Legal
Privacy Policy
Effective Date: May 8, 2026
1. Introduction
ImperaBudget (“ImperaBudget,” “we,” “us,” or “our”) is operated by Impera Budgeting, LLC, a Tennessee limited liability company and a wholly-owned subsidiary of Impera Solutions Holding, LLC. This Privacy Policy explains how we collect, use, share, and protect personal information when you use our website at imperabudget.com, our mobile applications, and related services (collectively, the “Service”).
Because we provide a financial product, we are also subject to the federal Gramm-Leach-Bliley Act (“GLBA”). This Privacy Policy includes the disclosures required by GLBA, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and similar laws in other states.
If you have questions, contact us at privacy@imperabudget.com.
2. Information We Collect
2.1 Information You Provide
- Account information: name, email address, password
- Profile information: optional display name, time zone, household composition
- Financial data: budgets, plans, transaction notes, subscription records, debt accounts, manual transactions
- Communications: messages you send to support
- Phone number: only if you opt in to SMS alerts
2.2 Information From Third Parties
- Plaid Inc. When you connect a bank or credit card account, Plaid provides us with account balances, transaction history, account ownership details, and institution metadata. Plaid handles your financial-institution credentials directly; we do not see, receive, or store them. Plaid's End User Privacy Policy is available at plaid.com/legal.
- Stripe. When you subscribe, Stripe provides a customer identifier and subscription status. Payment-card details are handled and stored by Stripe; we do not see, receive, or store them.
- Authentication providers. If you sign in with Google or Apple, we receive your verified email address and a unique identifier from that provider.
2.3 Information Collected Automatically
- Device and browser data: IP address, user agent, operating system, device identifiers
- Usage data: pages viewed, features used, timestamps, click and scroll events for product analytics
- Audit log events: sign-in, sign-out, password change, data export, account deletion request, and similar security-relevant actions
- Cookies and local storage: see Section 9
3. Categories of Personal Information (CCPA/CPRA)
For California residents, the categories of personal information we collect, as defined by the CCPA, include:
- Identifiers: name, email, IP address, account ID
- Customer records: account profile information
- Commercial information: subscription status and history
- Internet or network activity: usage data, audit log
- Geolocation data: approximate location derived from IP address only; we do not collect precise geolocation
- Inferences: budget categories, spending patterns, and forecasts derived for your own benefit
- Sensitive personal information: account log-in credentials and financial-account information, used solely to provide the Service
We do not collect biometric data, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, sexual orientation, immigration status, genetic data, or health information.
4. How We Use Information
We use personal information to:
- Provide, operate, and maintain the Service
- Authenticate users and protect account security
- Process subscription payments through Stripe
- Aggregate transaction data from connected institutions through Plaid (only for accounts you choose to connect)
- Generate AI-assisted categorization and insights through the Anthropic API for features you explicitly invoke
- Send transactional messages (account alerts, security notices, billing receipts, password resets)
- Send service announcements and, with your consent, occasional product updates
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Comply with legal obligations and enforce our Terms of Service
We do not use your information to train AI models. Data sent to Anthropic for AI features is governed by the Anthropic API Commercial Terms, which prohibit retention for model training.
5. How We Share Information
5.1 We Do Not Sell Your Data
We do not “sell” personal information as defined by the CCPA, and we do not “share” personal information for cross-context behavioral advertising. We have not done so in the preceding twelve (12) months.
5.2 Service Providers (Sub-processors)
We share information with vendors who process data on our behalf under written data-processing agreements. All sub-processors process and store data within the United States. Backup and disaster-recovery storage may use additional United States regions of the same providers.
| Vendor | Purpose |
|---|---|
| Supabase | Database, authentication, and file storage |
| Vercel | Web application hosting and content delivery |
| Stripe | Subscription payment processing |
| Plaid | Bank account aggregation (only if you connect) |
| Anthropic | AI features (transaction classification, Smart Budget Import) |
| Resend | Transactional email delivery |
| Twilio | SMS verification and alerts (only if you opt in) |
| Sentry | Error monitoring |
| Doppler | Secrets management (no end-user data) |
We may add or remove sub-processors as our service evolves. Material changes will be reflected in this list and, where required by law, communicated through email or in-app notification.
5.3 Legal Disclosures
We may disclose information when we have a good-faith belief disclosure is required to (i) comply with applicable law, court order, or other legal process; (ii) protect the rights, property, or safety of ImperaBudget, our users, or others; or (iii) detect, investigate, or prevent fraud or security incidents.
5.4 Business Transfers
If we are involved in a merger, acquisition, financing, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
6. GLBA Financial Privacy Notice
This section is our Financial Privacy Notice as required by the federal Gramm-Leach-Bliley Act.
Why we collect. We collect your nonpublic personal financial information to provide the budgeting, transaction management, subscription tracking, and related services you request.
What we collect. Information you provide directly (account profile, manual transactions, budgets) and information we collect from your linked institutions through Plaid (account balances, transaction history, institution metadata).
What we share. We share information only with the service providers listed in Section 5.2 to operate the Service, and as required by law (Section 5.3).
What we do not share. We do not share your nonpublic personal information with non-affiliated third parties for their marketing purposes. We do not sell, license, or rent your information.
Affiliates. Our only affiliate is our parent company, Impera Solutions Holding, LLC. We do not share customer data with our affiliate for the affiliate's marketing purposes.
Joint marketing. We do not engage in joint marketing arrangements that involve sharing your information.
Your right to limit sharing. Because we do not share your nonpublic personal information for marketing or with non-affiliated third parties (other than service providers), the federal opt-out under GLBA does not apply. State law may provide additional rights; see Section 7.
Security. We protect your information through administrative, technical, and physical safeguards described in Section 11 and our Written Information Security Program.
7. Your Privacy Rights
7.1 Rights Available to All Users
Regardless of where you live, you have the right to:
- Access: Download a copy of your data from Settings → Security in CSV or JSON.
- Correct: Edit your profile and most data directly in the Service.
- Delete: Delete your account from Settings → Security. A 30-day grace period allows you to reverse the decision; after that, all personal data is permanently erased except records we are required to retain by law (such as tax and payment records).
- Object: Email privacy@imperabudget.com to object to specific processing.
7.2 California Residents (CCPA/CPRA)
You have the right to:
- Know what personal information we have collected, the categories of sources, the purposes of collection, and the categories of recipients
- Delete your personal information, subject to legal exceptions
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information (we do neither, so this right is automatically honored)
- Limit the use and disclosure of sensitive personal information (we use sensitive PI only as necessary to provide the Service)
- Non-discrimination for exercising these rights
- Designate an authorized agent to make requests on your behalf
To exercise these rights, email privacy@imperabudget.com or use the controls in Settings. We will respond within forty-five (45) days as required by law. We may need to verify your identity by asking you to confirm information associated with your account.
7.3 Other State Residents
If you live in Colorado, Connecticut, Delaware, Iowa, Indiana, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, or Virginia, you have rights similar to those above under your state's privacy law. Email privacy@imperabudget.com to exercise them. We will respond within the timeframe required by your state's law.
7.4 Appeals
If we deny a privacy-rights request, you may appeal by replying to our denial email. We will respond to appeals within sixty (60) days.
8. Data Retention
We retain personal information for as long as your account is active and as needed to provide the Service. After you delete your account, we retain:
- Account profile and product data: erased within thirty (30) days of confirmation
- Transaction and payment records: retained for up to seven (7) years to comply with tax and financial recordkeeping laws
- Audit log events: retained for up to two (2) years for security investigation
- Backup snapshots: cycled out within ninety (90) days
9. Cookies and Tracking
We use cookies and similar technologies for authentication, session management, and product analytics. We do not use cookies for advertising or to track you across other websites. We honor Global Privacy Control (“GPC”) signals as a do-not-sell/share request.
You can disable cookies in your browser settings, but doing so may impair sign-in and core functionality.
10. Children's Privacy
The Service is not directed to children under thirteen (13). We do not knowingly collect personal information from children under 13. To use the Service, you must be at least 13 years old. To subscribe to a paid plan, you must be at least 18.
If you believe we have collected information from a child under 13, contact privacy@imperabudget.com and we will delete it promptly.
11. Security
We protect personal information using:
- TLS 1.2+ encryption for data in transit
- Encryption at rest for primary databases and backups
- Per-user authentication and Row-Level Security at the database layer
- Audit logging of administrative access
- Multi-factor authentication for ImperaBudget personnel with production access
- A documented Written Information Security Program (WISP) reviewed at least annually
No method of transmission or storage is one hundred percent secure. We will notify affected users and applicable regulators of a data breach as required by state and federal law.
12. International Users
The Service is currently offered only to United States residents. If you access the Service from outside the United States, you do so at your own risk and your information will be transferred to and processed in the United States.
13. Changes to This Policy
We will post any material changes to this Privacy Policy on this page and update the Effective Date. For significant changes, we will provide additional notice by email or in-app notification at least thirty (30) days before the change takes effect.
14. Contact
Impera Budgeting, LLC
Attn: Privacy
6688 Nolensville Road, Suite 108
Brentwood, Tennessee 37027
- Privacy: privacy@imperabudget.com
- Security disclosures: security@imperabudget.com
- General support: support@imperabudget.com
We respond to privacy inquiries within thirty (30) days.
© 2026 Impera Budgeting, LLC. All rights reserved.