Trust & security
How your money data is handled — without the legal-page jargon.
EU data residency
Your data lives in Frankfurt, Germany, on an OVH VPS (region os-de2) — application and database both. Transactional email goes through Brevo (France). All within the EU/EEA — covered by GDPR by default. OVH is French-headquartered, so the infrastructure provider is itself subject to EU law. Until 2026-07-28 the application ran on a DigitalOcean Droplet: data residency was already in the EU, but a US-headquartered provider meant a Schrems II / US Cloud Act sovereignty gap, accepted deliberately for the beta. The migration to OVH closed it.
Encryption in transit
Every connection between your browser and BudgetHQ uses TLS 1.3 — automatic via Let's Encrypt managed certificates. Traffic between our own services and the database is not TLS, and does not need to be: it never leaves the machine, travelling on a private network inside a single server rather than across the internet. We would rather tell you where the encryption is than imply it is everywhere.
GDPR-aligned by design
Your rights as a data subject under GDPR are baked into the product:
- Access — request a copy of everything we store about you.
- Rectification — fix anything that's wrong.
- Erasure — delete your account + all associated data on request.
- Portability — export your data in machine-readable formats (CSV, JSON).
Sub-processors
We use a small, focused set of third parties. What each one receives differs enormously, so this list says what actually goes where rather than filing them all under one reassuring label:
- Brevo (email delivery) — French company, EU data residency. Sees the recipient address, nothing else.
- Better Stack (uptime monitoring) — minimal metadata only (HTTP probe results + alert emails).
- Sentry (error monitoring) — EU region, Frankfurt. Receives crash reports, with personal fields stripped out before they leave your browser.
- Mistral AI (receipt scanning) — French company. Receives the receipt image itself, because that is what scanning it means. PRO plans only, only when you scan something, and we never store the image on our side.
- Mistral AI (spending insights) — receives category names and monthly totals. No merchant names, no transaction descriptions, no account numbers: the code that builds the request is tested to keep them out. PRO plans only.
What's coming before public beta
Before BudgetHQ moves out of stealth + opens to the public beta, we'll publish a full security posture page — detailed at-rest encryption specifics, SOC 2 / ISO 27001 status, complete sub-processor DPA cross-references, and our breach-disclosure policy with concrete SLAs. The page above covers what's defensible today; the deeper compliance surface lands when public beta brings actual scrutiny.