Legal

Information Security Policy

Version 1.0  ·  Effective date: May 15, 2026  ·  Last reviewed: May 15, 2026
Owner: Antwone Johnson  ·  Reviewed annually or upon material change

This policy applies to all systems, infrastructure, and data associated with Budget Silos, operated by Antwone Johnson ("we," "us," or "our"). It governs how we protect user data and maintain the security of the Service.

1. Purpose and Scope

This Information Security Policy establishes the security controls, practices, and responsibilities that govern the Budget Silos mobile application and its supporting infrastructure. It covers all data processed or stored by Budget Silos, including user account data, financial transaction data, and authentication credentials.

2. Access Control Policy

Access to systems and data is granted on a least-privilege basis. The following controls are in place:

3. Authentication and Token Security

Budget Silos uses industry-standard token-based authentication throughout:

4. Zero Trust Architecture

Budget Silos follows a zero trust model: no request is trusted implicitly, regardless of origin.

5. Data Protection and Encryption

6. Data Retention and Deletion Policy

Budget Silos retains user data only for as long as the user's account remains active.

Data type Retention period Deletion method
User account Until account deletion Automated via Supabase Auth admin API
Transaction data Until account deletion Cascade delete on account removal
Plaid access tokens Until bank disconnected or account deleted Removed from database on disconnect or account deletion
Authentication logs Managed by Supabase (30 days) Automatic

Users may delete their account and all associated data at any time from within the app (Settings → Delete Account). Deletion is immediate and permanent.

7. Vulnerability Management and Patching

8. End-of-Life (EOL) Software Policy

Budget Silos monitors the lifecycle status of all runtime and framework dependencies:

9. Periodic Access Reviews and Audits

10. Identity and Access Management (IAM)

Supabase Auth serves as the centralized identity provider for all Budget Silos users:

11. De-provisioning Policy

User access is revoked immediately upon account deletion. The deletion flow:

As a single-operator company, there are no employees to de-provision. If contractors or collaborators are added in the future, their access will be revoked within 24 hours of termination of the working relationship.

12. Incident Response

In the event of a suspected security incident:

13. Policy Changes

This policy is reviewed annually and updated as the Service evolves. Material changes will be reflected in the version number and effective date above. Questions about this policy may be directed to support@budgetsilios.com.