Secure bank connectivity via FCA-authorised TrueLayerRead-only access256-bit encryptionNo passwords stored
Security & Privacy
Built so we can't hurt you, even if we wanted to.
SubCut is designed around a single principle: we should be able to find money leaks in your account without ever being able to move money out of it. Here's exactly how that works.
Connectivity
How we connect to your bank
We connect to UK bank accounts through TrueLayer, the UK's leading open banking provider. TrueLayer is authorised and regulated by the Financial Conduct Authority (FRN: 793171) as an Authorised Payment Institution.
You authenticate directly with your bank using their official app or login page. SubCut never sees, handles, or stores your bank credentials.
Your bank issues TrueLayer a short-lived, read-only access token. We use that token to fetch transaction history — nothing more.
Permissions
What we can and cannot do
What we can do
- · Read your transaction history
- · Detect recurring charges and patterns
- · Surface duplicates and price increases
- · Show upcoming renewals
What we cannot do
- · Move, transfer, or withdraw money
- · Make payments on your behalf
- · Cancel subscriptions automatically
- · See or store your bank password
Cancellation is always a manual step. SubCut walks you through it — you confirm it with the merchant directly.
Your data
How your data is handled
CSV uploads are processed entirely in your browser. The file never leaves your device and is never uploaded to our servers.
Open banking data is held in an encrypted, short-lived session cookie scoped to your browser. We do not persist raw transaction data on our servers beyond what's required to show you the dashboard during your session.
We do not sell, share, or rent your data to third parties. Ever.
Encryption
Encryption in transit and at rest
- TLS 1.3 on every connection between your browser, SubCut, and TrueLayer.
- 256-bit AES encryption for any data we cache at the edge.
- ISO 27001 aligned infrastructure practices.
- Bank credentials never touch SubCut servers — they're entered directly into your bank's authentication flow.
Your rights
GDPR and your data rights
Under UK GDPR you have the right to access, correct, export, and delete the data we hold about you at any time.
You can disconnect your bank in a single click from the dashboard — that immediately revokes the access token and clears the session.
To delete your account and any associated data, email privacy@subcut.app. We respond within 7 days.