Privacy Policy

Email 2 Budget for YNAB  ·  Last updated: March 22, 2026

Email 2 Budget for YNAB ("we", "our", or "the Service") is a third-party tool that connects your bank transaction notification emails to your YNAB plan. We take privacy seriously. This policy explains exactly what data we touch, what we store, and the security controls that protect it. It also describes our relationship with the YNAB API and our commitment to never using AI on your financial data without your explicit consent.

1. Data We Collect

We collect only the minimum information required to operate the Service:

  • YNAB account identity — your YNAB user ID, obtained via YNAB OAuth, solely to identify your account within our system.
  • YNAB OAuth tokens — an access token and refresh token issued by YNAB when you sign in. These are used exclusively to post transactions on your behalf via the official YNAB API.
  • Account mapping configuration — the mapping rules you create (e.g., "bank account ending in 4521 → YNAB account X in plan Y") so the Service can route each transaction correctly.
What we do NOT collect or store:
  • Email body content, subject lines, or attachments — emails are processed in memory and immediately deleted.
  • Transaction amounts, merchant names, dates, or any financial details from those emails.
  • Bank account numbers or card numbers beyond what you explicitly type into the mapping configuration.
  • Any YNAB plan data beyond what is needed to confirm a successful transaction post.

2. Zero-Retention Email Processing

The core principle of this Service is process and discard. When a forwarded bank email arrives:

  1. The transaction details (amount, currency, merchant, account identifier) are extracted from the email in memory.
  2. Those details are posted directly to YNAB via the API.
  3. The email is immediately and permanently deleted. It is never written to any database, file system, or log.

We are a conduit, not a vault. At no point in time does a copy of your email content exist anywhere in our persistent storage.

3. AI Usage — Strictly Opt-In

We offer two modes for setting up email parsing:

  • Manual Setup (default, privacy-first): A member of our team works with you to configure extraction rules for your bank's email format. Your email content is never sent to any AI model.
  • AI-Assisted Setup (opt-in only): If you explicitly choose this option during onboarding, a small number of your initial bank emails are processed by Azure OpenAI Service (our AI model), hosted on our own Microsoft Azure infrastructure, to learn the extraction pattern. After the rules are established the AI is no longer involved, and all subsequent emails are parsed deterministically.
Important: AI processing of your emails will never happen unless you explicitly opt in during setup. You may change this preference at any time from the Settings page.

AI provider data handling: When AI-Assisted Setup is used, email content is sent to Azure OpenAI Service (our AI model), which is hosted within our own Microsoft Azure tenant. The following safeguards apply:

  • No data retention by the AI provider: Emails sent to Azure OpenAI Service are processed in real-time and are not stored by Microsoft. Prompts and completions are not retained after the API response is returned.
  • No model training: Per Microsoft's Azure OpenAI data privacy policy, customer data submitted to Azure OpenAI Service is not used to train, retrain, or improve Azure OpenAI foundation models.
  • No third-party access: Data sent to Azure OpenAI Service does not leave our Azure tenant and is not shared with OpenAI or any other third party.

4. How We Protect Your Data

We apply multiple layers of security to protect the limited data we do store:

  • Encryption at rest (RSA-OAEP256): Your YNAB OAuth tokens are encrypted before being stored in our database, using RSA-OAEP256 asymmetric encryption. The private key never leaves Azure Key Vault, a hardware-backed secrets management service used by financial institutions worldwide.
  • Encryption in transit (TLS): All communication between your browser, our servers, YNAB, and Google uses TLS. No data is ever transmitted in plaintext.
  • Isolated cloud infrastructure: The Service runs on Microsoft Azure. Processing happens inside Azure Functions with no persistent disk access. Our database (Azure Cosmos DB) is accessible only from within our private service boundary.
  • Principle of least privilege: Each component of the system only has access to exactly the secrets it needs, enforced through Azure Managed Identity and Key Vault access policies.
  • No shared credentials: Your YNAB tokens are stored and encrypted per-user. No single key can decrypt multiple users' tokens.

5. YNAB Integration & API Compliance

This Service integrates with the YNAB API as a registered third-party OAuth application. Our use of the YNAB API complies with YNAB's Terms of Service and OAuth requirements:

  • OAuth 2.0 authorization flow: You grant us access to your YNAB account through YNAB's own secure OAuth consent screen. We never ask for or store your YNAB username or password.
  • Scoped access: We only request the permissions needed to create transactions in the specific plans and accounts you configure.
  • Token refresh: We automatically refresh your YNAB access token when it expires so the Service continues to work without interruption. Tokens are refreshed securely server-side and stored encrypted.
  • No data resale: We do not sell, share, or otherwise transfer any YNAB data (or any other user data) to third parties.
  • Revocation: You can revoke our access to your YNAB account at any time from within YNAB's authorized applications settings. You can also delete your account from our Settings page, which permanently removes all your data from our system.

This application is an independent third-party tool and is not affiliated with, endorsed by, or sponsored by YNAB (You Need A Budget).

6. Email Forwarding

You forward bank notification emails to our service address from your email provider. We do not access your email account directly. We do not read, index, or store any emails beyond the bank notification emails that are forwarded to our service address, and even those are immediately deleted after processing as described in Section 2.

7. Data Retention & Deletion

  • Email content: Never retained. Deleted immediately upon processing.
  • Transaction data: Never stored. Posted directly to YNAB and discarded.
  • Account data (identity, tokens, mappings): Retained for as long as you have an active account. You can request full deletion at any time from the Settings page or by contacting us.
  • Logs: Application logs are retained for up to 30 days for error diagnostics. Logs do not contain email content or transaction details.

8. Your Rights

You have the right to:

  • Access the data we hold about you.
  • Correct inaccurate data.
  • Request complete deletion of your account and all associated data.
  • Withdraw your consent to AI-assisted parsing at any time (Settings page).
  • Revoke our YNAB API access at any time (via YNAB's app settings).

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, the "Last updated" date at the top of this page will change. If changes are material, we will notify active users by email. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.

10. Contact

For privacy-related questions, data deletion requests, or concerns about this policy, please contact us at import+support@email2budget.com.