Privacy Policy
Bifold is a personal budgeting app for iPhone. It reads your bank accounts so it can show you where your money goes. It does not sell your data, does not advertise to you, and contains no analytics or tracking software of any kind.
Who runs Bifold
Bifold is built and operated by Eeshan Kulkarni, an individual developer. There is no company, no staff and no third party with access to your data other than the service providers named below. Questions about this policy or your data go to eesh.kulkar@gmail.com.
What Bifold collects
Account identity
When you sign in with Apple, Bifold receives the identifier Apple issues for you and, if you allow it, your name and an email address. Apple lets you hide your real address behind a relay; Bifold works exactly the same either way. Bifold never sees your Apple password.
Financial data, through Plaid
Bifold uses Plaid to connect to your banks. You enter your bank credentials into Plaid's own screen; Bifold never sees or stores your bank username, password or multi-factor codes. Plaid returns, and Bifold stores:
- your accounts: name, type, the last four digits of the number, current and available balances, and the institution they belong to
- your transactions: date, amount, merchant and description, and the category Plaid assigns
- for investment accounts, the securities held and their quantities
Plaid's handling of your data is governed by Plaid's own end user privacy policy, linked above.
What you create in the app
Your categories, the recategorization rules Bifold learns when you correct a transaction, any manual assets you add, and your appearance preference.
What Bifold does not collect
No advertising identifier, no device identifier, no location, no contacts, no analytics events, no crash-reporting SDK, no session recording. Bifold contains no third-party tracking software. Nothing you do in the app is measured or reported anywhere.
Your consent
Before Bifold collects anything from your bank, the connect screen says what is collected and that it is never sold, and links to this policy. Continuing past that screen is your consent; the same notice appears again whenever you reconnect a bank, because reconnecting resumes collection. This policy is also reachable at any time from Settings › Legal inside the app.
How your data is used
Only to run the app for you: to show your balances and transactions, to sort spending into categories, to detect recurring charges on your device, and to keep your connections working. Your data is never used to train models, never sold, never rented, and never shared for anyone's marketing.
Who your data reaches
| Provider | What it receives | Why |
|---|---|---|
| Plaid | Your bank credentials (entered directly into Plaid, never into Bifold) and the resulting account and transaction data | The bank connection itself |
| Supabase (on Amazon Web Services) | Everything Bifold stores | Database, authentication and server code hosting |
| Apple | Your sign-in | Sign in with Apple, and app distribution |
| logo.dev, Google's favicon service, Financial Modeling Prep | A merchant's website domain or a stock ticker, and your device's IP address, at the moment a logo is fetched | Showing merchant and security logos. These requests carry no account identifier and no amounts, but they do reveal which merchants appear in your feed |
Bifold has no other recipients. Your data is not disclosed to anyone else except where the law requires it.
How your data is protected
- Everything travels over TLS 1.2 or better, end to end.
- Everything at rest is encrypted with AES-256 at the storage layer, including backups.
- The database enforces row-level security on every table: your rows are readable only by your signed-in session.
- Face ID, Touch ID or your device passcode is required before Bifold will open the bank connection screen, so a borrowed unlocked phone cannot add or reconnect an account.
- Plaid access tokens live in a table with row-level security enabled and no policies at all, so no user session of any kind can read them - only Bifold's server-side functions can.
More detail is in the security overview.
How long your data is kept, and how to erase it
Bifold keeps your data for as long as your account exists.
Disconnecting a bank (Settings › the bank › Disconnect) removes the connection at Plaid and deletes the stored access token immediately. The transactions already synced from that bank are kept, so your spending history and net worth over time do not develop a hole. If you want them gone as well, delete your account.
Deleting your account (Settings › Delete account) disconnects every bank at Plaid, then erases your accounts, transactions, categories, rules and sign-in record. This is immediate and cannot be undone. Point-in-time recovery is disabled on this project and no backup snapshots are retained, so the deletion is not shadowed by a restorable copy that outlives it. Nothing personal survives it. Full detail is in the data retention and disposal policy.
Your rights
You can see everything Bifold holds about you inside the app, correct a category at any time, disconnect a bank at any time, and delete everything at any time from Settings. If you would rather have a copy of your data or want a deletion carried out for you, email the address above and it will be handled within 30 days. Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA; Bifold honours them for everyone regardless of location, and does not sell or share personal information as those laws define it.
Children
Bifold is not directed at children under 13 and does not knowingly collect their data.
Changes
If this policy changes materially, the effective date above changes with it and the app will tell you before the change takes effect.