Privacy Policy
Last updated · 2 August 2026
- Your bills are encrypted on your device with a key only you hold. We cannot read them — not even if we wanted to.
- We store your name and email so you can sign in and manage your subscription. That's the only readable personal information we keep.
- We never see your bank login, card numbers, or account numbers.
- We don't sell your data and we don't run ad trackers. Ever.
1. Who we are
Shugo is a personal bill manager (“Shugo”, “we”, “us”). This policy explains what we collect, what we don't, and the choices you have. If anything here is unclear, email us at privacy@shugo.online.
2. What we collect
- Account details. When you sign in with Google we receive your name, email address, and profile picture. We use these to identify your account and manage your subscription.
- Your bills. Bill names, amounts, and due dates — encrypted on your device before they are stored anywhere.
- Your AI key (optional). If you add your own Anthropic API key, it is encrypted on your device and never sent to us.
- Basic technical data. Our hosting provider keeps standard request logs (such as IP address and browser type) for security and reliability.
- Public-page analytics. On our public pages only — never on any page showing your bills, your bank connection, or your settings — we use Google Analytics to count visits. It records a random identifier, the pages viewed, and an approximate location derived from your IP address. We don't load it at all for visitors in the EEA, the UK, or Switzerland. Section 9 has the detail and how to opt out.
We do not use advertising trackers, build advertising profiles, or sell your data to anyone.
3. What we never collect
- Your bank username or password. You enter those directly with our bank-connection provider — never with us.
- Full card numbers, bank account or routing numbers, or government identifiers such as a Social Security number.
Shugo has no place to put this information, because it never asks for it.
4. How your bills are protected
Your bills are encrypted on your device using strong encryption (AES-256). The key is derived from your recovery code or your device's passkey / biometric unlock. That key never leaves your device and we never receive it.
Anything stored outside your device — a cloud backup, or a copy we hold to sync between your devices — is a sealed encrypted file we cannot open. To us it is meaningless data.
The honest trade-off: if you lose your recovery code and all your devices, we cannot recover your bills for you. That is the cost of real privacy, and we'd rather tell you plainly than pretend otherwise.
5. Where your data lives
- On your device — always the primary copy.
- In your own Google Drive (optional) — if you turn on backup, an encrypted file is stored in a private app folder in your Drive.
- In a backup file you save yourself (optional) — also encrypted.
- On our servers — your account details (name, email), and, if cloud sync is on, the sealed encrypted file described above.
The companies that help us run Shugo
We don't run our own data centre. These are every company that touches your information, what each one gets, and why. We name them so you can check them yourself rather than take our word for it.
- Vercel — hosts the website and runs our server code. Sees the normal things any web host sees: your IP address and which pages you requested.
- Supabase — the database that stores your name, email, subscription status, and the sealed encrypted file. It cannot open that file, and neither can we.
- Resend — sends the one welcome email when you start your trial. Gets your name and email address, nothing else. No financial information ever.
- Stripe — handles payments. We never see or store your card number.
- Google — signs you in, and stores your backup if you turn that on. The backup goes to your Drive, not ours.
- Plaid — connects your bank, if you choose to connect one.
- Anthropic and ElevenLabs — optional AI features (reading bills from photos, and the assistant's voice). Both run on your own account with those companies, and the request goes from your browser straight to them — never through our servers.
If we ever add another company to this list, we'll update this page before we start sending them anything.
6. Connecting your bank
Connecting your bank is optional, and off until you turn it on in Settings. Here is exactly how it works — and what we can and can’t see — so you can decide before you opt in.
Shugo can connect to your bank using Plaid to make that connection.
What we use it for. Bank data powers the money features you see in the app: finding your recurring bills, showing your balance and what's left after bills, warning you before you run short, and the spending breakdowns — what you earned, spent and kept, your top merchants, category changes, subscriptions, fees and a tax set-aside estimate. If you turn the assistant on, it can read this same information to answer your questions about it. It is used to run these features for you, and nothing else — never advertising, never sold, never shared for anyone else's purposes.
- You enter your bank credentials with Plaid, never with Shugo. We never see or store them.
- Through Plaid, Shugo receives your transactions (up to about two years of history, so patterns like a yearly bill are visible), your account balances, and basic account details such as the bank name and account type.
- How that data reaches you — the one place it is not sealed with your key. Plaid's API can only be called with a secret, and a secret cannot live safely in a browser. So your transactions and balances travel from Plaid through Shugo's server on the way to your device. That relay keeps no copy: nothing is written to a database, a file, or a log. But for those moments the data is readable to our infrastructure, and we will not claim otherwise.
- How we know when to check. To refresh your data promptly, our server receives a notification from Plaid when your bank reports new activity. That notification contains no transaction content — no amounts, merchants, or account numbers, only a signal to sync — and we keep only the timestamp of it, the same kind of sync-timing record we already keep for a refresh you trigger yourself. Data still only moves to your device when you have the app open and unlocked; the notification just means we don't need to wait as long to check.
- Once it arrives, that information is encrypted on your device. We keep only the sealed encrypted file — we do not keep a readable database of your transactions. So if someone broke into our servers and storage, the risk is forward-looking, not backward-looking: they could see data belonging to people syncing during the break-in, but could not read anyone's history, because there is no stored bank credential, no archive of transactions, and no key that opens the sealed copies we hold.
- One case is different, and we'd rather name it than round it off. Shugo is code we send to your browser, and that code is what does the sealing. If an attacker ever gained the ability to change the app itself — a different and more serious break-in than reading our storage — tampered code could capture keys as people unlocked, and a stolen key opens that person's sealed file, history included. Every app that encrypts on your device shares this limit; we're telling you because most don't.
- You can disconnect your bank at any time from Settings. Shugo revokes the connection with Plaid so no further data is pulled, and removes the bank data held on your device.
Plaid's own handling of your information is governed by its End User Privacy Policy. Disconnecting in Shugo stops Shugo's access; to see or delete what Plaid holds about you, use Plaid Portal, which is theirs, not ours.
7. AI features
Shugo's bill scanning and assistant are optional and run on your own Anthropic API key. What you send goes directly from your device to Anthropic under your own account — it does not pass through our servers, and we never see it.
Be aware what “what you send” means for the assistant. So it can answer without guessing, each message you send carries a summary of your money with it — your bill names, amounts, due dates and payment status, your monthly totals by category, and, if your bank is connected, your earned/spent/kept figures and any fees found. Asking “what's due?” sends your bill list, not just those two words. Scanning a bill sends that photo. If you would rather none of it left your device, don't add an AI key — everything else in Shugo works without one.
Anthropic does not train its models on anything sent through its API — that is their Commercial Terms, which is what an API key falls under, and it is different from the consumer Claude apps. They delete what you send within 30 days. If their automated safety systems flag a request, they may keep it up to two years and staff may review it. You can remove your key at any time in Settings, which turns these features off.
The assistant's voice is a different company on different terms, and we want to be blunt about it rather than lump them together. If you add an ElevenLabs key, the reply text — which can contain your bill names and amounts — goes from your browser straight to them. Unlike Anthropic, ElevenLabs stores that text in your account history until you delete it, and uses it to train their models unless you switch that off in their privacy settings. Their no-storage mode is enterprise-only. We flag this in Settings before you connect a key, and Shugo's built-in device voice sends nothing anywhere — that is what you get if you leave ElevenLabs off.
8. Payments
Subscription payments are handled by Stripe. We receive only your subscription status and identifiers needed to keep your account active. We never see or store your card details.
9. Cookies, local storage, and analytics
We don't use advertising cookies, and we don't run advertising or cross-site trackers. Shugo uses your browser's local storage to keep you signed in and to hold your encrypted data on your device. Clearing your browser storage signs you out and removes the local copy — make sure you have your recovery code and a backup first.
Analytics. On our public pages — this one, the homepage, pricing, security, about, terms, and data retention — we use Google Analytics to understand how many people visit and which pages they read. It neverloads on any page showing your bills, your bank connection, or your settings. That separation is structural: the analytics component is not part of the signed-in app, so it cannot be switched on there by accident.
It runs in an analytics-only mode. Advertising storage, advertising user data, and ad personalization are all switched off, and cross-device Google Signals are disabled — so no advertising profile is built from it, and we don't sell or share it. Outside the EEA, UK, and Switzerland it sets a first-party cookie named _gaholding a random identifier, and collects that identifier, the pages you view, and an approximate location derived from your IP address. Google acts as our service provider under its data-processing terms, handling it only on our behalf — never for its own advertising, and nothing is sold or shared.
If you are in the EEA, the UK, or Switzerland, we don't load Google Analytics at all. Not a cookie, not a ping, nothing sent to Google — the tag is never put on the page in the first place. We would rather not measure European visits than send anyone's IP address abroad to count them.
To opt out: turn on Global Privacy Control in your browser or privacy extension and we will not set an analytics cookie, wherever you are. Blocking cookies for this site, or any tracker-blocking extension, works too.
10. Your choices
- Download your data — from Settings, save a readable copy of your data (your bills, income, and savings goals), or an encrypted backup file, at any time.
- Delete your bills — from Settings, at any time.
- Disconnect — turn off Drive backup or your bank connection whenever you like.
- Delete your account — from Settings → Delete my account. This erases your data on this device, removes the sealed encrypted copy on our servers and the backup in your Google Drive, and cancels your subscription — right away, and it can't be undone. Prefer we do it for you? Email privacy@shugo.online.
- Request a copy of your data — the readable download above gives you your own bills and profile directly; your account details (name, email) are the only readable information we hold, since everything else is encrypted and unreadable to us.
- Opt out of analytics — turn on Global Privacy Control in your browser and we won't set an analytics cookie on our public pages, wherever you are.
11. How long we keep things
We keep your account details for as long as your account is open, and the sealed encrypted file until you delete it or close your account. After you close your account, both are removed. One record survives closing your account, on purpose: if you unsubscribed from our emails (or one bounced), we keep that email address, the date, and which of those it was — nothing else — so we never email you again. Deleting it would un-do your opt-out. Records of payment processing (Stripe event ids, held so a payment is never processed twice) are removed after 90 days. Hosting logs are kept for a short period for security purposes. The public-page analytics described in section 9 holds no financial details and nothing that directly identifies you. We set Google Analytics to its shortest retention — 2 months — for event- and user-level data; Google may keep aggregate, non-identifying totals longer.
12. Children
Shugo is not intended for anyone under 16, and we don't knowingly collect information from children.
13. Changes to this policy
If we change how we handle your information, we'll update this page and change the date at the top. Significant changes will be highlighted in the app.
14. Contact us
Questions, requests, or concerns: privacy@shugo.online.