Privacy Policy
Last updated: July 2, 2026
Budget-Time (“we”, “us”) provides a Google Sheets add-on and companion service at budget-time.com that imports your financial account data into your own Google Spreadsheet. This policy explains exactly what we collect, what we deliberately do not collect, and how we handle it.
What we store
To operate the service we persist only the following:
- Your Google account identity - your email address and Google account identifier, used to recognize you and associate your subscription.
- Plaid connection credentials - the access token Plaid issues for each bank connection you create, encrypted at rest with AES-256. This token lets us fetch your data on your request; it is not your bank login and cannot be used without our server-side keys.
- Connection metadata - the institution's name and a sync cursor (a bookmark telling Plaid where the last import ended).
- Subscription state - your plan and its status, managed by Stripe. We never see or store your card number.
What we deliberately do not store
- No transactions, amounts, or merchant details
- No account balances, account numbers, or routing numbers
- No investment holdings or positions
- No bank usernames or passwords (these go directly to Plaid; they never touch our systems)
This is enforced in our software: our database schema contains no tables or fields for financial data, and this constraint is covered by automated tests on every release.
How your bank connects (Plaid)
Bank connections are powered by Plaid Inc. When you link an account, you authenticate directly with Plaid or your bank - your credentials are never visible to Budget-Time. Plaid's handling of your information is described in the Plaid End User Privacy Policy. You may revoke Plaid's access at any time via the add-on's “Disconnect” action or through your bank; disconnecting deletes the connection's access token from our systems and revokes it with Plaid.
Google user data & Limited Use disclosure
The add-on requests the minimum Google permissions needed to work:
- View and manage the spreadsheet the add-on is installed in - used solely to write your imported transactions into that spreadsheet. We cannot access your other Drive files or other spreadsheets.
- Connect to an external service - used to call our own API.
- Your email address - used to identify your account and subscription.
Budget-Time's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except with your explicit consent for support, for security purposes, or as required by law.
Payments
Subscriptions are processed by Stripe. Card details are entered on Stripe's hosted checkout and never reach our servers. See the Stripe Privacy Policy.
Security
- All traffic is encrypted in transit (TLS/HTTPS).
- Plaid access tokens are encrypted at rest (AES-256-GCM) with keys held outside the database.
- Webhooks from Plaid and Stripe are cryptographically verified before processing.
- Production access is restricted and protected by multi-factor authentication.
Data retention & deletion
Connection records are deleted immediately when you disconnect a bank or uninstall and request deletion. To delete your account entirely (identity, connections, subscription records), email [email protected] - we complete deletion within 30 days. Everything imported into your spreadsheet is yours and remains under your control in your Google account; we couldn't delete it if we wanted to.
Children
Budget-Time is not directed at children under 13 and we do not knowingly collect their data.
Changes & contact
We'll post any changes to this policy on this page and update the date above. Questions: [email protected].