Legal · Bujetto by Daisycloud

Privacy Policy

Effective July 1, 2026 · Version 1.0.0

The short version
  • Your financial data never leaves your device unless you choose to enable iCloud sync.
  • We collect no analytics, no crash reports, no telemetry, and no personal data whatsoever.
  • No third-party SDKs, no advertising networks, no trackers are included.
  • All data on-device and in iCloud is encrypted with AES-256-GCM before it is written to disk.
  • We cannot access your data — not even the ciphertext — because the key lives in your Keychain.
Section 01

Who we are

Bujetto is developed and published by Daisycloud Software, an independent two-person studio. You can reach us at support@daisycloud.us.

This Privacy Policy applies to the Bujetto application available on the Apple App Store for macOS and iOS/iPadOS.

Section 02

What data Bujetto stores — and where

All data you enter into Bujetto (transactions, invoices, subscriptions, vendors, budgets, tax figures, receipt images, and your account profile) is stored exclusively in two places:

On your device — inside the app’s sandboxed Application Support directory, as an AES-256-GCM encrypted file (ledger.enc).
In your personal iCloud Drive — only if you explicitly enable iCloud Sync in Settings. The file uploaded is the same encrypted ciphertext; Apple cannot read it.

Your data is never transmitted to Daisycloud’s servers or any third-party service. We have no server-side infrastructure that receives or processes your financial records.

Encryption details: Your ledger is encrypted at rest using AES-256-GCM via Apple’s CryptoKit framework. The 256-bit symmetric key is generated on first launch and stored in your device Keychain with kSecAttrSynchronizable = true, so iCloud Keychain propagates it to your other devices. The key never leaves Apple’s encrypted Keychain infrastructure. Manual exports are re-encrypted with a user-supplied password using 10,000-round HMAC-SHA256 key derivation.

Section 03

Receipt images and on-device AI

When you import a receipt or photo, Bujetto performs Optical Character Recognition (OCR) entirely on your device using Apple’s Vision framework. On macOS 26 / iOS 26 or later, structured parsing may additionally use Apple’s FoundationModels framework (also fully on-device).

  • No receipt image or extracted text is sent to any external server — including ours.
  • Receipt images are copied to a sandboxed Receipts/ folder inside the app’s Application Support directory and encrypted with the rest of your ledger on the next save.
  • Deleting a receipt record from within the app permanently removes the stored image file.
Section 04

Camera and photo library access

Bujetto requests camera access only to capture receipt photos directly in the app. Photos captured this way are processed on-device and stored in your encrypted ledger — they are not uploaded anywhere.

On iOS/iPadOS, Bujetto may request access to your Photos library to let you select a profile photo or import a receipt image. Selected images are processed on-device only.

You can revoke camera or photo library access at any time in System Settings → Privacy & Security.

Section 05

App Store Connect integration (optional)

If you choose to connect an App Store Connect account in Settings, Bujetto fetches your daily sales reports directly from Apple’s App Store Connect API using credentials you supply (API Key ID, Issuer ID, Vendor Number, and a .p8 private key). These credentials are stored in your encrypted ledger.

  • API calls go directly from your device to Apple’s servers — no proxy or intermediary.
  • Your .p8 private key is stored only in the encrypted ledger; it is never transmitted to Daisycloud.
  • You can clear these credentials at any time from Settings → Connected Services.
Section 06

iCloud sync

When you enable iCloud Sync, Bujetto copies your encrypted ledger.enc file to the iCloud Drive container iCloud.us.daisycloud.bujetto. This sync is governed by Apple’s iCloud Terms of Service and Apple’s Privacy Policy.

Key safeguards built into the sync system:

  • Bujetto never overwrites an existing cloud ledger without first confirming it is identical to or older than the local copy.
  • On first enabling sync, the app waits for Apple’s metadata query to confirm the iCloud container is empty before uploading — preventing accidental data loss on a second device.
  • Disabling sync copies the cloud ledger back to local storage before removing the cloud copy.
Section 07

Data we do not collect

Bujetto contains no analytics SDKs, crash-reporting SDKs, advertising identifiers, behavioral tracking, or user profiling of any kind. The app’s Privacy Nutrition Label (PrivacyInfo.xcprivacy) declares:

NSPrivacyTracking: false
NSPrivacyTrackingDomains: (empty)
NSPrivacyCollectedDataTypes: (empty)
NSPrivacyAccessedAPITypes: UserDefaults only (reason CA92.1)
Section 08

Authentication and account deletion

Bujetto uses local-only authentication. Your workspace password is never transmitted — it is hashed on-device with 10,000-round HMAC-SHA256 and stored in the system Keychain.

When you tap Delete Account in Settings, Bujetto permanently:

  • Deletes your hashed password credentials from the Keychain.
  • Deletes the AES-256 encryption key from the Keychain.
  • Deletes the local encrypted ledger file from disk.
  • Deletes the iCloud copy of the ledger (if iCloud Sync was enabled).
  • Deletes all stored receipt image files from the sandbox.

This operation is irreversible. Daisycloud has no ability to recover deleted data.

Section 09

Your rights under GDPR (EU users)

Because Daisycloud does not collect, process, or store any personal data on its servers, the majority of GDPR obligations are fulfilled entirely by you within the app — your data never reaches us.

  • Right of access: All your data is readable within the app at all times.
  • Right to erasure: Use Settings → Delete Account to permanently erase all data from your device and iCloud.
  • Right to portability: Use Settings → Backup → Export to create an AES-256 encrypted portable copy of your ledger.
  • Right to object: There is no processing of your personal data by Daisycloud to object to.

For any GDPR-related inquiry please contact support@daisycloud.us.

Section 10

Children’s privacy

Bujetto is not directed at children under 13 (or under 16 in the EU). We do not knowingly collect personal information from children. Because Bujetto collects no data from anyone, this policy applies uniformly regardless of age.

Section 11

Changes to this policy

If we make material changes to this Privacy Policy, we will update the effective date at the top of this page and, where appropriate, provide a notice within the app. Continued use of Bujetto after the updated policy takes effect constitutes acceptance of the revised terms.

Section 12

Contact

Questions, concerns, or requests regarding this policy:

Email: support@daisycloud.us

Developer: Daisycloud Software

Daisycloud
© 2026 Daisycloud Software · Made for Apple devices
Bujetto Screen Marker Support Privacy About us