Effective July 1, 2026 · Version 1.0.0
Bujetto is developed and published by Daisycloud Software, an independent two-person studio. You can reach us at support@daisycloud.us.
This Privacy Policy applies to the Bujetto application available on the Apple App Store for macOS and iOS/iPadOS.
All data you enter into Bujetto (transactions, invoices, subscriptions, vendors, budgets, tax figures, receipt images, and your account profile) is stored exclusively in two places:
ledger.enc).Your data is never transmitted to Daisycloud’s servers or any third-party service. We have no server-side infrastructure that receives or processes your financial records.
Encryption details: Your ledger is encrypted at rest using AES-256-GCM via Apple’s CryptoKit framework. The 256-bit symmetric key is generated on first launch and stored in your device Keychain with kSecAttrSynchronizable = true, so iCloud Keychain propagates it to your other devices. The key never leaves Apple’s encrypted Keychain infrastructure. Manual exports are re-encrypted with a user-supplied password using 10,000-round HMAC-SHA256 key derivation.
When you import a receipt or photo, Bujetto performs Optical Character Recognition (OCR) entirely on your device using Apple’s Vision framework. On macOS 26 / iOS 26 or later, structured parsing may additionally use Apple’s FoundationModels framework (also fully on-device).
Receipts/ folder inside the app’s Application Support directory and encrypted with the rest of your ledger on the next save.Bujetto requests camera access only to capture receipt photos directly in the app. Photos captured this way are processed on-device and stored in your encrypted ledger — they are not uploaded anywhere.
On iOS/iPadOS, Bujetto may request access to your Photos library to let you select a profile photo or import a receipt image. Selected images are processed on-device only.
You can revoke camera or photo library access at any time in System Settings → Privacy & Security.
If you choose to connect an App Store Connect account in Settings, Bujetto fetches your daily sales reports directly from Apple’s App Store Connect API using credentials you supply (API Key ID, Issuer ID, Vendor Number, and a .p8 private key). These credentials are stored in your encrypted ledger.
When you enable iCloud Sync, Bujetto copies your encrypted ledger.enc file to the iCloud Drive container iCloud.us.daisycloud.bujetto. This sync is governed by Apple’s iCloud Terms of Service and Apple’s Privacy Policy.
Key safeguards built into the sync system:
Bujetto contains no analytics SDKs, crash-reporting SDKs, advertising identifiers, behavioral tracking, or user profiling of any kind. The app’s Privacy Nutrition Label (PrivacyInfo.xcprivacy) declares:
Bujetto uses local-only authentication. Your workspace password is never transmitted — it is hashed on-device with 10,000-round HMAC-SHA256 and stored in the system Keychain.
When you tap Delete Account in Settings, Bujetto permanently:
This operation is irreversible. Daisycloud has no ability to recover deleted data.
Because Daisycloud does not collect, process, or store any personal data on its servers, the majority of GDPR obligations are fulfilled entirely by you within the app — your data never reaches us.
For any GDPR-related inquiry please contact support@daisycloud.us.
Bujetto is not directed at children under 13 (or under 16 in the EU). We do not knowingly collect personal information from children. Because Bujetto collects no data from anyone, this policy applies uniformly regardless of age.
If we make material changes to this Privacy Policy, we will update the effective date at the top of this page and, where appropriate, provide a notice within the app. Continued use of Bujetto after the updated policy takes effect constitutes acceptance of the revised terms.
Questions, concerns, or requests regarding this policy:
Email: support@daisycloud.us
Developer: Daisycloud Software