Legal

Privacy Policy

Last updated: September 26, 2026

The short version

  • Your budget data exists because you typed it — Rudopo has no bank connections and never asks for bank credentials.
  • We don't sell your data, run ads, build profiles from it, or use it to train AI models.
  • A short list of infrastructure providers touch your data, each for one job — sign-in, hosting, database, fault reports, email, and the AI tooling we use to build, run and support Rudopo.
  • Export everything or delete your account yourself, from Settings, anytime. Deletion is immediate and cannot be undone; a pseudonymised trial record is kept for 12 months so a free trial can't be repeated.
  • Rudopo is operated from the United States and open to sign-ups everywhere. Your data is stored in the US, except fault reports, which are kept in the EU.
  • This summary is a courtesy — the numbered policy below is the binding text.

1. Controller, scope and contact

Who is responsible for your data, and what this policy covers.

1.1 This Privacy Policy describes how Rudopo LLC (the "Controller", "we", "us") processes personal data in connection with the personal-budgeting service made available at rudopo.app (the "Service").

1.2 The Controller determines the purposes and means of the processing described in this Policy.

1.3 Territorial scope. The Service is operated from the United States and is offered to users wherever they reside. The rights described in section 10 are extended to every user.

1.4 This Policy applies to the Service and to the Controller's public website. It does not apply to any third-party website or service to which the Service may link, each of which is governed by its own privacy notice.

1.5 Enquiries concerning this Policy or the exercise of the rights described in section 10 may be addressed to hello@rudopo.app.

2. Definitions

The handful of terms this policy leans on.

2.1 "Personal data" (or "personal information") means information that identifies, relates to, or could reasonably be linked with you. "Processing" means any operation performed on personal data, including collection, storage, use, disclosure and erasure. "Controller" means the party determining why and how personal data is processed; "processor" means a party that processes it on the Controller's behalf and on its instructions.

2.2 "Customer Data" means the records you submit to or generate within the Service, as defined in the Terms of Service.

2.3 "Processor" describes each service provider listed in section 7, which processes personal data on documented instructions from the Controller.

3. Categories of personal data processed

Exactly what we hold: your login, your preferences, and the budget data you typed.

3.1 Account data. Electronic mail address; optional display name and profile image; authentication credentials or federated sign-in identifiers; a persistent account identifier; session state; and the internet protocol address and user-agent string recorded at sign-in. Authentication credentials are collected and held by the identity provider identified in section 7; the Controller neither receives nor stores any password.

3.2 Customer Data. The financial records you enter or import, comprising accounts, balances, transactions, amounts, dates, payees, memoranda, categories, budgets, labels, rules, reminders, recurring templates, reconciliations and notes, together with statement files you upload in CSV, OFX, QFX, QIF or PDF format and figures derived by the Service from that data. Customer Data exists within the Service solely because you entered or imported it.

3.3 Preference data. Interface settings including theme, layout, ordering and display preferences.

3.4 Support data. Where you submit a request through the in-application support facility: the content of your request; any image file you elect to attach, which may depict your own financial data; contextual technical information captured automatically, comprising the application route from which the request was submitted, the viewport dimensions and the browser user-agent string; and our response. Where you submit a testimonial and elect to permit its publication: a record of that election, the wording you agreed to, the time, and the credit you chose — your first name, your initials, or none — as it stood at that time. Where you correspond by electronic mail, the content of that correspondence and the associated address.

3.5 Technical and security data. Server logs maintained by the hosting processor, comprising internet protocol address, timestamp, requested path and user-agent string; audit records of security-relevant actions taken within your account; aggregate per-day activity counters; and, where a fault occurs, diagnostic information describing the failure.

3.6 Consent records. Where processing is founded on consent, a record of the purpose, the version of the notice consented to, and the time of grant or withdrawal, retained so that a grant or withdrawal of consent can be evidenced. Consents recorded through the consent facility also carry the internet protocol address and user-agent string at that time; the testimonial consent described in section 3.4 carries neither.

3.7 Source. All personal data is obtained directly from you, save for (a) the federated sign-in assertion supplied by your chosen identity provider where you elect social sign-in, and (b) the technical data in section 3.5, which is generated automatically in the course of your use of the Service.

4. Why we process personal data

Every purpose we use it for, and the legal basis for each. There is no marketing purpose on the list.

4.1 The Controller processes personal data only for the purposes set out below. Each purpose states why the processing is necessary; where a purpose is not necessary to provide the Service, it is carried out only with your consent.

  • Provision of the Service — creating and administering your account, storing and displaying Customer Data, computing budgets, reports and projections, converting currencies and operating reminders. Necessary to provide the Service you signed up for.
  • Authentication and session management — verifying your identity and maintaining your session. Necessary to provide the Service.
  • Support — receiving, investigating and answering your requests, and remedying the defects they identify. Necessary to answer you, and in our legitimate interest as regards using what you report to fix the underlying defect.
  • Testimonials — publishing on the Rudopo website a testimonial you have submitted, credited as you chose. Your consent, given only by ticking the box in the request form; a testimonial submitted without it is treated as private support data. You withdraw consent by deleting the request, whereupon any published quotation is removed. Nothing is published automatically.
  • Security, integrity and abuse prevention — logging, rate limiting, audit recording and investigation of suspected misuse. In our legitimate interest in protecting a financial application and its users against unauthorised access, automated abuse and service disruption. The data processed is limited to what that requires, is not enriched from external sources, and is never used for profiling.
  • Diagnosis of faults — recording and analysing technical failures. In our legitimate interest in the reliability and correctness of a service entrusted with financial records.
  • Backup and continuity — maintaining backups against loss or corruption. Necessary to protect the integrity and availability of your data.
  • Service communications — notices concerning security, availability, and changes to terms, pricing or this Policy. Necessary to provide the Service and to meet our legal duties.
  • Trial eligibility — applying the rule that each customer has one trial period, using the trial-period record described in section 9.1. In our legitimate interest in preventing repeated free trials.
  • Compliance with legal obligations — responding to lawful requests and satisfying retention duties. Required by law.
  • Optional communications — any communication not necessary to the Service. Only with your consent, which you may withdraw at any time without affecting anything done before you withdrew it.

4.2 The account data described in section 3.1 is necessary to create an account; without it the Service cannot be provided. Everything in section 3.2 is entirely at your discretion — the Service works with as little or as much as you choose to enter.

5. Data not processed; special categories; automated decision-making

What we deliberately don't collect, and the fact that nothing here makes automated decisions about you.

5.1 Data not collected. The Controller does not collect, request or store:

  • online-banking credentials of any kind; the Service maintains no connection to any financial institution and engages no account-aggregation provider;
  • payment-card numbers or other full payment instrument details; checkout is operated by a payment provider acting as merchant of record, and such details are not transmitted to the Controller;
  • advertising identifiers, cross-site tracking identifiers, or data obtained from data brokers; the Service contains no advertising network, advertising cookie or cross-site tracker;
  • biometric identifiers, precise geolocation, or government-issued identification numbers.

5.2 Sensitive information. The Controller does not seek or knowingly process information revealing health, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sex life or sexual orientation, or biometric or genetic data. Free-text fields such as memoranda and payee names are completed entirely at your discretion and may, depending upon what you enter, incidentally reveal information of a sensitive character. Such fields are stored as entered; they are not indexed for meaning, subjected to inference, used for profiling, or used to develop or train machine-learning models.

5.3 Automated decision-making. No decision producing legal effects concerning you, or similarly significantly affecting you, is taken on the basis of automated processing. Rule-based categorisation applies only rules you have yourself defined, and is reversible by you at any time.

5.4 Model training and disclosure for value. The Controller does not use personal data to develop or train machine-learning or artificial-intelligence models, and does not sell, rent or otherwise disclose personal data to any third party for consideration or for that third party's independent purposes.

6. Cookies, local storage and similar technologies

What gets stored in your browser. No advertising or tracking cookies.

6.1 Browsing the public pages of this website — the home page, the feature and pricing pages, the blog and these legal documents — sets no cookie whatsoever and causes your browser to contact no third party. Typefaces are served from the Controller's own domain rather than a font network, and no authentication, analytics or advertising script is loaded. You are not identified, and no record of your visit is associated with you.

6.2 Within the application, the Service sets cookies solely for authentication and session continuity. Such cookies are strictly necessary to deliver a service you have requested; no consent banner is presented because there is nothing optional to consent to. No advertising, analytics or cross-site tracking cookie is set.

6.3 The Service uses your browser's local storage for two purposes: (a) retention of interface preferences, which persist on your device until your account is deleted or you clear your browser storage; and (b) a cache of recently viewed application data, which enables the Service to render immediately upon opening and which is cleared upon sign-out. Local-storage contents remain on your device and are not transmitted to the Controller.

7. Recipients and processors

The named companies that touch your data, one job each, and the few other cases in which data is disclosed.

7.1 The Controller engages the processors below, each of which receives only such personal data as its function requires and processes it on documented instructions:

  • Clerk, Inc. (identity and authentication) — account data under section 3.1, including credentials, session state and sign-in metadata.
  • Vercel Inc. (application hosting and delivery) — all request traffic in transit, and the server logs described in section 3.5.
  • Turso (managed database) — all data stored by the Service, comprising sections 3.1 to 3.6.
  • Sentry (fault monitoring) — diagnostic data under section 3.5. The integration is configured to suppress request bodies and cookies and to disable performance tracing, and the Controller has elected the provider's European region for storage.
  • Zoho Corporation (electronic mail) — the content of support correspondence conducted by electronic mail under section 3.4.
  • Resend (transactional electronic mail) — your email address and the content of service messages the Controller sends you, such as notice that a free trial is about to end or that an account is scheduled for erasure. It is not used for marketing, and the Controller does not enable open or click tracking on these messages.
  • Anthropic PBC (artificial-intelligence tooling) — the Controller uses AI tooling supplied by Anthropic to build, operate and support the Service. Personal data processed by that tooling includes the support data described in section 3.4, including any image you attach, and the diagnostic data described in section 3.5.
  • Cloudflare, Inc. (authoritative domain-name service) — domain-name queries only; no application data.

7.2 The Controller obtains European Central Bank reference exchange rates from a public interface, obtains Banca d'Italia reference exchange rates for certain other currencies from Banca d'Italia, and once a day compares the rates it derives for currencies pegged to the US dollar with those published by Banca d'Italia. Such requests transmit currency codes and dates only and convey no personal data; the operators of those interfaces are accordingly not recipients of personal data.

7.3 Where you elect federated sign-in, your chosen identity provider acts as an independent controller in respect of the credentials you hold with it and of the authentication assertion you authorise it to release.

7.4 Dodo Payments Inc. acts as merchant of record and processes payment data as an independent controller under its own terms, presented at checkout. Card details are entered with Dodo and are never transmitted to or stored by the Controller, which receives only a customer identifier, a subscription identifier, the plan, its status, the end of the current period and any trial end.

7.5 Beyond the processors named above, personal data is disclosed only: (a) where required by valid legal process, in which case the Controller discloses the minimum lawfully required and, where not prohibited from doing so, notifies you in advance; (b) where strictly necessary to investigate fraud or abuse directed at the Service or its users; (c) to a successor entity in connection with a merger, acquisition or sale of assets, in which case the successor is bound by this Policy and you will be notified before the transfer takes effect; (d) to the members of a space you share or join, who see that space's data and the name and email address of each member and of each person invited to it; or (e) as a testimonial, under section 7.6.

7.6 The public Rudopo website is a recipient only of a testimonial you have consented to publish, credited as you chose, and of nothing else.

8. Where your data is stored

Who hosts it, where it goes when you use Rudopo from abroad, and the one category held separately.

8.1 The Service and its data are hosted in the United States, and the processors identified in section 7 are established principally there. Where you use the Service from outside the United States, your personal data is transferred to, and processed in, the United States.

8.2 Two details worth stating precisely:

  • Diagnostic fault data is held in the monitoring provider's European region rather than in the United States. That was a deliberate choice: it is the least sensitive category we process, and storing it in Europe costs nothing.
  • Each processor listed in section 7 processes personal data under the terms on which the Controller engages it, which govern what it may do with that data.

8.3 The Controller keeps those terms under review and will update this section upon any material change to a processor's contractual position or the location in which it stores data.

9. Retention and erasure

How long things are kept, and what happens when you delete your account.

9.1 Personal data is retained for the periods set out below and is thereafter erased or irreversibly anonymised.

  • Account data, Customer Data, preference data, audit records, activity counters and consent records — for the duration of the account, and erased upon its deletion, save for the trial-period record below.
  • Lapsed accounts — where a renewal charge fails, full access continues while the merchant of record retries collection for up to 7 days, after which an unrecovered subscription is cancelled. Where access under a subscription, including a free trial, ends and is not renewed, the account is restricted to viewing, exporting and deleting Customer Data, and the account and all Customer Data are permanently erased not earlier than 12 months after access ends. Notice is given by electronic mail before erasure, and resubscribing within that period restores full access and all Customer Data and cancels the erasure.
  • Accounts that never start a subscription — the account is restricted in the same way from the later of the date it was created and the date on which paid subscriptions were first offered, and the account and all Customer Data are permanently erased not earlier than 60 days after that later date unless a subscription is started before then. Notice is given by electronic mail before erasure.
  • Trial-period record — to apply the rule that each customer has one trial period, the Controller keeps a pseudonymised record comprising a keyed hash of the normalised email address, the start and end dates of the trial period, and the payment provider's customer and subscription identifiers. It is kept on the basis of the Controller's legitimate interest in preventing repeated free trials, survives deletion of the account, and is erased 12 months after the account is deleted.
  • Support data — until you delete the request within the Service, or until deletion of the account, whichever occurs first. Correspondence conducted by electronic mail is retained separately as ordinary business correspondence and is erased upon request.
  • Server logs — in accordance with the hosting processor's retention cycle.
  • Diagnostic fault data — in accordance with the monitoring processor's project retention period.
  • Backups — the point-in-time recovery copies kept by the database processor, for that processor's rolling retention period; and complete copies of the database that the Controller takes before a risky change to it, which are held on the Controller's own equipment and deleted once that change is complete. A copy taken before your account was deleted may therefore hold your data until that copy is deleted.
  • Database storage — deleted records are removed from the database at the moment of erasure and are thereafter unreachable by the Service. As is inherent to databases of this kind, the underlying storage may retain residual fragments on pages marked as free until those pages are reused in the course of normal operation. That storage is encrypted at rest, is not queryable, and is not accessible to the Controller.

9.2 Deletion of the account. You may delete your account at any time from Settings. Deletion takes effect immediately and is irreversible: it removes your spaces, accounts, transactions, preferences, support requests and authentication identity; the trial-period record described in section 9.1 is kept as stated there. There is no grace period and no facility to cancel a deletion once confirmed. The confirmation dialogue offers a complete backup download before the point of no return, and you are strongly advised to take it.

9.3 The Controller may retain personal data beyond the periods stated above only to the extent required to comply with a legal obligation, to establish, exercise or defend legal claims, or to prevent fraud, and only for so long as that purpose subsists.

9.4 Erasure initiated by the Controller. Where access under a subscription ends and is not renewed, or where no subscription is started for an account, erasure of the account is scheduled as set out in section 9.1. Notice of the scheduled date is given by electronic mail before it arrives, the account remains available for viewing, export and deletion until that moment, and resubscribing, or starting a subscription, at any time before it cancels the scheduled erasure. Section 9.2 (erasure at your own request, immediate and irreversible) is unaffected.

10. Your rights

What you can ask for — access, correction, export, deletion — and how to do it.

10.1 Subject to the conditions and exceptions provided by law, you have the rights set out below. Some of them are conferred by particular statutes on residents of particular places; the Controller extends all of them to every user, wherever they live.

  • Access — to know whether personal data about you is processed and, if so, to obtain a copy of it together with the information set out in this Policy.
  • Correction — to have inaccurate data corrected and incomplete data completed.
  • Deletion — to have your personal data erased.
  • Portability — to receive your data in a structured, commonly used, machine-readable format and to take it elsewhere.
  • Restriction and objection — to ask us to stop or limit processing carried out in our legitimate interests.
  • Withdrawal of consent — to withdraw any consent you have given, at any time, without affecting anything done before you withdrew it.
  • Non-discrimination — to exercise any of the above without being charged a different price or given a lesser service.

10.2 Exercise of rights. Rectification, portability and erasure are implemented within the Service itself: Customer Data is directly editable; a complete machine-readable export is available from Settings at any time; and account deletion operates as described in section 9.2. For any other request, write to hello@rudopo.app. The Controller responds without undue delay and in any event within one month of receipt, extensible by two further months where necessary having regard to the complexity and number of requests, in which case you will be informed within the first month.

10.3 Verification. Where the Controller entertains reasonable doubt as to the identity of the person making a request, it may request such further information as is reasonably necessary to confirm identity before acting on it.

10.4 Complaint. If you are dissatisfied with how a request was handled, write to hello@rudopo.app and say so — a person reads it. You may also complain to the data protection or consumer protection authority for your jurisdiction, including, where you reside in the European Economic Area, the United Kingdom or Switzerland, the supervisory authority of the country in which you live; in California, that is the California Privacy Protection Agency or the Office of the Attorney General.

11. United States state privacy rights

Extra rights some state laws give you, and our confirmation that we don't sell your data.

11.1 Where a state privacy statute of the United States applies to you, you may have rights to know what personal information is collected, to access and obtain a copy of it, to correct inaccuracies, to delete it, and not to be discriminated against for exercising those rights. The mechanisms described in section 10.2 serve those rights equally.

11.2 The Controller does not sell personal information and does not share personal information for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act as amended. No such activity has occurred at any time.

11.3 The Controller does not process sensitive personal information for the purpose of inferring characteristics about any individual.

12. Security of processing

The concrete measures protecting your data, not a vague promise that it's safe.

12.1 The Controller implements technical and organisational security measures appropriate to the risk, including:

  • encryption of all data in transit by transport-layer security, and encryption at rest at the database layer by the hosting processor;
  • supplementary application-layer encryption of complete data exports using AES-256-GCM, such that an exported archive cannot be read without the Controller's key;
  • delegation of credential handling to a specialist identity provider, such that no password is stored by the Controller;
  • authorisation of every request against verified account membership, with tenant isolation exercised by an automated test suite that includes deliberate cross-account access attempts;
  • rate limiting at both network and account level, with stricter limits upon data-export endpoints;
  • an operator console limited by design to account and billing metadata and to support requests, which cannot list Customer Data, with administrative privilege grantable only by direct database intervention;
  • environment-scoped secret management, the production environment failing to build where a required credential is absent;
  • reviewed, version-controlled database migrations rehearsed against a separate staging environment before application to production;
  • automated daily verification of production availability, including a database round-trip, with failure notification to the operator; and
  • point-in-time recovery maintained by the database processor, and complete copies taken before risky changes to the database, restoration from such a copy having been tested.

12.2 No method of transmission or storage is entirely secure, and the Controller does not warrant absolute security. The measures above are kept under review and revised as the Service evolves.

13. Personal data breach

What we do, and how fast, if something goes wrong.

13.1 Where a security incident results in the unauthorised acquisition of, or access to, personal data, the Controller shall notify affected users without undue delay, and shall notify the authorities required by applicable breach-notification laws within the periods those laws prescribe. Notification to users is made to the electronic mail address associated with the account and, where appropriate, within the Service. The Controller commits to notifying affected users even where a statute would not require it, if the incident is one they would want to know about.

14. Children

Rudopo isn't for children, and we don't knowingly hold their data.

14.1 The Service is not directed to children and may not be used by any person under the age of sixteen (16). The Controller does not knowingly process personal data relating to such a person and shall erase any such data upon becoming aware of it. A parent or guardian who believes that a child has provided personal data may write to hello@rudopo.app.

15. Amendment of this Policy

How this policy changes, and when we tell you first.

15.1 This Policy may be amended from time to time. The date stated at the head of this document reflects the version then in force. Where an amendment materially expands the categories of personal data processed, the purposes of processing, or the recipients to whom personal data is disclosed, notice shall be given by electronic mail or within the Service before the amendment takes effect.

16. Contact

Where to write.

16.1 Enquiries, requests under section 10 and complaints: hello@rudopo.app. Reports of suspected security vulnerabilities: security@rudopo.app. Postal address: Rudopo LLC, 701 South St. STE 100, Mountain Home, AR 72653, United States.