Privacy Policy
Last updated September 16, 2026
Bilancio Money reads your bank accounts so it can show you what you have and where it went. That is the only thing it does with your data. It is not sold, it is not shared with advertisers, and it is not used to train anything.
This policy explains exactly what is collected, where it lives, and who else touches it. It describes the service as it actually works today, not as it might work later; if that changes, this page changes with it.
Bilancio Money is operated by Guardiano del Faro LLC ("Bilancio", "we", "us"). You can reach us at privacy@bilanciomoney.com.
1. What we collect
Your account
When you sign in, our authentication provider (Clerk) gives us your email address and a user ID. If you have enabled multi-factor authentication, Clerk holds the phone number or authenticator secret — we never see it.
Alongside that we keep the state of your account: when your free trial started and ends, whether you have a subscription, and where it was bought. If you subscribe we store the identifiers Stripe or Apple give us for your subscription — a customer ID, a subscription ID, or Apple's transaction ID — so we can tell whether it is active. We do not receive or store card numbers (see section 2).
Notifications
If you turn on budget alerts in the iPhone app, we store the push token Apple assigns to that install of the app, whether it is a test or App Store build, and which categories you asked to be alerted about. We also record which alerts have already been sent, so you are not told the same thing twice.
The former waitlist
Before sign-up opened, people could join a waitlist on the website or in the iPhone app. If you did, we still hold your email address, the date, where you joined from, and whether an invitation was sent — nothing else — and the address was also passed to Clerk, which sent the confirmation. Sign-up is now open, and we no longer ask for addresses this way.
Your bank data, through Plaid
Bilancio connects to your bank using Plaid. You enter your bank credentials directly into Plaid's own secure interface. We never see, receive, or store your bank username, password, or security answers. Plaid returns an access token, which we encrypt before storing (see section 4).
We request one Plaid product — transactions — for accounts in the United States. Through it we receive and store:
| Category | What is stored |
|---|---|
| Institution | The bank's name and Plaid's identifier for it |
| Accounts | Account name and official name, the last four digits of the account number, account type and subtype, current and available balance, credit limit where applicable, and currency |
| Transactions | Amount, date, authorisation date, description, merchant name and identifier, whether it is still pending, payment channel, and the category Plaid assigns |
| Full record | The complete transaction record as Plaid returns it, kept so that a change in how we categorise things can be applied to your existing history without re-reading your bank |
Worth being specific about: that complete record can include details we do not display, such as the merchant's street address, city, region, postal code and geographic coordinates for a transaction, the merchant's website and logo, and counterparty information. Plaid decides what it contains. We store it as received and it is subject to everything in this policy — but you should know it is there.
Things you create
Categories you add, rules you set ("Starbucks is always Coffee"), categories you change on individual transactions, how you split a transaction between categories, any notes or tags you attach, changes you make to your budget, and precious-metal holdings you enter by hand (the metal and the number of ounces).
2. What we do not collect
- Bank credentials. These go to Plaid, never to us.
- Full account numbers. Only the last four digits, as Plaid supplies them.
- Social Security numbers, dates of birth, or government ID. Never requested.
- Payment card details. If you subscribe, your card is entered with Stripe (on the website) or held by Apple (in the iPhone app). Card numbers are never sent to us or stored by us.
- Analytics, advertising, or tracking data. There are no analytics scripts, no advertising pixels, and no third-party trackers anywhere on this site or in the app. We do not build a record of what you look at. Our hosting keeps short-lived technical logs of requests, described in section 6, for security and fixing faults — not for tracking.
3. How we use it
To run the product, and for nothing else:
- To show you your balances, transactions, categories, trends and forecasts
- To keep your data current by syncing with your bank through Plaid
- To apply the categorisation rules you have set
- To work out your free trial and whether your subscription is active
- To send the budget alerts you have turned on
- To contact you about your account or about the service itself
- To keep the service secure and to investigate faults
We do not sell or rent your personal information. We do not share it with advertisers or data brokers. We do not use your financial data to train machine-learning models. We do not build a profile of you for anyone else's benefit.
4. How it is protected
- Your Plaid access token — the credential that can read your accounts — is encrypted with AES-256-GCM before it is written to the database, with a unique initialisation vector for every token. The key is held as an encrypted secret in our hosting platform and is never stored alongside the data it protects.
- All traffic is over HTTPS.
- The database requires TLS and is not reachable from the public internet.
- Every request for your data is authenticated, and queries are scoped to your own user ID so one account cannot read another's.
No system is perfectly secure, and we will not claim otherwise. If we become aware of a breach affecting your data, we will tell you, and notify the authorities where the law requires it. To report a security problem, email security@bilanciomoney.com.
5. Who else touches your data
We use a small number of service providers. Each is bound by its own agreement and may only process your data to provide its service to us. None of them is permitted to sell it or use it for advertising on our behalf.
| Provider | What it does |
|---|---|
| Plaid | Connects to your bank and supplies account and transaction data. Governed by Plaid's own privacy policy, which you accept when you link an account. |
| Clerk | Handles sign-in, sessions and multi-factor authentication. |
| Cloudflare | Serves the website and runs the application, and keeps short-lived request logs. Also forwards email sent to our @bilanciomoney.com addresses to our inbox. |
| Neon | Hosts the database. |
| Stripe | Only if you subscribe on the website. Takes the payment and holds your card details, under Stripe's privacy policy. We receive your subscription's status and identifiers, never the card number. |
| Apple | Only if you use the iPhone app. Takes payment for subscriptions bought in the app, under Apple's terms; tells us whether that subscription is active. Also delivers budget alerts to your phone — the alert's text, such as a category name and whether it is over budget, passes through Apple's push notification service to reach you. |
| Google Fonts | Serves the typefaces the site uses. Your browser requests these from Google, which means Google receives your IP address. No other information is sent, and no cookie is set. |
| Google (sign-in) | Only if you choose “Continue with Google”. Google tells us your email address and basic profile so we know who you are. If you sign in with a password instead, Google is not involved. This is separate from Google Fonts above. |
6. How long we keep it
- Transactions and balances are kept until you disconnect the bank or delete your account. When you disconnect a bank, its accounts and transactions are deleted, along with any category changes you made to them.
- If your free trial or subscription ends, syncing stops, and seven days later we close your bank connections at Plaid. The history already in Bilancio is kept, so it is still there if you come back; it is deleted when you delete your account. If you connect the same bank again, the new connection replaces the closed one and its copy of your history.
- Your account is kept until you ask us to delete it.
- Push tokens are deleted when you turn alerts off on that phone, when Apple tells us the token no longer works, or when you delete your account.
- Former waitlist emails are kept until you ask us to remove yours, or until we delete the list.
- Request logs kept by our hosting provider are deleted automatically after a few days.
- Backups. Our database provider keeps a short restore history so the service can recover from a fault. Something you delete can remain in that history for up to 7 days before it is gone for good. It is not used for anything else.
- Payment records are kept by Stripe or Apple under their own policies and the tax and accounting laws that apply to them. Deleting your Bilancio account does not delete their records of what you paid.
7. Your choices and rights
Whatever jurisdiction you are in, you can ask us to:
- Disconnect a bank and delete everything that came from it
- Delete your account and all data associated with it
- Get a copy of the data we hold about you
- Correct anything inaccurate that we control
- Remove your email from our former waitlist
Disconnecting a bank and deleting your account are both in the app, under Banks. Disconnecting revokes our access at Plaid and then deletes that bank's accounts and transactions. Deleting your account does that for every connected bank, then erases your data and your sign-in. Neither can be undone.
Deleting your account does not cancel a subscription. Cancel it first — on the website from your account page, or for a subscription bought in the iPhone app, in your Apple account under Settings, your name, then Subscriptions.
For a copy of your data, a correction, or removal from our former waitlist, email privacy@bilanciomoney.com from the address on your account and we will action it within 30 days.
Deleting your account removes your records from our database. It does not by itself revoke Plaid's own copy of your data — to do that, use Plaid Portal, where you can see and revoke every connection you have made through Plaid to anyone.
If you are a California resident, you have rights under the CCPA/CPRA including access, deletion, correction, and the right to opt out of sale or sharing. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of, but the other rights are exercised as described above. We will not discriminate against you for exercising them.
8. Cookies
Bilancio uses cookies only to keep you signed in (set by Clerk) and, where our hosting provider needs it, to tell people from automated attacks. If you subscribe on the website, Stripe's checkout page sets its own cookies for payment and fraud prevention, under Stripe's policy. There are no advertising cookies, no analytics cookies, and no cross-site tracking.
9. Children
Bilancio is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us information, email us and we will delete it.
10. Where your data is held
Your data is stored and processed in the United States. If you use Bilancio from outside the United States, you are sending your information there.
11. Changes to this policy
If this policy changes we will update the date at the top. For a change that materially affects how we handle your data, we will tell you — by email or in the app — before it takes effect.
12. Contact
Privacy questions, requests, or concerns: privacy@bilanciomoney.com. Security reports: security@bilanciomoney.com. Help with the app: support@bilanciomoney.com.
Guardiano del Faro LLC, Texas, United States.