Secure bank connectivity via FCA-authorised TrueLayerRead-only access256-bit encryptionNo passwords stored

Security & Privacy

Built so we can't hurt you, even if we wanted to.

SubCut is designed around a single principle: we should be able to find money leaks in your account without ever being able to move money out of it. Here's exactly how that works.

Connectivity

How we connect to your bank

We connect to UK bank accounts through TrueLayer, the UK's leading open banking provider. TrueLayer is authorised and regulated by the Financial Conduct Authority (FRN: 793171) as an Authorised Payment Institution.

You authenticate directly with your bank using their official app or login page. SubCut never sees, handles, or stores your bank credentials.

Your bank issues TrueLayer a short-lived, read-only access token. We use that token to fetch transaction history — nothing more.

Permissions

What we can and cannot do

What we can do

  • · Read your transaction history
  • · Detect recurring charges and patterns
  • · Surface duplicates and price increases
  • · Show upcoming renewals

What we cannot do

  • · Move, transfer, or withdraw money
  • · Make payments on your behalf
  • · Cancel subscriptions automatically
  • · See or store your bank password

Cancellation is always a manual step. SubCut walks you through it — you confirm it with the merchant directly.

Your data

How your data is handled

CSV uploads are processed entirely in your browser. The file never leaves your device and is never uploaded to our servers.

Open banking data is held in an encrypted, short-lived session cookie scoped to your browser. We do not persist raw transaction data on our servers beyond what's required to show you the dashboard during your session.

We do not sell, share, or rent your data to third parties. Ever.

Encryption

Encryption in transit and at rest

  • TLS 1.3 on every connection between your browser, SubCut, and TrueLayer.
  • 256-bit AES encryption for any data we cache at the edge.
  • ISO 27001 aligned infrastructure practices.
  • Bank credentials never touch SubCut servers — they're entered directly into your bank's authentication flow.

Your rights

GDPR and your data rights

Under UK GDPR you have the right to access, correct, export, and delete the data we hold about you at any time.

You can disconnect your bank in a single click from the dashboard — that immediately revokes the access token and clears the session.

To delete your account and any associated data, email privacy@subcut.app. We respond within 7 days.