← Back to prebalance.appPrivacy Policy
Effective date: 2026-07-28 · Last updated: 2026-09-30
PreBalance ("PreBalance," "we," "us," or "our") is a personal budgeting and cash-flow application operated by PreBalance LLC, a Texas limited liability company. This Privacy Policy explains what information we collect through the PreBalance application and website at prebalance.app (the "Service"), how we use and protect it, and the choices and rights you have.
By using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
1. Our privacy-first approach
PreBalance is built to hold as little of your information as possible, and to be unable to read the most sensitive parts of it:
- We can't read your financial data. Your financial records are protected with end-to-end encryption. They are encrypted on your device with a key derived from your password — a key we never receive or store. Our servers hold only encrypted data (ciphertext) that we cannot decrypt. In short: we don't know who you are, and we can't read what you saved.
- You can stay anonymous. On the free tier you can use PreBalance without giving us an email, a name, or any identifying information.
- We don't sell your data, and we don't run advertising. We do not sell or rent your personal information, and the Service contains no third-party advertising or cross-site tracking.
The sections below give the detail behind these commitments.
2. Information we collect
a. Account information.
- You may use PreBalance without an account through a temporary, cookie-based trial that stores data locally and, if you choose to sync, under an anonymous identifier.
- You may create a free account without providing any identifying information (no email, name, or personal details) — using a username of your choice.
- If you provide an email address, we collect it. Email is optional on the free tier and is required only where billing exists (paid subscriptions).
- We collect authentication material needed to secure your account. Your password is never transmitted to us in readable form; the Service uses it on your device to derive your encryption key and sends only a derived verification value, which we store in hashed form.
b. Financial information you provide.
- The accounts, balances, transactions, bills, and other financial information you enter, and any statement files you import. This information is encrypted on your device, and we store only the ciphertext.
- When you import a statement file, the file is parsed in your browser. Only the resulting date-and-balance pairs are sent to us (encrypted); the underlying bank descriptions, merchant names, and payment memos never leave your device.
c. Payment information.
- If you purchase a subscription, your payment is processed by our payment provider acting as merchant of record (see Section 5). We do not collect or store your full card number; we receive limited billing metadata (such as subscription status and the contact details you provide at checkout).
d. Technical and usage information.
- We keep minimal operational logs necessary to run and secure the Service (for example, request timing and error information). **Request contents and sensitive headers are redacted and never logged. We do not** use device fingerprinting, and we do not track you across other websites or apps.
e. Website analytics.
- We measure basic traffic on our website using our own first-party analytics — no third-party analytics service, no advertising or tracking networks, and no cookies for this purpose.
- For each page view, and for each click on a call-to-action button, we record: the page path (not the query string), the referring URL your browser reports, and any campaign parameters in the link you followed (such as `ref` or `utm_source`). For a button click we also record which button it was (for example, "Get started" at the top of the page).
- To estimate how many distinct people visited on a given day, we store a **keyed, daily-rotating hash of your IP address instead of the address itself.** We do not store your IP address with these events; the hash is computed with a secret key, so it cannot be reversed to recover your address, and it changes every day, so it cannot be used to recognize you over time.
- If you arrive from a campaign link and start a trial, we record that **a signup occurred for that campaign.** This records the campaign only — no account identifier is stored with it, and we cannot tell which visitor became which user.
- These events are not linked to any account. There is no user identifier in this data, and we cannot determine whether a visit came from an existing user.
f. Cookies.
- We use two first-party cookies, both functional. We use **no analytics, advertising, or tracking cookies**, and no third party sets cookies through the Service.
- A session cookie, set when you sign in or start a trial, which keeps you signed in. It holds a random session identifier — not your password, and nothing about your finances.
- A returning-visitor cookie containing only the value `1`, set once you have registered, so that our website can send you straight to the application instead of the marketing page. It contains no identifier and says nothing about you beyond the fact that this browser has registered at some point.
- The session cookie is cleared when you sign out. Both are cleared when you delete your account. We do not use localStorage or similar device storage for analytics.
3. How we use your information
We use the information above to:
- Provide and operate the Service — store and synchronize your encrypted data across your devices, produce your budgets and forecasts, and send the reminders you have enabled.
- Authenticate you and protect the security and integrity of your account and the Service.
- Process subscription payments and manage billing for paid tiers.
- Send you transactional messages you would reasonably expect — such as billing and renewal notices, security notices, reminders you have turned on, and a one-time address-confirmation message if you add an email.
- Send you marketing or promotional messages only if you have separately opted in (see Section 7). Providing an email address does not, by itself, subscribe you to marketing.
- Understand how people find and use our website so we can improve it — measured in aggregate, never tied to your account.
- Comply with law and enforce our terms.
We do not use your financial data to build advertising or marketing profiles — and because that data is end-to-end encrypted, we could not read it for such purposes even if we wanted to.
4. How we store and protect your information
- End-to-end encryption. Your financial data is encrypted on your device before it reaches us; we store only ciphertext and cannot decrypt it. Your encryption key is derived from your password and never leaves your device in a form we can use.
- Encryption in transit. All communication with the Service is protected with TLS.
- Access and operational controls. We follow least-privilege access, store credentials only in hashed or wrapped form, rate-limit our interfaces, and maintain the security practices described in our Information Security Policy.
- Recovery trade-off. Because only you hold the key to your data, if you lose both your password and your recovery codes, we will not be able to recover your encrypted data for you. We provide recovery codes at sign-up for this reason.
No method of transmission or storage is perfectly secure, but our design is intended to ensure that even a compromise of our systems does not expose readable financial data.
5. How we share your information
We do not sell your personal information, and we do not share it for advertising. We share information only in these limited circumstances:
- Service providers. We use a small number of vendors to operate the Service, under agreements that limit their use of information to providing services to us:
- Paddle — our payment provider and merchant of record for subscription purchases.
- Our hosting/infrastructure provider — which stores your encrypted data; because the data is end-to-end encrypted, the provider holds only ciphertext it cannot read.
- Our email provider — used only to deliver messages if you provide an email address.
- Legal and safety. We may disclose information if required to do so by law or valid legal process, or to protect the rights, safety, and security of our users, the public, or PreBalance. Because your financial data is end-to-end encrypted, **we are unable to produce readable financial contents** in response to such requests.
- Business transfers. If PreBalance is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; we will require the successor to honor this Privacy Policy or provide notice of any change.
6. Data retention
We keep your information only as long as needed to provide the Service, and delete it on the following schedule:
- Trial (no account): trial data is deleted after 60 days of inactivity, with no 30-day window — your device keeps every row, and simply opening PreBalance again re-uploads them. The copy on our servers is encrypted with a key only your browser holds, so deleting it removes our copy and not yours.
- Free / non-paying accounts: after 12 months of inactivity an account is scheduled for deletion, and deleted 30 days later. Where we have a confirmed email address for the account, we email you when it is scheduled and again each week of that window. **Simply opening PreBalance and signing in cancels the deletion** — there is nothing to confirm and nothing to find. If a warning cannot be delivered — the mailbox no longer exists, or our email provider has stopped sending to it because a message was reported as spam — we hold off deleting for a further **30 days**, send a device notification if you have one enabled, and show you the notice in the app if you come back. We do not hold data indefinitely on the grounds that we cannot reach you: if we still cannot, deletion goes ahead on that extended schedule. If we have never had an email address for the account, the schedule above applies as stated, without the warnings.
- Paid subscribers: data is retained while your subscription is active and for **at least one year after your subscription expires**, so you can return without losing your history.
- Account deletion at your request: you can delete your account at any time from Settings. We keep it for 30 days and then delete it permanently. During those 30 days the account stops syncing and cannot be used — the only thing it can do is come back: sign in and press Restore, and everything is exactly as you left it. We email you the date when you delete, and again each week, if we have a confirmed address for you. After that date it cannot be undone.
The window exists because deleting a financial history is not recoverable and is usually a mistake. If you would rather not wait it out, exporting first and then deleting leaves you holding your own copy immediately — the export is offered in the same place.
Limited billing and tax records that our payment provider is legally required to keep may be retained by that provider as required by law.
- What we keep after you delete an account, and why. Two things, both small and both deliberate. First, the account's internal identifier — a random value that identified the account to our servers and nothing else — which we keep indefinitely so that the account can never be recreated. Without it, a device of yours that was still signed in elsewhere could quietly restore the account we had just deleted. Second, if the account was paid or held gifted time, a record of the plan, what it cost, the date it was paid through and our payment provider's reference. That is a transaction record, which we are required to keep for tax, and it is also what lets us restore what you had paid for if the deletion was a mistake — or someone else's doing. Neither includes your name, email address, username, or any of your financial data.
- Your own devices are not touched by deleting your account. Every device you were signed in on keeps its copy, so a deletion — yours or anyone else's — cannot wipe out your records everywhere at once. To remove a device's copy, sign out on that device or use "Delete local data" there.
- Website analytics: individual analytics events are deleted after 30 days. Before deletion they are folded into daily totals — counts per page and campaign — which contain **no per-visitor value at all.**
7. Your rights and choices
- Access and export. You can export your data at any time from within the Service.
- Correction. You can edit your financial data directly in the app at any time.
- Deletion. You can delete your account and its data at any time from Settings.
- Email and marketing. Marketing and promotional emails require a separate, explicit opt-in, and you can withdraw consent at any time. Transactional messages necessary to operate the Service (such as billing and security notices) are not marketing and cannot be opted out of while you maintain a relevant account.
- Regional rights. Depending on where you live — for example, under the EU/UK GDPR or the California Consumer Privacy Act (CCPA/CPRA) — you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object to certain processing. **We do not sell or "share" (as defined by the CCPA) your personal information.** You may exercise these rights by contacting us (Section 10); we will not discriminate against you for doing so.
Note: because your financial data is end-to-end encrypted and we cannot read it, some requests that require us to read that data may be fulfilled only through the in-app tools that let you access, export, correct, and delete it yourself.
8. International users
PreBalance is operated from the United States, and your information is processed in the United States and in the locations of the service providers listed in Section 5. If you access the Service from outside the United States, you understand that your information will be processed in the United States, where data-protection laws may differ from those in your country.
9. Children's privacy
The Service is not directed to children, and we do not knowingly collect personal information from children under 16. Because you can use PreBalance anonymously and your data is end-to-end encrypted, we generally cannot determine a user's age or access the contents of an account. Any account holder — or a parent or guardian acting on their behalf — can delete the account and all associated data at any time from Settings. If we become aware that we hold personal information associated with an identifiable account belonging to a child under 16, we will delete that account.
10. Contact us
If you have questions about this Privacy Policy or your information, or wish to exercise your rights, contact us at:
- Email: privacy@prebalance.app
- PreBalance LLC, Texas, USA
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice through the Service where reasonable. Your continued use of the Service after an update means you accept the revised policy.