Privacy Policy
Last updated July 23, 2026
Draft notice: this is a first-draft privacy policy describing what Cofre actually collects and does with your data today. It has not yet been reviewed by a lawyer — treat it as accurate but not final.
Cofre (“Cofre”, “we”, “us”) is a personal budget tracker operated by Osmio Services. This policy explains what information we collect when you use the Cofre web app, why we collect it, and how you can control or delete it.
1. Information we collect
Account information — your email address, name, and password (stored as a one-way bcrypt hash, never in plain text) or, if you sign in with Google, your Google account id and profile photo.
Financial data you enter — transactions, budgets, categories, projects, debts, assets, and savings goals you create manually inside Cofre.
Bank account data (Plaid) — if you connect a bank account, we receive your account name, type, balance, currency, and up to 90 days of transaction history from Plaid. The access token Plaid issues us is encrypted at rest (AES-256-GCM) and is never shown to us in readable form.
Gmail data — if you connect Gmail, Cofre requests read-only access (gmail.readonly) to search for receipt, order-confirmation, and invoice emails whose subject line looks like a receipt, order confirmation, or invoice — regardless of sender — limited to the last 90 days. We read the matching email’s subject and body to extract the merchant, order number, date, total, and line items. That extraction happens entirely on Cofre’s own server — the email content is never sent to any third-party AI or analysis service. We do not store the raw email body or attachments — only the resulting structured receipt (merchant, items, total, and the subject line) is saved to your account. Your Gmail OAuth tokens are encrypted at rest (AES-256-GCM) and are only used to fetch the emails matching that search — never to send email, read unrelated messages, or access anything outside that scope.
2. Google user data & Limited Use
Cofre’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, and we do not sell or share Gmail data with any third party.
3. How we use your data
We use the information above to show your dashboard, categorize spending, track budgets and debts, and automatically surface receipts you can import as transactions. We do not sell your data, and we do not use it for advertising or ad targeting.
4. Third parties we work with
To operate Cofre, some data is processed by service providers acting on our behalf, under their own confidentiality and security obligations:
- Plaid — bank account linking and transaction data.
- Google — Gmail and Google Sign-In, as described above.
- Resend — delivers transactional email (verification, password reset).
- Google Cloud — hosts our application and database infrastructure.
5. Your controls
You can disconnect Gmail or a bank account at any time from Settings → Integrations — this revokes our access token immediately. To delete your account and all associated data, contact us at the email below.
6. Security
Passwords are hashed with bcrypt and never stored in plain text. OAuth tokens for Gmail and bank connections are encrypted at rest with AES-256-GCM. All traffic to Cofre is encrypted in transit (HTTPS). No security measure is perfect, and we cannot guarantee absolute security.
7. Children’s privacy
Cofre is not directed to children under 13, and we do not knowingly collect data from them.
8. Changes to this policy
We may update this policy as Cofre changes. We’ll update the “Last updated” date above when we do.
9. Contact
Questions about this policy or your data? Email support@budgetcofre.com.