Privacy Policy
Last updated: August 23, 2026
Changes: August 10, 2026, deletion was made total: your support history is now removed with the account, along with every earlier copy of your data, and we no longer keep any marker that would recognize a returning account. Added what we keep about our own staff opening an account. August 5, 2026, Shared Locations was removed from Buhata, so its section is gone from this policy: we no longer collect location data. All stored location history has been deleted from our servers, and nothing sent by an older app version is stored. August 3, 2026, corrected how the account and the server copy are described. An account is required rather than optional, and the copy we hold covers everything in the app rather than only what you pick to share. The backup section was also renamed: it names no storage provider now, because Buhata never sent that file to one. August 1, 2026, added what employees can and cannot access, named the seven day location retention in the summary, described marketing consent and how to withdraw it, and noted that support may be handled from outside your country. July 30, 2026, first published.
Buhata is a life-tracking app for your money, tasks, family, and health. This policy explains what information the app handles and where it goes. The short version: Buhata needs an account, your entries are written to your device first and then copied to our server so they reach your other devices, and we never sell your information or show ads.
Who you are dealing with
Buhata is operated by Buhata LLC, a Florida limited liability company, document number L26000404649, of Pensacola, Florida 32534, United States. Buhata LLC decides what is collected and why, which under European law makes it the data controller. Write to [email protected] about anything in this policy.
This policy covers every version of Buhata: the Android app from Google Play, the iPhone, iPad and Mac apps from the App Store, the Windows desktop app, and the browser app at buhata.com. Where a platform differs, it says so.
Information stored on your device
Everything you enter in Buhata (financial entries, tasks, grocery lists, weight and water logs, health reminders, journal entries, family profiles) is written to your device first, which is why the app keeps working with no connection. While you are signed in, a copy is also sent to our server, as described below.
Buhata Cloud account (required)
Buhata needs an account. While you are online and signed out, the welcome screen cannot be dismissed, and the only way to open the app without one is to start it with no connection at all. We store your email address, a hashed password (we cannot see the original), your display name, and a copy of your Buhata data so it can appear on your other devices. That copy is made automatically while you are signed in, and it covers everything you keep in the app, including financial and health entries. If you join a household, the parts a household shares are also visible to the members you approve. You can delete your account in the app or at our account-deletion page; deletion removes your data from our servers after a 30-day recovery window. That includes your support history, and it includes every earlier copy we held. We keep nothing afterwards that could identify you or recognize you if you signed up again.
Signing in with Google, Apple or Microsoft
You can sign in with an email address and a code, or with a Google, Apple or Microsoft account. If you choose one of those, that company tells us your email address, a permanent identifier for you at that company, and your name if they hold one. That is all we ask for and all we receive. We never get your password, and we cannot see anything else in your account there: not your contacts, not your files, not your calendar.
We store the identifier so that signing in again recognizes you. Signing in this way tells that company you use Buhata, which is true of every service you sign into with them, and their own privacy policy governs what they do with that fact.
Apple lets you hide your real address and give Buhata a relay address instead. That works normally here. Everything still reaches you, and we never see the address behind it.
Voice commands (optional, paid feature)
Most of what you say never leaves your phone. Buhata reads a spoken sentence on the device itself, using a recognizer that learns the way you in particular talk: the words you use for things, the shops you name, the people you mention, the times you tend to mean. The longer you use it the more it handles alone, and for the great majority of everyday commands the sentence is understood where you said it and goes no further.
A sentence the device cannot resolve is sent to our server and passed to Anthropic, a language model provider, to be turned into an instruction such as “add milk to groceries”. That is the only time a spoken sentence leaves your device. Anthropic does not use it to train anything.
Two different things are kept, and they are worth telling apart.
What the microphone remembers is a shape, not a sentence. When a command is understood, Buhata stores the pattern it followed with the name and the amount replaced by blanks, filed under a one-way code built from your account and the words rather than the words themselves. Saying something similar later is matched against that pattern and the real values are read from the new sentence. That store is permanent and it is also unreadable: nothing in it can be turned back into what you bought, from whom, or for how much.
A short record of what was heard is kept separately, against your account, and this one does contain the sentence. It exists so that mistakes can be found and the recognizer corrected, which is the only way voice gets better at the words you actually use. It is deleted automatically after 30 days, it is erased immediately if you delete your account, and it is never used to build an advertising profile or shown to anybody outside the small number of people who keep Buhata running. It is not displayed anywhere in the app; if you want yours cleared sooner, write to [email protected] and we will do it.
Voice is always something you start by tapping the microphone. Buhata does not listen in the background and has no wake word.
Weather and exchange rates
We do not collect or store your location. If you enable weather, a coarse position (from your browser prompt on the web, or estimated from your network connection) is used once per fetch to request a local forecast, and is not kept by Buhata. Currency features fetch public exchange rates. These requests retrieve data for you; they do not send your personal content anywhere.
Children
Buhata is for adults. You must be 18 or older to hold an account, and there are no child accounts: a child in Buhata is a profile a parent creates and controls, with no login, no email address and no way to sign in. Chore pages shared with a child open through a one-time link that asks for nothing and stores nothing about them beyond the task itself. If you believe a child has created an account, write to [email protected] and we will remove it.
Who else touches your data
Buhata is a small company and runs on other companies’ infrastructure. These are all of them, and what each one gets:
- Railway hosts the server and the database, so the synced copy of your account sits on their infrastructure.
- Cloudflare serves this website and the browser version of the app, and protects both. It sees the requests that fetch a page, which means your IP address, the browser you used and the page you asked for. It uses those to block attacks, to tell a person from a bot, and to give us counts of how many people visited which pages. Those counts are worked out at their edge and reach us as numbers only. Cloudflare does not use any of it to advertise to you, no analytics script runs in your browser, and there is no cookie in any of it that follows you to another site.
- Sentry receives crash reports from the app: the error, where in the code it happened, the app version, and your account id, so we can tell one person hitting a bug forty times from forty people hitting it once. It is configured to send nothing else: no email address, no name, nothing you typed, no screen recording, and a rule in our test suite refuses the settings that would change that.
- Anthropic interprets the spoken sentences your device could not resolve on its own, which on Premium is the harder end of what people say. Most commands never reach them at all. What is sent is not used to train anything, and the voice commands section above says what Buhata keeps, for how long, and how to clear it.
- Google is involved only if you choose Sign in with Google, and then only to confirm who you are.
- Plaid is involved only if you buy Buhata Money and connect a bank. Plaid is the company that makes the connection and holds the credentials. Your bank username and password go to Plaid and your bank, never to Buhata, and Buhata never sees or stores them. What comes back to us is the account name, the balance and the list of transactions. Plaid has its own policy for the people who use it, at plaid.com/legal.
There is no analytics company on this list, no advertising network, and no data broker, because Buhata uses none. If that ever changes, this list changes with it before the change ships.
Connecting a bank
Bank connections are part of Buhata Money, which is a paid add-on. Nothing here applies unless you buy it and choose to connect an account.
Buhata reads. It never moves money. There is no way to send a payment, make a transfer or touch a balance from inside Buhata, and there is no plan to add one. The connection is one-way and read-only.
What we ask your bank for, through Plaid:
- The account name and type, so you know which account you are looking at
- The balance
- Your transactions, which is what lets Buhata fill in expenses and income instead of you typing them
What we do not ask for: your identity documents, your account and routing numbers, your investments, or anything that would let money leave your account.
Your bank login never reaches Buhata. You type it on Plaid’s own screen. What Buhata stores is a token that lets us read the accounts you chose, and that token stays on our server and never goes to your phone or your browser.
You can disconnect a bank at any time from the app, which removes the connection and the transactions we read from it. Deleting your Buhata account removes all of it as well, along with everything else, as described below.
Buhata Money has no fixed limit on connections, and each institution you connect adds one Space to your plan. The connection is billed to us per bank login, so the add-on is priced for personal and household use and is covered by the fair use and permitted use terms; use far outside what a household plausibly needs is what those terms exist for, and we will contact you before anything is ever restricted.
Bank connections work with banks in the United States and Canada for now. If your bank is somewhere else, the add-on is not offered to you and cannot be bought.
Where your data is held, and for how long
Buhata runs on servers in the United States. If you are in the United Kingdom, the European Economic Area or anywhere else with its own rules about data leaving the country, using Buhata means your information is handled in the United States, by us and by the companies listed above.
How long things are kept:
- Your account and everything in it stay until you delete the account.
- What you wrote to support is deleted when the account is.
- A record of what the microphone heard is deleted automatically after 30 days.
- Sign-in codes and invitation links expire in minutes or days and are destroyed when used.
- Security records, such as which devices signed in and when, are kept while the account exists so you can review and revoke them.
- Billing records are kept by our payment provider for as long as tax and accounting law requires, which is usually seven years, and that is outside our control.
Your rights over your information
Wherever you live, you can do all of the following, and you do not have to give a reason:
- See it. Export your data from Settings, as a plain file, on any plan including the free one. The file lists what it contains; for an account of anything held outside it, write to [email protected] and we answer within 30 days.
- Correct it. Every entry is editable in the app.
- Delete it. Delete your account from Settings, or ask us and we will do it.
- Take it elsewhere. The export is a readable file rather than a format only we can open.
- Object, or ask us to stop. Write to [email protected].
If you are in Europe or the United Kingdom, the lawful bases we rely on are simple ones: performing the contract you entered into when you signed up, which covers running the app, and our legitimate interest in keeping it secure and working. Voice commands are optional and you turn them on yourself. You may complain to your national data protection authority, and in the United Kingdom that is the Information Commissioner’s Office.
If you are in California, you have the right to know what is collected, to have it deleted, to correct it, and not to be discriminated against for asking. Buhata does not sell personal information and does not share it for cross-context behavioral advertising, so there is no opt-out to offer: it does not happen at all.
Deleting your account
You can delete your account and everything in it from inside the app. Deletion is scheduled 30 days ahead so a mistake can be undone, and after that it is final. Everything personal goes: your data, every earlier copy of it, and anything you wrote to support. What stays is what we are required to keep for tax, whatever other people made for themselves, and a record of what our own staff did, without anything they wrote about you. Account Deletion explains exactly what goes and what we must keep.
One narrow exception exists, and only for accounts that took part in the referral program. Deleting an account and making a new one would otherwise be a way to collect the same reward twice, so a small record is kept: a one-way hash of your email address and, where there was one, the reference your card issuer gives us, along with the date and a short reason. No name, no address, nothing you wrote, and nothing that can be turned back into your email or your card. It is kept for two years and then deleted automatically.
A second narrow exception exists for the Buhata Student program, and it works the same way. One student discount is allowed per school email address, ever, so when a .edu address is verified we keep a one-way cryptographic token of it. If the account is later deleted, everything readable goes, including the address itself, and only that token remains. It cannot be turned back into the address and it answers a single question: has this school email already been used for a Buhata Student offer. It is kept for as long as the student program exists, because deleting it would make every deleted account a fresh claim on the same discount. Your verified student email, the school domain, and the verification dates are visible to you in your account and to our support staff while your account exists, and they are deleted with it.
That record does one thing: it stops a new account from earning or triggering a referral reward. It does not stop you registering, signing in, paying or using any part of Buhata, and it is never used for marketing, for recognizing you, or for anything else. If you think it should not apply to you, write to us and a person will look at it.
Buhata is for adults. Child profiles exist inside a parent’s account, are controlled entirely by the parent, and cannot sign in. We do not knowingly collect personal information directly from children.
Invite links and keeping the referral program honest
Referral rewards are worth real money, so people try to farm them: one person making several accounts, or a household passing one subscription between its members. To catch that without asking anything extra of you, two values are worked out from the ordinary web request your browser or the app already sends, and only when you either arrive through somebody’s invite link or open your own invite screen.
The two values are a rough signature of the browser, being the user agent and the languages it accepts, and the network address the request came from. Both are put through a one-way hash with a secret key before anything is written down, so the address itself and the browser details are never stored. What is stored cannot be turned back into either one. It can only be compared with another stored value to answer one question: do these two signups look like they came from the same place. Those records are deleted after 180 days, and they are deleted immediately if you delete your account.
No advertising identifier is read. Nothing is asked of your phone, no identifier is kept on your device for this, and none of it follows you to any other app or website. It is used for one thing, deciding whether a referral reward is genuine, and it is shared with nobody. A match is never on its own a reason to refuse anybody: households share a network, families share a laptop, and a referral that looks unusual is held for a person to look at rather than rejected by a machine.
What we never do
- No ads, and no ad trackers.
- No tracking you across other apps or websites, and no device fingerprinting for advertising or profiling.
- No selling or renting your information to anyone.
- No reading your financial or health entries for any purpose other than showing them to you and your approved household.
How the site and the apps are protected
Buhata sits behind Cloudflare, which filters traffic before it reaches us. That means attacks are turned away at the edge, unusual bursts of requests are slowed down, and a browser is occasionally asked to prove it is a browser. Those checks look at the request rather than at you: an address, a rate, a pattern.
Every page is sent over HTTPS and nothing else is accepted. The browser is told, in the response itself, not to guess at file types, not to let another site frame Buhata, not to hand a full address to anybody you click through to, and to refuse any attempt by a page to reach your location, microphone, camera or payment methods. None of those are things Buhata’s website needs.
We use Cloudflare’s own counts of page visits. There is no analytics script in the pages, no advertising network, no session recorder, and nothing that follows you between sites. What we get is how many people opened a page, not who they were.
Security
Cloud traffic is encrypted in transit (HTTPS). Passwords are stored only as salted hashes. Our servers sit behind network-level protection and access to them is limited to the operator of Buhata.
If you have found a security problem in Buhata, the security page says where to send it and what happens next.
Employee access
Buhata employees and contractors can view account details to answer support requests: your email address, your plan, the devices signed in to your account, when your data last synced and how large it is, and your payment status. They cannot open the contents of your apps, which includes your notes, money entries, health records and medication lists, and there is no location history to browse: Buhata no longer stores any. Support may be handled by a contractor working outside your country, under a written confidentiality agreement.
Marketing email
There is none. Buhata does not run a mailing list, does not send product news or offers, and has no way to opt you into one: the setting that used to exist was removed along with the ability to send anything. The only email you will get is about your own account, such as a sign-in code, a receipt, a renewal notice, a security alert or a change to these policies, and those are part of the service.
Your choices
- Use Buhata offline for as long as you like once your account exists. Sync only happens when there is a connection.
- Export or delete your local data from the app’s settings.
- Delete your cloud account and synced data at any time.
Contact
Questions or requests: [email protected].
Buhata LLC, Pensacola, FL 32534, United States.
Changes
If this policy changes in a way that matters, we’ll say so in the app’s release notes and update the date above.
