Legal
Privacy Policy
Effective: February 23, 2026 · Terms of Service
This Privacy Policy explains how FS MEDIA (“AIbudget,” “we,” “us,” or “our”) collects, uses, and protects information when you use AIbudget (“Service”). By using the Service you agree to the practices described here.
1. Information We Collect
Account Information. When you create an account we collect your name, email address, username, and password (stored as a one-way hash). If you sign up via a team invitation, we also receive the email address your invitation was sent to.
Project and Budget Data. All budget line items, project settings, PO log entries, payroll entries, petty cash records, comments, and other data you create within the Service are stored on our servers so we can provide the Service to you.
Uploaded Files. When you use AI-assisted document extraction (invoice import, payroll receipt import), you upload files to be processed. These files are transmitted directly to our AI provider (Anthropic) and are not stored on AIbudget’s servers. They exist in memory only for the duration of the API call.
Usage Data. We may collect non-personally-identifiable information about how you interact with the Service, such as features used and general usage patterns, to improve the product.
Communications. If you contact us by email, we retain that correspondence to respond to your inquiry and improve our support.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Authenticate your identity and manage your account
- Send transactional emails: account verification, password resets, and team invitations
- Enable real-time collaboration features between team members
- Process documents through AI extraction when you request it
- Improve and develop new features
- Comply with our legal obligations
We do not sell your personal information to third parties. We do not use your budget data or project content for advertising purposes.
3. AI Processing — Anthropic
AIbudget uses Anthropic’s Claude API to power AI document extraction (invoices and payroll reports) and AI production report generation.
What is sent to Anthropic:
- Files you upload for extraction (invoice PDFs, payroll PDFs, images)
- Aggregated budget and financial data when you generate a production report
- Text prompts describing the extraction or analysis task
What is not sent to Anthropic: Your account credentials, personal contact information, or any data unrelated to the specific AI request you initiate.
Data handling: Uploaded files are not stored by AIbudget after the API call completes. Anthropic’s handling of API inputs is governed by Anthropic’s Privacy Policy. Anthropic’s API terms state that they do not train models on API inputs by default.
All AI features are opt-in actions — data is only sent to Anthropic when you explicitly trigger an extraction or report.
4. Third-Party Services
We use the following third-party services to operate AIbudget:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database and storage | All account and project data |
| Liveblocks | Real-time collaboration | User presence data during active editing sessions |
| Resend | Transactional email | Email address, name (for verification, invites, resets) |
| Anthropic | AI document processing | Uploaded files and budget data (per request only) |
| Vercel | Hosting and infrastructure | Server request logs, IP addresses |
Each of these services has its own privacy policy. We encourage you to review them if you have concerns about specific data practices.
5. Data Security
We take reasonable technical and organizational measures to protect your data:
- All data in transit is encrypted using TLS/HTTPS
- Passwords are stored as one-way bcrypt hashes and are never readable, even by us
- Account access is protected by email verification and brute-force lockout (5 failed attempts triggers a 15-minute lockout)
- API endpoints require authentication and enforce authorization checks to ensure users can only access their own team’s data
- Database access is restricted to application-level service roles
No method of electronic storage or transmission is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
6. Data Retention
We retain your account and project data for as long as your account is active. If you delete your account, we will delete your personal information and project data within a reasonable time, except where we are required to retain it by law or for legitimate business purposes (such as resolving disputes or enforcing agreements).
Uploaded files used for AI extraction are not retained — they are discarded immediately after the API response is returned to your browser.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access. Request a copy of the personal information we hold about you.
- Correction. Request correction of inaccurate information. You can update most account details directly in the app under Account Settings.
- Deletion. Request deletion of your personal information and account. Contact us at support@aibudget.co to request account deletion.
- Portability. Request an export of your data in a machine-readable format.
- Objection / Restriction. Object to or request restriction of certain processing activities.
To exercise any of these rights, contact us at support@aibudget.co. We will respond within 30 days. We may need to verify your identity before processing your request.
California residents have additional rights under the CCPA, including the right to know what personal information is collected and the right to opt out of the sale of personal information. We do not sell personal information.
8. Cookies
AIbudget uses session cookies required for authentication (to keep you logged in). These are strictly necessary for the Service to function and cannot be disabled without logging out.
We do not currently use advertising cookies, third-party tracking cookies, or analytics cookies.
9. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice in the Service before the change takes effect. The “Effective” date at the top of this page indicates when the policy was last updated.
11. Contact
Questions, concerns, or data requests? Contact us at support@aibudget.co.
FS MEDIA · Los Angeles, CA