Privacy Policy
Draft. This policy is being finalised before public launch and may change before it takes effect.
The short version.
- You tell us about your household's finances; we store that so the app can work, in the UK, and use it for nothing else.
- No advertising, no analytics, no trackers, no selling or sharing your data.
- Only strictly necessary cookies — the one you will normally have just keeps you signed in.
- You can download everything, or delete your account, yourself, from Settings.
- Deleted accounts leave the live database at once. Copies inside our backups age out on a fixed rolling window, and we tell you exactly how long that is.
1. Who we are
Oxygene Finance is run by Oxygene Group Ltd, a UK company. For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018) we are the data controller for the personal data described here, and we are registered with the Information Commissioner's Office (registration number [to be added]).
Contact: daniel@oxygene.xyz.
2. What we hold
Your account
- Your username, display name and email address, and whether you have confirmed the email.
- Your password — stored only as a one-way hash (bcrypt). We cannot read it, and neither can anyone who obtains the database.
- When the account was created and last signed in, and short-lived counters used to lock out password-guessing.
- If you use the mobile app: a name for each signed-in device (for example "Dan's iPhone") and when it was last used, so you can see and sign out devices from Settings.
Your household's finances — the part you enter
Everything in Oxygene Finance is information you type in or import yourself. Depending on which features you use, that can include:
- the people in your household (names, relationships and, if you add them, dates of birth);
- accounts, balances and their history; investment holdings; pensions; savings; debts;
- property you own, including its address or postcode, purchase price and mortgage;
- income, budgets, goals, notes in your journal, and any company you own;
- bank or card statement files you choose to import for spending analysis — the individual transactions are stored so the analysis and related features can use them.
We do not ask for, and you should not enter, bank account numbers, card numbers, passwords for other services, or National Insurance numbers. Nothing in the service needs them.
Technical information
- Our servers keep standard logs of requests: IP address, time, the address requested and the response. These are used to keep the service secure and to find faults.
- A record of significant account events — for example "password changed", "email confirmed", "device signed out" — so we can investigate problems and you can trust what happened to your account.
Payments
If you buy premium, the payment is taken by a specialist payment provider. We receive confirmation of the payment, the plan and its dates — never your full card number.
3. What we do not do
- We do not connect to your bank, pension provider or broker ("open banking") — nothing is pulled in without you putting it there.
- We do not use advertising, analytics or tracking services of any kind, on the website or in the app. There are no third-party scripts on our pages.
- We do not sell, rent or share your data with anyone for their own purposes.
- We do not use your financial data to market other products to you.
- We do not look at your data except where we need to — to fix a problem you have reported, to restore from a backup, or where the law requires it.
4. Why we use it, and our legal basis
| What for | Legal basis (UK GDPR Art. 6) |
|---|---|
| Running your account and the service you asked for — storing your figures, calculating with them, showing them back to you, sending account emails (confirm your address, reset your password). | Contract — we cannot provide the service without it. |
| Keeping the service secure: logs, rate limits, locking out password guessing, detecting stolen sign-in tokens, backups. | Legitimate interests — protecting you, other users and the service. |
| Taking payment for premium, and keeping the records the law requires. | Contract, and legal obligation (tax and accounting records). |
We do not rely on consent for any of the above, which means there is nothing hidden behind a consent box: this list is everything, apart from the one opt-in described in section 4a.
Financial information is not one of the "special categories" of personal data under the UK GDPR, but we treat it with the same care, because it is some of the most sensitive information a household has.
4a. Premium plans and launch news — only if you ask
Some parts of Oxygene Finance are premium. Where one of them appears on the website, you can tick "Email me about premium plans and launch news" and register your interest. This is the only marketing we do, and it applies only to people who tick that box. The box is never ticked for you, and the app on your phone never asks.
- What we keep: the fact that you opted in and the date and time you did, alongside the email address already on your account. We also note that you registered interest, so we know which features people are waiting for.
- What you get: occasional emails about premium plans — when they launch, what they include and cost — and major launch news. Nothing from anyone else, and nothing based on your financial figures.
- Legal basis: your consent (UK GDPR Art. 6(1)(a)).
- Withdrawing: any time, in Settings → Your plan, by switching off "Premium plans and launch news" — or by replying to any of these emails. Withdrawing is as easy as opting in, stops the emails, and changes nothing else about your account.
- Who sees the list: only us, to send those emails. It is never shared or sold.
5. Cookies and browser storage
Oxygene Finance sets only strictly necessary cookies — one in normal use, and a second only for the few moments of a Google or Apple sign-in:
| Name | What it does | How long |
|---|---|---|
fp_jwt |
Keeps you signed in. It is marked HttpOnly (page scripts cannot read it) and SameSite=Strict (other websites cannot use it). | 8 hours, or until you sign out |
fp_oidc |
Only while you are signing in with Google or Apple: a one-time check that the reply really answers the request you started. | Up to 10 minutes, deleted once sign-in completes |
The web app also remembers a few preferences in your own browser's storage — your colour theme, whether "hide values" is on, and your name for the sidebar. These never leave your device.
There are no analytics or advertising cookies, which is why we do not show you a cookie banner: there is nothing to opt out of. If that ever changes, we will ask first.
6. Signing in with Google or Apple
If you choose "Sign in with Google" or "Sign in with Apple", the provider confirms your identity and tells us:
- a unique identifier for you at that provider (it means nothing outside our link to them);
- your email address — with Apple, this can be a private relay address if you chose "Hide My Email";
- your name, if the provider shares it, which we use as your display name. You can change it in the app.
We do not receive your Google or Apple password, contacts, or anything else from your account with them. We do not tell Google or Apple anything about your finances. Their handling of the sign-in itself is covered by their own privacy policies.
7. Who else handles it
We use a small number of service providers ("processors") who act only on our instructions:
- Microsoft Azure — hosts the service and its database, and stores our backups, in the Azure UK South region.
- Azure Communication Services (Microsoft) — delivers the emails we send you (confirming your address, resetting your password). It receives your email address and the message. Link-tracking is switched off, so the links in our emails go straight to us.
- Our payment provider, once premium is on sale — see section 2.
To fill in prices and estimates, our servers also look things up from public data sources. These lookups are made by our server, not your device, and carry only what is needed for the lookup — never your name, email or balances:
- investment prices and exchange rates — the instrument's ticker or ISIN is sent to market data services (Yahoo Finance, the Financial Times markets data site, CoinGecko for crypto, OpenFIGI for identifier lookups, and Finnhub where configured);
- property estimates — the postcode of a property you ask us to value is sent to postcodes.io and HM Land Registry's open price-paid data.
We will list any new processor here before it starts handling your data.
8. Where it is kept, and how
- Your data is stored in the United Kingdom (Azure UK South), including backups.
- Everything between your device and us is encrypted in transit (HTTPS).
- Data at rest is on encrypted Azure storage.
- Passwords are hashed with bcrypt; email and password-reset links, and the mobile app's long-lived sign-in tokens, are stored only as one-way hashes.
- Every record belongs to one account, and every request is checked against the signed-in account, so one household can never read or change another's data. This is covered by automated tests that run before every release.
9. How long we keep it
While your account is open, we keep what you have entered, because keeping it is the service.
When you close your account, your sign-in and everything it holds — accounts, valuations, holdings, transactions, budget, journal, scenarios, family members, linked Google or Apple sign-ins and device sessions — are deleted from the live database immediately.
Backups. We take a backup of the database every night and keep a fixed number of the most recent ones; each night, the oldest backup beyond that window is deleted automatically. Copies of your data remain inside existing database backups until those age out. Backups cover the whole database, so individual records cannot be removed from a backup that already exists — the retention window is the erasure guarantee. The exact length of the window is shown in Settings, under "Close your account", and is read from the same setting the automatic deletion uses, so the number you see is the number that is enforced.
What remains after deletion. The app keeps a change history for your account (what was edited, and what it was before). When you close the account, that history is deleted with everything else. Where an administrator took an action on your account (for example unlocking it), the administrator's record that they did so is kept, but everything in it that described you is erased. A single record that an account was closed, and when, is kept without your name, username or email address.
Unconfirmed sign-ups. An email address that is never confirmed cannot be used to sign in or reset a password. It stays on the account (shown in Settings as awaiting confirmation) until you confirm it, change it, or close the account.
10. Your rights
Under UK data protection law you have the right to:
- See your data — and take a complete copy yourself, at any time, from Settings → Take your data with you (a single JSON file).
- Correct it — everything you entered can be edited in the app.
- Delete it — close your account yourself from Settings → Close your account on the web, or the equivalent in the app. You will be asked to prove it is you — your password, or, if you signed up with Google or Apple and have no password, a fresh sign-in with that Google or Apple account — and to type a confirmation, so nobody can do it by accident or from a borrowed session.
- Take it elsewhere — the export is a standard, readable format.
- Object to or restrict how we use it, where the law gives you that right.
To exercise any right you cannot handle yourself in the app, email us. We will reply within one month, and we will not charge you.
11. Other people's details, and children
Oxygene Finance is for adults (18 and over) managing their household's finances. You may record details of other people in your household — a partner, children, a parent you care for — so the plans can include them. Please only record what you need for that, and bear in mind they have the same rights over their information as you do over yours.
12. Changes to this policy
If we change how we handle personal data in a way that matters, we will email you before the change takes effect. The date at the top shows when this policy last changed.
13. Contact and complaints
Questions, requests or complaints about your data: daniel@oxygene.xyz.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office: ico.org.uk/make-a-complaint, or 0303 123 1113. We would appreciate the chance to put things right first.