Who is responsible for your information
Chimpanzee, LLC (“Chimpanzee,” “we,” “us,” or “our”) operates her budget and is responsible for the personal information described in this Policy.
For data-protection laws that use the term controller, Chimpanzee is generally the controller of personal information collected through her budget. Some companies described below process information for us as service providers or processors.
The short version
Here is the privacy model in plain English:
- We do not connect to your bank.
- We do not collect your banking password.
- We do not sell your personal information.
- We do not sell your budget.
- We do not use your budget for targeted advertising.
- We do not give advertisers access to your budget.
- We do not use your budget or receipt content to train our general-purpose AI models.
- The budgeting app itself does not use session replay.
- Optional marketing-site analytics load only when you agree where consent is required.
- You can edit your budget.
- You can export it.
- You can delete your account.
The sections below explain exactly what we collect and why.
What this Policy covers
This Policy applies to personal information we process through:
- the her budget website;
- the her budget budgeting application;
- account creation and sign-in;
- support and bug reports;
- waitlists we operate;
- receipt scanning;
- subscriptions if paid plans are introduced; and
- related communications with us.
It does not govern an independent third-party website or service merely because her budget links to it.
Information you put into your budget
If you create an account, we store the budget information you choose to enter. Depending on how you use her budget, that may include:
- budget categories;
- transactions;
- merchant names;
- transaction descriptions;
- notes;
- account labels;
- balances;
- income;
- expenses;
- financial goals;
- repeating payments;
- planned spending; and
- other information you choose to type, import, or confirm.
This is the heart of the product. We process it so her budget can calculate, organise, save, display, and sync the budget you asked us to maintain. We do not independently pull this information from your bank.
Information that may be sensitive
Budget information is financial information and can be private. Free-text fields, merchant names, categories, or receipts could also reveal information you consider particularly sensitive. For example, a transaction might indirectly reveal something about medical care, religious activity, political activity, or another private part of your life.
We do not use your budget to create profiles about sensitive characteristics or to target advertising. Please avoid putting information into a note or receipt that is not necessary for your use of the Service.
Where applicable data-protection law requires an additional legal condition or consent to process sensitive or special-category information that you deliberately provide, we will rely only on a lawful basis available for that processing and obtain separate consent where the law requires it.
Account information
To create an account, we need an email address. That email address is used to:
- identify your account;
- sign you in;
- secure the account;
- send authentication links;
- provide important service notices;
- respond to support issues; and
- contact you about material changes affecting your account.
If you use email-link sign-in, there is no separate her budget password for us to store.
Google sign-in
If you choose Google sign-in, Google provides the information needed to authenticate you, including your email address and related authentication information. We do not receive your Google password. Choosing Google also means Google knows that you used Google to sign in to her budget.
If you would rather not use Google sign-in, use another sign-in method we make available, such as an emailed sign-in link.
Trying the app without an account
We may offer a demonstration or sample budget so you can explore the product before creating an account. Unless the interface tells you otherwise, changes to that sample budget are not saved as your personal budget. Reloading or reopening the demo may reset it. There is no personal budget stored in our database from that demo because there is no account associated with it.
One exception, and it is explicit: if you choose to start your own budget from inside the demo, the budget on your screen is kept in your browser so that, after you create an account, you can choose to bring it into that account. It is uploaded and stored only if you pick that option — at which point it becomes your account’s budget data, covered by the sections above. Decline, or never finish signing up, and it stays in your browser and expires on its own within a week.
We may count which sample or demonstration experience was opened so we can understand which examples are useful. That count does not include the amounts or changes you make inside the sample budget.
Local browser preferences
A small amount of information may remain locally in your browser so the Service behaves properly. For example, we currently use a browser preference called herto_collapsed_v1 to remember which category groups you have collapsed. It contains interface identifiers, not your transaction amounts or merchant names, and it stays on your device.
Authentication and first-run preferences may also use cookies or similar local browser storage as described below.
Receipt scanning
If you choose to scan a receipt, the receipt image is sent to Anthropic’s API so software can identify information such as:
- merchant;
- amount; and
- date.
The extracted information is shown to you so you can review or confirm it. We do not intentionally store the receipt photograph in our own database or file storage. The image is transmitted for the purpose of completing the scan request.
Anthropic processes API content under its commercial/API terms. We use the commercial API rather than a consumer Claude account, and API content is not used for consumer-model training under the applicable commercial service terms.
If you confirm extracted information and save it to your budget, the resulting transaction information becomes part of your stored budget just like information you typed yourself. We may retain a count and date showing that a receipt scan occurred so we can enforce applicable usage limits. Do not scan a receipt that contains information you do not want processed for this purpose.
Feedback and bug reports
If you use the Report a bug or feedback feature, we may collect:
- what you wrote;
- the screen or page you were on;
- your browser user-agent information;
- your browser-window size;
- the email associated with your account if you are signed in; and
- an email you voluntarily provide if you are not signed in.
Your actual budget contents are not automatically attached to a bug report. To reduce automated abuse, we may generate a one-way hash from an IP address for temporary rate-limiting purposes. Where our current implementation uses a daily-changing salt, the resulting hash is not intended to provide a persistent identifier across days.
Waitlists
If we offer a pre-launch or feature waitlist and you join it, we may collect:
- your email address;
- where you joined the waitlist from; and
- a temporary or one-way technical value used to prevent abuse.
Unless we clearly tell you otherwise when you sign up, a launch waitlist address is used to send the message you asked for rather than enrolling you in unrelated marketing. When a waitlist has served its purpose, we delete or de-identify the list unless we have another lawful reason to retain a particular record.
Basic page analytics
We use Vercel Web Analytics to understand basic use of our pages. Depending on the page and Vercel’s operation of the service, this can include information such as:
- the page opened;
- referring page or link;
- browser type;
- operating system;
- device type;
- broad country-level location; and
- aggregate page-view information.
We do not send your budget fields, transaction amounts, merchant names, categories, balances, or notes to Vercel Web Analytics as analytics events. URLs used by the budgeting service should not contain your budget information.
Vercel may also process ordinary technical server logs necessary to host and secure the Service, including IP address, page request, timestamp, and similar request information.
Optional marketing-site analytics
On the marketing website, rather than inside the budgeting application, we may use PostHog for more detailed product analytics. This can help us understand things like:
- which links people use;
- where visitors stop;
- whether an interface is confusing; and
- a session replay reconstructing how the marketing pages were used.
Where consent is required, PostHog does not load until you choose to allow optional analytics. If you decline or ignore a consent request, optional analytics that require that consent do not load. If you previously consented, you can withdraw consent using the privacy or cookie controls available on the site.
We configure marketing-site session replay to mask user-entered fields. PostHog session replay does not run inside the budgeting app. Your budget is therefore not part of a marketing-site replay. We use this information to improve the website and product experience, not to build an advertising profile.
Cookies
Some cookies are necessary for the Service to work.
Authentication cookies
Used to keep you signed in and securely associate a browser session with your account.
Sign-in security cookies
A short-lived cookie or similar value may be used so that the browser that begins a sign-in attempt can safely finish it.
“Continue as” information
After certain sign-in methods, your browser may remember limited account information so the sign-in page can offer a quicker way to sign back in. Where this information remains after signing out, the interface will provide the applicable method for removing it.
First-run preferences
We may remember that you already completed a welcome or setup screen so the Service does not repeatedly show it.
Optional analytics cookies
Optional analytics on the marketing website may use cookies or similar technologies. Where consent is legally required, those technologies load only after you agree.
We do not use advertising cookies to follow your budget activity across unrelated websites.
Information we do not collect as part of the budgeting service
her budget is intentionally built without many categories of information commonly collected by financial applications. Unless you deliberately put something into your own budget or a future feature clearly tells you otherwise, we do not need or request:
- online-banking usernames or passwords;
- bank-account login credentials;
- full credit-card numbers for budgeting;
- Social Security numbers;
- government identification documents;
- credit reports;
- your contacts;
- your photographs other than a receipt you deliberately submit for scanning;
- precise GPS location;
- microphone recordings;
- your address book; or
- information purchased from a consumer data broker.
Broad country-level information may still be generated from ordinary web requests for analytics, security, or hosting purposes.
Paid subscriptions and payment information
At the date of this Policy, some or all of her budget may be available without charge. If paid plans are offered, payment details will be collected by the payment processor or merchant of record identified at checkout. The payment provider may collect information such as:
- your name;
- billing address;
- payment-card information;
- tax information; and
- other information needed to complete the purchase.
We expect to receive only the billing and subscription information reasonably necessary to administer your plan, such as:
- subscription status;
- plan;
- renewal date;
- payment status;
- transaction or customer identifier;
- billing country; and
- limited payment-method information provided by the processor.
We do not intend to store your complete payment-card number or CVV in the her budget application. Before paid plans launch, this Policy will be updated as needed to identify the applicable payment provider and accurately describe the information exchanged.
Why we use personal information
We use personal information only for reasonably identified purposes, including to:
- create and authenticate your account;
- provide and sync your budget;
- perform calculations you request;
- process receipt scans you initiate;
- save settings and preferences;
- operate paid plans if offered;
- answer support requests;
- investigate bugs;
- secure the Service;
- prevent fraud, spam, and abuse;
- maintain and improve the Service;
- understand basic use of our website;
- provide optional analytics when you consent;
- communicate material account, privacy, security, subscription, or legal information;
- comply with law and lawful legal process; and
- establish, exercise, or defend legal claims.
We do not repurpose your budget for targeted advertising. If we ever want to use personal information for a materially different purpose, we will update this Policy and obtain additional consent where required before doing so.
Legal bases for EEA and UK users
If European Economic Area or UK data-protection law applies, our legal basis depends on what we are doing.
Contract
We process information necessary to provide the Service you requested, including account information, authentication, your stored budget, syncing, calculations, exports, receipt scans you request, and subscription administration.
Consent
We rely on consent where required for optional technologies such as optional PostHog analytics, optional session replay, optional cookies that are not necessary to provide the Service, and another activity where applicable law specifically requires consent. You can withdraw consent at any time without affecting processing that was lawful before withdrawal.
Legitimate interests
Where permitted, we rely on legitimate interests to secure the Service, prevent abuse, diagnose technical problems, maintain ordinary server logs, respond to feedback, understand basic operation of the Service, protect our rights and users, and improve reliability. Our interest is operating a secure, reliable, understandable product while minimising unnecessary collection.
Legal obligations
We may process information when necessary to comply with tax, accounting, regulatory, court, law-enforcement, or other legal obligations that apply to us.
Legal claims
Where allowed by applicable law, we may process information as necessary to establish, exercise, or defend legal claims.
Who processes information for us
We use a small number of providers to operate her budget.
Supabase
Purpose: database and authentication infrastructure. May process: your account email, authentication information, and stored budget information.
Vercel
Purpose: website/application hosting, infrastructure, technical logs, and basic web analytics. May process: ordinary request information such as IP address, page, timestamp, device/browser information, broad location information, and aggregate analytics.
PostHog
Purpose: optional analytics and session replay on the marketing website when enabled. May process: interactions with marketing pages and masked replay information. Does not receive: your budgeting-app content through PostHog session replay, because PostHog replay does not run inside the budgeting app.
Anthropic
Purpose: receipt scanning when you deliberately use that feature. May process: the receipt image submitted for the request.
Resend
Purpose: email delivery, including waitlist messages where applicable. May process: the email address and message-delivery information needed to send that email.
Purpose: authentication when you deliberately choose Google sign-in. May process or receive: information involved in the Google authentication process, including the fact that you signed in to her budget.
Payment provider
If paid plans are introduced, the payment processor or merchant of record identified at checkout will process payment information.
We require service providers handling personal information for us to process it for permitted purposes and subject to appropriate contractual obligations.
We do not sell personal information
We do not sell your personal information for money. We also do not sell or share your personal information for cross-context behavioural advertising as those concepts are used by California privacy law. We do not give advertisers access to your budget. We do not use your budget to target ads. We do not operate an advertising data business.
If those practices ever changed, we would have to update this Policy and provide any notices, choices, and opt-outs required by law before beginning the new practice.
We do not train our models on your budget
We do not use your budget, transaction data, merchant data, notes, balances, or receipt content to train our own general-purpose AI models. When a receipt is processed through Anthropic’s commercial API, the image is used to perform the scan request under the applicable commercial/API service terms rather than being submitted through a consumer Claude account.
Legal disclosures
We may disclose information if we reasonably believe disclosure is necessary to:
- comply with a valid law, subpoena, court order, or legal process;
- respond to a lawful request from a government authority;
- protect the rights, property, or safety of Chimpanzee, our users, or another person;
- investigate fraud, abuse, or a security incident; or
- establish, exercise, or defend legal claims.
We do not voluntarily give governments open-ended access to user budgets. Where legally permitted and appropriate, we may notify an affected user of a request for their information.
Business transfers
If Chimpanzee is involved in a merger, acquisition, financing, reorganisation, bankruptcy, or sale of the her budget business or related assets, personal information may be transferred as part of that transaction. A successor receiving personal information remains subject to applicable privacy law. If a transaction results in a material change to how personal information will be used, we will provide any notice or choice required by law. A business transfer does not turn your budget into advertising inventory.
How long we keep information
We do not want to keep identifiable information indefinitely without a reason.
Account information
Kept while your account exists and for any limited period afterward that is reasonably necessary for security, legal, accounting, fraud-prevention, or dispute purposes.
Budget information
Kept while your account exists unless you delete the information sooner. Deleting your account removes associated budget rows from our active production systems.
Receipt photographs
We do not intentionally store receipt photographs in our database or file storage after the scanning request.
Receipt scan counts
Kept on a rolling basis as reasonably necessary to enforce the applicable monthly limit.
Waitlist information
Kept until the waitlist has served its stated purpose, unless another lawful retention reason applies.
Feedback and bug reports
Kept only as long as reasonably necessary to investigate the issue, communicate with you, improve the Service, maintain relevant technical records, or meet legal obligations.
Server and security logs
Kept for periods reasonably necessary for hosting, security, debugging, fraud prevention, and legal compliance, subject to provider and system retention settings.
Optional analytics
Kept according to our configured analytics-retention periods and only as long as reasonably necessary for the analytics purpose.
We may retain information longer where required by law, necessary to resolve a dispute, or necessary to protect the Service from fraud or abuse. We may retain de-identified or aggregated information where it can no longer reasonably be linked to you, subject to applicable law.
Deletion and backups
You can delete your account from Settings where that feature is available. Deletion removes your account and associated budget information from our active production systems.
Deleted information may remain temporarily in routine system backups until those backups expire under their normal retention cycle. Backup copies are not used as active account information and are retained for purposes such as system recovery, security, and continuity. Deleting an account is intended to be permanent, so export information you want to keep first.
Exporting your budget
Settings provides an export option where available, including CSV. The export is intended to let you keep a copy of your own information outside her budget.
Some privacy laws also provide a legal right to data portability. Where that right applies and the in-product export does not satisfy it, contact legal@her.to.
Correcting information
Most information in your budget can be corrected directly by editing it. You can also contact us if you believe other personal information we maintain about you is inaccurate. We may need to verify your identity before changing account-level information.
Your privacy rights
Privacy rights vary depending on where you live. Even where a particular privacy law does not apply to us, we try to make the practical rights people care about available directly in the product: see it, change it, export it, and delete it. Where applicable law gives you additional rights, we will honour them.
You can send a privacy request to legal@her.to. We may take reasonable steps to verify that a request relates to you before disclosing or deleting personal information.
EEA and UK privacy rights
If the GDPR, UK GDPR, or related data-protection law applies to you, you may have rights including:
- access to your personal information;
- correction of inaccurate information;
- erasure;
- restriction of processing;
- data portability;
- objection to certain processing;
- withdrawal of consent at any time where consent is the legal basis; and
- the right to complain to a data-protection supervisory authority.
These rights are not absolute and may depend on the processing involved and applicable exceptions.
Your right to object
Where we rely on legitimate interests, you may have a right to object to that processing based on your particular circumstances. You have an absolute right to object to direct marketing where applicable. her budget does not currently use your budget for direct-marketing profiling.
Automated decisions
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects, such as deciding whether you receive credit, employment, insurance, or a financial product. Receipt extraction and budgeting calculations do not make those kinds of decisions.
Complaints
If UK data-protection law applies, you may complain to the UK Information Commissioner’s Office (ICO). If EEA data-protection law applies, you may complain to the competent supervisory authority in the country where you live or work, or where you believe an infringement occurred. We would also like the opportunity to address a concern directly at legal@her.to.
United States state privacy rights
Residents of California and other U.S. states may have rights under state privacy laws. Depending on the law and whether it applies to Chimpanzee, those rights may include:
- knowing or confirming whether we process personal information;
- accessing personal information;
- obtaining specific pieces of personal information;
- correcting inaccurate information;
- deleting personal information;
- obtaining a portable copy;
- opting out of sale;
- opting out of sharing for cross-context behavioural advertising;
- opting out of targeted advertising;
- opting out of certain profiling;
- limiting particular uses of sensitive personal information; and
- appealing a denial of a privacy request.
We do not sell personal information or share it for cross-context behavioural advertising. We also do not use sensitive personal information for unrelated purposes that require a consumer to opt out of such use under California law.
If applicable law gives you a right to appeal our response to a request, reply to the decision or email legal@her.to with the subject Privacy Appeal. We will not unlawfully discriminate against you for exercising a privacy right. Where state law permits an authorised agent to submit a request for you, we may require appropriate proof of authorisation and verification.
California notice
For California residents, the categories of personal information we may collect include, depending on how you use the Service:
- identifiers, such as email address and IP-related technical information;
- customer-record information associated with an account or subscription;
- commercial information, such as subscription information if you purchase a plan;
- internet or electronic-network activity, such as technical logs and page activity;
- broad geolocation derived from an internet connection, such as country;
- user-generated budget and financial information you voluntarily provide; and
- inferences created only as necessary to provide features you request, such as receipt extraction.
We collect these categories from you, your browser or device, authentication providers you choose, and service providers involved in operating the Service. We use and disclose them for the purposes described in this Policy. We do not sell these categories or share them for cross-context behavioural advertising.
Canada
If Canadian privacy law applies, you may request access to personal information held about you and challenge its accuracy and completeness. Where processing is based on consent, you may withdraw consent subject to legal or contractual restrictions and reasonable notice. Withdrawal may mean we can no longer provide a feature that requires the information.
Questions or complaints about our privacy practices can be sent to the person responsible for privacy at legal@her.to. You may also have a right to complain to the Office of the Privacy Commissioner of Canada or the applicable provincial privacy authority.
Australia
If Australian privacy law applies to our handling of your personal information, you may have rights to:
- request access to personal information we hold about you;
- request correction;
- ask questions about our privacy practices; and
- make a privacy complaint.
Send requests or complaints to legal@her.to. You may also have the right to complain to the Office of the Australian Information Commissioner (OAIC).
International transfers
Chimpanzee operates from the United States, and your account and budget information are currently stored in the United States. If you live elsewhere, using her budget may therefore involve transferring personal information to the United States and other locations where our service providers process information. Those countries may have privacy laws different from the laws where you live.
Where European or UK law requires a transfer mechanism, we use or require appropriate safeguards made available by our providers, such as applicable Standard Contractual Clauses, UK transfer mechanisms, adequacy mechanisms, or another lawful basis for the transfer. You may contact legal@her.to for information about applicable transfer safeguards. Where another country’s privacy law imposes requirements for overseas processing or disclosure, we take reasonable steps required by that law.
Security
Financial information deserves careful treatment. We use technical and organisational measures intended to protect personal information. Our current protections include:
- encryption of traffic in transit;
- encryption of database information at rest;
- authentication controls;
- account-based access controls;
- database rules designed to keep one account from accessing another account’s budget;
- limited use of service providers; and
- efforts to minimise the data we collect.
No internet service can promise perfect security. If we discover a personal-data breach, we will investigate it and provide notices to users or regulators when applicable law requires us to do so. If you discover a security problem, contact legal@her.to.
Children
her budget is intended for adults. You must be at least 18 years old, or the age of legal majority where you live if higher, to create an account unless we expressly introduce a different age policy that complies with applicable law. We do not knowingly operate her budget as a service directed to children. If you believe a child has created an account contrary to this Policy, contact legal@her.to so we can investigate and take appropriate action.
Do Not Track and privacy preference signals
Some browsers send “Do Not Track” or other privacy-preference signals. Because her budget does not sell personal information or share it for cross-context behavioural advertising, there is currently no advertising sale or sharing profile to opt out of. Where applicable law requires us to recognise a legally valid universal opt-out mechanism for processing we perform, we will do so as required. Optional analytics that require consent remain subject to the consent controls described above.
Changes to this Policy
Products change, and privacy laws change too. When we materially change how personal information is collected, used, or disclosed, we will update this Policy and change the date at the top. If a change materially affects existing account holders, we will provide additional notice before it takes effect where appropriate or required by law. If applicable law requires consent to a new use, updating this page alone will not substitute for that consent.
Contact us
Questions, access requests, deletion requests, privacy complaints, and other privacy matters can be sent to legal@her.to. Please use Privacy Request in the subject line if you are exercising a legal privacy right.
We may need enough information to verify your identity and locate the relevant account, but we will not ask for more than reasonably necessary.
Chimpanzee, LLC · legal@her.to