The short version

Contents

  1. What we protect
  2. How encryption works
  3. Local-only by design
  4. Cloud backup
  5. Recovery key
  6. What we don’t do
  7. Questions or reports

1. What we protect

Your money data — transactions, budgets, accounts, goals — is encrypted on your phone. If someone takes your phone, opens the file, intercepts a backup, or breaks into your Google Drive, all they get is unreadable ciphertext.

We can’t protect against malware that reads your screen, someone forcing you to unlock the app, or you losing your phone with no backup. Keep your phone clean and take backups.

2. How encryption works

In plain English:

For technical details, email support@budgetlock.app.

3. Local-only by design

Budget Lock has no backend server. That means:

If anyone asks for your data, there is nothing on our side to hand over.

4. Cloud backup

Cloud backup is off by default. When you turn it on:

  1. You sign into your own Google account.
  2. Budget Lock can only see one private folder on your Drive — not your photos, documents, or anything else.
  3. Your file is encrypted on your phone before it uploads.
  4. Up to 30 versions are kept; older ones are pruned automatically.

Google sees an encrypted file. Without your password, it’s unreadable.

You can sign out, delete every backup, or revoke the link any time from Settings → Cloud Backup.

5. Recovery key

When you create a vault, Budget Lock generates a 24-character recovery key. Save it somewhere safe — a password manager, a fireproof box, or written down at home.

Important: If you forget your password and lose your recovery key, your data is permanently unrecoverable. There is no admin override and no reset link. We don’t have one because there’s no server where one could exist.

6. What we don’t do

Questions or reports

Security questions, vulnerability reports, or export-compliance queries: support@budgetlock.app