SubCut
FeaturesComparePricingAboutContact
Find my money leaks

Privacy policy

Your data, your control.

This policy explains what SubCut collects, why we collect it, and the control you have over it.

Last updated: 21 August 2026

What we collect

For an account, we store Supabase Auth identity data, normalized transaction fields, encrypted provider tokens, connection/consent metadata, derived commitments and findings, spending categories, sync results and recovery records. We do not store bank passwords or full provider response payloads.

The Waitlist stores the first name and normalized email you submit. Security controls may store short-lived rate-limit identifiers, including IP-derived identifiers for anonymous requests. We do not run third-party advertising analytics.

How we use and retain it

We use account data to authenticate you, identify recurring payments and spending patterns, provide cancellation guidance, verify recoveries and secure the service. We do not sell data or share it for third-party advertising.

Normalized financial data remains until its bank connection or account is deleted. The daily sync process removes rate-limit rows after 48 hours and sync-run records after 90 days.

Open banking and security

Bank data is retrieved through our open banking provider, which handles bank authorisation on our behalf. You can withdraw that consent at any time by disconnecting the bank from your dashboard. SubCut is not FCA authorised.

Access is read-only: SubCut cannot move money or initiate payments. Tokens are encrypted by SubCut before database storage and are never sent to the browser. Database access is tenant-scoped and financial writes are server-only.

Processors

Supabase provides authentication and database services; Vercel hosts the web application; our open banking provider handles bank authorisation and data retrieval; and Anthropic provides the AI processing described below. Processor sharing is limited to operating SubCut.

Optional AI processing

When enabled, categorisation sends a bounded normalized merchant and at most three redacted descriptions. An explanation sends bounded structured finding data. A cancellation draft sends a bounded service name and any bounded context you enter. Email addresses, URLs, sort codes and long number patterns are masked.

AI categorisation can influence summaries and findings; deterministic rules remain the fallback. Explanations and cancellation drafts run only after the relevant user action and are disclosed in the UI.

Access, correction and deletion

The dashboard can export the account dataset as JSON and normalized transactions as CSV. Encrypted credentials are excluded. A formal request can also cover processor records that are not present in the self-service file.

Account deletion requires a sign-in from the last ten minutes and literal confirmation. It removes matching Waitlist and authenticated rate-limit records, then the Auth identity and cascading application data. It reports success only after deletion completes. Disconnecting a bank removes that source and rebuilds findings from connections left.

UK GDPR rights may include access, correction, erasure, restriction, objection and portability. Contact hello@subcut.co.uk. We respond to formal requests within one calendar month unless the law permits an extension.

← Back to homepage
SubCut

SubCut watches your recurring spending, finds money you're losing, helps you act on it and verifies the saving.

HomeFeaturesComparePricingAboutContactPrivacyTermsSecurity

© 2026 SubCut. Read-only bank access. Never sold, never shared.