Privacy Policy
Last updated: 21 April, 2026
This Privacy Policy describes how Jack Ward ("we," "us," or "our") collects, uses, and shares your information when you use the Cuppi mobile application (the "App").
1. OUR PRIVACY PHILOSOPHY
We believe your data belongs to you. Our App is designed with a "Local-First" approach, meaning we aim to process as much data as possible on your device rather than on our servers.
2. WHAT DATA WE COLLECT A. Personal Data You Provide
- Account Information: When you register, we collect your email address and username.
- Subscription Data: Purchases are handled by the Apple App Store. We receive confirmation of your subscription status and an anonymous transaction ID to prevent fraud, but we do not see or store your credit card numbers or billing address.
- Authentication Data: If you enable 2-Step Verification, we process this via a standard authenticator app (TOTP). We do not collect or store your phone number for this purpose.
B. App Data (Cloud Sync)
To provide features like the Household Feed and multi-device syncing, the following data is encrypted in transit and synced to our secure servers located in the United Kingdom:
- Household names, unique Household IDs, and member lists.
- Budget entries, transaction titles, and household income/salary configurations.
- Receipt scans, itemised lists, and categorised spending.
- Pet profiles, including medication logs, vaccination history, microchip numbers, and veterinary health plan details.
- Shared notes or calendar entries created within the App.
C. Automated Assistant Data ("The Companion")
The "Companion" is an automated feature that aggregates your household data (like birthdays, bin days, and pet medications) to generate helpful reminders and monthly overviews. This relies on deterministic code, not generative AI. We do not use your household data to train any machine learning models.
D. Anonymous Usage Data (Analytics)
To help us improve Cuppi, we collect anonymous analytics regarding how you navigate the app (e.g., which screens you visit). This data contains no personally identifiable information. You can opt out of this tracking at any time via the Privacy section in your Security Centre.
3. HOW WE USE YOUR INFORMATION
We use your information solely to:
- Provide and maintain the Services.
- Synchronize your data across your logged-in devices.
- Generate automated household insights and notifications.
- Manage your account, verify subscription status, and provide customer support.
- Understand general app usage to improve the user experience (if opted-in, turned off by default).
We process your data based on:
- Contractual Necessity: To sync your data and manage your subscription.
- Legitimate Interests: To secure the app, prevent fraud, and improve the user experience.
- Consent: For anonymous analytics (Adult users only).
4. SHARING YOUR INFORMATION
We do not sell your data. We only share information in the following limited circumstances:
- Google (Firebase/Google Cloud): Data storage, cloud functions, and authentication. Data is stored on servers located in the United Kingdom.
- Apple Inc.: App Store processing, subscription management, and Apple Sign-In.
- Legal Requirements: If required by UK law or to protect our legal rights.
5. DATA STORAGE AND SECURITY
- Location: Your synced data is stored on secure servers located in the United Kingdom.
- Encryption: We use industry-standard encryption (SSL/TLS) to protect data during transfer. Furthermore, highly sensitive local caches on your device (such as cached images and pet data) utilize iOS system-level File Protection, meaning they are encrypted at rest when your device is locked.
- Retention: We keep your account data as long as your account is active. If you delete your account, your profile and associated household data are securely deleted from our active servers.
6. YOUR RIGHTS (UK GDPR)
As a UK resident, you have the right under data protection laws to:
- Access: Request a copy of the data we hold about you.
- Correction: Ask us to fix inaccurate or incomplete information.
- Deletion ("Right to be Forgotten"): Request that we delete your account and associated cloud data (which can be initiated directly within the App's Profile settings).
- Restriction/Objection: Object to our processing of your personal data or ask us to restrict it.
- Portability: Request a transfer of your data to yourself or a third party.
To exercise any of these rights, please contact us at support@cuppi.co.uk. We aim to respond to all legitimate requests within one month.
8. DATA CONTROLLER & CONTACT US
For the purposes of UK data protection law, Jack Ward is the "Data Controller" responsible for your personal data.
If you have questions about this policy or our privacy practices, please contact:
- Name: Jack Ward
- Email: support@cuppi.co.uk
- Location: United Kingdom
- ICO Registration Number: ZC129317
9. YOUR RIGHT TO COMPLAIN
We take your privacy seriously and would appreciate the chance to deal with your concerns directly. However, if you feel we have not resolved your issue, you have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.
Information Commissioner's Office Wycliffe House, Water Lane Wilmslow, Cheshire, SK9 5AF Helpline number: 0303 123 1113 Website: www.ico.org.uk
