Budge Privacy Policy
Effective date: August 14, 2026
This policy describes how Inyeon LLC, a New York limited liability company ("Inyeon," "we," "us"), handles personal information in the Budge mobile app and its supporting service (together, the "App").
Budge is a consumer app, operated in the United States. This policy is separate from, and does not incorporate, the Inyeon business platform's privacy policy — that document covers a different, business-only service.
Contact for anything in this policy: team@inyeon.dev
1. The short version
- Budge turns a mess you dump into a tree of steps, then keeps one current step visible until you complete it.
- You sign in with an email address or phone number through Inyeon's hosted sign-in page. Budge never sees or stores a password.
- We store dump text and step text to provide the service. That user content may include health, medication, or legal information. It is user content, not a structured health record.
- Voice is transcribed on-device when the device supports it. If on-device recognition is unavailable, we ask before using the platform cloud recognizer. There is no server speech-to-text in v1. We do not store audio.
- Breakdown uses OpenRouter and the downstream model vendors it routes to. We do not send a dump to a model until you are 17+, have accepted the legal terms, and have signed in.
- Crisis dumps produce no tree and no lock-screen text. Budge is not a crisis service.
- The current step may appear on the lock screen, widget, and notification unless you hide lock-screen details or the dump is crisis-flagged.
- We do not sell personal information, run advertising, or use third-party analytics SDKs. No cross-app tracking.
- You can export your data and delete your account from inside the App (Section 9).
2. Information you give us
Sign-in. You sign in with your email address or phone number on a page hosted by Inyeon (the identity provider Budge uses). We receive a verified identifier for you, plus your email address (for email accounts) or phone number (for phone-first accounts). Budge never receives or stores your password or any one-time code.
Age confirmation. You confirm you are 17 or older before any dump is sent to a model. The App is not directed at children.
Dumps. Text you type or share into the App so it can be broken down into steps. Voice dumps become text through speech-to-text (Section 4); we store the resulting transcript as dump text, not the audio.
Photos and files. When you share or capture an image, PDF, or Word (DOCX) document, that file is uploaded so we can extract text for a dump. Caps: 25 MB per file and 100 pages per document. Extraction runs on our servers in a background worker (not on the share tap). We delete the uploaded file after extract and keep the resulting text as dump content. Images and image-like scans are read with a vision model reached through OpenRouter (and the downstream model vendors it routes to). We do not run on-device OCR such as Tesseract. We still do not fetch URLs you share.
Edits and preferences. Changes you make to step trees, list placement, completion and defer actions, granularity preferences, and settings such as hide-on-lock-screen.
Purchases. If a paid plan is offered through the App Store or Google Play, the store handles the transaction. We receive a verification of the purchase to unlock the plan; payment card details go to Apple or Google, never to us.
3. Information the App creates as you use it
- Step trees produced from a dump: root and child steps, order, and status (including completion and deferral).
- Completion history and related timestamps needed to operate Do mode and surfaces outside the app.
- Crisis flags returned by breakdown when the model indicates crisis or harm content, used only to refuse a tree and keep that text off lock-screen surfaces.
- The push / widget / Live Activity tokens for your device when those surfaces are enabled.
- Server logs: our API logs a request id, method, path, status code, duration, and the requesting IP address, used for rate limiting and abuse prevention. Dump text, transcripts, and step text are not written into first-party logs.
4. Voice, AI breakdown, and sensitive content
Voice (speech-to-text)
- When your device supports it, transcription runs on-device.
- If on-device recognition is unavailable, we ask before using the platform cloud speech recognizer (Apple or Google).
- There is no server-side speech-to-text in v1. We do not run our own STT pipeline.
- Audio is not stored. Only the resulting text may be kept as a dump.
Breakdown (language models)
Dumps are broken into step trees by a large language model reached through OpenRouter, which routes to downstream model vendors. Things worth knowing:
- We do not send a dump to a model until age (17+), legal acceptance, and sign-in gates pass. Local capture may sit in the inbox until those gates are cleared.
- We send dump text for breakdown only. We do not send your password (we never have one) or unrelated account credentials with that request.
- Model providers reachable through OpenRouter have their own retention and training practices, which we do not control. We select providers and routing settings and we do not authorize use of your data to train models; we cannot make an absolute guarantee about a third party's internal handling.
- Generated steps can be wrong or poorly sized. You can edit, delete, merge, reorder, or discard them.
Photos, PDFs, and documents
When file or photo capture is used:
- The file is staged on the device, then uploaded after age, legal acceptance, and sign-in gates pass.
- A worker process extracts text off the request path. The dump stays queued until text is ready, then breakdown can run.
- PDFs and DOCX are parsed for text on our servers. Images and scans use OpenRouter vision (no Tesseract).
- Uploads are capped at 25 MB and 100 pages. The binary upload is deleted after extract; retained dump content is the extracted text.
- We do not follow or fetch shared URLs.
Health and other sensitive user content
We do not collect structured mood, symptom, diagnosis, or medication fields. Unstructured dumps and steps may include health, medication, psychiatry, money, or legal information. That material is user content you chose to enter, not a structured health record we designed the App to build. Treat it as sensitive personal information.
Crisis handling
If breakdown indicates a crisis or harm situation:
- The App produces no step tree and no lock-screen, widget, or notification text for that dump.
- We show that Budge is not a crisis service, and point to local emergency services and resources (in the US, 988; elsewhere, IASP).
- You may still type your own steps by hand or discard the dump.
We do not detect, diagnose, or treat mental health conditions. Refusing to operationalize a crisis dump is a safety refusal, not clinical care.
5. Device permissions
| Permission | Why |
|---|---|
| Microphone | Hold-to-talk dumps, only when you use voice capture. |
| Notifications | Ongoing notification / Live Activity for the current step, if you enable them. |
| Camera / photo library | Only when you capture or share a photo as a dump. |
The App does not request access to your contact list, location, calendar, or device health databases.
6. What appears outside the App
Budge has no social feeds or public profiles. The only surfaces that show your content outside the main UI are ones you enable for yourself:
- Lock screen, home-screen widget, and ongoing notification (and, on iOS, a session-scoped Live Activity where available) may show the current step text.
- You can hide lock-screen details in settings so those surfaces show a generic label instead of the step text.
- A crisis-flagged dump is never placed on those surfaces.
Nothing is shared with other users by the App. If you use the system share sheet yourself, that hand-off is under your control.
7. Who we share information with
We do not sell personal information and we do not share it for advertising. We use a small number of service providers, each for one job:
- Inyeon (the identity provider) — verifying your sign-in. Your credential lives there, not with Budge.
- OpenRouter and the downstream model vendors it routes to — breaking dumps into step trees (Section 4).
- Apple and Google platform speech services — only if you consent when on-device STT is unavailable (Section 4).
- Expo (or equivalent push infrastructure) — delivering notifications to your device when enabled.
- Apple and Google (and any store receipt verifier we use) — verifying a purchase if a paid plan exists.
- Our hosting provider — running the servers and database.
We also disclose information when the law requires it, to protect our rights or someone's safety, or in connection with a merger or sale of the business, in which case this policy continues to apply until you are given notice of a new one.
8. How long we keep things
We keep your account and its data while your account is open. Audio from voice capture is not retained. Uploaded photo and document binaries are deleted after text extract; the resulting dump text is kept with your account. Server logs are kept for a short operational window.
9. Export and deleting your account
Export. You can export your lists, steps, and completion timestamps from Settings (or the equivalent control in the App).
Delete. Delete your account from Settings → Delete account in the App, or email team@inyeon.dev.
What is erased: your account, dumps, step trees, completion history, preferences, and related app data — including completion history.
Your sign-in credential is separate. Your email or phone credential is held by Inyeon's identity provider, not by Budge, and survives Budge's deletion. To close it fully, delete it through Inyeon's account settings as well.
10. Your choices and rights
- Hide on lock screen. Turn on the setting so widgets and notifications do not show step text.
- Microphone and notifications. Deny or revoke them in system settings; voice and push features will not work without them.
- Export and deletion. Section 9.
- Correction. Edit or discard dumps and steps in the App.
Depending on where you live, you may have additional rights — to know what we hold, to request deletion, to correct information, or to appeal a refusal. Email team@inyeon.dev and we will respond as the applicable law requires. We will not discriminate against you for exercising a right.
We do not sell or share personal information as those terms are defined under California law, and we do not process it for targeted advertising.
11. Security
Traffic to our API is encrypted with TLS. Your credential is held by Inyeon's identity provider, so Budge holds no passwords to protect. Access to your account requires a verified sign-in token. No system is perfectly secure, but we design for the case where something leaks.
12. Children
Budge requires you to be 17 or older. It is not directed to children under 13 (or to anyone under 17), and we do not knowingly collect personal information from them. If you believe someone under 17 has created an account, email team@inyeon.dev and we will delete it.
13. Changes
If we change this policy we will update the effective date above, and for material changes we will notify you in the App before the change takes effect.
14. Contact
Inyeon LLC — team@inyeon.dev