is shared.United States and IrelandEU/Swiss-US Data Privacy Framework and Standard Contractual Clauses
ResendDelivers transactional email (address verification, password reset, trial notices).United StatesStandard Contractual Clauses

We may also disclose data where the law compels us to, or to establish or defend a legal claim. If we are ever served with a request for your data we will tell you unless we are legally forbidden from doing so.

10. Disclosure abroad

Some of our providers are established in the United States. Switzerland recognises the Swiss-US Data Privacy Framework, and for recipients outside it we rely on the European Commission’s Standard Contractual Clauses together with the additional safeguards required by Art. 16 revFADP and Chapter V GDPR. The table above records which basis applies to each provider.

11. How long we keep it

  • Account and financial data: for as long as your account exists.
  • Raw usage records: 90 days, after which only anonymous daily counts remain.
  • Session records: until expiry or sign-out.
  • Server and error logs: a short rolling window, normally measured in weeks.

When you delete your account we erase your account, financial, usage and authentication data. What survives is the minimum we are legally required to retain for accounting purposes, when applicable.

12. Your rights

Under both the revFADP and the GDPR you can:

  • Ask what data we hold about you and get a copy of it (Art. 25 revFADP, Art. 15 GDPR).
  • Have inaccurate data corrected (Art. 32 revFADP, Art. 16 GDPR).
  • Have your data deleted (Art. 32 revFADP, Art. 17 GDPR).
  • Receive your data in a portable, machine-readable format (Art. 28 revFADP, Art. 20 GDPR).
  • Object to processing based on our legitimate interests (Art. 30 revFADP, Art. 21 GDPR).
  • Ask us to restrict processing while a dispute is resolved (Art. 18 GDPR).
  • Withdraw any consent you have given, at any time.
  • Not be subject to a decision made solely by automated means. We make no such decisions about you.

You can exercise the most common of these yourself and immediately: your settings include a full data export and an account deletion that actually erases your data rather than flagging it as hidden. For anything else, write to contact@lemonbudget.app. We answer within 30 days, and we will not charge you or ask you to justify the request.

If you think we have handled your data unlawfully you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch). If you are in the EU or EEA you can instead complain to the supervisory authority of your country of residence or workplace.

13. Security

Beyond the encryption described above, we serve everything over TLS, store passwords only as hashes using a slow key-derivation function, support passkeys and rate-limit authentication endpoints to frustrate credential stuffing. Access to production systems is limited to those who need it.

If a breach occurs that is likely to result in a high risk to you, we will notify the FDPIC and any competent EU authorities as required and tell you directly.

If you believe you have found a vulnerability, please report it to contact@lemonbudget.app rather than disclosing it publicly. We will not pursue good-faith security research.

14. Children

The service is not directed at children. You must be at least 16 to create an account. If you believe a child has given us personal data, tell us and we will delete it.

15. Changes to this policy

We may revise this policy as the service changes. The version and effective date are shown at the top. If a change materially affects how we use your data we will tell you by email before it takes effect, rather than relying on you to notice a new date.

Privacy Policy - Lemonbudget