Ulsa Join waitlist

Privacy Policy - ulsa.co.uk/privacy - Last updated 7 September 2026

Privacy Policy

Last updated: 7 September 2026

1. Who we are

Last updated: 7 September 2026.

Version 1.2 corrects recipient and international-transfer disclosures. Ask Ulsa's external search capability, through which DuckDuckGo could receive assistant search queries, was removed on 5 September 2026. DuckDuckGo is a historical recipient, not a current recipient; removal does not establish whether a particular historical search occurred.

Ulsa is operated by JEMA Software Ltd, a company registered in England and Wales with company number 17136868. Its registered office is 124 City Road, London, EC1V 2NX. Our website is ulsa.co.uk and you can contact us at james@ulsa.co.uk.

Ulsa helps users organise financial records, connect bank transactions, upload receipts, ask budgeting questions, generate summaries, and receive spending insights. JEMA Software Ltd is the data controller for personal data processed through Ulsa unless this policy says otherwise.

2. What data we collect

We collect name and email address when you sign up or create an account.

We collect bank transaction data through Finexer Ltd, the FCA-authorised firm that provides Ulsa's open banking connectivity, when you choose to connect an account. This can include account information, balances, transaction descriptions, dates, amounts, and merchant information. We do not receive or store your bank login details.

We collect receipt images and documents that you upload so Ulsa can read, categorise, and store them for your records.

We collect AI chat messages and related context you provide when you ask Ulsa questions or request help inside the app.

We collect device information and app usage data, such as device type, operating system, feature usage, diagnostics, and error information.

We collect payment and subscription information through Apple in-app purchases and RevenueCat. We do not store your card details.

We collect profile data you provide during onboarding, including employment type, income bracket, job title, date of birth, budgeting preferences, and similar profile information.

If you accept optional cookies, Microsoft Clarity and the TikTok Pixel collect website interaction, browser, and device data. When a consented visitor submits a waitlist form, the TikTok Events API receives a hashed version of the signup email together with the page URL, browser user agent, and IP address for campaign measurement.

When your browser requests an image hosted by images.higgs.ai, that image delivery service receives request data including your IP address and browser information.

App update requests to Expo and exchange-rate requests to ExchangeRate-API disclose device and network request metadata, not your bank records. The website image is delivered through images.higgs.ai with an AWS CloudFront origin.

3. How we use your data

We use your data only where needed to provide, secure, maintain, and improve Ulsa. We do not sell your data to third parties. If you accept optional cookies, TikTok processes website interaction data and a hashed waitlist signup email for advertising campaign measurement and attribution.

  • Account and profile data is used to create your account, manage access, personalise onboarding, and provide the Ulsa service.

    Legal basis: Contract.

  • Bank transaction data is used to import records, categorise transactions, highlight subscriptions, and identify budget categories.

    Legal basis: Consent.

  • AI chat messages are used to answer your budgeting questions, provide guidance, and keep the context needed for the Ulsa service.

    Legal basis: Contract.

  • Receipt images and documents are used to read, categorise, store, and generate records you request from Ulsa.

    Legal basis: Contract.

  • Device and usage data is used to maintain, secure, test, debug, and improve the service.

    Legal basis: Legitimate interests.

  • Consented website interaction data is used through Microsoft Clarity for session recording and analytics, and through TikTok for advertising campaign measurement and attribution.

    Legal basis: Consent.

  • Payment data is used to process subscriptions, payment status, receipts, fraud prevention, and billing support.

    Legal basis: Contract.

4. Who we share data with

The recipients below support the app and website, including requested features, subscriptions, diagnostics, communications and consented website measurement. This is a recipient list, not a statement that every recipient is our processor: roles depend on the service and applicable arrangements. Finexer and our open banking agent relationship are described separately in section 4A.

Supabase: Hosts account, profile and financial records, authentication, uploaded files and server functions.

OpenAI: Processes AI questions and their financial context, receipt or document content submitted for analysis, and transaction descriptions and amounts for category suggestions where you opt in.

RevenueCat: Processes app-user identifiers, purchase receipts, subscription status and entitlements to manage mobile subscriptions.

Apple: Provides Sign in with Apple, App Store distribution, in-app purchases and subscription events under its own platform arrangements.

Sentry: Processes error events, diagnostic context and app/device information for fault monitoring.

Resend: Processes email addresses, message content and delivery information for service and separately consented marketing emails.

Formspree: Processes contact, partner, newsletter and complaint form submissions and associated request information.

Microsoft Clarity: Processes website interaction and browser/device information for session recording and analytics after optional-cookie consent. Microsoft describes Clarity as acting as a controller.

TikTok: Processes consented website events, browser/device information and hashed waitlist email addresses for advertising measurement and attribution.

Vercel: Hosts the website and processes web requests and aggregated, cookie-free Web Analytics.

images.higgs.ai: Delivers a website image; receives visitor IP addresses and browser request information. This image path does not send connected bank records.

Amazon Web Services (AWS CloudFront): Provides the origin CDN behind the images.higgs.ai website image. It receives the onward image request; whether the image service forwards visitor IP addresses or other browser metadata has not been verified.

Expo (650 Industries, Inc.): Delivers over-the-air app updates and processes update/device metadata, such as platform, runtime version, download identifiers and IP address. Ulsa does not send bank records through its update requests.

ExchangeRate-API (exchangerate-api.com): Receives a fixed GBP exchange-rate request from the app and associated device-network metadata, including IP address. No balances, transaction amounts or account identifiers are included; currency calculations run on your device.

Merchant logos may also be requested from image hosts specified in transaction data. These hosts receive image-request and network metadata. Their identities vary with the supplied logo URLs and the complete host inventory remains to be verified. A logo URL may reveal the associated merchant.

4A. Open banking and Finexer

Finexer Ltd is the FCA-authorised firm supplying the open banking connectivity used to link supported bank accounts. JEMA Software Ltd operates as Finexer's registered Account Information Services agent (JEMA FRN 1061485; Finexer FRN 925695) under the Payment Services Regulations 2017.

Finexer processes the information needed for bank consent and connectivity, including connected-account and transaction information. Our regulatory agent relationship does not by itself determine either organisation's UK GDPR role. Finexer has not yet confirmed that role, so this policy does not designate it as our processor, joint controller or independent controller.

Finexer's processing locations, onward recipients and applicable UK transfer arrangements remain subject to confirmation. Its UK establishment and FCA authorisation do not establish where all processing takes place.

5. International data transfers

The recipient-specific locations and transfer information below distinguish evidenced provider terms from arrangements that still require confirmation. We do not assert a safeguard where we have not evidenced one. CDN delivery can use edge locations worldwide, not just the country where a provider is established.

The EU-US Data Privacy Framework alone does not cover UK transfers. The UK-US data bridge applies only to covered transfers to an eligible US entity participating in the UK Extension. Where contractual safeguards are used for UK restricted transfers, EU SCCs need the applicable UK Addendum or another valid UK mechanism.

Dynamic merchant-logo hosts: processing locations, retention and applicable UK transfer safeguards vary by the supplied host and are being confirmed. No complete host or transfer inventory has been verified.

To request information about an applicable transfer safeguard or a copy where available, contact james@ulsa.co.uk.

Published provider terms do not by themselves verify which agreement, region and onward-transfer arrangements apply to Ulsa. Items marked as requiring confirmation remain outstanding. Finexer is addressed separately in section 4A.

  • Supabase - Cached production database connection metadata points to Ireland. The current database region and onward support/processing locations require confirmation; this is not an EU-only commitment for every Supabase service.

    UK transfer information: Supabase publishes a DPA incorporating SCCs and the UK Addendum. The applicable agreement and project-specific transfer arrangements require confirmation.

  • OpenAI - International processing; no UK-only or EEA-only API residency configuration has been verified for Ulsa.

    UK transfer information: OpenAI's published DPA identifies OpenAI OpCo, LLC for UK data and incorporates SCCs with the UK Addendum. Our applicable agreement and onward processing locations require confirmation.

  • RevenueCat - United States; its privacy policy also allows processing where its service providers operate.

    UK transfer information: RevenueCat's published DPA incorporates SCCs with the UK Transfer Addendum. The applicable account agreement and onward transfers require confirmation.

  • Apple - Apple identifies Apple Distribution International Limited in Ireland for UK users; its policy describes storage by Apple Inc. in the United States and international processing.

    UK transfer information: UK transfers to Ireland fall within UK adequacy regulations for the EEA. Apple's policy cites SCCs for onward transfers. We have not verified Apple certification under the UK Extension to the EU-US DPF; the mechanism for any direct UK-to-US transfer and the applicable service arrangements still require confirmation.

  • Sentry - Sentry offers US and Frankfurt event-data regions, with some metadata processed in the US. Ulsa's selected project region requires confirmation.

    UK transfer information: Functional Software, Inc. (Sentry) publishes DPA provisions for the UK Extension and fallback SCCs with the UK Addendum. Our DPA acceptance and the applicable certification/transfer scope require confirmation.

  • Resend - United States; an EU email-sending region is not an EU-only data-residency commitment.

    UK transfer information: The published DPA of Plus Five Five, Inc. (Resend) includes SCCs with the UK Addendum. The applicable account agreement and onward transfers require confirmation.

  • Formspree - United States; onward processing locations require confirmation.

    UK transfer information: Formspree states reliance on SCCs as processor. A UK Addendum, IDTA or other UK-specific safeguard and our applicable agreement have not been evidenced.

  • Microsoft Clarity - Microsoft Azure infrastructure; Microsoft describes international processing including the United States. No UK-only or EEA-only Clarity region is asserted.

    UK transfer information: For covered UK-to-US transfers, Microsoft Corporation is certified under the UK Extension to the EU-US Data Privacy Framework (the UK-US data bridge). The official register showed active status, with re-certification under review, on 2026-09-07.

  • TikTok - The locations applicable to Ulsa's Business Tools processing require confirmation; consumer-app residency statements are not treated as evidence for this integration.

    UK transfer information: The applicable UK Business Tools transfer terms and contracting entity require confirmation.

  • Vercel - Website delivery uses edge locations worldwide. Vercel's DPA describes primary US facilities and international processing; our specific log and analytics regions require confirmation.

    UK transfer information: Vercel publishes UK Extension participation and a DPA with SCCs and a UK Addendum for eligible plans. Our applicable plan, agreement and certification/transfer scope require confirmation.

  • images.higgs.ai - Image delivery may traverse edge locations worldwide. The service operator, processing and log-storage locations have not been verified.

    UK transfer information: A UK transfer safeguard and the operator's contractual/sub-processor arrangements have not been evidenced.

  • Amazon Web Services (AWS CloudFront) - CDN edge locations worldwide; the origin and logging regions for this image distribution have not been verified.

    UK transfer information: AWS publishes a DPA and UK Addendum in its service terms, but the image provider's applicable AWS contract and onward-transfer safeguard have not been evidenced. AWS is part of that delivery chain, not a separately appointed JEMA processor.

  • Expo (650 Industries, Inc.) - United States and update delivery infrastructure; CDN edge locations worldwide. Specific onward infrastructure and logging locations require confirmation.

    UK transfer information: Expo's privacy policy states certification under the UK Extension to the EU-US Data Privacy Framework. Certification scope and onward-transfer arrangements must be retained with the applicable account documentation.

  • ExchangeRate-API (exchangerate-api.com) - AYR Tech (Pty) Ltd, South Africa. Its policy lists servers in Ireland, South Africa and Germany; the serving location of an individual request is not established.

    UK transfer information: A UK-specific safeguard for transfers to South Africa and other non-adequate onward destinations has not been evidenced. The provider's general acceptance-of-terms wording is not treated as that safeguard.

6. Data retention

We keep account data while your account is active so we can provide the Ulsa service.

If you delete your account, we delete or anonymise your personal data within 30 days unless we are required to keep limited records for legal, fraud prevention, dispute, or security reasons.

Bank transaction data is not stored beyond what is needed to provide the service, maintain your records, generate spending insights, and support features you use.

Receipt images, AI chat history, profile data, and documents are kept while your account is active unless you delete them or delete your account.

7. Your rights under UK GDPR

Under UK GDPR, you have the right to access your data, correct inaccurate data, delete your data, receive data portability, object to processing, restrict processing in certain circumstances, and withdraw consent where processing is based on consent.

In-app account deletion is available from the app settings. You can also request deletion by contacting us.

To exercise your rights, contact james@ulsa.co.uk. We may need to verify your identity before responding. We aim to respond within one month unless the request is complex or we are legally allowed more time.

You have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk. Our ICO registration reference is C1952072.

8. Cookies

We use essential cookies and similar technologies needed for site operation, security, sign-in, and session management. After you accept optional cookies, we also use Microsoft Clarity analytics and TikTok advertising technologies. Vercel Web Analytics collects aggregated page-view data without third-party cookies.

For more information, see our full Cookie Policy .

9. Security

We use technical and organisational measures designed to protect your data. Data is encrypted at rest using AES-256 where supported by our infrastructure providers.

Data is encrypted in transit using TLS 1.3 where supported by the client, server, and provider connection.

We use row level security on user data so users can access only their own records.

We perform regular security reviews and monitor errors and suspicious behaviour to improve the security and reliability of Ulsa.

10. Changes to this policy

We may update this privacy policy from time to time. If we make material changes, we will notify users by email or in-app notification.

The latest version will always be available on ulsa.co.uk.

11. Contact us

Contact: james@ulsa.co.uk.

Company: JEMA Software Ltd.

Company number: 17136868.

Registered office: 124 City Road, London, EC1V 2NX.

Website: ulsa.co.uk.

App: Ulsa.

Version 1.2 - Last updated 7 September 2026