01Who we are and what this policy covers
Bablo ("Bablo," "we," "us," or "our") is a personal finance app for iPhone. It connects to your bank and credit accounts and shows you one honest number: what is actually safe to spend once your bills, savings, and goals are accounted for.
This Privacy Policy explains what information we collect, why we collect it, who we disclose it to, how long we keep it, and the choices you have. It applies to the Bablo iOS app and to the babloapp.com website — together, the "Services."
Terms we use throughout
- "Personal information" means information that identifies, relates to, or could reasonably be linked with you.
- "Financial Information" means the account and transaction data described in Section 2(B) — your linked institutions, account names and types, balances, the last four digits of an account number, individual transactions, and the budget settings, goals, and notes you create from them. Financial Information is the most sensitive category we hold, and several commitments in this policy apply to it specifically.
- "Financial Data Provider" means Plaid Inc., the service that establishes and maintains the connection between Bablo and your financial institutions. See Section 5.
- "Service provider" means a company that processes information on our behalf, under contract, and only for the purposes we specify.
The Services are offered to residents of the United States and are operated from the United States. This policy is incorporated into our Terms of Service, which govern your use of Bablo — including the dispute resolution and arbitration provisions that apply to disagreements about your data.
02Information we collect
Information reaches us from four sources — from you directly, from your financial institutions through our Financial Data Provider, automatically from your device, and from a small number of third parties — and a fifth category is generated by the app itself as it runs. This section describes each in turn, and then states plainly what we do not collect.
A. Information you provide to us
- Account and identity. The email address you sign in with. If you use Sign in with Apple, the identifier Apple provides and — if you allow it — the name and private relay email address Apple returns. Bablo uses passwordless sign-in, so we never collect or store a password for your Bablo account.
- Your first name, which the app asks for during onboarding so it can address you by name.
- Settings and content you create. Budget settings and expected income, including corrections you make to what a paycheck is worth or when it arrives; savings goals and their names; notes you attach to transactions; category corrections, custom categories you create, and standing rules such as "always file this merchant here"; upcoming expenses you tell us to set aside for; spending plans you commit to; merchants you choose to watch, with the labels and monthly targets you give them; and choices such as marking a transaction "don't count this." Goal names, category names, watch labels, and notes are free text, so they contain whatever you choose to write.
- Support correspondence. If you email us, we receive your message, your address, and anything you include.
- Waitlist signups. If you join the waitlist on babloapp.com, we store the email address you enter and the marketing channel you arrived from. See Section 9 for the technical information recorded with it.
B. Financial Information from your linked accounts
When you link an account through our Financial Data Provider, we receive and store the information needed to build and maintain your budget:
- Your linked institutions, and each account's name, official name, type, subtype, current and available balance, and the last four digits of the account number (the "mask") so you can tell similar accounts apart.
- Transactions — date, amount, merchant, description, category, and pending status.
- Recurring-stream information the provider derives, which we use to recognize your income and your regular bills.
- The notices our Financial Data Provider sends our servers about each connection — that new transactions are ready, or that a bank needs reconnecting — kept as we received them for 90 days. These are records about the connection rather than about you, and unlinking does not remove them; deleting your account does.
We never receive or store your bank username, password, security questions, or multi-factor codes. See Section 5.
C. Information collected automatically
Device and app information
Our diagnostics and analytics providers automatically receive standard technical context with each event: app version and build, device model and type, operating system version, device language and locale, time zone, screen dimensions, and network type. Our crash-diagnostics provider also receives a device-scoped identifier derived from Apple's per-vendor device identifier, which distinguishes one installation from another without identifying you.
Usage information
We record a fixed, enumerated set of in-app milestones — for example that a sign-in was started or completed, which onboarding steps were reached, which tab was viewed, and that a notification was opened — together with app opens, updates, and backgrounding. Section 9 describes exactly how this is constrained.
Diagnostics
When the app crashes, freezes, or errors, we receive a diagnostic report containing the code-level stack trace, the device and app context above, and a trail of the screens and controls involved — recorded as internal class and identifier names, not as the text displayed on your screen. We also receive basic session data, such as when the app was opened and for how long, so we can tell whether a release is stable.
Network information
Like any internet service, our servers and our providers' servers observe the IP address your device connects from. Being specific about where it is kept:
- Sign-in and session records. Our authentication platform records the IP address and app or browser user-agent of each sign-in and active session as part of its security audit trail. These are tied to your account and are removed when you delete it.
- Website waitlist and demo requests, for abuse prevention — see Section 9.
- Not against your app activity. Our own application logs do not record IP addresses alongside what you do in the app, and our analytics and diagnostics providers are instructed not to store it at all.
Merchant logos
One outbound connection is worth naming because it is not to us. Some merchants in your subscriptions list are shown with their logo, and your phone loads that image directly from the address our Financial Data Provider supplies with the transaction. Like loading any image on the internet, that request shows the image's host your device's IP address and which logo was requested. We send it nothing else about you.
D. Information from third parties
- Apple — the identifier, and optionally the name and relay email, returned by Sign in with Apple; and, through our subscription management provider, your subscription status.
- Our Financial Data Provider — the account and transaction data described above, plus the status of each connection so we can tell you when a bank needs to be reconnected.
- Our subscription management provider — which plan you are on, when it renews, and whether it is active.
E. Information we do not collect
Some of the clearest things we can tell you are about what is absent. The Bablo app does not request, access, or collect:
- Your location. The app contains no location functionality of any kind and asks for no location permission.
- Your camera, photos, microphone, contacts, calendar, or health data. The app requests none of these permissions. The only system permissions it ever asks for are Face ID (or Touch ID) for the optional app lock, and notifications if you turn them on.
- Any advertising identifier. The app never reads Apple's advertising identifier and never presents the App Tracking Transparency prompt, because there is nothing it would be asking to do.
- Your bank credentials. See Section 5.
- Your payment card details. Purchases are processed by Apple; card numbers never reach us. See Section 10.
- Your Social Security number, date of birth, or government identification. Bablo never asks for them.
F. Information we generate about you
Not everything we hold came from somewhere else. Running the app produces its own records, and you should know they accumulate:
- A day-by-day history of your position — a daily snapshot of what was left to spend and what had gone out that month, and a daily record of whether you stayed under your limit. Our servers write the snapshot on a schedule, so it is recorded whether or not you opened the app that day. This is what makes streaks, month-close recaps, and "versus your usual month" possible.
- Patterns and assessments derived from your transactions: which spending is recurring, which is a bill, which merchants you visit regularly, month-end projections, and the coaching guidance built from them — including a short rolling summary of previous coaching, described in Section 6.
- A copy of each notification we send you — its title and body — so the app can show you a history in the bell inbox, plus a record of which notifications already went out so you don't get the same one twice. Because notification text includes financial details, that inbox holds them too.
All of this is kept for as long as your account exists and is erased when you delete it.
G. Demo mode
The app offers a demo you can enter with a shared demo address and password, without creating an account of your own. A demo gives you a temporary account preloaded with a made-up person's finances — no real bank is connected, and none of the data in it belongs to anyone. Anything you do inside it is stored on our servers like ordinary app data and is deleted automatically after a few days without use. Because the demo is open to anyone, we record the IP address of each attempt and whether it succeeded, purely to block automated abuse; those records are deleted within about two days. The shared demo password is not a password for any personal account — passwordless sign-in still applies to yours.
H. Aggregated and de-identified information
We may aggregate or de-identify information so that it no longer identifies you or your device — for example, counting how many users complete onboarding, or how long a screen takes to load. We use this to understand and improve the Services. Where we hold information in de-identified form, we maintain it as de-identified and do not attempt to re-identify it, except to test that de-identification is effective. We do not sell, license, or publish aggregated data derived from your Financial Information.
03How we use your information
We use your information only to run, secure, and improve the Services you signed up for:
- To calculate your safe-to-spend number, spending breakdowns, forecasts, and goal progress.
- To identify recurring income and bills so your budget stays accurate.
- To sync new transactions and keep balances current.
- To generate the budget setup and coaching guidance described in Section 6.
- To send the notifications you have enabled, as described in Section 7.
- To authenticate you, manage your subscription, and provide customer support.
- To detect, investigate, and prevent fraud, abuse, and security incidents, and to keep the Services reliable.
- To comply with law, respond to lawful requests, and establish or defend legal claims.
- For any other purpose you consent to at the time.
We do not use your Financial Information to build advertising or marketing profiles, we do not use it to infer characteristics about you, and we do not sell it. See Section 11.
04Our legal bases for processing
Where privacy law requires us to identify a legal basis for processing your personal information, we rely on the following:
Performance of a contractProviding the Services you asked for: linking accounts, calculating your budget, syncing transactions, managing your subscription.
Legitimate interestsKeeping the Services secure and working, preventing fraud and abuse, diagnosing crashes, and understanding which features are used — balanced against your privacy interests, which is why the data involved is minimized as described in Section 9.
ConsentSending push notifications, enabling the biometric app lock, and any use you specifically agree to. You can withdraw consent at any time, as described in Section 16.
Legal obligationRetaining records and responding to lawful requests where the law requires it.
05Plaid and your bank connection
Bablo uses Plaid Inc. as its Financial Data Provider to connect securely to your financial institutions. Plaid is the same service used by many of the largest finance apps.
Bablo never sees your bank username or password. You enter them into Plaid's own secure screen, which runs inside the app but is not accessible to our code. Your credentials travel from your device to Plaid and are never transmitted to, processed by, or stored on Bablo's servers.
In return, Plaid gives Bablo a token that lets us read your account and transaction data on a read-only basis. Bablo cannot initiate transfers, move money, make payments, or change anything at your bank. That token is encrypted with AES-256-GCM before we store it, and it is never exposed to the app on your phone.
By linking an account you also agree to Plaid's handling of your data under the Plaid End User Privacy Policy. Plaid is an independent controller of the data it collects from you, and its policy governs that activity.
Ending a connection
You can cut a connection at any time, in any of these ways:
- Unlink the bank inside Bablo. We ask Plaid to revoke the connection so its access token can no longer reach your bank, then delete that institution's accounts and transactions from Bablo. If Plaid cannot be reached at that moment, we still complete the disconnection on our side and flag the connection for manual removal.
- Delete your Bablo account, which does the same for every linked institution. See Section 14.
- Revoke access at the source — through your bank's own website, or through Plaid's portal at my.plaid.com.
Two limits worth knowing. Unlinking does not delete what Plaid itself holds about you — use the Plaid portal above for that. And some things you created from those transactions are tied to your account rather than to the bank connection — category rules you set, spending patterns, planned expenses — so they remain until you delete your account.
06AI-powered budget analysis
To set up your budget and to power Coach, Bablo analyzes your financial data to recognize patterns — your salary, your regular bills, where your spending is drifting. Part of that analysis is performed by a third-party artificial intelligence provider acting as our service provider.
What we send
So that you can judge this for yourself, here is what a request to that provider can contain:
- Recent transactions — merchant names, amounts, dates, and categories.
- Summary figures: your net cash position, expected monthly income, expected fixed expenses, and your projected month-end balance.
- Names and amounts for upcoming bills and recurring subscriptions.
- Your savings goals — name, target, how much you have saved so far, your monthly contribution, and whether the goal is reached or paused. Goal names are text you wrote yourself, so they may be personal.
- A short rolling summary of previous coaching, so guidance stays consistent between sessions.
What we never send
We never send your name, email address, account identifier, bank credentials, or full account numbers. The provider receives financial context without the identity it belongs to.
How the provider may use it
We use a paid service tier whose terms provide that your data is not used to train or improve the provider's models. The provider processes it to return a result to us, and may retain it briefly for abuse monitoring, under terms that prohibit using it for its own purposes.
This analysis is advisory, and you always get the final say. It suggests categories, flags what looks like a recurring bill, and drafts the guidance shown in Coach. It does not approve or deny you anything, does not affect your credit, and makes no decision producing a legal or similarly significant effect. Every figure it produces can be corrected in the app, and your corrections take priority over whatever the model inferred.
07Notifications
If you turn on notifications, we register your device with Apple's Push Notification service and store, in our own database, the resulting device token together with your account identifier, the app version, and your device's language and time zone. The token is removed when you sign out or delete your account.
Notification content includes your financial details. A daily brief or bill reminder can contain dollar amounts, merchant and bill names, and your own savings-goal names — for example, how much you have left this month, or what is due in the next few days.
These messages pass through Apple's servers to reach your phone, and by default they appear on your lock screen, where anyone holding your phone can read them. If that concerns you, you can hide notification previews in iOS Settings under Notifications → Show Previews (choose "When Unlocked" or "Never"), or turn Bablo's notifications off entirely — in iOS Settings, or in the app.
08Cookies and similar technologies
babloapp.com sets no cookies. We use no advertising pixels, no tracking beacons, and no cross-site identifiers, and our fonts are served from our own domain rather than a third party's.
Two small things are stored in your browser, and we would rather name them than hide behind an absolute:
- A session-storage entry recording which marketing channel brought you to the site, so that if you join the waitlist we know which link worked. It is cleared when you close the tab and is never shared.
- A network error-reporting policy set by our hosting provider, which asks your browser to report failed connections to that provider for about a week. It carries no identifier and records no successful visits.
The app behaves the same way: no advertising SDKs, no cross-app tracking SDKs, and no App Tracking Transparency prompt, because there is nothing we would be asking permission to do.
09Analytics and advertising
We do not advertise to you, and we do not participate in any advertising network. We run no ad SDK, we do not build audiences, and we do not disclose identifiers — hashed, encrypted, or otherwise — to advertising platforms. Nothing in this section is used to market to you anywhere.
In the app
We use two service providers: one for crash and error diagnostics, one for product analytics. We deliberately keep your Financial Information out of both, and the mechanism is worth describing because it fails safe:
- Analytics events are limited to a fixed list of milestone names, and their properties are filtered through a strict allowlist of permitted keys with a length cap. Any value not on that list is discarded before it leaves your device, so a dollar amount or merchant name cannot reach the provider even by mistake.
- Screen recording, screenshot capture, screen-content capture, and automatic interaction capture are all switched off for both providers. No image or rendering of your screen ever leaves the device.
- Network request URLs and payloads are excluded from diagnostic reports, because those URLs would otherwise carry query filters describing your accounts and dates.
- IP addresses differ between the two, so we will not lump them together. For analytics, every event overrides the IP field with a placeholder and switches off the location lookup, so your address is not stored against your activity and no approximate city or region is derived from it. For crash diagnostics, the provider's SDK attaches the connection IP to a report on their side, and turning off personal-data collection does not stop it — so a crash report can carry your IP address until it ages out on that provider's retention schedule. We would rather tell you that than imply a symmetry that does not exist.
- You are identified to both only by your randomly generated account identifier — never your name or email address — plus, for the diagnostics provider, the device-scoped identifier described in Section 2(C).
Before you sign in, analytics events are recorded against a random device-scoped identifier with no profile attached. Signing out unlinks the device from your account identifier.
On the website
We count page visits and waitlist signups with a deliberately minimal setup from the same analytics provider: it stores nothing on your device, respects your browser's Do Not Track setting, records no sessions, is configured so that visitor IP addresses are not stored with the analytics data and no approximate location is derived from them, and cannot follow you across other sites. No account is identified, because there is no sign-in on the website.
One honest caveat about IP addresses. Your device has to connect to a server for that server to answer, so the address is unavoidably visible in transit — that is true of every website and app you use. What we control is what happens next, and we instruct our providers to discard it rather than record it against you. We would rather explain that than claim your IP address is never seen at all.
Technical information recorded with a waitlist or demo request
When you submit the waitlist form, our server records the IP address, browser user-agent string, and referring page along with your submission; that technical metadata is cleared after 90 days, while your email address is kept as described in Section 14. When you request a demo instance, we record only the IP address of the request and whether it succeeded, and those records are deleted within about two days. We use both only to detect and block automated abuse.
Do Not Track and opt-out preference signals
Our website analytics honors your browser's Do Not Track setting, and when your browser sends a Global Privacy Control signal we do not load or run analytics on that visit at all — nothing is queued and nothing is sent. Global Privacy Control is a browser signal, so it does not apply to our iOS app, which has no equivalent to receive. Because we do not sell or share personal information and serve no targeted advertising, such a signal has nothing to disable — but it is respected regardless.
10How we disclose your information
We do not sell your information, and we do not disclose it to anyone so they can market to you. We disclose it only in the circumstances below.
A. Service providers
We share information with companies that process it on our behalf, under contract, and only to operate Bablo. Three of them matter most, because you interact with them directly or because they handle Financial Information:
- Our Financial Data Provider (Plaid) — connects to your institutions and retrieves transactions and balances. See Section 5.
- Our AI provider — performs the analysis described in Section 6, strictly as our service provider and never to train its models.
- Apple — Sign in with Apple, app distribution, in-app purchases, and delivery of push notifications. As noted in Section 7, notification content passing through Apple includes financial figures and merchant names.
Beyond those, we use the ordinary kinds of vendor any app needs. Each is bound by contract to safeguard your information and use it only to operate Bablo:
- Cloud hosting, database, and content delivery providers — store and serve your data, and host this website. Our hosting provider necessarily processes the IP address your browser connects from.
- Subscription management — tracks which plan you are on and when it renews. Receives your account identifier, your subscription status, and a device identifier that its software transmits automatically. It never receives your Financial Information.
- Crash diagnostics and product analytics — as described in Section 9.
- Email delivery — sends your sign-in code and waitlist messages. Receives your email address and the contents of the message being sent, which never include Financial Information.
B. Legal process and safety
We may disclose information where we believe in good faith that it is necessary to comply with applicable law or valid legal process; to respond to a lawful request from a government or regulatory authority; to enforce our Terms of Service; or to protect the rights, property, or safety of you, of Bablo, or of others.
When we receive a demand for your information, we review it for validity and scope, and we push back on requests that are overbroad or improper. Where the law allows it and no legal order prohibits it, we will notify you before disclosing your information so that you have an opportunity to object.
C. Corporate transactions
If Bablo is involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction. This policy continues to apply to the transferred information, and we will notify you before your information becomes subject to a materially different privacy policy.
D. With your direction or consent
We disclose information to anyone else only when you ask us to or agree to it.
We describe most vendors by category rather than by name because the specific companies change as the app evolves, and a policy that names them is out of date the moment one does. If you want to know exactly which providers we use today, email privacy@babloapp.com and we will tell you.
11What we never do
- We never sell or rent your personal or financial information to anyone.
- We never show you ads or disclose your information to advertisers.
- We never move, transfer, or spend your money — the bank connection is read-only.
- We never ask for or store your bank login credentials.
- We never use your Financial Information to build a profile of you for any purpose other than running the app.
- We never let our AI provider train its models on your data.
12How we protect your information
- Encrypted in transit. All traffic between your phone, our backend, and our providers is protected with industry-standard TLS encryption.
- The bank token is encrypted by us, on top of that. The token connecting Bablo to your bank is encrypted with AES-256-GCM at the application layer before it is stored, so it is not readable from the database alone. It is never sent to the app on your phone. Storage-level encryption of our database is provided by our cloud hosting provider.
- Read-only access. Even in the unlikely event of a breach, the bank connection cannot be used to move money.
- Biometric app lock. You can lock Bablo behind Face ID or Touch ID, falling back to your device passcode. Your biometric data is handled entirely by iOS, is never accessible to the app, and never leaves your device.
- Least-privilege access. Our internal tables holding operational records are restricted so they cannot be read through the public API under any user's credentials, and access to production data is limited to those who need it.
- Redaction in operational logs. Credentials, tokens, and secrets are stripped from our logs automatically. Note that our internal audit records do retain financial values, as described in Section 14.
- Breach notification. If a security incident affects your information, we will notify you promptly and as required by law.
You have a part in this too. Because sign-in is passwordless, whoever controls your email account can sign in to Bablo. Keep that account secured and protected with its own strong authentication, keep a passcode on your phone, and tell us immediately at privacy@babloapp.com if you believe your account has been accessed by someone else.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work hard to protect your information and to limit what we hold to what the app actually needs.
13Information stored on your device
Bablo keeps very little on your phone, but it is not nothing, and you should know what is there:
- Your sign-in session is stored in the iOS Keychain, the system's protected credential store.
- A snapshot of your linked accounts — including balances and the last four digits of each account number — is cached in the app's private container so your accounts appear immediately when you open the app. It is protected by iOS app sandboxing and file protection, and it is deleted when you sign out.
- Preferences and one-time flags, such as your chosen display style and which prompts you have already seen.
- The email address you last signed in with, so the app can offer it on the sign-in screen. This is deliberately kept after sign-out for convenience; it is removed when the app is deleted.
The diagnostics and analytics tools described in Section 9 also keep a small amount of their own storage — the random identifier they use for your installation, and any reports waiting to be sent. It holds no financial data.
Deleting the app does not remove everything. Your cached accounts, preferences, and remembered sign-in address go with it. But your sign-in session and app-lock setting live in the iOS Keychain, and iOS deliberately preserves Keychain items across app deletion — reinstalling the app can pick them up again. Sign out first if you want them gone.
And deleting the app never deletes your account on our servers. That is a separate action — see Section 14.
14Data retention and deletion
We keep your information for as long as your account exists, so the app can show your history and budget. Retention does not depend on whether you have a paid subscription: if a subscription lapses, nothing is deleted.
Your controls
- Unlink an institution at any time. This deletes that institution's accounts and transactions from Bablo and asks our Financial Data Provider to revoke the connection. If that revocation request fails, we record it and complete it by hand — and you can always revoke it yourself at my.plaid.com.
- Delete your account in the app — open the Me tab and tap Delete account. This permanently erases your profile, linked connections, accounts, transactions, goals, notes, and settings from our live systems; asks our Financial Data Provider to disconnect every bank you linked; removes your push device tokens; and purges the copies of your data that our internal operational and audit logs would otherwise retain. What we keep afterward is a record that a deletion took place, together with the internal code that stood for your account — a random string which, once your data is gone, no longer points to anything of yours. We keep that for 30 days, and we keep it on purpose: it is what lets us answer you if you write and ask whether your deletion actually completed. The queue that sends the deletion requests to our analytics and subscription providers holds the same code until each of them confirms, and is cleared a week later. One further limit we would rather record than gloss over: our authentication platform's own audit trail is not always ours to delete. Email privacy@babloapp.com and we will confirm the state of your deletion — or ask us to carry it out for you in the first place.
What deletion does not reach
We would rather be specific than reassuring:
- Our Financial Data Provider keeps its own records under its own retention policy. We cannot delete those for you — use my.plaid.com.
- Encrypted backups still contain your data until they age out on their normal schedule, and our hosting provider keeps platform logs on its own schedule.
- Our analytics and subscription providers hold records under the anonymous identifier that stood for your account. Deleting your account queues a deletion request to each of them, which we retry until it succeeds — you do not need to ask.
- Our crash-diagnostics provider is the exception, and it is a real one. It offers no way to delete one person's reports: crash events are immutable and can only be removed by discarding an entire issue, which would destroy other people's diagnostics too. So your crash reports — identified by that anonymous identifier, and possibly carrying the IP address described in Section 9 — remain until they age out on that provider's own retention schedule, which is a matter of weeks, not years. None of them contain your Financial Information.
- The website waitlist is separate. Deleting your account does not remove you from it — use the unsubscribe link in any email, or ask us.
How long we keep each kind of information
Account and Financial InformationFor as long as your account exists, then erased on deletion as described above.
Internal audit recordsUp to 12 months. These record changes to your data for security and troubleshooting and do contain financial values, with credentials and secrets stripped. They are purged when you delete your account.
System event logs30 days. Credentials and secrets are stripped automatically.
Bank webhook records90 days.
Waitlist technical metadata90 days for the IP address, user-agent, and referring page.
Waitlist email addressesKept while you are subscribed. If you unsubscribe, the address is kept indefinitely on a suppression list, specifically so we can honor the opt-out — ask us and we will remove the record entirely.
Crash diagnostics and product analyticsHeld by our providers for limited periods set in their retention configuration, and not linked to your name or email address.
BackupsEncrypted backups are maintained by our cloud hosting provider and expire automatically on that provider's retention schedule. Deleted data persists in a backup only until the backups containing it age out.
After deletion we may retain limited records where the law requires it — for example, basic transaction records for tax purposes — and any such records remain protected under this policy.
15Where your information is processed
Bablo is operated from the United States, and the Services are offered to U.S. residents. Our database and application servers are hosted in the United States (in a U.S. West region), and our crash-diagnostics and product-analytics providers process data in the United States.
Three exceptions are worth naming precisely. This website is served through a global content delivery network, so the page you are reading was delivered from the network location nearest you, and that provider processes your connection there. Our AI provider routes requests across its own global infrastructure, so the analysis described in Section 6 may be performed outside the United States. And push notifications are delivered through Apple's global notification network, which routes through whichever of Apple's locations serves your device — as Section 7 explains, those messages can contain financial figures and merchant names.
If you access the Services from outside the United States, you understand that your information will be transferred to, processed, and stored in the United States, whose data protection laws may differ from those of your location.
16Your rights and choices
You may have the right to access, correct, export, or delete the personal information we hold about you, and to object to or restrict certain processing. We extend these rights to every Bablo user, regardless of where you live. If you live in a U.S. state with its own privacy law, Section 17 sets out the specifics.
Exercising your rights
Email privacy@babloapp.com from the address associated with your account. Many rights are also exercisable directly in the app: you can correct categories and figures as you go, and you can delete everything from the Me tab.
Verification
We verify your identity by confirming control of the email address on your account. For requests involving Financial Information, we may ask for additional information sufficient to confirm that you are the person the information belongs to. We will not use anything you provide for verification for any other purpose.
Authorized agents
You may designate an authorized agent to submit a request on your behalf. We will ask the agent for written permission that we can verify, and we may contact you directly to confirm it.
Appeals
If we decline to act on your request, you may appeal by replying to our response. We will inform you in writing of our decision and the reasons for it. If we deny the appeal, we will give you a way to contact your state attorney general.
Communications and notifications
- Marketing email. Every marketing message we send includes an unsubscribe link, and also supports your mail app's built-in unsubscribe button. Unsubscribing takes effect immediately for all future marketing email. Note that it records an opt-out against your address rather than deleting it — we keep the address on a suppression list precisely so the opt-out stays enforceable, since a deleted record could be re-added by a later signup. A later signup through the form for that same address counts as fresh consent and lifts the suppression — the form cannot verify who submitted it, so if that ever happens without your doing, the unsubscribe link in the next email removes you again in one press. To have the record removed outright, write to privacy@babloapp.com.
- Operational email — such as your sign-in code, or notice of a material change to this policy — is not something you can opt out of while you have an account, because it is part of providing the Services.
- Push notifications can be turned off at any time in the app, or in iOS Settings under Notifications. See Section 7 for how to hide their content without turning them off.
Withdrawing consent
Where we rely on your consent, you may withdraw it at any time. Withdrawing consent does not affect processing already carried out, and some withdrawals — such as unlinking every account — will prevent the app from working as intended.
17U.S. state privacy rights
If you reside in California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, your state's privacy law gives you the rights described below. Rather than granting them state by state, we extend all of them to every Bablo user regardless of where you live.
Categories of personal information we collect
In the categories these laws use, we have collected the following over the past 12 months:
- Identifiers — your email address, your first name, the identifier Apple provides if you use Sign in with Apple, a randomly generated user ID, device identifiers, and — for website waitlist and demo requests only — IP address.
- Personal information under Cal. Civ. Code § 1798.80 — the Financial Information described in Section 2(B): your linked institutions, account names and types, balances, the last four digits of account numbers, and transactions; and the content you create in the app — savings-goal names, custom category names, watch labels, notes you attach to transactions, and anything you include in support correspondence.
- Commercial information — your subscription status and renewal date.
- Internet or other electronic network activity information — app version, device model and type, operating system, language, time zone, screen dimensions, network type, in-app usage milestones, diagnostic and crash reports, and IP address and user-agent as described in Section 2(C).
- Inferences — the patterns we derive from your transactions in order to run the app: which spending is recurring, which is a bill, which merchants you use regularly, and the projections and coaching guidance built from them.
We collect these from you directly, from your financial institution through our Financial Data Provider once you link an account, from Apple, from our subscription management provider, and automatically from your device. We process them for the business purposes described in Section 3, and we disclose them for those purposes only to the categories of recipient listed in Section 10.
Access
You have the right to confirm whether we process your personal information and to access it, including the categories collected, the categories of sources, the business purposes for processing, and the categories of third parties to whom we disclose it.
Deletion
You have the right to request that we delete the personal information we hold about you. You can also do this yourself at any time — open the Me tab and tap Delete account, as described in Section 14.
Correction
You have the right to request that we correct inaccurate personal information we maintain about you.
Portability
You have the right to obtain a copy of your personal information in a portable and, to the extent technically feasible, readily usable machine-readable format.
List of third parties (Oregon and Minnesota)
If you are an Oregon or Minnesota resident, you have the right to request a list of the specific third parties to which we have disclosed personal information. Email privacy@babloapp.com and we will provide it.
Sale, sharing, and targeted advertising
You have the right to opt out of the sale or sharing of your personal information and of its processing for targeted advertising or for profiling that produces legal or similarly significant effects. We do none of these things. We have not sold or shared personal information in the preceding 12 months, we serve no advertising, and we run no advertising or cross-app tracking technology — so there is no opt-out for you to exercise. We honor Global Privacy Control signals regardless. We also do not knowingly sell or share the personal information of consumers under 16.
Sensitive personal information
You have the right to limit our use and disclosure of sensitive personal information. The Financial Information we collect is treated as sensitive under California law. We use it solely to perform the Services you signed up for — building your budget, categorizing spending, forecasting, and tracking goals. We never use it to infer characteristics such as your health, ethnicity, religion, sexual orientation, or political views, and never to profile you for advertising or for decisions about your eligibility for anything. We do derive spending patterns from your transactions, because that is the budget itself. Because we do not use it for any purpose that would require an opt-out, this right has nothing further to restrict, though you are welcome to contact us to confirm that.
Anti-discrimination
You have the right not to receive discriminatory treatment for exercising any of these rights. We will not deny you the Services, charge you a different price, or provide a different level or quality of service because you made a request. We offer no financial incentive or loyalty program in exchange for personal information.
Submitting a request
Email privacy@babloapp.com from the address associated with your account. Verification, authorized agents, and appeals are described in Section 16. We respond within the period required by applicable law and will tell you if we need an extension that law permits.
California "Shine the Light"
California Civil Code § 1798.83 permits California residents to request information about disclosures of personal information to third parties for those third parties' direct marketing purposes. We make no such disclosures.
Notice to Nevada residents
Nevada law gives residents the right to direct a business not to sell certain personal information. We do not sell personal information as defined by Nevada law, and we have no plans to. You may still submit a request to privacy@babloapp.com.
18Links to other services
Bablo and this site link out to places we do not control: your bank's own site during linking; Plaid's own site, its end-user privacy policy, and its portal at my.plaid.com; a biller's own website when you tap through from a bill in the app; Apple's support and purchase-support pages, and the App Store once Bablo is listed there; and — on our comparison pages — the pricing pages of other budgeting apps.
Once you follow one of those links, that company's privacy policy governs, not ours. We are not responsible for their practices, and we would suggest reading their policies before handing over anything sensitive.
19Children's privacy
Bablo is intended for a general adult audience. As set out in our Terms of Service, you must be at least 18 years old to use the Services. Bablo is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with information, contact privacy@babloapp.com and we will delete it and close the account.
20Changes to this policy
We may update this policy as the app evolves or the law changes. When we do, we will revise the "Last updated" date at the top of this page. If a change is material, we will give you notice in the app or by email before it takes effect, as the law requires. We encourage you to review this page periodically. Continuing to use Bablo after an update takes effect means you accept the revised policy.