Legal
privacy policy.
Last updated: 2 July 2026 · Effective immediately
Caveat: This Privacy Policy is provided for informational purposes and represents our current practices. It does not constitute legal advice. If you have specific legal questions about data protection in your jurisdiction, consult a qualified legal professional. Uburu makes reasonable efforts to comply with applicable data protection laws globally, but laws change — this policy may not capture every local requirement. Last reviewed by legal counsel: April 2026.
🔒 End-to-end encrypted
TLS 1.3 in transit · AES-256 at rest
🚫 Never sold
Your data is never sold to advertisers
🇪🇺 EU hosting
SOC 2 Type II in progress · EU infrastructure
🗑️ 30-day deletion
Full purge within 30 days of account removal
General Policy
1. Information We Collect
We collect: (a) information you provide directly — name, email address, account credentials, and profile data entered during onboarding; (b) financial data you upload — bank statement files and the transaction data parsed from them, savings goals, and AI chat history; (c) technical information — IP address, browser type, device identifiers, session tokens, and usage logs; and (d) with your consent, anonymous product-analytics events — which features you use and how you move through the app, described in Section 5. We never collect or store your online banking passwords or login credentials.
2. How We Use Your Information
We use your information to: (a) provide, maintain, and improve the Service; (b) generate AI-powered spending insights and categorise your transactions; (c) send transactional emails — welcome messages, monthly digests, account alerts; (d) respond to your support inquiries; (e) detect and prevent fraud, abuse, and security incidents; and (f) comply with legal and regulatory obligations. We do not use your financial data to train our AI models without your explicit, affirmative consent.
3. Data Storage and Security
Your data is stored on infrastructure hosted in the European Union; we are working toward SOC 2 Type II certification (audit in progress). All data in transit is encrypted using TLS 1.3. All data at rest is encrypted using AES-256. Bank statement data is isolated per user with row-level security. We conduct regular security audits and penetration tests. Access to production data is restricted to authorised personnel on a strict need-to-know basis.
4. Data Sharing
We do not sell, rent, or trade your personal or financial data to third parties for marketing purposes. We may share data with: (a) service providers acting as data processors on our behalf — cloud hosting, email delivery, payment processing, and consent-based product analytics (Mixpanel, EU-hosted) — under strict data processing agreements and confidentiality obligations; (b) law enforcement or regulatory authorities when required by a valid legal order; (c) a successor entity in the event of a merger, acquisition, or asset sale, with at least 30 days' advance notice to users and the opportunity to export or delete data.
5. Cookies, Analytics & Tracking
We use essential cookies to maintain your login session and security state. With your explicit consent, we use a privacy-minimal product-analytics service (Mixpanel, hosted in the European Union) to understand which features are used and how people move through the app, so we can improve it. This is OFF by default — nothing is sent until you choose "Allow" on our in-app consent prompt, and you can withdraw consent at any time (we also honour your browser's Do-Not-Track setting). We capture only anonymous, aggregate usage events tied to a pseudonymous identifier — never your financial amounts or balances, never your statement contents or the transactions parsed from them, never merchant names, and never who you are paired with. IP addresses are not stored with these events. We do not use third-party advertising, retargeting, or behavioural ad-tracking cookies, and we never sell this data. You can manage these preferences at any time from the in-app prompt or your browser settings.
6. Data Retention
We retain your account and transaction data for as long as your account is active. Upon account deletion, all data is permanently purged within 30 days. Uploaded bank statement files are retained for 12 months to support re-analysis and are then automatically deleted, unless you request earlier removal. You may request immediate deletion of any specific data by emailing privacy@uburu.io.
7. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a minor has provided personal information, we will delete it promptly. If you believe a child has created an account, contact privacy@uburu.io.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting a prominent notice in the application at least 14 days before changes take effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after that date constitutes acceptance of the updated policy.
9. Contact and Data Controller
Uburu Technologies Ltd is the data controller for the purposes of GDPR and applicable data protection laws. For privacy questions, data subject requests, or to reach our Data Protection Officer: privacy@uburu.io — Uburu Technologies Ltd, 123 Finance Street, London, EC1A 1BB, United Kingdom.
Jurisdiction-Specific Rights
🇪🇺 European Union & EEA — GDPR
If you are located in the European Union, European Economic Area, or United Kingdom, the General Data Protection Regulation (GDPR) and UK GDPR apply to your data. Your rights include: (a) Right of access — request a copy of all personal data we hold about you; (b) Right to rectification — correct inaccurate or incomplete data; (c) Right to erasure ("right to be forgotten") — request deletion of your personal data where there is no compelling reason for continued processing; (d) Right to restriction — ask us to limit how we use your data; (e) Right to data portability — receive your data in a structured, machine-readable format; (f) Right to object — object to processing based on legitimate interests or for direct marketing; (g) Right not to be subject to automated decision-making with legal or similarly significant effects. To exercise any of these rights, email privacy@uburu.io. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority — in the UK, this is the ICO (ico.org.uk); in Ireland, the DPC (dataprotection.ie); in Germany, the relevant Landesdatenschutzbehörde.
🇺🇸 United States — CCPA / State Privacy Laws
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA grants you the following rights: (a) Right to know — request disclosure of the categories and specific pieces of personal information we collect, use, disclose, and sell; (b) Right to delete — request deletion of personal information we have collected from you, subject to certain exceptions; (c) Right to correct — request correction of inaccurate personal information; (d) Right to opt-out of sale — we do not sell personal information, but you may formally opt out at any time; (e) Right to non-discrimination — we will not discriminate against you for exercising your CCPA rights. We do not sell personal information as defined under the CCPA. Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other state privacy laws grant similar rights. To submit a request, email privacy@uburu.io with "Privacy Rights Request" in the subject line.
🇳🇬 Nigeria — NDPR
If you are located in Nigeria, the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023 apply to your data. As a data subject, you have the right to: (a) access your personal data held by Uburu; (b) rectify inaccurate or outdated personal data; (c) object to the processing of your personal data; (d) request deletion of your personal data; and (e) lodge a complaint with the Nigeria Data Protection Commission (NDPC). Uburu processes Nigerian users' data in compliance with NDPR lawful bases, including consent and legitimate interests. To exercise your rights, email privacy@uburu.io.
🇿🇦 South Africa — POPIA
If you are located in South Africa, the Protection of Personal Information Act (POPIA) 2013 applies. Your rights under POPIA include: (a) the right to be notified that your personal information is being collected; (b) access to your personal information; (c) the right to request correction or deletion of your personal information; (d) the right to object to processing of your personal information; and (e) the right to lodge a complaint with the Information Regulator (inforeg.org.za). Uburu's Information Officer can be contacted at privacy@uburu.io. We process South African users' data on lawful bases including consent and legitimate purpose.
🇧🇷 Brazil — LGPD
If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD) — Law No. 13.709/2018 — applies to your data. Your rights under the LGPD include: (a) confirmation of the existence of processing; (b) access to your data; (c) correction of incomplete, inaccurate, or outdated data; (d) anonymisation, blocking, or deletion of unnecessary or excessive data; (e) portability of data to another service provider; (f) deletion of personal data processed with your consent; (g) information about data sharing; (h) the right to revoke consent at any time; and (i) the right to lodge a complaint with the ANPD (gov.br/anpd). To exercise these rights, email privacy@uburu.io.
🇨🇦 Canada — PIPEDA / Quebec Law 25
If you are located in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Law 25 (Act 64) apply to your data. Your rights include: (a) access to your personal information; (b) correction of inaccurate personal information; (c) withdrawal of consent at any time, subject to legal or contractual obligations; and (d) the right to complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca). Quebec residents have additional rights under Law 25, including the right to data portability and the right to de-indexation. To exercise your rights, email privacy@uburu.io.
🇸🇬 Singapore — PDPA
If you are located in Singapore, the Personal Data Protection Act (PDPA) 2012 applies. Your rights under the PDPA include: (a) the right to access your personal data held by Uburu; (b) the right to correct errors in your personal data; (c) the right to withdraw consent, with reasonable notice; and (d) the right to data portability (for selected categories of data). You may also lodge a complaint with the Personal Data Protection Commission (pdpc.gov.sg). Uburu does not transfer your personal data outside Singapore without adequate protections as required by the PDPA. To exercise your rights, email privacy@uburu.io.
🇰🇪 Kenya — Data Protection Act
If you are located in Kenya, the Data Protection Act 2019 applies. Your rights under the Act include: (a) access to your personal data; (b) rectification of inaccurate, misleading, or incomplete personal data; (c) erasure of personal data that is no longer necessary or was unlawfully processed; (d) restriction of processing; (e) data portability; and (f) the right to object to processing. You may also lodge a complaint with the Office of the Data Protection Commissioner (odpc.go.ke). To exercise your rights, email privacy@uburu.io.
Privacy questions? Email our Data Protection Officer at privacy@uburu.io. We respond to data subject requests within 30 days.