Privacy Policy

Surplus reads your bank data to work out what’s safe to spend. This policy sets out exactly what we collect, why we collect it, who we share it with and what you can ask us to do about it. The short version: your financial data is yours, we never sell it and we never use it for advertising.

1. Who we are

Surplusapp Ltd (“Surplus”, “we”, “us”) is the data controller for the personal data described in this policy. We are a private limited company registered in England and Wales under company number 16584501.

  • Registered office: 113 Estcourt Road, Watford, England, WD17 2PY
  • ICO registration number: ZC065000
  • Data protection lead: Shiv Patel
  • Contact: support@surplusapp.co.uk

2. The data we collect

We collect the following and nothing beyond it:

  • Account data - your email address, used to sign you in and manage your account.
  • Bank data - account names, masked account numbers, balances, transaction dates, amounts, descriptions and merchant details. This is retrieved read-only through Yapily from the accounts you choose to connect.
  • Information you add yourself - anything you enter in the app to improve your plan, such as payslip figures, goals and budget settings.
  • Support data - the messages you send us and our replies.
  • Device and technical data - IP address, device identifiers, app performance data and error logs. Personal details are scrubbed from error reports before they reach us.
  • Website data - if you join the beta waitlist, your email address and a record of the consent you gave. If you answer a beta tester survey, the answers you choose and anything you write in its optional note, stored against the random code in your survey link rather than your name.

We do not collect special category data - we do not ask about your health, religion, politics, ethnicity or sexuality and we do not try to infer them from your spending. We do not access your contacts, your photos or your location. We do not buy personal data from anyone.

3. How we use your data and our lawful basis

Under UK GDPR we need a lawful basis for everything we do with your data. This is ours, purpose by purpose.

What we do Data used Lawful basis
Run the app - show your balances, categorise transactions, work out safe-to-spend, budgets and goals Account data, bank data, information you add Performance of our contract with you
Connect to your bank and refresh your accounts Bank data Your consent, given through Yapily when you connect an account
Send service messages, such as telling you a bank connection is about to expire Account data Performance of our contract with you
Keep the service secure, stable and free of abuse - error logging, diagnostics, fraud prevention Device and technical data Our legitimate interests in running a secure, reliable service
Answer your support messages Support data, account data Performance of our contract and our legitimate interests in supporting our users
Send beta and early-access emails Website data Your consent
Understand what beta testers need, from the survey answers you choose to send Website data Our legitimate interests in improving Surplus before launch
Meet our legal and regulatory obligations Any of the above, where we are required to Compliance with a legal obligation

Where we rely on consent you can withdraw it at any time - disconnect a bank in the app, or use the unsubscribe link in any marketing email. Withdrawing consent doesn’t affect anything we did with your data before you withdrew it.

4. Open banking and Yapily

Surplus is an agent of Yapily Connect LTD., an authorised payment institution regulated by the Financial Conduct Authority under the Payment Services Regulations 2017 (Firm Reference Number: 827001). Yapily provides you with regulated account information services through Surplus as its agent.

You can check Yapily Connect Ltd’s authorisation on the FCA Register under firm reference number 827001. What that arrangement means in practice:

  • Read-only. UK open banking separates two permissions: account information services, which read your accounts, and payment initiation services, which move money. Surplus connects for account information only. The connection carries no payment permission, so Surplus cannot move your money.
  • We never see your bank login. You authenticate directly with your bank in its own secure flow. Your PIN, password and biometrics are never shared with us and we never store them. We will never ask you for them.
  • Your consent lasts 90 days. UK open banking rules require you to reconfirm access every 90 days. We’ll prompt you in the app. If you don’t reconfirm, we stop fetching new data.
  • You can disconnect at any time. Unlinking an account in the app revokes access at your bank and deletes the financial data we hold for that connection.

Because Yapily provides the regulated service, Yapily’s own privacy notice and end user terms also apply to the bank connection.

5. AI and automated processing

Surplus uses AI in two places: categorising your transactions, and the assistant that answers your questions in the app. Here is exactly how your data is handled in each.

  • Categorising transactions sends the transaction description and amount to Google’s Gemini model through Vertex AI. Your name, email, account numbers and other identifiers are not sent with it.
  • The assistant is powered by OpenAI. To answer a question about your money it receives the financial information needed to answer it - figures drawn from your own accounts. It never receives your bank login, because we never hold one.
  • Your data is never used to train AI models. Neither provider is permitted to train their models on anything we send them. This is a condition of the terms we use, not a preference we have expressed.
  • No decisions with legal or similarly significant effects. Surplus does not credit-score you, does not assess you for products and does not approve or refuse you anything. There is no automated decision-making of the kind Article 22 of the UK GDPR covers. If that ever changes, we will update this policy first and explain the logic and consequences.
  • A human is available. If an AI output about your money looks wrong, contact us and a person will look at it.

AI output can still be wrong, incomplete or out of date. It is information to help you decide - never advice and never a recommendation to buy a particular financial product. See our terms and conditions for what that means.

6. Who we share your data with

We share data only with the service providers we need to run Surplus. Each is bound by a contract that limits them to acting on our instructions. We name the ones whose handling of your data you would actually want to know about, and describe the rest by what they do.

Recipient What they do Where Safeguard
Yapily Connect Ltd The regulated open banking connection to your bank UK / EEA UK adequacy
Google (Gemini via Vertex AI) Categorising transactions, from description and amount only United States SCCs with UK Addendum, UK Extension to the DPF
OpenAI Powering the in-app AI assistant United States SCCs with UK Addendum, UK Extension to the DPF
Cloud hosting and database Storing and processing your account and financial data EEA UK adequacy
Error monitoring Crash and error reports, with personal details scrubbed EEA UK adequacy
Product analytics Which features get used, so we can improve them EEA UK adequacy
Website hosting Serving this website and its cookieless analytics United States SCCs with UK Addendum
Email and productivity Our email, including support conversations United States SCCs with UK Addendum, UK Extension to the DPF
Apple App distribution, the TestFlight beta and any future payments United States SCCs with UK Addendum

We keep a current list of every named sub-processor behind those categories. If you’d like it, email support@surplusapp.co.uk and we’ll send it to you.

We never sell your personal data. We never share your financial data with advertisers, data brokers or credit reference agencies and we never use your transaction data for third-party advertising.

We may also disclose data where the law requires it - to regulators, law enforcement or a court - and to our professional advisers. If Surplus is ever sold or merged, your data may transfer to the buyer, who would be bound by this policy until they tell you otherwise.

7. Where your data is stored and international transfers

Your account and financial data is stored in the European Economic Area - specifically Frankfurt, Germany. Our backend hosting, error monitoring and product analytics are all in the EEA too. Transfers from the UK to the EEA are covered by the UK’s adequacy regulations.

Some processing does happen outside the EEA. Our AI providers work in the United States - transaction descriptions and amounts at Google, assistant conversations at OpenAI - as do our email, this website’s hosting and the App Store. Those transfers are covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it.

Several of our EEA-hosted providers are US companies. Where their staff can access data held in the EEA in order to support the service, the same Standard Contractual Clauses and UK Addendum apply. You can ask us for details of the safeguards covering any particular transfer.

8. How long we keep your data

  • While your account is open - we keep your data so that the app works.
  • If you disconnect a bank - the financial data for that connection is deleted.
  • If you delete your account - your data is removed from our live systems immediately and from our backups within 30 days.
  • If your account is inactive for 2 years - we delete the account and the data in it.
  • Support messages - kept for up to 2 years so we can resolve disputes and see the history of an issue.
  • Error logs - kept for 30 days.
  • Beta waitlist emails - kept until the beta closes or you unsubscribe, whichever comes first.
  • Beta survey answers - kept for up to 2 years so we can see how the product changed, then deleted.

Where the law requires us to keep something for longer - tax records, for example - we keep only what the law requires and only for as long as it requires.

9. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you and get a copy of it.
  • Correct anything inaccurate or incomplete.
  • Erase your data - you can delete your account and everything in it from the app settings at any time.
  • Withdraw consent to bank access, by disconnecting the account.
  • Port your data - we’ll provide it in a machine-readable format such as CSV or JSON.
  • Restrict or object to processing we carry out under legitimate interests, including any direct marketing.

To exercise any of these, email support@surplusapp.co.uk or use the delete-account feature in the app. We’ll respond within one month. We may need to verify your identity first. We won’t charge you unless a request is clearly unfounded or excessive.

If you’re unhappy with how we’ve handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.

10. How we protect your data

  • Encrypted at rest - your data is encrypted in our database using AES-256.
  • Encrypted in transit - everything travels over TLS 1.2 or better.
  • Encrypted on your phone - the local database is encrypted with AES-256 and the key is held in the iOS Keychain, reachable only when your device is unlocked.
  • Separated by user - row-level security in the database means no other user can reach your data.
  • No bank credentials, anywhere - your bank login is handled by your bank. It never touches our systems.
  • Consent tokens are vaulted - the token that permits access to your accounts is held in an encrypted vault on the backend, never in the app and never in an ordinary database table.

No system is completely secure and we won’t pretend otherwise. If a breach ever affects your personal data and poses a risk to you, we will tell you and the ICO as the law requires.

11. Cookies and analytics

This website uses no advertising cookies, no cross-site tracking and no third-party ad networks. Our analytics are cookieless: we see aggregate page views and performance, not individuals. Because we set no non-essential cookies, there is no consent banner to click through.

12. Children

Surplus is for adults. You must be 18 or over to use it, which is also a condition of UK open banking access. We do not knowingly collect data about anyone under 18. If we find that we have, we delete it.

13. Marketing

We only send marketing emails if you’ve asked for them - for example by joining the beta waitlist. Every one has an unsubscribe link and we act on it straight away. Service messages about your account, such as a bank connection expiring, aren’t marketing and will continue while your account is open.

14. Changes to this policy

We update this policy when what we do with data changes. If a change is material, we’ll tell you by email or in the app before it takes effect rather than quietly editing the page.

Contact us

Questions about this policy, or about what we hold on you? Email support@surplusapp.co.uk and it will reach Shiv Patel directly.