Privacy Policy
Last Updated: September 4, 2026
1. Introduction
Squirlo ("we," "our," or "us") operates the Squirlo mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our App.
By using the App, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Name and email address
- Password (stored securely in hashed form)
- Authentication credentials if you sign in via Google or Apple
2.2 Financial Information
To provide our budgeting services, we collect:
- Transaction details (name, amount, category, date)
- Recurring payment schedules and bills
- Expense and income categories you create
- Monthly income (if provided)
- Currency preference
2.3 Connected Bank Account Information
If you choose to connect a bank account through Plaid, we receive:
- Account details such as account name, type, currency, and the last four digits of the account number
- Institution details such as the name of the bank or financial institution you connect
- Balances for each connected account, both current and available
- Transactions such as merchant or description, amount, date, pending status, and the category assigned by Plaid
We do not receive or store your online banking username or password. See Section 5 for more detail on how bank connections work.
2.4 Onboarding Information
During onboarding, we may collect:
- Your financial goals and obstacles
- How you heard about the App
- Whether you have used other budgeting apps
2.5 Device and Usage Information
We automatically collect:
- Device type and platform (iOS or Android)
- Push notification tokens
- App usage events (e.g., screen views, feature usage, sign-in method)
- Interaction with notifications
2.6 Subscription Information
If you subscribe to Squirlo Pro, we collect:
- Subscription status, tier, and renewal period
- Purchase history related to in-app purchases
2.7 Information You Provide to AI Features
If you choose to use the App's AI-powered features, we process:
- Chat messages you type or speak to the in-app assistant
- Voice recordings you make to add a transaction or category by voice, and the transcript produced from them
- Photos of receipts you take or upload to add a transaction, and the details extracted from them
Voice recordings and receipt photos are used only to produce the transaction or category details and are not stored on our servers. See Section 6 for how AI features work.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our budgeting services
- Connect to the bank accounts you link through Plaid, import your transactions and balances, and keep them up to date
- Automatically categorise imported transactions and match them to your budgets and recurring payments
- Power the App's AI features, including the in-app assistant, voice and receipt entry, transaction categorisation, spending insights, forecasts, and savings suggestions (see Section 6)
- Process and manage your subscription
- Send push notifications, including weekly summaries, budget alerts, recurring payment reminders, and inactivity nudges (you can opt out of each type in Settings)
- Analyse usage trends to improve the App
- Authenticate your identity and secure your account
- Respond to support requests and feedback
4. Third-Party Services
We use the following third-party services that may process your data:
| Service |
Purpose |
Data Shared |
| Supabase |
Authentication and database hosting |
Account information, financial data |
| Plaid |
Secure bank account connections and transaction retrieval |
Bank account, institution, balance, and transaction data; Squirlo user ID |
| OpenAI |
AI processing for the assistant, voice and receipt entry, transaction categorisation, insights, forecasts, and suggestions |
Chat messages, voice recordings, receipt photos, and the transaction, category, budget, and spending data needed for each feature (see Section 6) |
| ElevenLabs |
Converting the assistant's written replies into speech |
The text of the assistant's replies |
| RevenueCat |
Subscription and in-app purchase management |
User ID, purchase and subscription data |
| PostHog |
Product analytics |
Anonymised usage events, device type, platform |
| Expo |
Push notification delivery |
Device push tokens, notification content |
| Google Sign-In |
Authentication |
Email, name (if you choose Google sign-in) |
| Apple Sign-In |
Authentication |
Email, name (if you choose Apple sign-in) |
Each third-party service operates under its own privacy policy. We encourage you to review their policies.
5. Bank Account Connections (Plaid)
Squirlo uses Plaid Inc. to let you securely connect your bank accounts to the App, so that transactions and balances can be imported automatically instead of entered by hand. Bank connections are optional, and you can use the App without linking an account.
- We never see your bank login. You enter your credentials directly with Plaid or with your bank. Your banking username and password are never shared with, transmitted to, or stored by Squirlo.
- What Plaid shares with us. Plaid connects to your financial institution on your behalf and provides Squirlo with the account, institution, balance, and transaction data described in Section 2.3.
- Read-only access. Squirlo requests read-only access. We cannot move money, make payments, or initiate transfers from a connected account.
- Plaid’s own privacy policy. Plaid processes your information under its own privacy policy, available at plaid.com/legal. We encourage you to review it before connecting an account.
- Disconnecting an account. You can disconnect a bank account at any time in the App’s Settings. You can also manage or revoke Plaid connections directly at my.plaid.com.
6. Artificial Intelligence Features
Squirlo uses artificial intelligence ("AI") to make budgeting faster and easier. This section explains which features use AI, what data they process, and who processes it.
6.1 Which features use AI
- In-app assistant. Answers questions about your spending, budgets, merchants, and upcoming bills, and can read its replies aloud.
- Voice and receipt entry. Turns a voice note or a photo of a receipt into a transaction or category for you to review before saving.
- Transaction categorisation. Suggests a category for transactions imported from a connected bank account, and can propose a new category when none of yours fits.
- Insights, stories, and forecasts. Writes short summaries of your spending, weekly recaps, and month-end spending forecasts.
- Suggestions. Recommends which categories are essential and where you might be able to save.
- In-app messages. Adjusts the wording of some home-screen messages so they read naturally.
6.2 What data is processed
To provide these features, we send the AI provider only the information needed for that feature. Depending on the feature, this may include your chat messages, voice recordings, receipt photos, transaction descriptions, amounts and dates, your category names and budgets, merchant totals, monthly income, recurring payments, and currency. We do not send your name, email address, password, bank login, or bank account numbers to AI providers.
6.3 Who processes it
AI processing is carried out on our behalf by two providers. We access both through their developer APIs, and each processes data under its own privacy policy, which we encourage you to review.
- OpenAI, L.L.C. provides the text, image, and speech-to-text models behind the assistant, voice and receipt entry, categorisation, insights, forecasts, and suggestions. OpenAI does not use data sent through its API to train or improve its models. OpenAI may keep API inputs and outputs for up to 30 days to monitor for abuse, after which they are deleted. Audio sent for transcription is not kept for abuse monitoring.
- ElevenLabs Inc. converts the assistant's written replies into speech. ElevenLabs receives only the text of those replies, never your messages, recordings, photos, or account details. ElevenLabs keeps that text and the generated audio in our account's generation history until we delete it. Those entries are not linked to your identity or account. We have opted out of ElevenLabs using our data to improve its models.
6.4 How we handle AI data
- Voice recordings and receipt photos are processed in memory and are not stored on our servers.
- Chat conversations are held on your device. We do not keep a copy of your conversations with the assistant on our servers.
- AI-generated insights, messages, and suggestions are saved to your account so the App can show them without regenerating them each time. They are deleted with your account.
- Suggestions are reviewable. AI-suggested categories, transactions, and recommendations are suggestions only. You can review, change, or reject them, and nothing is moved or paid on your behalf.
6.5 Accuracy and limits
AI-generated content can be inaccurate or incomplete. It is provided for general information only and is not financial, legal, or tax advice. Please check anything the App generates before relying on it.
6.6 Choosing not to use AI features
AI features are optional. You can use the App without the assistant, voice or receipt entry, or connected bank accounts, and enter and categorise transactions by hand. Because categorisation, insights, and forecasts run automatically on the data in your account, the only way to stop all AI processing is to stop using those features or delete your account.
We cannot reach into our AI providers' systems to delete individual requests on your behalf. Data sent to OpenAI is deleted automatically within 30 days under OpenAI's abuse-monitoring policy. Assistant reply text held at ElevenLabs is not linked to your identity, so it cannot be deleted for one person, and it contains no name, email, or account details.
7. Data Storage and Security
- Your data is stored securely in cloud-hosted databases (Supabase).
- Some data is cached locally on your device for performance.
- We use industry-standard security measures, including encrypted connections (HTTPS) and hashed passwords, to protect your information.
- Bank connections are secured using access tokens issued by Plaid, which are stored encrypted on our servers. We never receive or store your online banking username or password.
- Data sent to our AI providers is transmitted over encrypted connections and limited to what each feature needs.
- While we take reasonable steps to protect your data, no method of electronic storage or transmission is 100% secure.
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you with our services. If you delete your account, we will delete or anonymise your personal data within a reasonable timeframe, except where we are required to retain it by law.
If you disconnect a bank account, we delete the stored Plaid access token for that account and stop receiving new data from it. Transactions already imported into the App remain in your account until you delete them or delete your account.
Voice recordings and receipt photos are not retained after processing. AI-generated insights and suggestions are kept in your account and deleted with it. OpenAI may keep data sent to it for up to 30 days for abuse monitoring, and ElevenLabs keeps the assistant reply text it receives, which is not linked to your identity, until we delete it, as described in Section 6.3.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your personal data
- Export your data in a portable format
- Withdraw consent for data processing where consent is the legal basis
- Opt out of marketing communications and push notifications
- Disconnect any linked bank account and stop further data collection from it
- Review or change any AI-suggested category, transaction, or recommendation, and stop AI processing by not using those features or deleting your account (see Section 6.6)
To exercise any of these rights, please contact us at the email address below.
10. Children's Privacy
The App is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
11. Push Notifications
We may send you push notifications for weekly summaries, budget alerts, recurring payment reminders, and engagement nudges. You can manage your notification preferences within the App's Settings, or disable push notifications entirely through your device settings.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy within the App and updating the "Last Updated" date above. Your continued use of the App after changes are posted constitutes your acceptance of the revised policy.
13. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
Email: [email protected]