Privacy Policy
Last updated: 27 September 2026
Gibbon helps you understand your own money. We use read-only Open Banking access, keep most of your data on your device, encrypt sensitive tokens, never sell your data, and let you delete everything at any time.
1. Who we are
Gibbon ("we", "us", "the app") is a personal finance app for people in the United Kingdom, built and run by an independent developer based in the UK, who is the data controller. You can reach us at support@gibbon-app.download. This policy explains what we collect, why, and your rights under the UK GDPR and Data Protection Act 2018.
2. Data we collect
Account and identity
When you sign in with Apple, we receive an Apple user identifier and, if you allow it, your name and an email address (which may be a private relay address). We do not receive your Apple password.
Bank and card data (via Open Banking)
If you connect a bank, our Open Banking provider (TrueLayer) shares, with your consent, your account details, balances, card details, transactions, direct debits and standing orders. This is read-only data. Gibbon cannot initiate payments or move money.
Email data (optional)
If you choose to connect an email account (Gmail or another inbox via app password), Gibbon reads messages only to detect subscription receipts, price changes and cancellations. We look for purchase and billing emails. We do not read unrelated messages for any other purpose, and you can disconnect email at any time.
Usage and device data
To run the app and send alerts we process a device push token, basic device information, and in-app settings you choose (budgets, goals, categories, preferences).
3. How we use your data
- To show your balances, transactions, net worth, budgets, goals and subscriptions.
- To categorise and score transactions and calculate what is safe to spend.
- To detect recurring charges, price rises and likely-cancelled subscriptions.
- To check which payments are subscriptions. If you are signed in, Gibbon sends the payee name, dates and amounts of payments that could be subscriptions (for example a streaming service, or the same price charged more than once) to an automated language model run by Cloudflare Workers AI on our behalf. Card, account and reference numbers, email addresses, postcodes and payments that look like they are to a person are removed or not sent. The answer is kept on your device; it is not stored on our servers and is not used for advertising.
- To send the notifications you turn on (for example low balance or a large purchase), including when the app is closed.
- To operate, secure and improve the app.
We do not sell your personal data. We do not use your bank or email data for advertising.
4. Legal basis for processing
- Consent for connecting your bank through Open Banking and for connecting email. You can withdraw consent at any time by disconnecting.
- Contract to provide the features you ask for.
- Legitimate interests to keep the app secure and working, balanced against your rights.
5. Open Banking
Bank connections are provided by TrueLayer, an account information service provider authorised and regulated by the Financial Conduct Authority. When you connect a bank you authorise access directly with your bank, and you can revoke that access at any time from within Gibbon or through your bank. Access is read-only. Gibbon is not a bank and does not provide regulated financial advice.
6. Email access and Google user data
Connecting an email account is entirely optional. It exists only to make subscription tracking more accurate: matching a bank payment to the receipt that names what you bought, spotting price changes, and noticing when a subscription has been cancelled. Gibbon works fully without it.
What we access
If you connect Gmail, Gibbon asks Google for read-only access to your mailbox (the gmail.readonly permission). Gibbon cannot send, delete, move or change any email, and cannot see your Google password. Gibbon only requests messages that look like purchases or subscription changes, using a search for things such as receipts, order confirmations, invoices and cancellation notices sent in the last 90 days. Other email is not requested.
How we use it
For each matching message, Gibbon reads the sender, subject, date and text, and extracts only these details: the merchant, the amount and currency, the item or plan, the order number, the purchase or cancellation date, and the date access ends. This extraction is automated, using a text model hosted by our infrastructure provider, Cloudflare. No person reads your email, and your email is never used to train any model.
The extracted details are used only inside Gibbon, to show you what each payment was for, to label subscriptions, and to tell you when a subscription has been cancelled or changed price.
What we store
- The extracted details listed above, plus the email subject, sender and the address it was found in, so you can see where a match came from (up to the 500 most recent items).
- A list of message IDs already processed, so the same email is not read twice.
- The access and refresh tokens Google issues when you connect, so Gibbon can check for new receipts in the background. These tokens are encrypted at rest (AES-256-GCM) and are deleted when you disconnect the account.
The full text of your email is not stored. It is processed in memory and discarded once the details are extracted.
Sharing and Limited Use
We do not sell Google user data, use it for advertising, or share it with anyone except Cloudflare, which hosts and runs Gibbon's servers on our behalf. We do not allow people to read your data, except with your explicit permission for a specific support request, where needed for security, or where the law requires it.
Gibbon's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting and deletion
You can disconnect any email account at any time in Gibbon (Profile, Email receipts, Remove). This deletes the stored Google tokens and the processed-message list for that account, and Gibbon stops all further access. You can also revoke Gibbon's access from your Google Account at myaccount.google.com/permissions. The extracted receipt details are deleted when you delete your Gibbon account, or on request by emailing us.
7. Where your data lives
Most of your financial data (transactions, budgets, goals, snapshots) is stored locally on your device. Authentication tokens are kept in the device secure store.
To send notifications while the app is closed, we store a limited set of data on our servers (hosted on Cloudflare): an encrypted Open Banking refresh token and minimal bookkeeping needed to avoid duplicate alerts. Refresh tokens are encrypted at rest. Server data is processed in line with this policy.
8. Who we share data with
We use a small number of trusted service providers (sub-processors) strictly to run the app:
- TrueLayer - Open Banking connectivity.
- Apple - Sign in with Apple and push notification delivery.
- Google or your email provider - only if you connect email.
- Cloudflare - backend hosting, storage for alerts, and the automated subscription check (Workers AI).
We share data with these providers only as needed to deliver the features above. We do not sell or rent your data to anyone.
9. Data retention
On-device data stays until you delete it or remove the app. Server-side data (such as your encrypted refresh token) is kept while your connection is active and is deleted when you disconnect the bank, delete your account, or after a period of inactivity. When you delete your account we remove the data we hold on our servers.
10. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, and port your data, and to withdraw consent. In Gibbon you can:
- Disconnect any bank or email connection at any time.
- Delete your account and associated data from the app settings.
- Contact us to exercise any other right.
You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
11. Security
We use device secure storage, encryption of sensitive tokens at rest, and transport encryption. No system is perfectly secure, but we take reasonable steps to protect your information and limit what we store.
Children
Gibbon is not intended for anyone under 18 and we do not knowingly collect data from children.
Changes to this policy
We may update this policy. Material changes will be reflected by the date above and, where appropriate, surfaced in the app.
12. Contact
Questions or requests, including deleting your data: support@gibbon-app.download.