Security & Privacy

Your trust is table stakes.
Bank-level protections
- Open Banking (PSD2 compliant). We use FCA-regulated aggregator GoCardless for read-only access; we never see or store your credentials.
- Encryption. All data in transit and at rest uses 256-bit AES with rotating keys.
- Zero-knowledge architecture. Transaction texts are anonymised before AI processing; human staff cannot trace purchases back to individuals.
Data usage & control
- You own your data. Export or delete everything—instantly—from Settings → Data Control.
- No ads. Subscription revenue keeps us ad-free; we never sell data.
- Transparent AI. Models are trained only on anonymised spend labels and emotion tags you provide. No external profiling.