Privacy Policy
Last updated: September 6, 2026
Changes: August 27, 2026, named the payment and email companies in the list of who touches your data, named our representatives in the European Union and the United Kingdom, and described the daily drawing and job applications. August 10, 2026, deletion was made total: your support history is now removed with the account, along with every earlier copy of your data, and we no longer keep any marker that would recognize a returning account. Added what we keep about our own staff opening an account. August 5, 2026, Shared Locations was removed from Buhata, so its section is gone from this policy: we no longer collect location data. All stored location history has been deleted from our servers, and nothing sent by an older app version is stored. August 3, 2026, corrected how the account and the server copy are described. An account is required rather than optional, and the copy we hold covers everything in the app rather than only what you pick to share. The backup section was also renamed: it names no storage provider now, because Buhata never sent that file to one. August 1, 2026, added what employees can and cannot access, named the seven day location retention in the summary, described marketing consent and how to withdraw it, and noted that support may be handled from outside your country. July 30, 2026, first published.
Buhata is a life-tracking app for your money, tasks, family, and health. This policy explains what information the app handles and where it goes. The short version: Buhata needs an account, your entries are written to your device first and then copied to our server so they reach your other devices, and we never sell your information or show ads.
Who you are dealing with
Buhata is operated by Buhata LLC, a Florida limited liability company, document number L26000404649, of Pensacola, Florida, United States, whose full postal address is in the Terms. Buhata LLC decides what is collected and why, which under European law makes it the data controller. Write to [email protected] about anything in this policy.
This policy covers every version of Buhata: the Android app from Google Play, the iPhone, iPad and Mac apps from the App Store, the Windows desktop app, and the browser app at buhata.com. Where a platform differs, it says so.
Our representatives in Europe and the UK
Buhata LLC is in the United States and has no office in Europe or the United Kingdom, so we’ve appointed representatives in both under Article 27 of the GDPR. You can go to them instead of us about anything in this policy, and they’ll pass it on.
In the European Union: Instant EU GDPR Representative Ltd, Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland. Contact Adam Brogden at [email protected], or use the request page at buhatallc.gdprlocal.com/eu.
In the United Kingdom: GDPRLocal Ltd, 1st Floor Front Suite, 27-29 North Street, Brighton, England BN1 1EB. Contact Adam Brogden at [email protected], or use the request page at buhatallc.gdprlocal.com/uk.
Going to a representative doesn’t take away your right to complain to your own data protection authority. In the United Kingdom that’s the Information Commissioner’s Office, where Buhata LLC is registered under reference ZC231158.
Information stored on your device
Everything you enter in Buhata (financial entries, tasks, grocery lists, weight, water and mood logs, a workout schedule, journal entries, household profiles) is written to your device first, which is why the app keeps working with no connection. While you are signed in, a copy is also sent to our server, as described below.
Buhata Cloud account (required)
Buhata needs an account. While you are online and signed out, the welcome screen cannot be dismissed, and the only way to open the app without one is to start it with no connection at all. We store your email address, a hashed password (we cannot see the original), your display name, and a copy of your Buhata data so it can appear on your other devices. That copy is made automatically while you are signed in, and it covers everything you keep in the app, including financial and health entries. If you join a household, the parts a household shares are also visible to the members you approve. You can delete your account in the app or at our account-deletion page; deletion removes your data from our servers after a 30-day recovery window. That includes your support history, and it includes every earlier copy we held. We keep nothing afterwards that could identify you or recognize you if you signed up again.
Signing in with Google, Apple or Microsoft
You can sign in with an email address and a code, or with a Google, Apple or Microsoft account. If you choose one of those, that company tells us your email address, a permanent identifier for you at that company, and your name if they hold one. That is all we ask for and all we receive. We never get your password, and we cannot see anything else in your account there: not your contacts, not your files, not your calendar.
We store the identifier so that signing in again recognizes you. Signing in this way tells that company you use Buhata, which is true of every service you sign into with them, and their own privacy policy governs what they do with that fact.
Apple lets you hide your real address and give Buhata a relay address instead. That works normally here. Everything still reaches you, and we never see the address behind it.
Voice commands (optional, paid feature)
Most of what you say never leaves your phone. Buhata reads a spoken sentence on the device itself, using a recognizer that learns the way you in particular talk: the words you use for things, the shops you name, the people you mention, the times you tend to mean. The longer you use it the more it handles alone, and for the great majority of everyday commands the sentence is understood where you said it and goes no further.
A sentence the device cannot resolve is sent to our server and passed to Anthropic, a language model provider, to be turned into an instruction such as “add milk to groceries”. That is the only time a spoken sentence leaves your device. Anthropic does not use it to train anything.
Two different things are kept, and they are worth telling apart.
What the microphone remembers is a shape, not a sentence. When a command is understood, Buhata stores the pattern it followed with the name and the amount replaced by blanks, filed under a one-way code built from your account and the words rather than the words themselves. Saying something similar later is matched against that pattern and the real values are read from the new sentence. That store is permanent and it is also unreadable: nothing in it can be turned back into what you bought, from whom, or for how much.
A short record of what was heard is kept separately, against your account, and this one does contain the sentence. It exists so that mistakes can be found and the recognizer corrected, which is the only way voice gets better at the words you actually use. It is deleted automatically after 30 days, it is erased immediately if you delete your account, and it is never used to build an advertising profile or shown to anybody outside the small number of people who keep Buhata running. It is not displayed anywhere in the app; if you want yours cleared sooner, write to [email protected] and we will do it.
Voice is always something you start by tapping the microphone. Buhata does not listen in the background and has no wake word.
Weather and exchange rates
We do not collect or store your location. If you enable weather, a coarse position (from your browser prompt on the web, or estimated from your network connection) is used once per fetch to request a local forecast, and is not kept by Buhata. Currency features fetch public exchange rates. These requests retrieve data for you; they do not send your personal content anywhere.
The daily drawing
If you enter the daily drawing and win, we keep your account id, the code that proves the win, and the date. That’s all, and it’s deleted with your account.
Your win only appears on the public Hall of Fame if you’ve turned that on. It’s off unless you switch it on, you can switch it back off whenever you like, and nothing about a win is published without it.
Age
Buhata is an adult service. You must be 18 or older to hold an account, and everyone in a household has their own adult sign-in. We don’t ask for a date of birth, we don’t record an age, and we don’t knowingly collect information from anyone under 18. A chore page shared by link opens in an ordinary web browser, asks for nothing, and stores nothing about whoever opens it beyond the task being ticked.
What we do keep is the confirmation itself. When you create an account you confirm you are 18 or older, and we store which version of the Terms you accepted and the date. That is two fields on your account, and it is included in your data export. We keep no age and no date of birth because storing one would mean collecting that information about people under 18 in order to prove none are here.
If you believe someone under 18 holds an account, write to [email protected] and we’ll remove it. If they are a member of a Space you run, reporting the member brings it to us the same way. Once we know, we close the account and delete its contents.
Who else touches your data
Buhata is a small company and runs on other companies’ infrastructure. These are all of them, and what each one gets:
- Railway hosts the server and the database, so the synced copy of your account sits on their infrastructure.
- Cloudflare serves this website and the browser version of the app, and protects both. It sees the requests that fetch a page, which means your IP address, the browser you used and the page you asked for. It uses those to block attacks, to tell a person from a bot, and to give us counts of how many people visited which pages. Those counts are worked out at their edge and reach us as numbers only. Cloudflare does not use any of it to advertise to you, and there is no cookie in any of it that follows you to another site. The one analytics script this site runs is Google Analytics, described under measurement below, and it never runs inside the app.
- Sentry receives crash reports from the app: the error, where in the code it happened, the app version, and your account id, so we can tell one person hitting a bug forty times from forty people hitting it once. It is configured to send nothing else: no email address, no name, nothing you typed, no screen recording, and a rule in our test suite refuses the settings that would change that.
- Anthropic interprets the spoken sentences your device could not resolve on its own, which on Premium is the harder end of what people say. Most commands never reach them at all. What is sent is not used to train anything, and the voice commands section above says what Buhata keeps, for how long, and how to clear it.
- Google, Apple and Microsoft are involved only if you choose their sign-in button, and then only to confirm who you are.
- Plaid is involved only if you buy Buhata Money and connect a bank. Plaid is the company that makes the connection and holds the credentials. Your bank username and password go to Plaid and your bank, never to Buhata, and Buhata never sees or stores them. What comes back to us is the account name, the balance and the list of transactions. Plaid has its own policy for the people who use it, at plaid.com/legal.
- Stripe takes your payment if you subscribe on buhata.com. Your card number goes to Stripe and never to us; what we hold is your plan, an identifier for you at Stripe, and a reference for the card that can’t identify it. If you bought through Google Play, the App Store or the Microsoft Store, that store handled the payment instead.
- Resend carries our email. Sign-in codes, receipts, renewal notices, security alerts and anything you write to support pass through it.
- Open-Meteo provides the forecast and the air quality when the Weather tool is on. It receives the coordinates of the place you chose, or your phone’s approximate position rounded to about a hundred meters, and nothing about your account. If the app has no position and no chosen city, it asks ipapi.co to guess your city from your internet address once, and that guess is used the same way.
- The Canadian Centre for Child Protection checks every picture and document shared inside a Space, through their Project Arachnid Shield service, before anybody can open it. This is how we keep child sexual abuse material off Buhata, and it is not optional: a file nobody has checked is never shown to anybody. Three things about it you should know. They act as an independent controller of what we send rather than on our instruction, so their own rules apply to it as well as ours. If a file matches nothing known, they may keep it as long as they need to; if it matches, the copy we sent is not kept. And the groups that classify material with them are not all in Canada, so an analyst in Australia, Cambodia, Colombia, Albania or Mexico may be able to view a file we send. Their policy is at projectarachnid.ca.
- Microsoft does the same check with PhotoDNA, alongside the above rather than instead of it. The picture is sent to make a fingerprint that is compared with known material, Microsoft acts on our instruction and keeps no copy, and a match is reported by us rather than by them.
Two things we want to be plain about, because a file you share at work is not a thing you expect to leave the company you shared it in. Every picture and document uploaded into a Space is sent for checking before it is shown to anyone, including files that turn out to be entirely ordinary, and there is no way to opt a Space out of it. Malware scanning happens too, on our own servers, and those files go nowhere.
Google, through Google Analytics, on the website only: it receives the page you viewed and a shortened form of your IP address, and it sets one cookie that tells pages of this site apart. Where the law requires consent it waits for you to accept the cookie notice, and if you decline, nothing from Google is loaded; the cookies page says which regions those are and what happens elsewhere. It does not run inside the Buhata app. There is no advertising network on this list and no data broker, because Buhata uses none. If that ever changes, this list changes with it before the change ships.
Connecting a bank
Bank connections are part of Buhata Money, which is a paid add-on. Nothing here applies unless you buy it and choose to connect an account.
Buhata reads. It never moves money. There is no way to send a payment, make a transfer or touch a balance from inside Buhata, and there is no plan to add one. The connection is one-way and read-only.
What we ask your bank for, through Plaid:
- The account name and type, so you know which account you are looking at
- The balance
- Your transactions, which is what lets Buhata fill in expenses and income instead of you typing them
What we do not ask for: your identity documents, your account and routing numbers, your investments, or anything that would let money leave your account.
Your bank login never reaches Buhata. You type it on Plaid’s own screen. What Buhata stores is a token that lets us read the accounts you chose, and that token stays on our server and never goes to your phone or your browser.
You can disconnect a bank at any time from the app, which removes the connection and the transactions we read from it. Deleting your Buhata account removes all of it as well, along with everything else, as described below.
Buhata Money has no fixed limit on connections, and each institution you connect adds one Space to your plan. The connection is billed to us per bank login, so the add-on is priced for personal and household use and is covered by the fair use and permitted use terms; use far outside what a household plausibly needs is what those terms exist for, and we will contact you before anything is ever restricted.
Bank connections work with banks in the United States and Canada for now. If your bank is somewhere else, the add-on is not offered to you and cannot be bought.
Where your data is held, and for how long
Buhata runs on servers in the United States. If you are in the United Kingdom, the European Economic Area or anywhere else with its own rules about data leaving the country, using Buhata means your information is handled in the United States, by us and by the companies listed above. For people in the European Economic Area and the United Kingdom, that transfer rests on the Standard Contractual Clauses in each company's agreement with us, with the UK addendum, and several of them also hold the EU-US Data Privacy Framework certification with its UK extension. Our representatives, named above, can give you a copy of the clauses on request.
How long things are kept:
- Your account and everything in it stay until you delete the account.
- What you wrote to support is deleted when the account is.
- A record of what the microphone heard is deleted automatically after 30 days.
- Sign-in codes and invitation links expire in minutes or days and are destroyed when used.
- Security records, such as which devices signed in and when, are kept while the account exists so you can review and revoke them.
- Billing records are kept by our payment provider for as long as tax and accounting law requires, which is usually seven years, and that is outside our control.
- A job application deletes itself a year after you send it.
Your rights over your information
Wherever you live, you can do all of the following, and you do not have to give a reason:
- See it. Export your data from Settings, as a plain file, on any plan including the free one. The file lists what it contains; for an account of anything held outside it, write to [email protected] and we answer within 30 days.
- Correct it. Every entry is editable in the app.
- Delete it. Delete your account from Settings, or ask us and we will do it. The little that can stay behind is listed on the account deletion page.
- Take it elsewhere. The export is a readable file rather than a format only we can open.
- Object, or ask us to stop. Write to [email protected].
- Withdraw consent. Where we rely on your consent, for your body entries or for measurement on this website, you can withdraw it as easily as you gave it, in Settings or through the cookie notice, and what was done before stays lawful.
- No decisions by machine. Nothing about you is decided by automated means alone in a way that has a legal or similarly significant effect on you, and nothing profiles you for advertising.
If you are in Europe or the United Kingdom, the lawful bases we rely on are simple ones: performing the contract you entered into when you signed up, which covers running the app, and our legitimate interest in keeping it secure and working. Voice commands are optional and you turn them on yourself. You may complain to your national data protection authority, and in the United Kingdom that is the Information Commissioner’s Office.
If you are in California, you have the right to know what is collected, to have it deleted, to correct it, and not to be discriminated against for asking. Buhata does not sell personal information and does not share it for cross-context behavioral advertising, so there is no opt-out to offer: it does not happen at all.
Deleting your account
You can delete your account and everything in it from inside the app. Deletion is scheduled 30 days ahead so a mistake can be undone, and after that it is final. Everything personal goes: your data, every earlier copy of it, and anything you wrote to support. What stays is what we are required to keep for tax, whatever other people made for themselves, and a record of what our own staff did, without anything they wrote about you. Account Deletion explains exactly what goes and what we must keep.
One narrow exception exists, and only for accounts that took part in the referral program. Deleting an account and making a new one would otherwise be a way to collect the same reward twice, so a small record is kept: a one-way hash of your email address and, where there was one, the reference your card issuer gives us, along with the date and a short reason. No name, no address, nothing you wrote, and nothing that can be turned back into your email or your card. It is kept for two years and then deleted automatically.
A second narrow exception exists for the Buhata Student program, and it works the same way. One student discount is allowed per school email address, ever, so when a .edu address is verified we keep a one-way cryptographic token of it. If the account is later deleted, everything readable goes, including the address itself, and only that token remains. It cannot be turned back into the address and it answers a single question: has this school email already been used for a Buhata Student offer. It is kept for as long as the student program exists, because deleting it would make every deleted account a fresh claim on the same discount. Your verified student email, the school domain, and the verification dates are visible to you in your account and to our support staff while your account exists, and they are deleted with it.
That record does one thing: it stops a new account from earning or triggering a referral reward. It does not stop you registering, signing in, paying or using any part of Buhata, and it is never used for marketing, for recognizing you, or for anything else. If you think it should not apply to you, write to us and a person will look at it.
Buhata is an adult service, as the Age section above sets out. We don’t knowingly collect personal information from anyone under 18, and the app asks for no date of birth and records no age.
Invite links and keeping the referral program honest
Referral rewards are worth real money, so people try to farm them: one person making several accounts, or a household passing one subscription between its members. To catch that without asking anything extra of you, two values are worked out from the ordinary web request your browser or the app already sends, and only when you either arrive through somebody’s invite link or open your own invite screen.
The two values are a rough signature of the browser, being the user agent and the languages it accepts, and the network address the request came from. Both are put through a one-way hash with a secret key before anything is written down, so the address itself and the browser details are never stored. What is stored cannot be turned back into either one. It can only be compared with another stored value to answer one question: do these two signups look like they came from the same place. Those records are deleted after 180 days, and they are deleted immediately if you delete your account.
No advertising identifier is read. Nothing is asked of your phone, no identifier is kept on your device for this, and none of it follows you to any other app or website. It is used for one thing, deciding whether a referral reward is genuine, and it is shared with nobody. A match is never on its own a reason to refuse anybody: households share a network, families share a laptop, and a referral that looks unusual is held for a person to look at rather than rejected by a machine.
What we never do
- No ads, and no ad trackers.
- No tracking you across other apps or websites, and no device fingerprinting for advertising or profiling.
- No selling or renting your information to anyone.
- No reading your financial or health entries for any purpose other than showing them to you and your approved household.
How the site and the apps are protected
Buhata sits behind Cloudflare, which filters traffic before it reaches us. That means attacks are turned away at the edge, unusual bursts of requests are slowed down, and a browser is occasionally asked to prove it is a browser. Those checks look at the request rather than at you: an address, a rate, a pattern.
Every page is sent over HTTPS and nothing else is accepted. The browser is told, in the response itself, not to guess at file types, not to let another site frame Buhata, not to hand a full address to anybody you click through to, and to refuse any attempt by a page to reach your location, microphone, camera or payment methods. None of those are things Buhata’s website needs.
We use Cloudflare’s own counts of page visits, and, from September 2026, Google Analytics on this website. In the regions where consent is required it runs only after you accept the cookie notice, and if you decline, nothing from Google is loaded; elsewhere it runs by default and the cookies page says how to turn it off. There is no advertising network, no session recorder, and nothing that follows you between sites. What we get is which pages were opened and roughly how people move between them, not who they were.
Security
Cloud traffic is encrypted in transit (HTTPS). Passwords are stored only as salted hashes. Our servers sit behind network-level protection and access to them is limited to the operator of Buhata.
If you have found a security problem in Buhata, the security page says where to send it and what happens next.
Employee access
Buhata employees and contractors can view account details to answer support requests: your email address, your plan, the devices signed in to your account, when your data last synced and how large it is, and your payment status. They cannot open the contents of your apps, which includes your notes, money entries, health records and medication lists, and there is no location history to browse: Buhata no longer stores any. Support may be handled by a contractor working outside your country, under a written confidentiality agreement.
If you apply for a job
Applying through our careers page sends us your name, your email address, the country you’re in, any links you give us, your answers to the role’s questions, and your CV if you attach one. We use it to consider the application and for nothing else.
We keep an application for a year and then it deletes itself, the file along with the record. If you’d rather it went sooner, write to [email protected] and we’ll remove it.
Marketing email
There is none. Buhata does not run a mailing list, does not send product news or offers, and has no way to opt you into one: the setting that used to exist was removed along with the ability to send anything. The only email you will get is about your own account, such as a sign-in code, a receipt, a renewal notice, a security alert or a change to these policies, and those are part of the service.
Your choices
- Use Buhata offline for as long as you like once your account exists. Sync only happens when there is a connection.
- Export or delete your local data from the app’s settings.
- Delete your cloud account and synced data at any time.
Health and fitness information
Weight, water, mood and workout entries are treated as consumer health data under the laws of several US states, and they have their own policy: the Consumer Health Data Privacy Policy. It covers what we hold, why, who sees it and how to remove it. The app asks for your explicit consent before the first of these entries is kept, records the date and the wording version, and lets you withdraw in Settings, which deletes them. Buhata has no menstrual, fertility, pregnancy, symptom, medication or diagnosis tracking of any kind.
If you are in a US state with its own privacy law
Several states give residents rights over sensitive personal information, which in our case means health and fitness entries and nothing else. Whichever state you are in, our position is the same one and we apply it to everybody rather than by residence:
- We do not sell personal information, and we do not share it for cross-context behavioral advertising or targeted advertising, so there is no opt-out to offer.
- We do not profile you in a way that produces legal or similarly significant effects.
- We collect health and fitness information only when you enter it, and only to show it back to you.
Residents of California, Virginia, Colorado, Connecticut, Oregon, Texas, Montana and other states with comparable laws can exercise the rights described above by writing to [email protected]. We will answer within 45 days, we will not charge you, and we will not treat you differently for asking. If we refuse a request you may appeal to the same address, and if we refuse the appeal we will tell you how to complain to your state attorney general.
If something goes wrong
If personal information is exposed in a way that puts you at risk, we will tell you. We will notify affected people without undue delay once we understand what happened, and we will say what was involved, what we have done, and what you should do. Where the law requires it, we notify regulators too, which in the European Union and the United Kingdom means within 72 hours of becoming aware.
We would rather tell you early and be wrong about the scale than wait until the picture is perfect. Security reports from researchers go to [email protected], and how we handle them is on the Security page.
Complaints, and who to go to
If you are unhappy with how we have handled your information or answered a request, write to [email protected] and say so plainly. We will look at it ourselves and answer in writing within 45 days. If we got it wrong we will say so and fix it.
You never have to come to us first, and coming to us does not use up any other route. You can complain directly to your own data protection authority, to the Information Commissioner’s Office in the United Kingdom, or to your state attorney general in the United States.
For matters under the European Union’s Digital Services Act, including notices about content, our point of contact is [email protected], and it accepts correspondence in English. Legal process and preservation requests are covered on the Law Enforcement Guidelines page.
Contact
Questions or requests: [email protected].
Buhata LLC, United States. Our full postal address is in the Terms.
Changes
If this policy changes in a way that matters, we’ll say so in the app’s release notes and update the date above.
