---
title: Privacy Policy
slug: privacy
version: 1.1
effective: 2026-10-19
---

# Bucketize Privacy Policy

**Version 1.1 · Effective October 19, 2026**

Bucketize is a budget-planning service operated by **Lilac Impact Ventures LLC**, a Delaware limited liability company (**"Bucketize"**, **"we"**). This policy explains what personal data we collect about the people we deal with directly, why, and what choices you have.

> **In short (not part of the policy):** We collect the minimum an account needs — your email, your name, and the settings you choose. We set no cookies and use no third-party advertising or analytics services; the one usage measurement we make ourselves is how much time signed-in users spend active in the product. We don't sell personal data. Budget, headcount and vendor data that a customer puts into Bucketize belongs to that customer, is governed by our Data Processing Addendum rather than this policy, and is never used to train AI models. Questions: privacy@bucketize.org.

## 1. What this policy covers — and what it doesn't

This policy covers personal data we decide how to use, as a **controller** (or "business" under U.S. state law). That means data about:

- **Account holders and users** — people who sign in to Bucketize (as an organization owner, administrator, budget owner, delegate, or other role);
- **Website visitors** — people who browse bucketize.org;
- **Demo requesters and correspondents** — people who ask for a demo or email us;
- **FP&A Hiring Tracker subscribers** — people who subscribe to our public job-tracker digest.

This policy **does not** cover **Customer Data**: the budgets, forecasts, invoices, contracts, and headcount and compensation records that a customer organization and its users place in the Service, including information about the customer's employees, candidates and vendors. For Customer Data the customer is the controller and we are its **processor** (or "service provider"), acting only on the customer's instructions under our [Data Processing Addendum](/dpa). If your information is in a customer's workspace and you are not yourself a Bucketize user, see §10.

## 2. What we collect

### 2.1 Account holders and users

| Data | Where it comes from | Why |
|---|---|---|
| Email address, full name, optional avatar | You, at signup, or your identity provider if you sign in with SSO, or the administrator who invited you | To create and secure your account, identify you to your colleagues in the product, and contact you about the Service |
| Password (stored only as a salted hash) | You | Authentication. If you use SSO we never see a password. |
| Organization memberships, roles and access grants | The administrators of each organization you belong to | To enforce who can see and change what |
| Sign-in times, session and device tokens, IP address of requests | Automatically | Security, session management, abuse prevention |
| Active-time records: when you were active in the Service and for how long, per organization. They hold times only — no pages viewed, clicks, IP address or device details. | Automatically, while you are signed in and actively using the Service | To understand how much the Service is used, so we can support customers and decide what to improve |
| Things you write in the product that are about you or addressed to us (support requests, "Report a problem" submissions, feedback) | You | To help you and improve the Service |
| Diagnostic records: error reports, failed-request events, and a sample of masked session recordings (see §6) | Automatically, from your browser and our servers | To find and fix bugs |
| AI assistant usage records: the question you asked, the assistant's answer, which tools it used, and token counts | Automatically, when you use the AI assistant | To operate, meter and troubleshoot the assistant, and to show you your history |
| Preferences (theme, selected organization, view settings) | You, stored in your browser | So the product remembers how you like it |

What you enter *into* budgets, plans and invoices is Customer Data and belongs to the organization whose workspace it is in.

### 2.2 Website visitors

We collect **no** personal data from ordinary browsing beyond the standard web-server logs kept briefly by our hosting provider (IP address, browser type, requested pages, timestamps) for security and capacity. We set no cookies and use no analytics or advertising services (§6).

### 2.3 Demo requests and correspondence

If you request a demo we collect your name, work email, job title and company size, and we infer your company from your email domain. Demo requests are delivered to our team's mailbox; they are not stored in the product database. If you then book a time, the scheduling is handled by Calendly under [its privacy policy](https://calendly.com/privacy). If you email us, we keep the correspondence.

### 2.4 FP&A Hiring Tracker subscribers

The FP&A Hiring Tracker (bucketize.org/fpalead) is a public page listing companies that are hiring senior finance roles. If you subscribe to the email digest we collect your **email address** and chosen **frequency**. Digest emails contain no tracking pixel; links in them carry a subscriber identifier so that, when you click through, we can record that a visit came from the email. Visit records hold only the source ("email" or "direct"), the subscriber identifier if present, and the time — no IP address, user agent or referrer. Every digest has a one-click unsubscribe; unsubscribing deletes your record immediately. The tracker lists job postings by company; it does not list individual people.

## 3. How we use personal data

| Purpose | Data | Legal basis (where one is required) |
|---|---|---|
| Providing and securing the Service, authenticating you, enforcing access controls | Account data, sign-in and session data | Performance of our contract with you or your organization; legitimate interest in security |
| Communicating with you about your account and the Service (invitations, approval requests, reminders, security notices, changes to these terms) | Email, name, role | Contract; legitimate interest |
| Weekly digests to organization roles that opted into them (budget-change and IT-seat digests) | Email, name, role | Contract; you can turn these off in settings |
| Support, troubleshooting and fixing bugs | Support messages, diagnostic records | Legitimate interest in a working product |
| Operating the AI assistant and metering its use | AI usage records | Contract |
| Understanding how much the Service is used, to support customers and prioritize improvements | Active-time records | Legitimate interest in running and improving the Service |
| Sending the FP&A Hiring Tracker digest | Subscriber email, frequency | Consent (you subscribed); withdraw by unsubscribing |
| Responding to demo requests and correspondence | Contact details, message | Legitimate interest; steps at your request before a contract |
| Complying with law, resolving disputes, enforcing our terms | Whatever is relevant | Legal obligation; legitimate interest |

We do **not** use personal data for advertising, profiling for marketing, or automated decisions that produce legal or similarly significant effects on you. We do not use personal data — or Customer Data — to train AI or machine-learning models (see §5).

## 4. How we share personal data

- **Subprocessors.** Companies that host and run parts of the Service for us: our hosting and edge network, our database and authentication provider, our email-delivery providers, our error-monitoring service, and the AI model providers behind our AI features. Each is bound by a contract restricting it to processing on our instructions. The current list, what each one processes, and where, is at [bucketize.org/subprocessors](/subprocessors). We give customers advance notice before adding one.
- **At your organization's direction.** Administrators can connect third-party systems (accounts-payable, ERP, HRIS/payroll, applicant-tracking, contract-management and identity providers). When they do, data flows from those systems into the workspace under the organization's control. Your organization's administrators can also see your name, email and role, and what you do in the workspace.
- **Other users in your organization.** Your name and email are visible to colleagues in the same workspace, for example as the owner of a budget line or the author of a change.
- **Legal.** We may disclose personal data when we believe in good faith it is required by law, subpoena or court order, or to protect the rights, safety or property of Bucketize, our customers or the public. Where permitted, we will tell the affected customer first.
- **Business transfers.** If Bucketize is involved in a merger, acquisition or sale of assets, personal data may transfer to the successor, which will be bound by this policy for data collected under it.

We do not sell personal data and have not done so. We do not share it for cross-context behavioral advertising.

## 5. AI features

Parts of the Service use large language models from third-party providers (currently Anthropic and OpenAI) to analyze budgets, match invoices, map uploaded files and answer questions. What is sent to a provider is the data needed to answer the request — for example budget line names and amounts, invoice vendor names, or text you uploaded — and, when a user asks about recent changes, the **name or email of the colleague who made a change** may be included so the assistant can say who did what. Under our provider contracts, none of this is used to train models; providers may retain requests briefly (currently up to 30 days) for abuse monitoring. Organization administrators can turn AI features off. The full commitments are in [§7 of our Terms](/terms#7-ai-features) and on the [subprocessor page](/subprocessors).

## 6. Cookies, local storage and similar technologies

**We set no cookies.** The Service keeps what it needs in your browser's local storage instead:

- your sign-in session (access and refresh tokens), removed when you sign out;
- which organization and budget tree you last had open, removed when you sign out;
- preferences such as theme, view layouts, filter choices, whether you have seen the product tour, and a remembered SSO domain if you use single sign-on;
- on the FP&A Hiring Tracker page, a flag that you have already subscribed so we do not show the signup form again.

None of these is used to track you across websites or to identify you to third parties. Our hosting provider's edge network may set its own short-lived cookies for security and bot detection.

**Error monitoring and session replay.** We use Sentry to capture errors and performance data, and Session Replay to record a **sample** of sessions (about 10% of ordinary sessions, and sessions in which an error occurs) so we can see what went wrong. Replays are configured so that **all text, form inputs and media are masked in your browser before anything is sent**, and we never record a page load that carries an authentication token. We strip authentication tokens from every error report.

**Usage measurement.** While you are signed in, the Service notes about once a minute that you are active — the tab is in front and you have recently clicked, typed or scrolled — and adds that time to a record of your sessions (§2.1). This is our own measurement, kept in our own database and sent to no analytics provider. It records times only: not which pages you open, what you click or type, your IP address or your device.

**Third-party resources.** The demo-booking page loads Calendly's scheduling widget after you submit the form; Calendly may set its own cookies, under its own policy. When you view amounts in a currency other than U.S. dollars, your browser fetches exchange rates from a public rates service, which sees your IP address as any web request does. Fonts are served from our own domain. We embed no social-media, advertising or analytics scripts.

**Do Not Track / Global Privacy Control.** Because we do not track visitors across sites or sell or share personal data, there is nothing for these signals to switch off; we treat them as an opt-out request in any case.

## 7. How long we keep personal data

| Data | Retention |
|---|---|
| Account data (email, name, memberships) | For as long as your account exists. Ask us to delete your account and we will do so within 30 days, except that your name may remain on historical records in your organization's workspace (for example, as the author of a past change) because those records belong to your organization. |
| Sign-in and session records | Sessions expire when you sign out or after a period of inactivity; sign-in timestamps are kept with the account |
| Server and edge logs | A limited period, typically days |
| Error reports and session replays (Sentry) | Up to 90 days |
| In-app diagnostic events (failed requests, client errors) | Up to 90 days |
| AI assistant usage records | Up to 12 months, or until your account is deleted |
| Active-time records | Up to 24 months, or until your account is deleted |
| Support and "Report a problem" correspondence | Up to 24 months after the matter is closed |
| Demo requests and email correspondence | Up to 24 months |
| FP&A Hiring Tracker subscription | Until you unsubscribe, which deletes it immediately. Visit records: up to 24 months. |

Customer Data retention, including what happens when a customer leaves, is set out in the Terms and the Data Processing Addendum.

## 8. Security

We protect personal data with encryption in transit and at rest, per-organization isolation enforced in the database, role-based access control, encrypted storage of integration credentials, audit logging and automated authorization testing. Our current security practices are described at [bucketize.org/security](/security). No system is perfectly secure; if we confirm a breach affecting your personal data we will notify you or your organization as the law requires.

## 9. Your rights and choices

Whatever your location, you can ask us to **access**, **correct**, **delete** or **export** the personal data we hold about you as a controller, to **object** to or **restrict** a particular use, or to **withdraw consent** where consent is the basis. To do so, email **privacy@bucketize.org** from the address on your account, or use the settings in the product where a control exists (profile details, digest settings, unsubscribe links). We will verify your identity, respond within 30 days (or the period the law allows), and will not treat you differently for exercising a right. You may use an authorized agent if they can show your permission. If we decline a request we will say why, and you may ask us to reconsider.

**If you are a user in a customer's workspace**, some of what you see about yourself is Customer Data under your organization's control — for example your role, or budget lines you own. We will fulfil what we can directly and refer the rest to your organization's administrators.

**California and other U.S. states.** In the past 12 months we have collected the categories described in §2 (identifiers; professional information such as job title; internet activity such as diagnostic records; and, for account holders, account credentials, which we use only to authenticate you). We collect them from you, your organization, your identity provider and your browser, for the purposes in §3, and disclose them to the recipients in §4. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use or disclose sensitive personal information for purposes other than providing the Service. You have the rights described above, including the right to know, delete, correct and non-discrimination, and to appeal a decision by emailing privacy@bucketize.org.

**European Economic Area, United Kingdom and Switzerland.** Our legal bases are listed in §3. Bucketize is established in the United States and processes personal data there (§11). Where we transfer personal data from these regions, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum and Swiss adaptations as applicable), and for Customer Data our DPA incorporates them. You have the rights described above, and the right to lodge a complaint with your local data-protection authority. Where we rely on legitimate interests, you can object and we will stop unless we have compelling grounds.

## 10. If your information is in a customer's workspace but you are not a user

Customers use Bucketize to plan budgets and headcount. That means a workspace may hold your name, title, compensation or payroll figures (if you are an employee or planned hire), your name and contact details (if you are a vendor contact or invoice approver), or your email (if you were invited but have not joined). In those cases the customer decided to collect that data and is responsible for it; we process it only on the customer's instructions and cannot change or delete it without them. Please direct requests about that data to the organization concerned — typically your employer or the company you do business with. If you contact us instead, we will forward your request to the customer within five business days and tell you we have done so.

## 11. Where we process data

Bucketize is operated from the United States. Our production database and authentication service run in the AWS **us-east-1** region (Virginia); our application runs on a global edge network that processes requests close to where they originate; our error-monitoring and AI providers are in the United States. Details are on the [subprocessor page](/subprocessors).

## 12. Children

The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal data from children; if you believe we have, contact us and we will delete it.

## 13. Changes to this policy

We will post updates at bucketize.org/privacy with a new effective date. For material changes we will notify account holders by email or in the product before the change takes effect. The change log at the end of this page records what changed.

## 14. Contact

Lilac Impact Ventures LLC (d/b/a Bucketize)
privacy@bucketize.org · security@bucketize.org · legal@bucketize.org
Postal address: on request at the email addresses above.

---

*Change log — v1.1 (2026-10-19): added active-time records — our own measurement of how long signed-in users are active in the Service (§2.1, §3, §6, §7); the summary now says "no third-party advertising or analytics services" to match. v1.0 (2026-09-07): first published version.*
