Last updated: July 5, 2026
Budget by Mail — Privacy Policy
Budget by Mail ("the app", "we") turns the transaction-alert emails your bank already sends into a categorized budget inside a Google Sheet you own. This policy explains what data the app accesses, how it's used, and what leaves your Google account.
What the app accesses
- Gmail (read & label): the app reads the transaction-notification
emails you route into its Gmail label, and applies labels (e.g.
processed) so it doesn't reprocess them. It reads only messages in that label as part of the pipeline; it does not read your wider mailbox for any other purpose. - Your Google Sheet: it writes parsed transactions and dashboards into the active Budget by Mail spreadsheet.
- Your email address: used to verify you against the invitation allowlist for the shared AI service.
How your data is used
- Categorization (data leaves Google): to extract and label each transaction, the contents of that transaction email (merchant, amount, date, description) are sent to an AI provider — Anthropic by default, or a provider you choose with your own API key. On the shared key, these requests pass through our proxy server on the way to the AI; with your own key they go directly to your provider. This is the only data that leaves your Google account in normal use.
- Storage: your transaction history lives only in your Google Sheet. We do not store your transactions on our servers. The shared proxy forwards AI requests and does not persist their contents. AI providers may retain API requests transiently under their own policies (e.g. Anthropic does not train on API data).
- Reporting a parsing issue (optional): if you use the in-app "Report a Parsing Issue" tool, that specific transaction's details are sent to the operator to improve parsing. The tool shows exactly what will be sent and asks you to confirm first.
Anonymous usage analytics
To understand how the app is used and where to improve it, Budget by Mail sends a small amount of anonymous usage data to Google Analytics: counts and timings such as how many transactions are recorded per day, how many institutions you track, which features you use, the run duration, and the app version. Each installation is identified only by a random ID — never your email or any personal identifier. We never send financial data, merchant names, dollar amounts, category names, or email content in analytics.
Analytics is on by default. To turn it off, set the “Usage analytics” cell on
your Control sheet to FALSE.
What we do NOT do
- We do not sell your data, or share it with third parties except the AI provider used to categorize transactions (above).
- We do not use your data for advertising.
- We do not use your Gmail or Sheet data to train AI/ML models, and we do not allow humans to read it, except (a) with your explicit action when you submit a parsing-issue report, or (b) as required for security or to comply with law.
Third-party AI providers
Depending on your configuration, transaction-email contents are processed by one of: Anthropic (default), OpenAI, or Google (Gemini), each under its own privacy policy.
Data retention & deletion
Because your data lives in your own Google Sheet and Gmail, you control it directly — delete the spreadsheet, remove the Gmail labels, or uninstall the add-on at any time to stop all processing. To request deletion of any parsing-issue report you sent us, email us below.
Contact
Questions or requests: max@maxwheeler.com.