๐Ÿ•Š๏ธ Aviary

Privacy Policy

Last updated 4 September 2026

Aviary (โ€œweโ€, โ€œusโ€) is an independently developed, personal budgeting app. This policy explains what we collect, why, and how you can control or remove it. It applies to the Aviary Android and iOS apps and to this website.

Who this is

Aviary is developed and operated by an individual developer based in India. For any privacy question or request, write to [your support email].

What we collect

  • Account information. Email address, display name, profile picture URL, and a device description (e.g. โ€œPixel 8 ยท Android 15โ€), collected when you sign in with Google or an emailed one-time code. Authentication is handled by our identity provider, WorkOS.
  • The financial data you enter. Envelopes, budgets, transactions, item names, notes, subscriptions, and investment holdings you add. Amounts, item names, notes, and AI chat text are encrypted at rest with AES-256-GCM before they reach our database. Dates, category names, payment methods, subscription and holding names are stored as plain text so search and filtering work; we don't encrypt those.
  • Receipt photos, for bill scanning only. If you use the scan-a-bill feature, the photo is sent to Google's Gemini model to read the amount and merchant off it, and is not stored by us afterward.
  • Money Brain / AI chat. If you ask our AI assistant a question, we send it your recent transactions, envelope balances, and subscription and investment summaries so it can answer accurately, along with the text you type. Conversations are stored in our database so you can revisit them, and you can delete them at any time.
  • Product analytics. The mobile app sends your email and name, screen views, and a handful of product events (e.g. logging an expense, moving money, scanning a bill) to PostHog, an analytics provider based in the United States. No amounts or item text are included in these events. You can turn this off in Settings โ†’ Your data โ†’ Analytics; turning it off stops new data from being sent.
  • Push notifications. A push token identifying your device, used to send budget alerts, bill reminders, and digests. Notification text can include category names and amounts (e.g. โ€œYou've overspent โ‚น500 in Foodโ€), delivered through Google's and Apple's push services.
  • Diagnostics you choose to send. If you report a bug or send feedback, we include your app version and device model to help us reproduce it.

How we use it

To run the budgeting features you use, to answer questions you ask our AI assistant, to send the notifications you've enabled, to fix bugs, and to understand which features are actually used so we can improve them. We don't sell your data, and we don't use it for advertising.

Who we share it with

Data only goes to the services that make the app work:

  • WorkOS โ€” sign-in and account identity.
  • MongoDB Atlas โ€” where your data is stored, with the encryption described above.
  • Google Gemini โ€” receives transaction and budget context for Money Brain and AI briefs, and receipt photos for bill scanning. Google does not use this data to train its models under our API agreement with them.
  • PostHog โ€” product analytics, U.S.-hosted, toggleable off as described above.
  • Expo / Google Firebase โ€” delivers push notifications.
  • Vercel โ€” hosts the app and its API, and stores data exports you request.

Some of these providers are located outside India, including in the United States, so using Aviary means your data may be processed there.

How long we keep it

Deleting an envelope, transaction, or your whole account moves it into a recoverable, inaccessible state for 7 days โ€” enough time to undo an accidental deletion by signing back in โ€” after which it is permanently deleted from our active systems, including your account with our identity provider.

Your rights

You can access, correct, export, or delete your data at any time from Settings โ†’ Your data, or the account page on the web. You can withdraw consent for analytics at any time (see above). Under India's Digital Personal Data Protection Act, you have the right to access, correct, and erase your personal data, to nominate someone to exercise these rights on your behalf, and to file a grievance with us at [your support email] โ€” we'll respond within 30 days. If you're in the EU/UK or California, you have equivalent rights under GDPR or the CCPA, including the right to data portability; we don't sell personal information, so there's nothing to opt out of there.

Security

Financial values, item names, notes, and AI chat text are encrypted at rest with AES-256-GCM before they're written to our database, so a leaked backup or exposed connection string only turns up ciphertext. This isn't end-to-end encryption โ€” our server decrypts your data to run your budget and answer AI questions โ€” so it protects you if the database leaks, not if our server itself is compromised. All traffic between the app and our servers is encrypted in transit (HTTPS).

Children

Aviary isn't directed at children, and we don't knowingly collect data from anyone under 18. If you believe a child has provided us data, contact us and we'll delete it.

Changes to this policy

If this policy changes materially, we'll update the date at the top and, for significant changes, note it in the app.

Contact

Questions, requests, or complaints about your data: [your support email].

Privacy PolicyTermsDelete your account