Privacy Policy
Before public launch. This policy describes the service as it works today. We may still change it before public launch, and if we do we will tell you.
The short version.
- You tell us about your household's finances; we store that so the app can work, in the UK, and use it for nothing else.
- No advertising, no third-party analytics, no selling your data. We count how the service is used — which pages are opened, whether setup gets finished — on our own servers, never with your figures, and you can switch that off in Settings.
- The phone app checks our update service (Expo) for fixes, which sees a random install number and your IP address — nothing about your finances.
- Only strictly necessary cookies — the one you will normally have just keeps you signed in.
- If you share your household with someone — a partner, someone in the family, an adviser or an accountant — they see the sections you choose, and a copy of those is kept on their phone if they use the app. Your journal stays private unless you choose to share it. You decide who, you can see when they last looked, and you can end it.
- Some things you may choose to record — a disability or illness benefit, for example — say something about health. We store them only after you have given your explicit consent, and withdrawing it deletes them.
- You can download what you have entered, a complete copy of everything we hold about you, or delete your account, yourself, from Settings.
- Server logs are kept for thirty days. An account nobody signs in to for two years is closed three months after we email a warning.
- Deleted accounts leave the live database at once. Copies inside our backups age out on a fixed rolling window, and we tell you exactly how long that is.
1. Who we are
Oxygene Finance is run by Oxygene Group Ltd. For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018) we are the data controller for the personal data described here. We are registered with the Information Commissioner's Office, registration number ZB933043.
Oxygene Finance is a service of Oxygene Group Ltd, a company registered in England and Wales (company number 15954292). Registered office: A4g Suite Nepicar House, London Road, Wrotham Heath, Kent, TN15 7RS, United Kingdom.
Contact: privacy@oxygene.xyz. For anything else, see Support.
2. What we hold
Your account
- Your display name and email address (and, for older accounts, a username), and whether you have confirmed the email.
- Your password — stored only as a one-way hash (bcrypt). We cannot read it, and neither can anyone who obtains the database. If you sign in with Apple, Google or Microsoft, there may be no password at all.
- When the account was created and last signed in, and short-lived counters used to lock out password-guessing.
- Which version of our Terms of Service and this policy you accepted, and when.
- Your plan (free or premium), and a record of changes to it — when a trial or premium access started and ended.
- If you use the mobile app: a name for each signed-in device (for example "Sam's iPhone") and when it was last used, so you can see and sign out devices from Settings.
Your household's finances — the part you enter
Everything in Oxygene Finance is information you type in or import yourself. Depending on which features you use, that can include:
- the people in your household (names, relationships and, if you add them, dates of birth);
- accounts, balances and their history; investment holdings; pensions; savings; debts;
- property you own, including its address or postcode, purchase price and mortgage;
- income, budgets, goals, notes in your journal, and any company you own;
- state benefits you record for someone in your household — see section 8, because some say something about health;
- which actions you tick off in a life-event guide, such as the guides for a bereavement, a serious illness or a new child;
- bank or card statement files you choose to import for spending analysis — the individual transactions are stored so the analysis and related features can use them.
We do not ask for, and you do not need to enter, bank account numbers, card numbers, passwords for other services, or National Insurance numbers. Nothing in the service needs them.
Technical information
- Our servers keep standard logs of requests: IP address, time, the page or address requested (without anything after a "?") and the response. These are used to keep the service secure and to find faults. Before a line is written, email addresses, sign-in tokens and anything that looks like an amount of money are removed from it. Logs are deleted after thirty days.
- A record of significant account events — for example "password changed", "email confirmed", "device signed out" — so we can investigate problems and you can trust what happened to your account.
- Diagnostic error reports. When the app or the website hits an error, it sends us a short report so we can fix it: the error message and where in the code it happened, the page or screen, the app version and build, the type of device (web, iPhone or Android), and your account number if you were signed in. Before a report leaves your device, and again when we receive it, we remove email addresses, sign-in tokens, web addresses' query details and anything that looks like an amount of money, so a report never contains your financial figures. We do not use a third-party crash service. Reports are deleted after thirty days.
- Feedback you send. When you use "Send feedback" or "Report this problem", we keep your message, the category you chose, and the details the form says it attaches: the app version, the page you were on, any error reference and your browser or device type. Never your figures. We use it to answer you and to fix what you found.
Usage statistics
To see which parts of Oxygene Finance people use and where they get stuck, the website and the app tell us when certain things happen, and we count them. We collect this ourselves, on our own servers; no analytics company is involved.
- What we record: the name of the event — for example "signed in", "opened the Accounts page", "finished a setup step", "opened a Premium page", "the app's sign-in ended unexpectedly" — with a few fixed words about it, such as the page's name, how you signed in (email, Apple, Google or Microsoft) or which setup step it was. Also the time, whether it came from the website, an iPhone or an Android phone, the app version, and your account number if you were signed in.
- What we never record: any figure — no amounts, balances or values — and no account names, notes or anything else you type. We do not record your email address or your IP address with these events. Everything a device sends is checked against a fixed list of events and words, and anything else is thrown away, including anything that looks like an amount of money.
- What we use it for: totals and trends — how many people finish setting up, how many come back after a week, which Premium features people look at, whether the app or the website is used more — to decide what to improve. Not for marketing, and never shared. The people who run the service see only totals across households, together with counts of the kinds of accounts and households in use (never amounts or names), and any total under five is hidden so that no household can be picked out.
- Switching it off: Settings → Usage statistics, on the website or in the app. Off stops it for your account on every device, and deletes what we hold for you. Your browser or phone then remembers not to send anything, even before you sign in.
- How long: thirteen months, then deleted. When you close your account your events are deleted at once; we keep a single count that an account was closed, how long it had been open and whether it had been set up, with no account number on it.
Payments
Premium is not on sale yet. If you buy premium in future, the payment will be taken by a specialist payment provider. We will receive confirmation of the payment, the plan and its dates — never your full card number.
3. What we do not do
- We do not connect to your bank, pension provider or broker ("open banking") — nothing is pulled in without you putting it there.
- We do not use advertising or third-party analytics services, on the website or in the app, and there are no third-party scripts on our pages. The usage statistics in section 2 are our own. The one third party the phone app talks to directly is our update service, described in section 9.
- We do not sell, rent or share your data with anyone for their own purposes. We do not enter data partnerships: we do not sell or license your data, or figures built from it, including "anonymised" or aggregated benchmarks, to anyone.
- We do not use your financial data to market other products to you.
- We do not look at your data except where we need to — to fix a problem you have reported, to restore from a backup, or where the law requires it. If you ask us to help you get back into your account, we can set a temporary password for it; that is recorded in your account's history.
4. Why we use it, and our legal basis
| What for | Legal basis (UK GDPR Art. 6) |
|---|---|
| Running your account and the service you asked for — storing your figures, calculating with them, showing them back to you, sharing them with the people you choose, sending account emails (confirm your address, reset your password, an invitation you asked us to send). | Contract — we cannot provide the service without it. |
| Keeping the service secure and working: logs, rate limits, locking out password guessing, detecting stolen sign-in tokens, error reports, backups, and checking for app updates. | Legitimate interests — protecting you, other users and the service, and fixing faults. |
| Answering feedback and support messages. | Legitimate interests — helping you, and improving the service. |
| Usage statistics (section 2): counting how the service is used, without figures, to improve it. | Legitimate interests — improving the service. You can object at any time with the switch in Settings, which stops it at once. |
| Recording which terms you accepted, and taking payment for premium once it is on sale, with the records the law requires. | Contract, and legal obligation (tax and accounting records). |
Apart from health information (section 8) and the one opt-in in section 4a, we do not rely on consent, which means there is nothing hidden behind a consent box.
Financial information is not a "special category" under the UK GDPR, but we treat it with the same care, because it is some of the most sensitive information a household has.
4a. Premium plans and launch news — only if you ask
Some parts of Oxygene Finance are premium. Where one of them appears on the website, you can tick "Email me about premium plans and launch news" and register your interest. This is the only marketing we do, and it applies only to people who tick that box. The box is never ticked for you, and the app on your phone never asks.
- What we keep: the fact that you opted in and the date and time you did, alongside the email address already on your account. We also note that you registered interest, so we know which features people are waiting for.
- What you get: occasional emails about premium plans — when they launch, what they include and cost — and major launch news. Nothing from anyone else, and nothing based on your financial figures.
- Legal basis: your consent (UK GDPR Art. 6(1)(a)).
- Withdrawing: any time, in Settings → Your plan, by switching off "Premium plans and launch news" — or by replying to any of these emails. Withdrawing is as easy as opting in, stops the emails, and changes nothing else about your account.
- Who sees the list: only us, to send those emails. It is never shared or sold.
The launch list on our website
Before sign-up opens to everyone, our website has a Register interest form for people without an account.
- What we keep: the email address you type, the wording of the box you ticked and when, which page the form was on, and when you confirmed. Nothing else: no name, no account and no network address.
- Confirming: we send one email with a button. Until it is pressed we send nothing else to that address, and if it is not pressed within seven days we delete the address.
- What you get: launch news and an invitation when sign-up opens.
- Legal basis: your consent (UK GDPR Art. 6(1)(a); PECR regulation 22).
- Leaving: every email has a link to leave the list. Leaving deletes your address straight away.
- How long: until you leave the list, or three months after sign-up opens to everyone, whichever comes first. Then we delete the whole list.
5. Cookies and browser storage
Oxygene Finance sets only strictly necessary cookies — one in normal use, and a second only for the few moments of an Apple, Google or Microsoft sign-in:
| Name | What it does | How long |
|---|---|---|
fp_jwt |
Keeps you signed in. It is marked HttpOnly (page scripts cannot read it) and SameSite=Strict (other websites cannot use it). | 8 hours, or until you sign out |
fp_oidc |
Only while you are signing in with Apple, Google or Microsoft: a one-time check that the reply really answers the request you started. | Up to 10 minutes, deleted once sign-in completes |
The web app also keeps some things in your own browser's storage on that device:
- your preferences — colour theme, whether "hide values" is on, your name for the sidebar, and notices you have dismissed;
- for a few planners — the company planner, paying yourself from your company, Safety Net, survivor planning and the budget's retirement settings — the figures you type into them.
We do not read these from your browser; they stay on that device. The planner figures are removed from the browser when you sign out, when your session ends, and when you close your account, so the next person to use a shared computer does not see them. Your preferences (theme, sidebar layout, and whether usage statistics are off) stay, because they hold nothing about your finances.
There are no analytics or advertising cookies. The usage statistics in
section 2 use no cookie and no identifier stored for them: the website
and the app send them straight to our own servers, a few at a time, with the sign-in you
already have. If you switch them off,
your browser keeps one note saying so (fp_analytics_off), so that it sends nothing
even before you sign in. The Data (Use and Access) Act 2025 allows statistics about how a
service is used to run unless you object, provided you are told clearly and can object easily —
which is why there is a switch in Settings rather than a banner.
6. Signing in with Apple, Google or Microsoft
If you choose "Sign in with Apple", "Sign in with Google" or "Sign in with Microsoft", the provider confirms your identity and tells us:
- a unique identifier for you at that provider (it means nothing outside our link to them);
- your email address — with Apple, this can be a private relay address if you chose "Hide My Email";
- your name, if the provider shares it, which we use as your display name. You can change it in the app;
- with Microsoft, an identifier for the organisation the account belongs to. A personal Microsoft account has a fixed one; a work or school account has your employer's or college's. We record it so we can tell which kind of account you signed in with.
If you sign in with a work or school Microsoft account, your organisation's administrators may
be able to see that you have signed in to Oxygene Finance, and you may lose access to it if you
leave. A personal account avoids both. We ask Microsoft only for your identity (the
openid, email and profile permissions): we never ask
for access to your organisation's directory, email or files, and we send your organisation
nothing. What it can see is the sign-in record its own systems keep. We store the
organisation's identifier with your sign-in, and nothing else about the organisation.
If you signed in with Apple, closing your account, or unlinking Apple in Settings, also asks Apple to revoke Oxygene Finance's access to your Apple ID, so the app no longer appears under "Sign in with Apple" in your Apple account settings.
We do not receive your password at any of these providers, your contacts, or anything else from your account with them. We do not tell them anything about your finances. Their handling of the sign-in itself is covered by their own privacy policies.
7. Sharing your household
Every plan includes one partner seat, and on premium you can invite more people, including a financial adviser or an accountant. Sharing is always your choice, and you control it:
- Who, and as what. You say who each person is to you: a partner, someone in the family or a friend, a financial adviser, or an accountant. They are view only: they cannot change anything, and they cannot download your data as a file.
- What they see. The sections you choose for them: Money & Property, Plans & Goals, Spending Analysis, Tax & Company, Family & Handover, and the Journal. Everyone you share with also sees the dashboard and the people you have recorded, with their names and dates of birth. Plans & Goals includes any benefits you have recorded, including disability and illness benefits; Family & Handover includes the steps you have ticked in the life-event guides. Your journal is private unless you tick it for someone. Each role starts with the sections it usually needs (an accountant, for example, Money & Property and Tax & Company), and you can change them before inviting and at any time after. Settings shows you the list before an invitation is sent.
- Advisers and accountants. A professional you share with decides for themselves what to do with what they see and what they record about you, under their own privacy notice and professional rules: for that, they are a separate controller, not us. We do not pick advisers for you or introduce you to them, and we are not paid by them. Access you give them is a view of your own records that you can end at any time; it is not their firm's record-keeping system, and we tell them so in the invitation.
- The invitation. We send an email to the address you give us, and keep that address with the invitation until it is used or cancelled, or until you close your account.
- On their phone. If they use the app, a copy of your household is kept on their phone so it works offline. When you remove their access it stops at once on our side, and their phone deletes its copy the next time it connects.
- A record of access. We note when someone you have shared with opens your household, once a day. Settings shows, beside each person, the date they last looked, and a list of who opened your household on which days over the last ninety days. These records are kept for thirteen months.
- Letting Oxygene support look. If you have asked us about your figures, you can let our support team see your household for 72 hours, from Settings. They see Money & Property, Plans & Goals, Tax & Company and Family & Handover, view only: not your journal and not your bank transactions. Each day they look is recorded in the same list, the access ends by itself after 72 hours, and you can end it sooner. We use what we see only to answer your question.
- Ending it. You can remove someone's access, and they can remove themselves, at any time, from Settings. Nobody is emailed either way. Leaving or being removed is free on every plan. Once someone has left, your record of access names them only by the name they had when they left, never by their email address, and not at all once they close their account.
- A legacy contact. You can name someone to tell us if you die: someone you share with, or an email address. We keep who you named, and show it to them when they sign in with that confirmed address; it lets them see nothing. They can only tell us, and later accept your household, signed in to their own account and confirming their password at the time; someone named by email address needs to create an account with that address first. If they tell us, we email you, a member of our team checks a death certificate and the right to act for your estate, and we wait twenty-one days from their request before your household passes to them. We keep a note of which kinds of document we saw and when, never copies.
- Handing over or dividing your household. You can hand your household to someone you share with, and it moves when they accept. If you separate, you can move a person recorded in your household, with the accounts in their name, to their own household. We do either on someone's request only with the agreement of both people, or a court order.
Only share with someone the people in your household would be comfortable seeing their details.
If you are recorded in someone else's household — as a partner, child or parent, without an account of your own — and want to be removed, ask the account holder to remove you: on the Family page, they open your entry and choose Remove, which deletes your name, date of birth and any benefits recorded for you. Accounts in your name must first be moved to someone else or deleted. If you would rather not ask them, or they will not, email privacy@oxygene.xyz. We will ask the account holder to remove you, and if they do not, we will remove your details ourselves where the law gives you that right. If you tell us you are worried about your safety, we will not tell the account holder who asked. We will tell you what we did within one month.
8. Health and disability information
Financial information is not a "special category" under the UK GDPR. Some things you may choose to record are: a disability or illness benefit (for example Personal Independence Payment, Attendance Allowance, Employment and Support Allowance or Carer's Allowance), or using the guide for not being able to work through illness, tells us something about someone's health. The same is true of a pregnancy, if you use the new-child guide.
- It is optional. Nothing in the service needs it. The rest of the app works without it.
- Our legal basis is your explicit consent (UK GDPR Art. 9(2)(a)). The first time you save any of it, the app shows what is stored, why, and how to take it back, and saves nothing until you agree. We keep a record of your consent: the words you were shown, their version, where you saw them and when. The answers you give to the illness guide's questions are used to work out the guide and are not stored.
- You can withdraw it at any time, in Settings → Health and disability information. Withdrawing deletes every disability or illness benefit and every ticked step in those guides straight away. You can also delete a single benefit, or untick a single step, and it is gone from the live database.
- If it is about someone else — a partner, child or parent you care for — please only record it if they would be comfortable with that, and bear in mind that anyone you share your household with will see it.
9. Who else handles it
We use a small number of service providers ("processors") who act only on our instructions:
- Microsoft Azure — hosts the service and its database, and stores our backups, in the Azure UK South region, with a second copy of the backups in UK West.
- Azure Communication Services (Microsoft) — delivers the emails we send you (confirming your address, resetting your password, invitations). It receives your email address and the message, and its data location is set to the United Kingdom. Once an email is handed to your own email provider, it is held wherever that provider keeps your mail. Link-tracking is switched off, so the links in our emails go straight to us.
- Expo (650 Industries, Inc., United States) — the phone app checks Expo's update service for fixes each time it opens. That request carries a random number that identifies this installation of the app, the app's version, and your IP address — never your name, email address or figures. The number is made when the app is first opened and stays the same each time it opens after that; it can move to a new phone with a backup of the old one, and it is gone when the app is deleted. Expo uses it only to deliver updates, not to track you or to advertise. Expo relies on the UK Extension to the EU-US Data Privacy Framework for this transfer.
- Apple, Google and Microsoft, only if you sign in with them — see section 6.
- A payment provider, once premium is on sale — see section 2.
To fill in prices and estimates, our servers also look things up from public data sources. These lookups are made by our server, not your device, and carry only what is needed for the lookup — never your name, email or balances:
- investment prices and exchange rates — the instrument's ticker or ISIN is sent to market data services (Yahoo Finance, the Financial Times markets data site, CoinGecko for crypto, OpenFIGI for identifier lookups, and Finnhub where configured);
- property estimates — the postcode of a property you ask us to value is sent to postcodes.io and HM Land Registry's open price-paid data.
We will list any new processor here before it starts handling your data.
10. Where it is kept, and how
- Your data is stored in the United Kingdom (Azure UK South), including backups, which also have a second copy in the United Kingdom (Azure UK West) in case a whole data centre region fails. If you use the app, a copy is also kept on your phone, and on the phone of anyone you share your household with.
- A few things happen outside the UK, and none of them involves your figures:
- if you sign in with Apple, Google or Microsoft, that sign-in happens with them, wherever they run it (see section 6);
- the phone app's update check goes to Expo in the United States (see section 9);
- our emails are sent from the UK by Azure Communication Services, and then held by your own email provider, wherever it keeps your mail.
- Everything between your device and us is encrypted in transit (HTTPS).
- Data at rest is on encrypted Azure storage: Azure encrypts the server's disks and the backup store by default.
- Backups are also encrypted before they leave our server, with a key the server itself does not hold, so a copy of a backup on its own cannot be read.
- Passwords are hashed with bcrypt; email and password-reset links, invitation codes and the mobile app's long-lived sign-in tokens are stored only as one-way hashes.
- Every record belongs to one account, and every request is checked against the signed-in account, so one household can never read or change another's data. This is covered by automated tests that run before every release.
11. How long we keep it
While your account is open, we keep what you have entered, because keeping it is the service.
| What | How long |
|---|---|
| Link to confirm your email address | Expires after twenty-four hours |
| Link to reset your password | Expires after thirty minutes |
| Signed-in device on the phone app | Ninety days without use, or until you sign it out |
| Diagnostic error reports | Deleted after thirty days |
| Usage statistics | Deleted after thirteen months, or at once when you switch them off or close your account |
| Launch list address, not confirmed | Deleted after seven days |
| Launch list address, confirmed | Until you leave the list, or three months after sign-up opens to everyone, whichever comes first |
| Feedback you sent | While your account is open; deleted when you close it |
| Server request logs | Deleted after thirty days |
| Household invitations (and the address they were sent to) | Deleted thirty days after they were used or expired, or when you cancel them |
| The record of when people you share with opened your household | Thirteen months |
| Health and disability information | Until you delete it or withdraw your consent |
| Your consents, the terms you accepted, your plan history and your account's history of changes | While your account is open; deleted when you close it |
| Backups of the database | A fixed rolling window, shown in Settings (see below) |
Accounts nobody uses. If nobody signs in to an account for two years — on the website or the phone app — we email the account's address to say it will be closed in three months. Signing in before then is all it takes to keep it. If nobody does, the account is closed exactly as if you had closed it yourself. We do not close an account we have not been able to warn.
When you close your account, your sign-in and everything it holds — accounts, valuations, holdings, transactions, budget, journal, scenarios, family members, benefits, feedback, linked Apple, Google or Microsoft sign-ins and device sessions — are deleted from the live database immediately.
Backups. We back up the database every hour, so that if something goes wrong we lose at most about an hour of what people have entered. Each backup is encrypted before it leaves our server, and is then stored in a way that stops it being changed or deleted until a fixed retention window has passed. At the end of the window it is deleted automatically. The storage service runs that deletion once a day, so a backup can outlast the window by up to two days. Copies of your data remain inside existing database backups until those age out. Backups cover the whole database, so individual records cannot be removed from a backup that already exists — the retention window is the erasure guarantee. The exact length of the window is shown in Settings, under "Close your account", and is read from the same setting the automatic deletion uses, so the number you see is the number that is enforced.
What remains after deletion. The app keeps a change history for your account (what was edited, and what it was before). When you close the account, that history is deleted with everything else. Where we took an action on your account (for example unlocking it), our record that we did so is kept, but everything in it that described you is erased. A single record that an account was closed, and when, is kept without your name, username or email address.
Unconfirmed sign-ups. An email address that is never confirmed cannot be used to sign in or reset a password. It stays on the account (shown in Settings as awaiting confirmation) until you confirm it, change it, or close the account.
The test service. If you are testing Oxygene Finance before public launch, the test service is wiped at the end of the testing cycle and nothing on it moves to the main site. The tester notice explains this.
12. Your rights
Under UK data protection law you have the right to:
- See your data — at any time, from Settings → Take your data with you: a copy of everything you have entered (a single JSON file you can import again), and everything we hold about you, as a readable summary and in full. That copy also covers your account, consents, the terms you accepted, your plan history, who can see your household and when they last looked, invitations, sign-in methods and devices, feedback, error reports and usage statistics, and says why we hold each and for how long. Server logs and copies inside backups are not in it; email us for those.
- Correct it — everything you entered can be edited in the app.
- Delete it — close your account yourself from Settings → Close your account on the web, or the equivalent in the app. You will be asked to prove it is you — your password, or, if you signed up with a provider and have no password, a fresh sign-in with that Apple, Google or Microsoft account — and to type a confirmation, so nobody can do it by accident or from a borrowed session.
- Take it elsewhere — the export is a standard, readable format.
- Object to or restrict how we use it, where the law gives you that right — for usage statistics, with the switch in Settings.
- Withdraw consent where we rely on it — for marketing emails and for health information, in Settings. Withdrawing consent for health information deletes it.
To exercise any right you cannot handle yourself in the app, email privacy@oxygene.xyz. We will reply within one month, and we will not charge you.
13. Other people's details, and children
Oxygene Finance is for adults (18 and over) managing their household's finances. You may record details of other people in your household — a partner, children, a parent you care for — so the plans can include them. Please only record what you need for that, and bear in mind they have the same rights over their information as you do over yours. If someone who is not a user asks us about data recorded about them, we will help them, and may need to contact the account holder — section 7 says how someone can be removed.
You may also record the people who look after your money — a solicitor, an accountant, a financial adviser, an executor — with their work phone number, email address, your reference with them and what they deal with, so that you, and anyone you share with or who takes over, can reach them. We hold these details for you, to show them back to you and in your handover pack; we do not contact these people or use their details for anything else. Please record only what you need for that.
14. Changes to this policy
If we change how we handle personal data in a way that matters, we will email you before the change takes effect, and the app will show a short notice asking you to accept the new version. The date at the top shows when this policy last changed.
15. Contact and complaints
Questions or requests about your data: privacy@oxygene.xyz.
To complain about how we handle your data, email privacy@oxygene.xyz and say it is a complaint. We will acknowledge it within thirty days, look into it, and tell you the outcome and what we have done. We keep a record of every complaint.
If you are still unhappy, you can complain to the Information Commissioner's Office: ico.org.uk/make-a-complaint, or 0303 123 1113. We would appreciate the chance to put things right first.