Security & your data
Plain statements you can check. We don't hold a SOC 2 or ISO certificate yet and we won't pretend otherwise — here is what is true today, by design.
What the tag does
- Records what happens after an ad click on your site: timing, scroll and mouse movement, repeat visits, the advertising click ID, and technical characteristics of the visit (IP address, browser, device).
- Loads asynchronously and fails open. If our servers are unreachable, blocked by an ad blocker, or refused by your content-security policy, your page renders exactly as it did before.
- Under 30 KB, first-party, zero third-party runtime dependencies — every byte is ours and auditable.
What the tag never does
- Never reads form fields, page text, names, emails, addresses or payment details. Interaction metadata only.
- Never sets tracking cookies for advertising, never tracks visitors across other websites, never sells or shares data with advertisers.
- Never modifies your page, overrides your other scripts, or runs in the critical rendering path.
- Never retries in a loop if delivery fails — losing telemetry is our problem, slowing your site is never acceptable.
Where your data lives
- Application and database hosted in London (UK) — Fly.io and Neon (AWS eu-west-2). Edge network and TLS by Cloudflare.
- Encrypted in transit (TLS 1.2+, HSTS) and at rest by our hosting providers.
- Sub-processors are listed in our Privacy Policy.
How long we keep it
- Raw click telemetry is kept for 90 days — Google's ~60-day claim window plus a buffer — then deleted. Aggregates that identify nobody may be kept for reporting.
- Close your account and we delete your telemetry within 30 days.
What access we ask for
- Your website: one tag, which you can remove at any time.
- Google Ads: read-only at first. Blocking and claim filing each need a separate permission you grant explicitly, when you're ready.
- Sign-in: no passwords stored — one-time email links or Google sign-in.
- Payment: nothing during early access. No card on file.
Your visitors, wherever they are
- We process visitor data as your processor under UK and EU GDPR, and handle it to the same standard for visitors in the US, Canada or anywhere else.
- Guidance for your own privacy notice is in our Privacy Policy.
Found something?
- Report security issues to ivo@savemybudget.io. We read every report, acknowledge within two working days, and won't take action against good-faith research. Machine-readable details: /.well-known/security.txt
We'll add certifications here when we have them, not before. Last updated 14 September 2026.