Breadmaxxer (“we,” “us,” “our”) operates a personal finance tracking application. This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using Breadmaxxer you agree to the practices described here.
Account information. Email address, display name, and authentication credentials (sign in with Google or email/password). If you claim a handle, your handle, display name and avatar are visible to other signed-in users — see Other Users & Social Features.
Financial data. Transaction records you provide through manual entry, CSV import, or bank connection (dates, amounts, merchant names, and categories), along with account balances and account types. For connected credit cards and loans, this also includes account details such as credit limits, interest rates (APR), minimum payments, statement balances, and payment due dates — used to power your spending, cash-flow, and card-payoff insights.
Shift and earnings data. Hours worked, hourly rates, tips, and wages you log in the shift tracker.
Usage data. Feature interactions, streak progress, and goal/budget configurations needed to operate the service. Feature interactions means which parts of the app you open and what you do there, counted under your account so we can see which parts are working, and deleted with it. We do not run third-party analytics or ad trackers inside the app. On our public pages only, we use cookieless analytics (Vercel Web Analytics and PostHog); these stop once you sign in.
Device information. When you sign in, submit feedback, or enable push notifications, we store your browser’s User-Agent string and a derived device identifier, so we can recognize the devices on your account, alert you to a sign-in from a device you haven’t used before, and let you revoke a device from Settings → Security. We also store an approximate location for each sign-in (city, region, country) derived from your IP address. We do not store your raw IP address, though standard hosting-provider request logs may contain User-Agent and IP data.
Location. Optional, off until you allow it, and read only while the app is open — we do not track you in the background. With your permission we use your position to pre-select the job you are clocking in at and to prompt you when you arrive, or when you leave while still on the clock. The matching happens on your device: your current position is never sent to us, written to a log, or given to the AI assistant.
From your device we keep up to five approximate points per job, each rounded to about 110 metres, stored on your account and encrypted — and a place is only saved after you clock in there twice, so somewhere you went once is never sent to us. Your device also stores two things locally that are not locations and never reach us: whether this browser has ever allowed location, and how vague its last reading was. Settings → Preferences → Privacy → Location turns location off for every device you sign in to and erases every saved point in one tap; deleting a job, or your account, deletes them too.
A job’s address. You can also type one or more addresses for a job. What you type is sent to Google Maps Platform to suggest matching places and to turn the address you save into coordinates; we then store the address and the rounded point on your account, encrypted. This is separate from device location — typing an address neither uses nor turns on your device’s position, and it stays stored while device location is off. Remove one from the job in Settings → Income, or all of them with “forget where my jobs are”.
Photos and files you give us. A receipt photo you scan is read by the AI provider to fill in the transaction; we keep a smaller copy of it only if you save that transaction, attached to it. A scan you do not save is not kept. A photo or screenshot you add a wishlist item from is kept the same way, as that item’s picture, and for an item added by link we keep a copy of the product image the link points to. A resume you upload for job search is kept until you delete it. All of these are encrypted before they are stored, are never shown to other users, and are listed together in Settings → Documents, where you can view or delete any of them. Deleting a transaction or wishlist item deletes its photo within a day; deleting your account deletes them all.
When you connect a bank account, we use Plaid Inc. to access your account information on your behalf. We never see, store, or have access to your bank login credentials — Plaid handles authentication directly with your institution. Through Plaid we receive the financial data described under Information We Collect. When you disconnect your bank in Settings, the connection is revoked at Plaid and the associated records are removed.
Plaid’s own privacy practices are governed by the Plaid End User Privacy Policy.
We do not sell, rent, or share your personal or financial data with third parties for marketing or advertising purposes.
Bread is powered by AI models from Anthropic (Claude) and Google (Gemini). When you chat with Bread, your message and the financial context relevant to your question are sent to whichever provider handles the request, solely to generate a response. We access both through their paid business APIs, under which your conversations are not used to train their models. See Anthropic’s Privacy Policy and the Gemini API Terms.
Web search. When answering your question needs a current fact from outside your own records — a price, a rate, something in the news — Bread may run a web search using the search tool built into whichever provider is handling the request. What reaches the search is the query Bread forms, not your transactions or balances.
Personalization. Bread keeps a private profile of you built from your activity in the app — patterns in your money, the goals and topics you raise, and how you interact with Bread. When something you say looks worth remembering, Bread shows it to you first, so you can confirm it, correct it, or block it permanently; items awaiting your answer are stored encrypted. The profile stays within your account and is never sold or shared. Review it, clear it, or turn personalization off in Me → Bread; with it off, none of this is collected.
Your chats. Conversations are kept until you delete them, encrypted at rest, and readable by no other user. Alongside each message we store an “embedding” — a list of numbers derived from your message — and for each conversation a short note of what it is about, written by the same AI that answers you, encrypted like the chat, with an embedding of that note; these let Bread find related earlier conversations in your own history. The embeddings are not encrypted the way the text is, because Bread has to compare them to search, and an embedding can in principle be partially reconstructed into text; treat each as a copy of the text it came from that is held only on our servers, readable by no other user, and never shared. Deleting a chat removes its messages, its note and their embeddings immediately; deleting your account removes all of them. A private chat is never written at all; see Private Chat (Incognito Mode) below.
Bread provides informational insights only, not financial, investment, or tax advice. You should not rely on Bread’s responses as a substitute for professional financial guidance.
Start a private chat, Bread’s incognito mode, from the ghost in the chat header. Nothing from it is saved: no messages, no memory, and no thread in your recents. It’s gone when you leave.
Bread still sees your numbers exactly (balances, card rates, minimums and due dates, income, spending, bills and shifts), so its answers are just as accurate. It isn’t given your name and email, what it remembers about you, or your past chats. Names on Zelle, Venmo and Cash App transfers, your card numbers, and store details in bank descriptions are removed first, and your goals and plans are shared as amounts only.
A private chat is read-only: it can’t change anything in your account, even if you ask. Your message still goes to the AI provider answering it, as in any chat. The only records kept are the usage rows every chat leaves (timing and credits used) and, in any chat, a safety note without your words if a message describes harm to yourself or others or an attempt to break the app.
Your data is stored with Supabase, which provides our managed database and authentication. We employ industry-standard access controls, encryption in transit and at rest, and isolated execution environments for privileged operations. Authentication credentials are managed by our identity provider; we never see or store your Google password. For fraud detection and account security we log security-relevant events on your account (sign-ins, two-factor changes, bank-connection changes, deletion requests), which you can view at Settings → Security. We also keep records of fraud, abuse, and Terms violations, and may act on them, including limiting, suspending, or terminating accounts.
No system is ever fully secure, and we can’t guarantee that a breach will never happen. If one does, we’ll notify affected users promptly.
We retain your data for as long as your account is active. You can delete individual transactions, goals, budgets, bank connections, or AI chats at any time through the app. Conversations with the AI assistant are kept until you delete them (deleting a chat yourself removes it immediately); they are not purged on an automatic schedule.
You can request account deletion at any time from the Settings page. Deletion is handled in two stages:
Once the purge completes, the deletion is irreversible — we cannot restore your data. The one exception is feedback you submitted through the in-app feedback form, which we retain indefinitely to improve the product. Before retention, all direct and indirect identifiers (user ID, email, display name, device identifiers, and anything else that could link the feedback back to you) are stripped.
Each provider processes data in accordance with their own privacy policies. We only share the minimum data necessary for each service to function.
If you’re a California resident, the CCPA gives you these rights:
To exercise any of these rights, contact us at hi@breadmaxxer.com. We’ll verify your request through your account and respond within the timeframes required by law.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising as defined under the CCPA. If this ever changes, we will update this policy and provide a clear opt-out before doing so.
Breadmaxxer is for adults 18 and older. It is not directed at anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has an account or has provided us with personal data, please contact us and we will close the account and delete the data promptly.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app or by updating the “Last updated” date above. Continued use of Breadmaxxer after changes constitutes acceptance of the updated policy.
For privacy questions, data access requests, or deletion requests, contact us at hi@breadmaxxer.com.
Other Users & Social Features
Your money is never visible to another user. Your transactions, balances, income, shifts, goals, budgets, streaks and your chats with Bread are yours alone, whatever you do with the features below.
Handles. You can claim a handle (like @sam). Once you do, other signed-in users can find you by that handle or your display name, and a search shows them your handle, display name and avatar — nothing else. If you never claim a handle you cannot be found or followed, and the rest of the app works exactly the same.
Following. You can follow other people and they can follow you; when you follow each other, you are shown to one another as friends. We let someone know when you follow them. Your followers and the people you follow are visible to you, not published on your account. If you turn on a private account in Settings, new follow requests wait for your approval; people already following you stay followers, and going private does not remove them. You can remove a follower at any time, which ends only their follow of you — they are not told, and they can follow you again. You can also block someone: you stop following each other, they cannot follow you again, and neither of you appears in the other’s search results or suggested connections. Blocking is not announced, though the person blocked may be able to tell. Unblocking restores what they can see; it does not restore the follows. The list of people you have blocked is visible only to you, and we never tell anyone that they have been blocked. You can unfollow anyone at any time, and deleting your account removes you from everyone else’s lists.
Suggested connections. How we suggest people you may know — and what neither person is shown — is described under How We Use Your Data. The workplace half is off unless both people leave workplace suggestions on; the half drawn from your existing network is not tied to that setting. Dismissing a suggestion stops that person being suggested to you again, and declining a follow request stops it in both directions. Neither is a block, and neither is announced.