Skip to main content
Budget Tool

Privacy notice

Last updated 31 August 2026.

One section is still outstanding: the hosting provider has not been chosen. Everything else is complete and accurate. Where a provider is named below as a commitment rather than a fact, it says so.

Who is responsible for your data

Budget Tool is built and run by Michael Shreeves, as an individual rather than as a company. I am the data controller for the personal data described here, and I am the person who answers when you get in touch.

Email [email protected] about anything on this page — a question, a correction, a request about your own data, or a complaint. I aim to reply within five working days, and I will always tell you what I can do and by when.

As a sole individual operating at this scale I am not required to appoint a Data Protection Officer, so there is not one to name.

What we collect, and why

When you register an organisation

What Why Lawful basis
Your first and last name To identify you in the application, and to attribute the actions you take Performance of a contract
Your email address To sign you in, to confirm you control the address, and to send password resets Performance of a contract
Your password To authenticate you. Stored only as a one-way hash and never recoverable Performance of a contract
Your organisation's name To create and identify your organisation Performance of a contract

While you use the application

  • An audit record of what you do. Every significant action — creating, changing or deleting records, approving budgets, importing data, issuing API credentials — is recorded with your identity, the time, and what changed. This exists so an organisation can answer "who changed this?", and is a legitimate interest in maintaining an accurate financial record. Passwords, two-factor secrets and API tokens are never recorded in it.
  • When you last signed in, so administrators can identify dormant accounts.
  • A two-factor secret, if you enable two-factor authentication. It is encrypted at rest, and recovery codes are stored only as one-way hashes.
  • Whatever your organisation puts into it. Budget and supplier data may name individuals. Your organisation decides what it enters; it is the controller of that content and we process it on their behalf.

Server logs

Ordinary application logs record request activity, errors, and events such as a rate limit being reached. Password reset links are deliberately never written to logs outside a developer's own machine.

What we do not do

  • No advertising, no profiling, and no automated decision-making about you.
  • No analytics or tracking scripts. The application sets one cookie, to keep you signed in.
  • We do not sell or share your data with anyone for their own purposes.

Who else processes your data

A hosting provider stores the database and runs the application, and a mail provider delivers confirmation and password-reset messages. [The specific providers are not yet named because the production host has not been chosen. This will be completed, with each provider and the country it operates in, before the application is used with real people's data.]

If your organisation configures its own email provider — which Budget Tool supports — that provider becomes a processor for your organisation's messages, chosen by you rather than by me. Your own privacy notice should say so.

I do not sell your data, and I do not share it for advertising.

Styling libraries are requested from a public content delivery network when you load a page, which means that network receives your IP address. Fonts are not — the typeface is served from this application, so loading a page sends nothing to a font provider.

How your data is protected

These are properties of the software itself, and you can hold me to them:

  • Passwords and password-reset tokens are hashed, never stored in a form anybody can read.
  • Secrets that have to be recoverable, such as two-factor keys and mail credentials, are encrypted at rest.
  • Every organisation's data is isolated from every other organisation's, enforced in the database layer rather than trusted to individual queries.
  • Sensitive actions are recorded in an audit trail, without ever recording a password or a token.
  • Access is role-based, and two-factor authentication is available to every account.

Where your data is held

Budget Tool will be hosted in the United Kingdom, on infrastructure provided by a third-party hosting provider certified to ISO/IEC 27001. I select hosting on that basis, and I work to Cyber Essentials practices in how the application is built and configured.

To be precise about what that does and does not mean: the ISO 27001 certification is the hosting provider's, covering their infrastructure. Budget Tool itself is not certified, and I do not claim it is. [The provider will be named here once the host is chosen, at which point this becomes a statement of fact rather than a commitment.]

How long we keep it

What Kept for Why that long
Your account — name, email address, role While your organisation's account is open It is what signs you in and what names you on the records you approve
Budgets, forecasts and imported transactions Six years from the end of the financial year they relate to The period UK businesses are expected to keep accounting records for
Audit trail — who changed or approved what, and when Six years, alongside the records it evidences An audit trail that outlives its records proves nothing; one that dies first leaves them unexplained
Sign-in and security records 12 months Long enough to investigate unauthorised access, no longer
Invitations that were never accepted Until they expire, then deleted An unaccepted invitation is an email address with no purpose left
Backups 35 days, rolling Deleted data disappears from backups within this window as they age out

When an organisation closes its account, I delete or anonymise its data on the schedule above rather than keeping it indefinitely. Ask me at any time and I will tell you what is held.

Ending an account

You can close your own account at any time, from Settings, without asking anyone. It signs you out immediately and stops you signing in again. An administrator at your organisation can also remove you, with the same effect.

Closing or being removed is reversible: an administrator at your organisation can restore the account. It is not the same as having your personal data deleted, and the application does not pretend otherwise.

Asking for your data to be deleted

Ask an administrator at your organisation to erase your account, or email me directly. Erasure is irreversible, and this is exactly what it does:

  • Removed: your name, email address, password, two-factor setup, any invitation ever sent to your address, and your name on every entry in the audit log.
  • Kept: the budgets, forecasts and imports you created, and the approvals you gave — shown as a removed user rather than under your name.

That second part is a deliberate limit on erasure, and you are entitled to know the reason for it. Those records belong to your organisation rather than to you, and they are financial records it is required to keep accurate. An approval with nobody attached, or a budget whose figures silently changed because its author left, is not an accurate record. So the identity is removed and the record stays. The lawful basis for keeping it is our legitimate interest in an accurate and accountable financial history, and your organisation's own legal obligation to retain accounting records.

The audit log keeps a record of what each account did, after that account ends. While the account exists that includes the name and email address it acted under; after erasure the entry survives with the name replaced. This is retained for six years on the basis of our legitimate interest in security and accountability — without it, closing an account would be a way of erasing what was done with it.

Deactivating an account is a third, milder thing: it suspends access without removing anything, and an administrator can undo it.

Your rights

You can ask for a copy of your data, ask for it to be corrected or erased, object to processing, or ask for it to be restricted. Where a request would conflict with keeping an accurate financial or audit record, we will explain which parts we can act on and why.

Email [email protected] and I will respond within one month, as the law requires. If you are not satisfied, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.

Changes to this notice

This notice is versioned with the application, so its history is visible in the source repository. Material changes will be notified to organisation administrators.

Back to sign in

Guides Get help Accessibility statement Privacy notice